Privacy

Privacy

What the site collects, in specifics, written in plain terms rather than as a legal notice. Everything below describes what the system does today.

If you are just reading

No cookies are set for visitors. There are no cross-site identifiers and no ad pixels. Your browser talks only to couchcommons.com, with one exception: a video loads from YouTube's privacy-enhanced player (youtube-nocookie.com) only after you press play.

We use PostHog, a product analytics tool hosted in the United States, to count visits and see where people get stuck: page views, clicks, scrolling, page speed, page errors, and on the join page, that the form was started and sent. No session recordings, no ad tracking, and it never sees your messages to a therapist or anything you type into a form or our search. PostHog knows a visit, not a person. The visit gets a random ID that is kept only in that browser tab's temporary storage and is deleted when you close the tab. PostHog's code and your visit data pass through our own server, which removes your IP address before anything reaches PostHog. PostHog does not run on member pages, and it keeps no profile of anyone.

We also count page opens with our own script and our own server, as before. Each time a page here is opened, we add one to that page's total for the day, sorted by the kind of place you came from: an AI assistant, a search engine, a social site, another page on this site, no referring page, or somewhere else. If an AI assistant sent you, we also note which one — ChatGPT, Claude, or Perplexity, for example. Your browser works out the kind and sends us only the page and that kind, plus the assistant's name when there is one. This counter never stores the address you came from.

For each clinician we also keep two daily totals: how many times their page was opened, and how many times each kind of their contact links was used. All of these are counts, not people. None of them holds your IP address, your browser, a cookie, or any ID for you.

Search queries on /find are never logged, by us or by PostHog. What you type when you are trying to describe what is happening to you does not become a record. It never leaves your browser. On /find, PostHog records only that the page was opened, left, or hit an error, with no search words and no filters.

If you contact a clinician

You do not send a message through Couch Commons. A clinician's page lists the ways they chose to be reached — their website, a booking page, an email address, a phone number, or a public profile of theirs — and the link takes you straight there. What you say next is between you and the service you picked. We never see it.

When you follow one of those links we add one to a daily total: how many times one of that clinician's contact links was used on that day. That total holds no name, email, message, address, browser, referring page, or identifier that could tie one click to another. The number is clicks, not people — if you click twice, that is two. PostHog also sees the click, under the random visit ID described above, and never what you write.

Couch Commons used to relay messages. It no longer accepts them, and the email addresses and message text collected under the old relay have been destroyed.

If you apply or join to be listed

The application asks for a name, an email, a credential, a licensing state and a license number, plus a website and a note if you choose to add them. The membership checkout asks for the same core identity details before sending you to Stripe. There are no card fields on our forms; Stripe handles the card.

Our server also tells PostHog when a new member reaches each setup step: checkout started, consent to the license check given, profile written, profile approved, and profile published. Each of those notes is the step's name and a random member number, nothing else: no name, email, license number, or profile text.

The license number is how we prevent the same professional license from claiming two accounts and how we check you against the state registry. Once a profile is published, the receipt shows the license number alongside the state, the type, and the date, the same way the issuing registry already displays it.

If you are a member

Members sign in by a magic link sent to their email address. No passwords exist here, so there are none to store, reset, or leak. The session cookie is HttpOnly and applies only over HTTPS.

What a member can see about you

A member's dashboard carries day-granularity counters and nothing else. It does not carry the text of anyone's search, or a session, an IP address, or a user agent. There is nothing in it that could point back at a person.

How long records are kept

Expired magic links, sessions, and one-minute handoff tokens cannot be used. Their token values are stored only as hashes. The service now has a cleanup rule for deleting them after a 30-day troubleshooting window, and for deleting a declined or withdrawn clinician application 90 days after that decision.

These cleanup rules are not currently running on an automated schedule, so these records are not being automatically deleted. This page will state otherwise only after a scheduled cleanup has produced an executed deletion receipt.

An unfinished membership checkout is reviewed after 30 days. We do not delete it from age alone: Stripe must first show that there is no delayed payment, refund, dispute, or other open billing state.

Account and profile records are kept while a membership is active. License-check history, consent records, billing events, audit records, and delivery receipts are not automatically deleted today. Some may need to remain after an account closes to prove a license check, reconcile money, prevent duplicate actions, resolve a dispute, or meet a legal obligation. Couch Commons does not currently promise a fixed post-membership deletion period for those records.

Daily page totals are deleted once they are 13 months old. The service checks for them when it starts and once a day. A clinician's daily profile-view and link-click totals are kept with their account. They are not deleted on a schedule, and closing the account does not delete them. All of these are counts, not visitor histories, and contain no search text, IP address, browser identifier, referring address, or session.

Backups and deletion requests

The server keeps the seven newest nightly database snapshots. Restore-tested disaster-recovery copies are kept off the server for 90 days. A record deleted from the working database can therefore remain in a protected backup until that backup expires. Backups are used for recovery, not ordinary account lookup.

To ask for access, correction, or account deletion, emailinfo@couchcommons.com. We will identify what can be deleted and what must remain because of an active dispute, security investigation, payment or accounting requirement, license-verification record, or legal hold.

Questions

Questions go to info@couchcommons.com.