Privacy policy
Last updated: August 18, 2026
afterflow provides alumni program software for behavioral health treatment centers and recovery programs. We take the sensitivity of recovery data seriously. This policy explains what we collect, how we use it, who we share it with, how long we keep it, and what happens if something goes wrong.
1. Who this policy covers
This policy covers visitors to use-afterflow.com, staff at treatment programs that use afterflow (our customers), and alumni whose information a program manages in afterflow. Programs are the data controllers for their alumni records; afterflow processes that data on the program's behalf and under its instructions.
2. What we collect
- Account data: name, work email, role, and authentication credentials for program staff.
- Alumni program data: records a program stores about its alumni, such as contact details, sobriety dates, milestone check-in responses, event RSVPs, referrals, and giving history. Programs control what they enter.
- Walkthrough and contact requests: name, email, phone, and program details you submit through our booking form.
- Usage and device data: log data, IP address (hashed where used for rate limiting), and basic analytics needed to run and secure the service.
3. How we use data
- Operating the alumni workspace: check-ins, milestones, events, and reporting.
- Sending milestone and check-in messages a program schedules to its alumni.
- Securing the service: authentication, role-based access, abuse prevention.
- Responding to sales and support requests.
- Improving the product using aggregated, de-identified usage patterns.
We do not sell personal information, and we do not use alumni recovery data for advertising.
4. HIPAA posture
afterflow is alumni engagement software, not an electronic medical record. Depending on how a program uses it, alumni records may include information that qualifies as protected health information (PHI) under HIPAA. We operate the service with a HIPAA-adjacent security posture: encryption in transit and at rest, role-based access controls, workspace isolation with row-level security, audit trails on sensitive actions, and least-privilege access for our own team.
If your program is a covered entity and intends to store PHI in afterflow, contact us at contact@use-afterflow.com before onboarding so we can discuss the agreements your program needs, including whether a Business Associate Agreement is appropriate for your deployment.
5. Subprocessors
We use a small set of vendors to run afterflow. Each processes data only as needed to provide its function:
- Lovable Cloud - application hosting, deployment, and transactional email delivery.
- Supabase - database, authentication, and file storage.
- Stripe - payment processing for subscriptions, event tickets, giving, and merch. Card details never touch our servers.
- OpenAI - optional message polish. When a program enables it, suggested outreach copy (risk band and signal labels, not full check-in answers) may be sent to OpenAI to shorten wording. Risk scores themselves are computed in afterflow and do not require OpenAI. It is not used to train third-party models.
- Google - optional "Sign in with Google" authentication.
- Apple - optional "Sign in with Apple" authentication.
We will update this list before adding a new subprocessor that handles customer data.
6. Data retention
Alumni program data is retained for as long as the program's subscription is active. When a subscription ends, the program may request an export of its data; we delete customer data from production systems within 60 days of account closure and from encrypted backups within 90 days. Booking-form leads that do not become customers are deleted within 12 months. Security logs are kept up to 12 months.
7. Breach notification
If we confirm a breach of security affecting personal information, we will notify affected customer programs without undue delay and no later than 72 hours after confirmation, with what we know about the scope, the data involved, and the steps we are taking. We will cooperate with affected programs on any notification obligations they have to individuals or regulators, and we will publish a post-incident summary when remediation is complete.
8. Your choices and rights
Alumni can ask their program to correct or delete their record at any time. Alumni messages afterflow sends on a program's behalf include an unsubscribe link; using it stops further afterflow email to that address. Program staff can also mark a member do not contact. Program staff can manage their account data in the app. Depending on where you live, you may have additional rights (access, deletion, portability) - contact us and we will honor them or route the request to the responsible program.
9. Contact
Questions about this policy or our data practices: contact@use-afterflow.com. See also our terms of service.
