Consumer Health Data Privacy Policy
Draft — last updated 2026-09-04, pending legal review before public launch.
CommonGround is operated by Common Ground Dating LLC.
This policy is specifically about your HIV/HSV status -- the consumer health data at the center of what CommonGround is. It supplements, and does not replace, our general Privacy Policy, which covers your account, messages, and other data more broadly. Consent version: 2026-09-04.1 -- see "Material changes" below for what that means.
What health data we collect
Your HIV/HSV status (any combination of HIV+, HSV-1, HSV-2) as you self-report it on your profile. That is the only health-data category CommonGround collects -- we do not collect lab results, prescriptions, provider information, or proof-of-status documents.
Source
Directly from you. You type it in when you set up or edit your profile; nothing is inferred, purchased, or received from a third party.
Purpose
To match you with other members who already share that context, and to display it on your profile to authenticated members the same way your city is displayed -- the entire premise of CommonGround is removing the disclosure barrier by making status a normal, visible profile field rather than something hidden or revealed later.
How we process it
Encrypted in transit and at rest, same as the rest of the app. Two separate consent actions gate it, not one bundled step: collection consent before it is stored at all, and disclosure consent before it is shown to other members. Withdrawing disclosure consent stops new sharing immediately, enforced at the database access-control layer, not just in the app's interface. Withdrawing collection consent erases the stored status outright. Manage both any time from Settings.
Sharing and recipients
Visible to other authenticated CommonGround members once you've granted disclosure consent -- never to the public, never indexed by search engines. We never sell it and never share it for advertising or with a data broker. The only outside parties who process it are the infrastructure providers who run the app on our behalf, under contract, never for their own purposes: Supabase (database and access control), Vercel (hosting). Resend, our email provider, does not receive status data -- it only delivers account emails like password resets. None of our processors are ad-tech or analytics vendors, and CommonGround has no such vendor of any kind.
We cannot fully control what another member does with status they can see on your profile. Our Terms and Community Guidelines prohibit screenshotting or sharing another member's profile or status outside the app, but that is a contractual and community-enforcement commitment, not a technical guarantee -- another member could still misuse what you've made visible to them, the same limitation that applies to anything shown to another person on any platform.
Your rights
Confirmation of processing, access and export, correction, withdrawal of either consent, and full account deletion are all available immediately from Settings → Privacy & Data Center, without contacting anyone. If you can't or don't want to log in, or need an appeal, use our public privacy request form instead -- see Contact for general questions. We aim to resolve any request well within the 45-day maximum our standards set, and specifically within 30 days for a health-data deletion handled outside self-service.
Retention
Your status is retained until you withdraw collection consent (which erases it immediately) or delete your account (which erases everything). Your consent history itself -- the record of what you consented to and when -- is kept as an append-only audit trail even after a withdrawal, so there is always provable evidence of what was accepted and when it changed; it does not contain your status value itself once withdrawn, only the fact and timing of the consent event. Routine infrastructure backups may retain deleted data for a limited period before they roll over.
Material changes
If we materially change what health data we collect, how we use it, or who it's disclosed to, we treat that as a new notice version. A version change requires renewed consent from every member before the affected activity continues for them -- continued use of the app alone is never treated as accepting a material health-data change. The version shown at the top of this page is the one currently in effect.
What this policy does not claim
CommonGround is not a covered entity or business associate under HIPAA, and we do not claim HIPAA compliance. Encryption in transit and at rest is not the same as absolute confidentiality -- CommonGround's own systems can access status data where necessary to operate the service, respond to a safety report, or handle a support request, and several states have their own statutory confidentiality protections for HIV/STI status that may apply independently of this policy.
Legal review
This policy is a draft pending legal review before public launch, not a final legal document -- see our general Privacy Policy for the same notice and context.
