People share hard things. We protect what they share.
Behavioral health support only works when people feel safe being honest. Chaperone is built so the information people share is collected with purpose, handled with care, and never turned against them. This page explains our privacy posture for buyers; for the binding terms, see our Privacy Policy.
Privacy that supports people, not a system that watches them.
We collect what we need to connect someone with a Peer Coach and support their journey. We don’t build surveillance profiles, and we don’t treat people’s most vulnerable moments as data to be exploited. Intelligent guidance assists the work within strict limits; it never makes privacy decisions on its own.
A few clear principles guide every decision about data
These aren’t aspirations bolted on after the fact. They shape how the platform is designed, configured, and operated.
Data minimization
We collect the least information needed to provide support and operate the service. Fewer fields, clearer purpose, less to protect, and less ever at risk.
Purpose limitation
Information is used for the reasons people expect (supporting their care, keeping them safe, and improving the service) and not repurposed for unrelated ends.
We don’t sell data
People’s personal and health information is not sold or rented to advertisers or data brokers. Support is the product; people are never the product.
Protected by design
Encryption in transit and at rest, access controls, and a HIPAA-informed posture are part of how the platform is built. These are not optional add-ons.
Retention with intent
We keep information only as long as it’s needed to provide support and meet legal and contractual obligations. Then it’s disposed of responsibly.
Transparency
We explain what we collect and why in plain language, so people, and the organizations that bring us in, can understand and trust how data is handled.
A HIPAA-informed posture for protected health information
Where Chaperone handles protected health information on behalf of a covered entity, we operate under a HIPAA-informed posture and stand ready to enter into a Business Associate Agreement. Administrative, physical, and technical safeguards are designed to protect PHI across the platform and our managed infrastructure.
- Business Associate Agreements available for qualifying engagements
- Administrative, physical, and technical safeguards for PHI
- Minimum-necessary access to sensitive information
- Breach notification and incident response processes
What you can expect during diligence
A clear picture of how PHI is governed, so your privacy and compliance review can move quickly.
- Documentation of data flows and storage
- Subprocessor and data-residency information
- Security questionnaire support
- Role-based permissions scoped to the work each person does
- Least-privilege access to sensitive information by default
- Audit trails across access to and changes in sensitive records
- Configurable access boundaries per deployment
- Human review of AI-assisted summaries and safety signals
Who can see what, and a record of when they did
Not everyone should see everything, and every access to sensitive information should be accountable. Role-based permissions limit who can view a person’s information to those who need it to provide support. Audit trails record sensitive actions, so access is traceable and reviewable rather than assumed.
Support people feel, not monitoring they fear
Chaperone is designed to help, not to watch. People stay informed about how their information is used and have meaningful control over their experience.
Not a surveillance tool
We don’t track, profile, or monitor people’s behavior for any purpose beyond providing support and keeping people safe. The goal is connection, never observation.
Informed & consensual
People are told, in plain language, what’s collected and why. Consent and clear communication come first. There are no hidden uses of someone’s information.
Meaningful control
People can ask what we hold, request corrections, and exercise their privacy rights. The available choices and how to use them are described in our Privacy Policy.
This page describes our posture; the policies define the terms
For binding language on data handling, rights, and disclosures, review the published notices below.
Questions about how we handle data?
Bring your privacy review, your DPA, or your security questionnaire. We’ll walk through our posture with your team, or help someone find the right support path.
