Your privacy is our priority. We ensure your data stays secure and protected.
Effective Date: July 26th, 2026
Last Updated: July 26th, 2026
You Are Accountable, Inc. (“Accountable,” “we,” “us,” or “our”) provides a recovery-accountability platform that includes coaching, check-ins, identity verification, and drug testing and monitoring services. We care deeply about the privacy of the people who use our services, and we understand that the information we handle is often sensitive. This Privacy Policy explains what personal information we collect, how we use and share it, how we protect it, and the choices and rights you have.
CONSENT
BY ACCESSING OR USING THE SERVICES, WEBSITE, MOBILE APP OR WEB APP, YOU AGREE THAT YOU HAVE READ, UNDERSTAND THIS PRIVACY POLICY, AND CONSENT TO THE COLLECTION AND USE OF INFORMATION IN ACCORDANCE WITH THIS PRIVACY POLICY. BY USING OUR SERVICES YOU AGREE TO THE TERMS AND CONDITIONS OUTLINED IN THIS PRIVACY POLICY. YOUR CONTINUED USE OF OUR SERVICES CONSTITUTES IMPLICIT CONSENT TO THE COLLECTION, PROCESSING, AND SHARING OF YOUR PERSONAL DATA AS DESCRIBED HEREIN. IF YOU DO NOT AGREE WITH THIS PRIVACY POLICY, DO NOT ACCESS OR USE THE SERVICES OR SITES.
This Privacy Policy is incorporated into and made a part of our Terms of Use and any other agreement that references this Privacy Policy or that governs access to or use of our Services.
1. Scope
This Privacy Policy applies to our website at https://www.youareaccountable.com, our mobile application and web application, and the related services we provide (collectively, the “Services”). It does not govern the separate contractual terms between Accountable and the treatment programs, providers, or payers we work with — those are addressed in our Terms of Service and applicable business agreements.
A note on how we operate. The Services combine a technology platform with recovery support services. Accountable operates the platform, technology, monitoring tools, and administrative services. Accountable’s platform supports both non-clinical peer counseling and physician-led services.
Peer counseling provided by Accountable is non-clinical peer support delivered by trained peer recovery specialists employed by You Are Accountable, Inc. Peer recovery coaching is not therapy, medical care, or a substitute for treatment by licensed professionals, and it does not diagnose, treat, cure, or prevent any disease or disorder.
Alternatively, when Services are provided through Accountable’s third- party medical service provider network, a physician will monitor and evaluate the recovery coaching services you receive. Where professional physician or clinical services are provided — including services billed to Medicare or a health insurance plan — they are provided by the following third-party medical service providers: You Are Accountable Medical PA, You Are Accountable Medical NY PC, You Are Accountable Medical NJ PC, and You Are Accountable Medical TX PA and other associated provider groups.
When Accountable provides services on behalf of a healthcare provider, treatment program, or payer (a “Partner”), we may handle certain health information as a “business associate” under HIPAA. See Section 11 (Health Information and HIPAA) below.
2. Information We Collect
We collect information about you when you use our Services, including personal and non-personal information. “Personal information” is any information that may identify, relate to, describe, or be capable of being associated with or reasonably linked, directly or indirectly, with a particular identified or identifiable person or household.
Information you provide to us including:
Account and profile information — such as your name, email address, mobile phone number, mailing address, date of birth, and login credentials.
Identity verification information — a selfie image and test-submission videos that may include your face, which you provide to verify your identity and submit test evidence. To verify identity, submissions are compared against your enrolled reference photo; depending on the type of submission, face-geometry data is generated momentarily to perform the comparison or a face template is created and retained (see Section 3).
Drug testing and monitoring information — test submissions, results, scheduling information, and related notes used to support testing, screening, breathalyzer/alcohol monitoring, and compliance review.
Session audio and documentation notes — during coaching or care sessions, we use voice transcription and AI-assisted note-taking to create written documentation records. We do not retain the audio recording of the session. A transcript is generated in real time and retained for up to 24 hours to support note generation, after which it is automatically deleted; we retain only the final written notes, which are reviewed and, where necessary, edited by your coach. (See Section 4 for details on our use of AI.)
Communications — messages you exchange with your coach or care team, and feedback, support requests, or other communications you send us.
Insurance and benefits information — if your Services are billed to Medicare or a health plan, we collect insurance and eligibility information such as your insurer or plan name, member/subscriber ID, group number, Medicare Beneficiary Identifier (MBI), and claims and reimbursement information. We use this to verify coverage and obtain payment for your Services.
Payment information — if you pay for a subscription directly, billing details are collected and stored by our third-party payment processor, Stripe. We do not store or collect your full payment card details.
Employment Information – if you apply for a job with us, we collect the information you provide in your application for potential employment.
Employee Information – if you are employed by us, we collect employee information for various employment-related purposes and background checks, including your employee identification number, identifiers and address details, contact information, employment details, job location, financial or payroll-related information, other potentially sensitive personal information (including national or state identification numbers), and dependent information for the administration of certain employee benefits or programs. This information is used to conduct background checks and for other purposes in the ordinary course of employment (e.g., to facilitate onboarding, manage compensation, provide benefits, and review performance).
Information we may collect automatically: As you navigate and use the Website, Mobile App and Web App certain information can be passively collected—that is, gathered without the user actively providing the information or being concurrently made aware of the collection of information—using various technologies. We passively collect a variety of types of information in a variety of ways, including:
Device and usage information — such as IP address, device type and operating system, browser type and version, mobile device identifiers, app version, pages or screens viewed, time spent, and dates and times of access (“Usage Data”).
Approximate location information — we derive approximate (city-level) location from your IP address when you use the Services, for analytics and security purposes. We do not request location permissions from your device, and we do not collect your precise location.
Cookies and similar technologies — used on our public website for functionality, security, analytics, and measuring the effectiveness of our marketing. We do not use advertising pixels, marketing tags, or third-party advertising tracking within the logged-in application. Our cookies, tokens and similar technologies (collectively, “Tracking Technologies”) also are used for administering the website, including without limitation, for authentication, to remember users’ settings, to customize the content and layout of the website for users, to contact you about the services, and to improve our internal operations, the content of our website and our services. Users may be able to control the use of, or reject or disable, some Tracking Technologies at the individual browser level. If you reject or disable Tracking Technologies, you may still use our Website, but your ability to use some features or areas of our Website may be limited. We use Tracking Technologies to identify your device and keep track of your Internet session with our Website. Using these Tracking Technologies, we may automatically end your session on our Website after a period of inactivity (as determined by us in our sole discretion). We also use Tracking Technologies that allow us to recognize your device when you return to the Website within a certain period of time (as determined by us in our sole discretion) and automatically log you back into your account with us. UNLESS YOU AFFIRMATIVELY LOG OUT of your account PRIOR TO YOUR SESSION ENDING (whether by you or by us), YOU WILL BE AUTOMATICALLY LOGGED BACK IN THE NEXT TIME YOU OR ANY USER OF YOUR DEVICE VISITS OUR SITE within the period of time determined by us. If you do not wish to be automatically logged back in when you (or someone using your device) next initiate a session with our Website (using the same device that is being used for your current session), you should log out of your account (i) prior to ending your session, or (ii) if you will be inactive on our Website for more than a few minutes.
Web Logs. In conjunction with the gathering of data through cookies, Web servers may log records such as your device type, operating system type, device advertising identifier, browser type, domain, and other system settings, as well as the language your system uses and the country and time zone where your device is located. The Web server logs also may record the address of the Web page that referred you to our Website, the IP address (and associated city and state or province for the IP address) of the device you use to connect to the Internet, and data about your interaction with our Services, such as which pages you visit.
Pixels/Web Beacons. We may place tags on our web pages called “web beacons” (or “pixels”), which are files that link web pages to particular web servers and their cookies. We use pixels for security and fraud-prevention purposes. We also may include web beacons in e-mail messages to record whether an email has been opened or whether certain links in the email have been clicked. We do not use third-party pixels to serve retargeted advertising, and we do not permit pixel providers to use information collected on our Website for their own advertising purposes.
Website analytics and attribution data — on our public website, we use Google Analytics to understand how the site is used, and we measure how visitors arrive at our site (for example, from an advertisement). These measurement events are routed through a privacy-filtering platform (OursPrivacy) that removes health information and identifying details before data reaches third-party analytics or advertising platforms. For more information on how Google uses this data, visit Google’s Privacy Policy and Google’s page on How Google uses data when you use our partners’ sites or apps.
Application diagnostics and product analytics — within the application, we use Sentry for crash and error reporting and PostHog for product analytics (which features are used and how). This usage data is associated with your account. Our analytics provider derives approximate (city-level) location from your IP address at the time an event is received; the raw IP address itself is not retained in our analytics. Crash and error reports do include your IP address, which is retained by our crash-reporting provider under the contractual safeguards described below. It is designed to exclude the content of your health information — such as test results, session content, and messages — and these providers process it on our behalf under contractual safeguards, including Business Associate Agreements. Online Analytics. We may use third-party web analytics services on our Website, such as those of Google Analytics. These service providers use the sort of technology described in this “Information we may collect automatically” section to help us analyze how users use the Website, including by noting the third-party web site from which users arrive. The information (including your IP address) collected by the technology will be disclosed to or collected directly by these service providers, who use the information to evaluate your use of the Services. To prevent Google Analytics from using your information for analytics, you may install the Google Analytics Opt-out Browser Add-on by clicking here.
IP Addresses and Related Data. The servers used to operate and provide the Website may collect data pertaining to you and the equipment, software, and communication methods you use to access the Internet and the Services, including Internet protocol (“IP”) addresses assigned to the computers and other devices from where you access the Internet, your Internet service provider (ISP), device ID numbers and unique identifiers, your media access control (MAC) address, your operating system, your computer screen resolution, your web browser type, the pages you access on the website or apps, the websites you access before and after visiting the Services, the length of time you spend on the website or apps, date and time stamps, clickstream data, your approximate geographic location, performance statistics, and usage data. The Company may use this information to administer the website and its servers, to generate statistical information, to monitor and analyze website traffic and usage patterns, to monitor and help prevent fraud, to investigate complaints and violations of our policies, and to improve the website and Services.
We may combine this information with other collected information (including personal information) and information obtained from third parties for security reasons and to protect our rights or the rights of others. The suppliers that we use to provide the website may collect information about your visits to the website and other websites. Some of this information may be collected using cookies and similar tracking technologies as explained under “Tracking Technologies.”
Social Media. The website may allow you to connect to and share information with social media platforms and we may be required to implement cookies, plug-ins, and APIs provided by those social media platforms in order to facilitate those communications and features. We may share information that you provide us or that we may collect about your use of the website with those platforms and that information will be subject to their privacy policies. We encourage you to review the privacy policy of any social media platform that you use in connection with the website. In addition, by choosing to use any third-party social media platform or choosing to share content or communications with any social media platform, you allow us to share information with the designated social media platform. We cannot control any policies or terms of such third-party platform. As a result, we cannot be responsible for any use or disclosure of your information or content by third-party platforms, which you use at your own risk.
Information from third parties:
From your Partner — if you are enrolled through a treatment program, provider, or payer, that Partner may share enrollment, program, and compliance information with us.
From service providers — our laboratory partners return test results to us, and our identity-verification provider (Amazon Web Services, using its Rekognition service) returns identity-match results to us.
We do not knowingly collect more information than is needed to provide the Services. We do not consider personal information to include information that can no longer be used to identify a specific natural person, whether in combination with other information or otherwise such as, for example, de-identified or aggregated consumer information.
Information from other sources:
We may receive personal data about you from other sources to supplement data already collected. This may include publicly available data or data provided by third parties. We may combine this data with the data we already have. We will handle this data in accordance with this Privacy Policy and the purposes outlined when the data was collected. We will notify you if there are any material changes to the way we intend to use this data. Please note that we are not responsible for the accuracy of the data provided by third parties or any consequences arising from the use of such data.
3. Face Data (Photos, Biometric Data and Videos for Identity Verification)
Because face-related data is especially sensitive, we describe our practices for it in detail here.
What we collect. When you choose to verify your identity or submit test evidence, we collect a selfie image and test-submission videos, which may include your face. We store your enrolled reference photo, and identity verification is performed by our identity-verification provider (Amazon Web Services Rekognition) in one of two ways, depending on the type of submission:
Breathalyzer (alcohol monitoring) submissions: face-geometry data is generated momentarily to compare your submission against your enrolled reference photo and is not stored or retained by us or our provider after the comparison is complete. The image captured with each breathalyzer submission is retained as part of your testing record.
Video-recorded drug test submissions: a face template — stored face-geometry data derived from your face — is created and retained to verify your identity across submissions. The video of each drug test submission is retained for 60 days after it is taken and is then automatically deleted, unless we are required by law to retain it longer; your test result remains part of your testing record.
Face-geometry data and face templates may constitute “biometric identifiers” under certain state laws, and we treat them as such in both cases. We do not collect TrueDepth/ARKit facial maps from your device.
How we use it. We use identity photos, test videos, and the face-geometry data generated for matching solely to verify your identity, prevent fraud, and support compliance review of test submissions. We do not use this content for advertising or marketing, and we do not use it to identify you to anyone other than ourselves.
How we share it. We do not sell or share identity photos, test videos, or face-geometry data with third parties for advertising or analytics. We disclose them only to the service providers that operate our identity-verification and storage features on our behalf (Amazon Web Services), under contractual confidentiality, security, and HIPAA business-associate obligations.
How we store it. Photos and videos are transmitted via encrypted channels and stored encrypted at rest on our cloud infrastructure. Face-geometry processing occurs within our identity-verification provider’s environment, and face templates for drug-test verification are stored by that provider on our behalf; our employees do not directly handle face-geometry data or face templates. Access to photos and videos is restricted to authorized personnel with a need to know.
How long we keep it. We retain your enrolled reference photo and the image captured with each breathalyzer submission for the duration of your account or program to support test verification and compliance. Drug test videos are automatically deleted 60 days after they are taken, unless a legal requirement, litigation hold, or court-mandated program requires longer retention; test results are retained as part of your record. We delete them — including the face templates held by our identity-verification provider for drug-test verification — upon account deletion or a verified deletion request, and in any event within the retention period below, unless we are required to retain them by law. We retain biometric data only as long as needed for the purpose above, and we destroy it by the earlier of: when that purpose is satisfied, or within twenty-four (24) months of your last login (your last interaction with the Services), unless a longer period is required by law. Destruction on this schedule is automated. Our full written retention-and-destruction schedule is set out in our separate, publicly available Biometric Data Retention and Destruction Policy.
Device biometric authentication (Face ID / Touch ID). If you enable Face ID or similar device biometrics, that feature is used only by your device to unlock credentials stored in the device keychain (e.g., the iOS Secure Enclave). We do not receive or store your device biometric identifiers.
We separately obtain your consent before collecting or processing biometric data for identity verification. You may decline; however, we may be unable to provide identity-dependent features without it.
Your choices. You may withdraw consent or request deletion of your biometric data at any time by contacting us using the details below, subject to legal retention requirements.
4. Automated Processing and Artificial Intelligence (AI)
We use automated tools, including artificial intelligence, to help deliver and support our Services. We are transparent about where AI is involved.
Where we use AI. We use AI-assisted tools to:
Verify and validate identity — to confirm that the person submitting a selfie, video, or test evidence is the enrolled individual, and to detect signs of fraud or tampering.
Review monitoring submissions — to support review of medication-management records, drug testing, and breathalyzer/alcohol monitoring submissions for completeness, validity, and possible irregularities.
Transcribe sessions and generate documentation — during coaching or care sessions, we use voice transcription and AI-assisted note-taking to produce written documentation records.
Session recordings are not retained; transcripts are deleted within 24 hours. When AI note-taking is used during a session, the audio is transcribed in real time and the audio recording itself is not stored. The transcript is retained for up to 24 hours to generate and quality-check the draft written notes and is then automatically deleted. Your coach reviews the draft notes and edits them where necessary; only the final written notes are kept as part of your documentation record. We transcribe voice to text only; we do not create voiceprints or use voice for biometric identification.
Human oversight. AI outputs support and do not replace review by your coach, care team, or our compliance staff. Decisions that meaningfully affect you (for example, a determination about a test result or program compliance) require human review and decision making. If you have questions, contact us using the details in Section 19.
AI service providers. Our AI features are powered by third-party providers acting as our service providers: Deepgram (voice transcription) and OpenAI (documentation note generation), each under a Business Associate Agreement, and Amazon Web Services Rekognition (identity verification) under our AWS Business Associate Agreement. These providers process data only on our behalf under contractual confidentiality, security, and HIPAA obligations. We do not permit them to use your information to train their own models for unrelated purposes.
No advertising or profiling. We do not use AI to build advertising profiles or to make automated decisions for marketing purposes.
5. How We Use Your Information
We use personal information to:
provide, operate, and maintain the Services, including identity verification, coaching, check-ins, and drug testing and monitoring;
communicate with you, including service notifications and messages from your coach or care team (see Section 6 for SMS specifics);
verify and validate identity, and review medication-management, drug testing, and breathalyzer/alcohol monitoring submissions, using automated and AI-assisted tools (see Section 4);
derive approximate location from your IP address for analytics and security purposes, such as detecting suspicious account activity;
create and maintain documentation records from coaching or care sessions, using voice transcription and AI-assisted note-taking;
support compliance review and reporting to your Partner, where applicable;
verify insurance eligibility and submit claims to, and obtain reimbursement and payment from, Medicare and health plans for your Services (a “payment” purpose under HIPAA);
process payments and manage subscriptions;
detect, prevent, and respond to fraud, abuse, security incidents, and other harmful activity;
improve and develop our Services, including troubleshooting and analytics;
Provide data upon request from your payor or health plan;
provide customer support when you have questions or encounter issues with our services. This may include troubleshooting, resolving complaints, and addressing your concerns.
to understand how our services are used and to make improvements. This includes enhancing the user experience and developing new products.
For workers’ compensation as authorized by, or to the extent necessary to comply with, state workers compensation laws that govern job-related injuries or illness;
We may aggregate and anonymize your data to create statistical or research reports, which do not personally identify you. This information may be used for business analysis, marketing, and sharing with partners or clients. These reports may also be used to fulfill our contractual obligations.
comply with legal obligations and comply with or enforce our agreements; and
In addition to the purposes listed above, we may use your personal information for other legitimate purposes, provided that they are compatible with the original reasons for which your data was collected. For these other purposes, we will rely on legitimate interests or other lawful bases as required by applicable laws.
We do not sell your personal information, and we do not use sensitive information (including health and face data) for advertising.
6. SMS / Text Messaging
Consent. When you create an account or engage with our Services, you are asked to agree to our Terms and Conditions, which include your consent to receive SMS/text messages from You Are Accountable, Inc. By providing your mobile phone number and agreeing to our Terms and Conditions, you expressly consent to receive text messages from Accountable, including automated service notifications from our platform and direct messages from your assigned coach or care team. Message frequency may vary. Message and data rates may apply.
Marketing messages. Marketing communications are separate and optional. We ask for your consent to marketing emails or texts through a distinct opt-in; declining or withdrawing marketing consent does not affect the Services.
No sharing of SMS consent or mobile information. We will not share your mobile information, including opt-in data and consent, with any third parties for marketing or promotional purposes. All categories described in this Privacy Policy exclude text-messaging originator opt-in data and consent; this information will not be shared with any third parties.
Opt-out. You may opt out of receiving SMS/text messages at any time by replying with any of the following keywords: STOP, QUIT, END, REVOKE, OPT OUT, CANCEL, or UNSUBSCRIBE. You may also opt out by emailing us at hello@youareaccountable.com. Upon receiving your opt-out request, we will promptly cease sending SMS/text messages to your mobile number. Opting out of SMS communications will not affect your ability to use our Services or receive other forms of communication from us. Please note that opting out of SMS messages does not cancel a paid subscription — subscription changes and cancellations are managed through your account portal.
7. How We Share Information
We will not share your personal information with third-parties, unless explicitly authorized to do so or outlined in this Policy. Please note that when your personal information is shared with an authorized third-party, the information received by that third-party is controlled by that company and therefore becomes subject to that company’s Privacy Policy.
We may share your personal information with the following:
With your Partner. If you are enrolled through a treatment program, provider, or payer, we share program, testing, and compliance information with that Partner as part of providing the Services.
With people you designate (your Care Team). With your written consent, we share information — such as progress, testing, and compliance updates — with individuals you designate, such as family members, sponsors, or other members of your personal care team. You choose who is included and what is shared, and you may revoke this consent at any time by contacting us or updating your settings. Where your records are protected by 42 C.F.R. Part 2, these disclosures are made only pursuant to a Part 2-compliant written consent.
With Medicare and health plans for payment. Where your Services are covered by Medicare or a health plan, we share the information necessary to verify eligibility, submit claims, and obtain reimbursement and payment. This includes disclosures to the Centers for Medicare & Medicaid Services (CMS) and its contractors, and to your health plan or its administrators. These payment-related disclosures are made consistent with HIPAA and applicable program requirements.
With service providers. We share information with vendors who assist us in delivering our Services. These include:
Service Providers: We may share your personal information with third-party service providers who assist us in delivering our Services. These service providers include third party fulfillment companies, shipping and delivery companies, provider networks, and partner laboratories. We will only share the necessary data to fulfill their specific tasks and will have contracts or agreements in place to ensure they process your data securely. The lawful basis for sharing data with service providers is typically the necessity for the performance of a contract or, in some cases, legitimate interests, provided that these interests are not overridden by your data protection rights.
Laboratory Testing and Clinician Services: If you utilize our testing we will use your information for laboratory testing services or clinician oversight services and your personal information will be transmitted to the applicable laboratory or healthcare provider.
Business Partners: In some cases, we may share personal information with our business partners and affiliates, but only when it is necessary for the performance of a contract, the provision of services, or as part of a legitimate business interest. For example, we may share data with a partner organization involved in co-branded events or services. Sharing data with business partners and affiliates may be necessary for the performance of a contract or based on legitimate interests, especially when these partnerships are essential for delivering integrated or co-branded services.
Cloud hosting, storage, and identity verification — Amazon Web Services (AWS), which stores our data (including encrypted photos and videos) and operates our identity-verification technology (AWS Rekognition), under a Business Associate Agreement.
Payment processing — Stripe (see Section 14).
AI transcription and documentation — Deepgram (transcription) and OpenAI (note generation), each under a Business Associate Agreement.
Website analytics, attribution, and privacy filtering — Google Analytics, and OursPrivacy, the privacy-filtering platform through which our website measurement events are routed, under a Business Associate Agreement. Our websites, like almost all other websites, use cookies and other technologies to make the website work as you expect and to collect and share information.
Application diagnostics and product analytics — Sentry (crash and error reporting) and PostHog (product analytics), each under a Business Associate Agreement, limited as described in Section 2.
SMS delivery — Twilio, used to send the text messages described in Section 6.
Laboratory testing partners — our Third-Party Laboratories, which process test specimens and return results on our behalf.
For legal and safety reasons. We may share your information if the law requires us to, such as in response to a valid court order, subpoena, or other legal process. We may also share information if we believe it is necessary to protect someone’s rights, safety, or property, or to help prevent fraud or serious harm. If your information is protected by 42 C.F.R. Part 2 (which protects certain substance use disorder treatment records), we will only share it when that law allows us to, such as during a medical emergency or when required by a court order that meets Part 2’s legal requirements. Where a Partner relationship makes us a HIPAA business associate, any such disclosure is handled consistent with HIPAA.
In a business transfer. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Privacy Policy. Records protected by 42 C.F.R. Part 2 are transferred only as permitted by Part 2.
With your direction or consent. We share information when you ask us to or otherwise consent.
Other Legitimate Business Interests: In certain cases, we may share personal information with other parties for legitimate business interests. The sharing of this personal information may be based on legitimate interests. We will always ensure that such sharing is conducted in accordance with applicable data protection laws and respect your rights.
Integration of Third-Party Platform, Services and Websites: The Website may be linked to, rely on and be integrated with websites, applications, interfaces, services and websites or platforms operated by other companies, including third-party services and clients. We are not responsible for the privacy practices of such websites, applications, interfaces, services and platforms operated by third parties that are linked to, rely on and/or integrated with the Website. Once you leave the Website via a link, access a third-party service, you should check applicable privacy policies to determine, among other things, how related companies process personal information they may collect about you. This Policy applies solely to information collected by the Company.
8. How We Protect Your Information
We use administrative, technical, and physical safeguards designed to protect personal information against accidental or unlawful misuse, theft, destruction, loss, alteration, or unauthorized disclosure or access. These include encryption of data in transit and at rest, access controls limiting access to authorized personnel with a need to know, and daily backups stored separately from our primary host environment. Where we act as a HIPAA business associate, our safeguards are designed to be consistent with the HIPAA Security Rule.
No method of transmission or storage is completely secure, and internet and online service providers may experience interruptions outside our control. While we work diligently to protect your information, we cannot guarantee absolute security. If we become aware of a breach of security affecting your information, we will notify you and any affected Partner as required by applicable law.
9. Cookies and Tracking
Where tracking does and does not occur. Cookies, pixels, and similar technologies are used only on our public website (youareaccountable.com). We do not use advertising pixels, marketing tags, or third-party advertising tracking technologies within the logged-in application (our mobile app and web application). The application uses only the operational diagnostics and product analytics described in Section 2, which are associated with your account, designed to exclude the content of your health information, and protected by contractual safeguards, including Business Associate Agreements with those providers.
Cookies on our public website. The categories we use are:
Strictly necessary / session cookies — required to operate the site.
Preference cookies — to remember your settings and choices.
Security cookies — to support the security of the site.
Analytics cookies — to measure and improve how the site is used, through Google Analytics. You can learn about Google’s practices at https://policies.google.com/privacy and opt out using Google’s browser add-on at https://tools.google.com/dlpage/gaoptout.
Advertising measurement and attribution — We measure whether people visit our website after seeing one of our advertisements so we can understand which outreach is effective. To help protect your privacy, these measurement events are first processed through our privacy-filtering service provider (OursPrivacy), which is contractually required to protect your information. The service is designed to remove or limit health information and other identifying details before measurement information is sent to our advertising partners, including Meta, LinkedIn, Google, and Microsoft (Bing). We use this information to measure the performance of our advertising campaigns and attribute website visits to those campaigns. We do not use this information to build advertising profiles about you or to target advertisements to you based on your health information.
We do not use behavioral-remarketing cookies and we do not serve targeted advertising based on your health information. You can manage non-essential cookies through the Cookie Settings control on our website and through your browser settings; if you disable some cookies, parts of the site may not function properly.
Do Not Track / Global Privacy Control. Our website recognizes and honors Global Privacy Control (GPC) signals: if your browser sends a GPC signal, we treat it as a request to opt out of any sale or sharing of your personal information and configure non-essential tracking accordingly. There is no settled industry standard for legacy “Do Not Track” browser settings, and we treat GPC as the operative opt-out signal. Visitors from states with consumer health data laws (such as Washington and Nevada) are asked for consent before non-essential tracking technologies are used.
10. Data Retention
We keep personal information for as long as needed to provide the Services and your program, and afterward as required to comply with our legal obligations, resolve disputes, support compliance and record keeping, and enforce our agreements. Identity photos, test videos, and face templates are retained as described in Section 3. Approximate location derived from IP addresses is retained with our analytics data. Session audio is not retained, and transcripts are automatically deleted within 24 hours — we keep only the final written documentation notes, as described in Section 4. Drug test videos are automatically deleted 60 days after they are taken (unless legal requirements dictate longer), while test results are retained as part of your record, as described in Section 2. When information is no longer needed, we delete or de-identify it.
11. Health Information and HIPAA
Much of the information we handle relates to your health, treatment, or recovery, and is “protected health information” (“PHI”) under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”). Our role under HIPAA depends on the context:
As a covered entity. Where we provide services and bill Medicare or a health plan directly for them, we may act as a HIPAA covered entity (a healthcare provider that conducts standard electronic transactions, such as submitting claims). As a covered entity, we may use and disclose your PHI for treatment, payment, and healthcare operations without separate authorization, as permitted by HIPAA, and we maintain a separate Notice of Privacy Practices (available at https://www.youareaccountable.com/notice-of-privacy-practices) that describes your rights and our duties in more detail.
As a business associate. Where we provide Services on behalf of another healthcare provider, treatment program, or payer (a “Partner”), we act as a business associate under a Business Associate Agreement with that Partner, and we use and disclose PHI only as permitted by that agreement and applicable law. In that case, your Partner’s own Notice of Privacy Practices governs many of your rights, and you may need to direct certain requests (such as access or amendment of treatment records) to your Partner.
In all cases, we disclose PHI to Medicare/CMS and health plans as necessary to verify eligibility and obtain payment for your Services.
Substance use disorder records (42 C.F.R. Part 2)
Because we support addiction recovery, many of your records are substance use disorder (“SUD”) treatment records protected by a federal confidentiality law, 42 C.F.R. Part 2 (“Part 2”), which provides protections beyond HIPAA. Under the modernized Part 2 rule (in effect and enforced as of February 16, 2026) we will disclose your Part 2 records only with your written consent or as otherwise permitted by Part 2 (for example, in a medical emergency, for permitted research, or pursuant to a court order that meets Part 2’s requirements). You may provide a single consent authorizing all future uses and disclosures for treatment, payment, and healthcare operations, and you may revoke your consent at any time.
The specific uses and disclosures of your SUD records, and your rights regarding them, are described in full in our separate Notice of Privacy Practices (also called our Patient Notice).
If you have questions about how HIPAA or Part 2 applies to your information, contact us using the details in Section 19.
12. Your Privacy Rights
Depending on where you live, you may have some or all of the following rights regarding your personal information:
Access / Know — request the categories and specific pieces of personal information we hold about you.
Correct — request that we fix inaccurate personal information.
Delete — request that we delete your personal information, subject to legal exceptions.
Portability — request a copy of certain information in a portable format.
Opt out — opt out of any “sale” or “sharing” of personal information and of certain profiling. As noted above, we do not sell or share personal information as those terms are defined under applicable law.
Limit use of sensitive information — request that we limit the use of sensitive personal information to what is necessary to provide the Services.
Non-discrimination — we will not discriminate against you for exercising any of these rights.
How to exercise your rights. Submit a request by emailing privacy@youareaccountable.com or by calling (646) 450-7641. We will verify your request before responding, typically within 45 days, and will let you know if we need more time. You may use an authorized agent to submit a request on your behalf, subject to verification.
Rights in your health and SUD records. The rights listed above apply to personal information generally. Your rights in your protected health information and substance use disorder records (including access, amendment, accounting of disclosures, requesting restrictions, and confidential communications) are governed by HIPAA and 42 C.F.R. Part 2 and are described in our Notice of Privacy Practices. If you are enrolled through a Partner and your request concerns treatment or health records, we may direct your request to that Partner or coordinate with them, consistent with HIPAA.
13. NOTICE TO RESIDENTS OF CALIFORNIA, COLORADO, CONNECTICUT, MONTANA, OREGON, TEXAS, UTAH AND VIRGINIA OR WHERE REQUIRED BY APPLICABLE LAW
CCPA. This section supplements the information contained in the Policy and applies solely to users, and others who reside in California to the extent required under the California Consumer Privacy Act (as amended by the California Privacy Rights Act) (the “CCPA”) and to other, certain U.S. State residents to the extent required under such U.S. State’s applicable law. The CCPA sets forth certain obligations for businesses that “sell” personal information. Based on the definition of sell under CCPA and under current regulatory guidance, we do not engage in such activity and have not engaged in such activity in the past twelve months. We do not allow third parties to serve targeted advertising to users on our Website.
California’s Shine the Light Statute. A California resident who has provided personal information to a business with whom he/she has established a business relationship for personal, family, or household purposes (a “California Customer”) may request information under the California Civil Code Section 1798.83 (California’s Shine the Light Statute) about whether the business has disclosed personal information to any third parties for the third parties’ direct marketing purposes. In general, if the business has made such a disclosure of personal information, upon receipt of a request by a California Customer, the business is required to provide a list of all third parties to whom personal information was disclosed in the preceding calendar year, as well as a list of the categories of personal information that were disclosed. California Customers may request further information about our compliance with this law by contacting us at any of the following:
Mail: Attn: Privacy Officer, You Are Accountable, 331 Newman Springs Road, Building 3, Suite 320, Red Bank, NJ 07701. Email: privacy@youareaccountable.com. Phone Number: 646-450-7641. Please note that we are only required to respond to one request per California Customer each year under Code Section 1798.83.
Rights Under State Consumer Privacy Laws. Residents of states with comprehensive consumer privacy laws have certain rights described herein. If you are a resident of such a state (“Applicable Residents”), you may exercise your privacy rights, where applicable to you under the law of your state, at any time, by contacting us at any of the following:
Mail: Attn: Privacy Officer, You Are Accountable, 331 Newman Springs Road, Building 3, Suite 320, Red Bank, NJ 07701. Email: privacy@youareaccountable.com. Phone Number: 646-450-7641.
This section describes practices regarding the collection, use, disclosure, and sale of “personal information” and the rights of Applicable Residents regarding their personal information under the applicable state consumer privacy laws in the United States (“Applicable State Data Protection Law”). This section applies to Applicable Residents who are considered a “Consumer” or an equivalent term under the Applicable State Data Protection Law. The section does not apply to information that is exempt from an Applicable State Data Protection Law. For example, Applicable State Data Protection Laws do not apply to information that is already protected by certain other laws such as HIPAA, to information that is already publicly available from governmental sources, or to de-identified or aggregated consumer information.
You Have a Right to Know. Applicable Residents have the right to request that we disclose what Personal Information we collect, use, and disclose. This is called the “Right to Know”. Under the Right to Know, you can request a listing of the types of Personal Information we have collected about you, the sources of that information, how we use the information (e.g., our business or commercial purposes for collecting, or selling Personal Information), other individuals and businesses with whom we share Personal Information, and the specific pieces of Personal Information that we have collected about you. If you would like to make a request under your Right to Know, you may request this through privacy@youareaccountable.com or by calling 646-450-7641. When you make a request under your Right to Know, you can expect the following:
We will verify your identity. We will verify your identity using the following process: Our customer care team will ask questions based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.
We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at privacy@youareaccountable.com or by calling 646-450-7641.
We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
In certain cases, a Right to Know request may be denied. For example, if we cannot verify your identity or if providing you the information could create an unreasonable risk to someone’s security (for example, we do not want very sensitive information disclosed inappropriately). If we deny your request, we will explain why we denied it. If we deny a request, we will still try to provide you as much of the information as we can, but we will withhold the information subject to denial.
The Right to Access. Applicable Residents have the right to request that we provide a portable copy of the personal information we collect, use, disclose, and sell. You can request a listing of the types of personal information we have collected about you, the sources of that information, how we use the information (e.g., our business or commercial purposes for collecting or selling personal information), other individuals and business with whom we share personal information, and the specific pieces of personal information that we have collected about you. If you would like to make a request under your Right to Access, you may request this through privacy@youareaccountable.com or by calling 646-450-7641. When you make a request for a portable copy of your information, you can expect the following:
We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.
We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed above.
We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why.
In certain cases, a request for access may be denied, for example, if we cannot verify your identity. If we deny your request, we will explain why we denied it.
You have a Right to Request Deletion. Applicable residents have a right to request the deletion of their Personal Information collected or maintained by us, subject to certain limitations. If you would like information about you to be deleted, you may request deletion through privacy@youareaccountable.com or by calling 646-450-7641. When you make a request for deletion, you can expect the following:
After you submit a request deletion, you will need to confirm that you want your information deleted.
We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.
We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed below. We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why. In certain cases, a request for deletion may be denied, for example, if we cannot verify your identity, the law requires that we maintain the information (e.g., in case of certain tests) or if we need the information for internal purposes such as ongoing research.
If we deny your request, we will explain why we denied it, treat your request as a request to opt out of the sale or sharing of your information (as described in “You Have the Right to Opt-Out” below), and delete any other information that is not protected from deletion.
You may have a Right to Request the Correction. Where provided by the law of your state, Applicable Residents also have the right to request the correction of inaccurate Personal Information collected or maintained by us. If you would like information about you to be corrected, you may request correction through the contact information at privacy@youareaccountable.com or by calling 646-450-7641. When you make a request for correction, you can expect the following:
After you submit a request for correction, you will need to confirm what information is incorrect and requires correction. We will verify your identity based upon information that you previously have provided. Where possible, we will use information we already hold about you in order to confirm that you are who you say you are.
We will confirm our receipt of your request within 10 days. If you have not received a response within a few days after that, please let us know by contacting us at the webpage or phone number listed below.
We will respond to your request within 45 days of receipt of the request, if possible. If necessary, we may need an additional period of time, up to another 45 days, but we will reply either way within the first 45-day period and, if we need an extension, we will explain why. In certain cases, a request for correction may be denied, for example, if we cannot verify your identity. If we deny your request, we will explain why we denied it.
You Have the Right to Opt-Out. This Section also serves as a Notice to residents of states with comprehensive consumer privacy laws of their right to opt-out of the sale of personal information and of the use and/or disclosure of personal information for certain types of targeted advertising and consumer or household profiling. Residents of California have a right to direct businesses not to sell their personal information or share their personal information for cross-context behavioral advertising. Residents of other states with comprehensive consumer privacy laws have the right to direct businesses not to process their personal data for purposes of (i) targeted advertising, (ii) selling or otherwise transferring personal data in exchange for monetary or other valuable consideration, or (iii) profiling in furtherance of decisions that produce legal or similarly significant effects concerning the consumer. Under Applicable State Data Protection Law, this is known as the “right to opt out.” In general, we will only use your personal information to perform services or provide the goods reasonably expected by you, internal reporting and analytics purposes, for other purposes in the ordinary course of business, and to facilitate first-party marketing and analytics. We do not sell your personal information for monetary consideration. Nevada law also gives Nevada consumers the right to request that a company not sell their personal information for monetary consideration to certain other parties. This right applies even if their personal information is not currently being sold in that manner. If you are a Nevada consumer and wish to exercise this right, please send an email with the subject line “Nevada Resident Do Not Sell Request” to privacy@youareaccountable.com.
Rights Regarding Use and Disclosure of Sensitive Personal Information. Sensitive personal information includes the “sensitive personal information” described in above, such as information concerning your health. In general, we will only use your sensitive personal information to perform services or provide the goods reasonably expected by you, for internal reporting and analytics purposes, contractual requirements, for other internal purposes in the ordinary course of business.
Your Right to Appeal. If we refuse to take action on any of the above rights, consumers who are residents of states whose comprehensive consumer privacy laws provide a right of appeal can appeal this decision by emailing us at privacy@youareaccountable.com. We shall inform you in writing of any action taken or not taken in response to the appeal, including a written explanation of the reasons for the decision, within the timeframe required by the law of your state of residence (generally 45 to 60 days of receipt of your appeal).
Authorized Agents. If you are a California resident and would like, you may designate an authorized agent to make a request under the CCPA on your behalf. If you are a resident of another state whose comprehensive consumer privacy law provides for it, you may have a right to designate an authorized agent to make a request to opt out on your behalf. We will deny requests from agents that do not submit proof of authorization from you. To verify that an authorized agent has authority to act for you, we may require a copy of a power of attorney or require that you provide the authorized agent with written permission and verify your own identity with us.
14. Payments
If you purchase a paid subscription directly, payment processing is handled by our third-party processor, Stripe. Your billing details are collected and stored by Stripe; we do not store or collect your full payment card details. Stripe’s use of your information is governed by its own privacy policy (https://stripe.com/privacy). Stripe adheres to the standards set by the PCI-DSS as managed by the PCI Security Standards Council, which help ensure the secure handling of payment information. Subscription changes and cancellations are managed through your account portal.
15. International Data Transfer
We are based in the United States, our Services are offered only to individuals located in the United States, and we process and store information on servers located in the United States. We do not offer, market, or direct the Services to individuals in the European Economic Area, the United Kingdom, or other jurisdictions outside the United States, and this Privacy Policy is not intended to create rights under, and the Services are not operated in accordance with, the GDPR or other non-U.S. data-protection regimes. If you temporarily access the Services while traveling outside the United States, your information will continue to be transferred to, stored, and processed in the United States and handled in accordance with this Privacy Policy and U.S. law.
16. Links to Other Sites
The Services may contain links to websites or services that we do not operate. If you click a third-party link, you will be directed to that third party’s site. We have no control over, and are not responsible for, the content or privacy practices of any third-party sites. We encourage you to review the privacy policy of every site you visit.
17. Minors and Age Requirements
The Services are available to individuals 13 years of age and older. We do not permit individuals under 13 to use the Services, and we do not knowingly collect personal information from children under 13, consistent with the Children’s Online Privacy Protection Act (COPPA). If you believe a child under 13 has provided us personal information, please contact us and we will take appropriate steps to delete it.
Users aged 13–17. If you are between 13 and 17, you may use the Services only as allowed by applicable law or with the consent and involvement of a parent or legal guardian. Where required by law, we obtain parental or guardian consent before collecting certain categories of information from users under 18, including biometric data used for identity verification.
18. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last Updated” date above and, where appropriate, provide additional notice (such as by email or in-app notification). Your continued use of the Services after an update takes effect means you accept the revised Privacy Policy.
19. Contact Us
If you have questions, requests, or concerns about this Privacy Policy or our handling of your information, you can reach us:
Email: privacy@youareaccountable.com. Phone: (646) 450-7641. Mail: You Are Accountable, Inc., 331 Newman Springs Road, Building 3, Suite 320, Red Bank, NJ 07701. Web: https://www.youareaccountable.com/contact-us.
Stay connected. Stay accountable.
