FREQUENTLY ASKED QUESTIONS

1. Security & Privacy Basics

  1. We use multiple layers of protection: Separation of data: identity info, payment tokens, and recovery content live in separate, protected stores.
  2. Encryption: data is encrypted in transit (HTTPS/TLS) and at rest using strong industry standards.
  3. Least-privilege access: production data is not visible to staff by default; all rare “break-glass” access is time-limited, approved, and audited.
  4. Minimization: we collect the least amount of personal information needed to operate the service.
  1. Identity (PII): account email (and optional phone), consents, country/region, and account metadata.
  2. Payments: we never store card numbers. We only keep payment processor tokens (e.g., Stripe customer/payment method IDs).
  3. Recovery content: your journals/Oracle/step entries are stored without your real name, and linked to your account via internal references—not by email or card data.
  1. No, not by default. Access to raw recovery content is blocked for all staff. In a rare, documented support or legal scenario, a “break-glass” process may grant short-lived access for specific items, with manager approval, reason codes, and immutable audit logs. We design to avoid this wherever possible.
  1. We provide a Private Mode option for highly sensitive notes: content is encrypted on your device before it’s sent to us, using a passphrase only you know. If you enable Private Mode and lose your passphrase, we cannot recover those entries. Some features (like server-side search) may be limited in Private Mode.
  1. No. We don’t sell personal information. If we share metrics with sponsors or partners, they’re aggregated and de-identified (e.g., total events hosted, anonymous engagement stats).

2. Accounts, Access

  1. You need an email for sign-in, but you can use a display name (not your real name) in community spaces. Your recovery content is stored without real-name fields.
  1. Yes. We strongly recommend enabling 2FA in your account settings to protect against unauthorized access.
  1. From a trusted device, sign in and log out all sessions in Security settings. Change your password and (if enabled) rotate your Private Mode passphrase for future entries.
  1. In Account → Privacy:Export: download your recovery entries and account data (common formats like JSON/CSV; Private Mode entries remain encrypted).
  2. Delete: delete entries or your full account. Backups roll off on a schedule; some legal/audit records may be retained as required by law.

3. Payments & Nonprofit Status

  1. Payments are processed by Stripe (PCI-DSS Level 1). We never see or store your card number—only Stripe tokens.
  2. Why can’t I purchase inside the app?
  3. To protect your privacy, we keep payments on our website (Stripe) so your billing info stays separate from recovery content. You can then log into the app for access.
  1. Yes. Our mission is accessibility. Sponsors and donors help us keep core features free. Optional premium features/events may be available.

4. Oracle, Safety & Boundaries

  1. No. The Oracle provides supportive reflections and education, not professional advice. It won’t predict the future, diagnose, prescribe, or tell you to take financial risks.
  1. The Oracle immediately pauses regular guidance and shows crisis resources (e.g., 988 in the U.S., relevant hotlines by country if available), with supportive language. We encourage contacting local emergency services if there is immediate danger.
  1. No. We block predictions, prophecy-like claims, and instructions that could cause fear, self-harm, financial loss, or unsafe behavior. The Oracle is designed to empower you, not direct your life choices.
  1. It’s personalized and paced to you. We honor traditional wisdom and also offer a modern, flexible framework that focuses on self-discovery, daily actions, and compassion.

5. Safety & Boundaries

  1. Data is stored in reputable, secure cloud infrastructure. For U.S. users, data is typically stored in the U.S. For other regions, storage location may vary by compliance needs.
  1. App logs: typically ~90 days for security/operations, then deleted or aggregated.
  2. Backups: encrypted and kept only as long as needed for resilience; they roll off on a schedule.
  3. Crisis-flagged sessions: see Logging & Admin Review below.
  1. We require valid legal process (e.g., subpoena, court order, or warrant) and we notify users unless legally prohibited. If content is end-to-end encrypted in Private Mode, we cannot decrypt it. See our Law Enforcement Guidelines page for details.

6. Logging, Admin Review & Future-Proofing

  1. We use multiple layers of protection: Separation of data: identity info, payment tokens, and recovery content live in separate, protected stores.
  2. Encryption: data is encrypted in transit (HTTPS/TLS) and at rest using strong industry standards.
  3. Least-privilege access: production data is not visible to staff by default; all rare “break-glass” access is time-limited, approved, and audited.
  4. Minimization: we collect the least amount of personal information needed to operate the service.

Yes. We maintain an Admin Portal where trained staff can update:

    1. Response libraries (greetings, questions, takeaways)
    2. Crisis keyword lists and resource links
    3. Tone and session flow rules (non-code configurations) These updates let us rapidly improve safety and quality without redeploying the whole app.

7. Third-Party Services & Integrations

Common services include:

    1. Payments: Stripe (tokenized—no card storage by us)
    2. AI processing: OpenAI models (we minimize personal information in requests)
    3. Security/edge: modern WAF/DDoS/bot protections
    4. Email & notifications: reputable transactional providers
    5. We perform vendor reviews and limit what each provider can access.
  1. We avoid sending personal identifiers with recovery content. Where possible, we send pseudonymous references. If you enable Private Mode, select content is encrypted on your device first.

8. Community, Ambassadors & Events

  1. No. Ambassadors help coordinate events and outreach. They do not see your journals or private Oracle interactions.
  1. Through sponsors, donors, and grants. We may share aggregate, anonymized impact metrics (e.g., attendance totals), but not personal content.

9. Compliance, Rights & Policies

  1. SOBERSINQ is not a medical provider and generally doesn’t act as a HIPAA covered entity. We still follow strict privacy and security practices and use reputable vendors. If we ever provide HIPAA-regulated services, we will do so using compliant infrastructure and agreements.