Privacy Policy

Effective date: June 30, 2026  |  Last updated: June 30, 2026

This Privacy Policy explains how Recovery Club America LLC, doing business as MindClub America, together with its subsidiaries and affiliated programs (including InHome Recovery) ("MindClub," "we," "us," or "our") collects, uses, discloses, and protects information when you use our mobile applications, websites, and related services (collectively, the "Service").

MindClub is a mental-health and wellness platform. Some of the information we handle is health information that may be protected under the Health Insurance Portability and Accountability Act ("HIPAA") and similar laws. Our handling of Protected Health Information ("PHI") is described in more detail in our HIPAA Notice of Privacy Practices. Where the Notice of Privacy Practices and this Privacy Policy conflict with respect to PHI, the Notice of Privacy Practices controls. Records relating to substance use disorder treatment receive additional protection under a federal confidentiality law (42 CFR Part 2); the Notice of Privacy Practices explains how we handle them.

This Service is not for emergencies. If you are in crisis or thinking about harming yourself or others, call or text 988 (Suicide & Crisis Lifeline) or 911, or go to the nearest emergency room. See our Terms of Service for more.

1. Information We Collect

We collect the following categories of information. Not all of it applies to every user – what we collect depends on the features you use (for example, whether you connect with a therapist).

1.1 Account and identity information

Name, username, email address, phone number, date of birth, mailing address, time zone, and profile photo. Sign-in and account credentials are handled by our own self-hosted authentication system; passwords are stored only in hashed form, never in plain text.

1.2 Demographic and self-reported information

Information you choose to provide in onboarding and surveys, such as age group, gender, ethnicity, self-reported wellness and stress ratings, personal goals, and prior therapy experience.

1.3 Health and clinical information (PHI)

If you use our care and therapy features, we collect and store health information, which may include: diagnoses, presenting symptoms, prescribed-medication information, clinical/therapy notes created by your provider, appointment records, messages between you and your provider, therapy-consent records, and records synchronized with an external electronic health record (EHR) system used by your provider.

1.4 Self-reported wellness information

Information you log in the app, such as journal entries, mood logs, sleep entries, habit tracking, mental-fitness plans, activity and learning completions, and responses to validated self-assessment questionnaires (which may screen for areas such as mood, anxiety, stress, resilience, emotional regulation, substance use, and adverse experiences). We also record health-risk/safety referrals generated within the Service.

1.5 Community content

Posts, comments, reactions, and event RSVPs you create in community or discussion features, along with moderation-related metadata. These features are also governed by our Community Guidelines.

1.6 Payment information

If you make a payment for the platform, our payment processor handles your payment-card details directly, and we store a customer identifier and related status information. We do not store full payment-card numbers. Billing for clinical or therapy services is handled separately through the electronic health record system your provider uses.

1.7 Device, technical, and usage information

Device push-notification tokens, IP address and browser/user-agent (recorded in access and security logs), login events, content you view (such as videos watched), feature usage, and information collected through cookies and similar technologies on our websites.

1.8 Access and audit logs

To protect health information, we maintain access logs recording who accessed certain records (such as clinical notes and provider messages), when, the type of access, and associated technical details such as IP address and user agent.

2. How We Use Information

We use information to:

  • Provide care and coordination – connect you with providers, manage appointments and scheduling, enable provider–patient messaging, and synchronize records with your provider's EHR where applicable.
  • Deliver Service features – power journaling, mood and sleep tracking, assessments, mental-fitness plans, the educational content library, and community features.
  • Manage your account – registration, authentication, and support.
  • Communicate with you – send appointment reminders, service and security notices, and (only where you have opted in) wellness and marketing messages, via push notification, email, and/or SMS, consistent with your communication preferences.
  • Process payments – where fees apply.
  • Promote safety – identify and respond to potential risk-of-harm situations and route to crisis resources, and to keep our community safe.
  • Improve and secure the Service – analytics, troubleshooting, fraud and abuse prevention, and securing our systems.
  • Comply with legal obligations – including recordkeeping, audit, and regulatory requirements applicable to health services.

Our use and disclosure of PHI for treatment, payment, and health-care operations is described in the HIPAA Notice of Privacy Practices.

3. How We Share Information

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose information only as described here. Where a service provider may handle PHI, we enter into a Business Associate Agreement (BAA) as required by HIPAA.

3.1 Your care team and providers

Health information is shared with the licensed providers involved in your care and, where applicable, synchronized with the EHR system your provider uses.

3.2 Sponsoring organizations

If your access is sponsored by an employer, health plan, or other organization, that organization receives only aggregate utilization statistics about its sponsored population – for example, the number of accounts created, the number of screenings completed, the number of members who needed or received therapy services, and engagement counts. Sponsoring organizations do not receive your identity or any of your individual clinical or self-reported health information.

3.3 Service providers (subprocessors)

We use service providers (subprocessors) to help operate the Service, and we share information with them only as needed for them to perform their functions, under contract. These providers support functions such as: payment processing; electronic health record (EHR) and clinical record management; electronic signature of consent documents; cloud hosting, storage, and media processing; website analytics; and push, email, and SMS notifications.

3.4 Mobile and SMS opt-in

If you opt in to text messages, we do not sell your mobile opt-in information, and we do not share it with third parties or affiliates for their marketing or promotional purposes. We share it only with the vendors that help deliver the messages you requested, such as our SMS provider and the carriers and aggregators that route the texts.

3.5 Legal, safety, and protective disclosures

We may disclose information when required by law or legal process, to protect the rights, safety, or property of users or others, to respond to a serious and imminent threat to health or safety, or as otherwise permitted or required by law.

3.6 Business transfers

If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy and applicable law.

4. Cookies and Tracking Technologies

Within the MindClub app and member dashboard, we use only functional cookies necessary to operate the Service – for example, to keep you signed in and maintain your session. We do not use advertising or analytics cookies on the app or dashboard.

On our public marketing website, we use Google Analytics to understand general site traffic and improve the site. You can control cookies through your browser settings; disabling some cookies may affect functionality. We do not currently respond to "Do Not Track" browser signals, as there is no consistent industry standard for them.

5. Data Retention

We retain your personal information for as long as your account is active. When you delete your account, we delete the personal information associated with it, except where we are required or permitted by law to retain certain records – for example, health and clinical records subject to medical-records-retention requirements, and security or audit logs. Clinical records maintained in your provider's electronic health record system are retained for the period required by applicable law. Information may also persist in backups for a limited period before being overwritten.

6. Your Privacy Rights

Depending on where you live and the nature of the information, you may have rights to:

  • Access the personal information we hold about you and request a copy;
  • Correct inaccurate information;
  • Delete your account and associated personal information, subject to the legal retention requirements described above;
  • Restrict or object to certain processing, and withdraw consent where processing is based on consent.

To exercise any of these rights, contact us using the details below. We handle these requests manually and will verify your identity before responding.

California residents have the rights described under the CCPA/CPRA, including the rights to know, delete, and correct personal information, and to opt out of the sale or sharing of personal information. As noted above, we do not sell your personal information or share it for cross-context behavioral advertising, and we will not discriminate against you for exercising your rights.

Your rights with respect to Protected Health Information (including the right to access, amend, and request an accounting of disclosures of your PHI) are described in our HIPAA Notice of Privacy Practices.

7. Security

We use administrative, technical, and physical safeguards designed to protect your information. These include access controls and least-privilege authorization, encryption of data in transit and at rest (including files stored with our cloud provider), audit logging of access to sensitive records, rate limiting, and input validation. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.

8. Age Requirement and Minors

Self-service accounts are for adults aged 18 and older; account registration is restricted to 18+ and enforced at sign-up through our identity provider. We provide services only to individuals aged 13 and older, and we do not provide services to, or knowingly collect personal information from, children under 13.

Care for a minor (ages 13–17) is arranged by the minor's parent or legal guardian, who must contact us by phone at (833) 833-9655. The parent or legal guardian provides signed consent for the minor's treatment, and the minor signs an age-appropriate assent. Any information we maintain about a minor in connection with that care is handled in accordance with this Policy and our HIPAA Notice of Privacy Practices, subject to applicable state law governing minors' health information.

If we learn that we have collected personal information from a child under 13, we will delete it.

9. United States Only

The Service is intended for users in the United States, and all information is processed and stored in the United States. The Service is not directed to individuals in the European Union, the United Kingdom, or other regions outside the United States.

10. Changes to This Policy

We may update this Policy from time to time. We will post the updated Policy with a new "Effective date." For material changes, we will provide additional notice – such as email or an in-app notice – before or at the time the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated Policy.

11. Contact Us

Recovery Club America LLC d/b/a MindClub America
106 Mission Ct, Suite 201a
Franklin, TN 37067
Phone: (833) 833-9655
Email: [email protected]

For questions about Protected Health Information, see our HIPAA Notice of Privacy Practices.