SFFC Mobile Application Privacy Policy
| Application name | SFFC Care Engagement System (the "SF App") |
| Published by / Developer of record | Safe Families for Children Alliance, an Illinois nonprofit corporation, EIN 45-3194102 ("SFFC") |
| Effective date | 9/1/2026 |
| Last updated | 8/26/2026 |
| Permanent policy URL | www.safe-families.org/app-privacy |
| Data deletion request URL | www.safe-families.org/app-privacy |
| Privacy Officer | Abel Ortiz · privacy@safefamilies.net · 773-653-2200 |
1. About This Policy and How to Reach It
This Privacy Policy explains what information the App collects, how it is collected, how it is used, who it is shared with, how long it is kept, how it is protected, and the choices and rights available to you. It applies to the SFFC mobile application on iOS and Android, the SFFC web portal that supports it, and the servers and services that operate behind it.
This Policy is:
- Available at an active, publicly accessible, non-geofenced URL that is not password protected and is not delivered as a PDF;
- Linked in the App Store Connect privacy policy field and, in the Google Play Console privacy policy field;
- Accessible inside the App at any time without logging in, from the sign-in screen and from Menu → Legal & Privacy → Privacy Policy;
- Presented in full during account activation and re-presented for affirmative acknowledgment whenever it is materially changed.
SFFC is the entity named in the App's App Store and Google Play listings and is the controller and, where applicable, the HIPAA covered entity or business associate responsible for information handled through the App.
↑ Back to top2. Who This Policy Covers
The App is a closed, invitation-only, role-based application. It is not a consumer social product and it is not available for open public registration. This Policy covers four categories of users and one category of data subject:
| Role | Who they are | How they get access |
|---|---|---|
| Workforce users | SFFC employees, family coaches, family coach supervisors, supervisors, program directors, and contracted case management staff | Account provisioned by SFFC administrator only |
| Volunteer users | Individuals applying to become, or serving as, resource friends, family friends and/or hosting families | Self-initiated application, then SFFC approval |
| Circle of Support team members | Approved community members and volunteers organized into support teams around a family or program | Invitation by SFFC staff |
| Family / participant users | Adults in families receiving Family Friends, parent mentoring, or hosting services, and their authorized representatives | Invitation by SFFC staff after service enrollment |
| Family members who are not users | Children, other household members, and collateral contacts described in records, but who do not hold accounts | No account; information about them is entered by workforce users |
Uploads come from all three account-holding groups. Workforce users, volunteers, and families receiving services can each upload documents to the App, including medical and behavioral health records and legal documents. Uploaded documents are protected according to their contents, not according to who uploaded them — see Sections 4.4 and 4.5.
Children do not hold accounts. The App is not directed to children and no one under 18 may create or hold an App account. Information about minor children is entered only by authorized workforce users under Section 13.
↑ Back to top3. Summary of Our Core Commitments
- We do not sell personal information. We have never sold it and we do not exchange or transfer personal or sensitive user data to any third party for monetary or other valuable consideration.
- We do not use the App for advertising. There is no advertising SDK, no ad identifier collection, no ad network, no retargeting, and no ad measurement in the App.
- We do not track you across other companies' apps or websites. The App does not implement the App Tracking Transparency tracking permission because it performs no tracking as Apple defines it, and it does not read the device advertising identifier.
- We do not use your information — and specifically do not use protected health information or substance use disorder records — to train, fine-tune, or improve any artificial intelligence or machine learning model, whether ours or a third party's.
- We collect the minimum necessary. Every field, permission, and disclosure is limited to what is required for the specific program function it supports.
- You can delete your account and your data from inside the App, as described in Section 15.
4. Information We Collect
We collect information in four ways: (a) you provide it directly; (b) an authorized SFFC workforce user enters it about a family receiving services; (c) it is generated automatically by your use of the App; and (d) we receive it from a third party you authorized, such as a background check vendor or a referring agency.
4.1 Account and identity information (all users)
Name; role; SFFC program affiliation; email address; mobile phone number; username; hashed authentication credentials; multi-factor authentication method and device enrollment; profile photo (optional); preferred language; account status and permission level; time zone; and the terms and policy versions you accepted with date and time.
4.2 Family notes and service records (about families receiving services)
Entered by staff and volunteers about families with an open referral for Family Friend and Hosting services:
- Family and household composition, including names, ages, dates of birth, and relationships of adults and children;
- Contact information and address;
- Referral source and referral reason, which may include a child welfare agency, court, treatment provider, or self-referral;
- Case identifiers, program enrollment dates, service plan goals, and service authorization details;
- Progress notes, contact notes, visit notes, supervision and monitoring observations, missed-visit records, and safety observations;
- Assessments, screening results, and risk and protective factor documentation;
- Health and behavioral health information relevant to service delivery, including diagnoses, medications, treatment appointments, accommodations, and disability-related needs;
- Substance use disorder ("SUD") information, including SUD diagnosis, treatment participation, treatment program identity, testing results, recovery status, and related counseling information, where a family has authorized its disclosure to SFFC or where SFFC operates a Part 2 program;
- Child welfare, court, safety plan, and protective services information;
- Incident reports, critical incident and mandatory reporting records;
- Materials the family or worker uploads, including documents, photographs, and scanned records.
This category is treated as the most sensitive data in the App. It is access-controlled at the individual case level, is not visible to volunteers or community members, and is not surfaced in group chat, notifications, or material needs requests.
4.3 Volunteer application and credentialing information (volunteer users)
Collected when a person applies to be a volunteer (Host Family, Family Friend, Family Coach, Resource Friend and other Safe Family volunteer roles). Maintained for the duration of volunteer service.
- Application responses: legal name and any former names, date of birth, Social Security number only where required to run a statutorily mandated background screening, home address and address history, phone, email;
- Motivation statements, experience, availability, service preferences, languages spoken, and capacity limits;
- Uploaded credential documents: reference letters and the identity and contact details of references; background check results and consents; fingerprint-based criminal history and child abuse and neglect registry results; sex offender registry checks; driver license image, number, class, expiration, and endorsements; motor vehicle record; automobile insurance declarations page, carrier, policy number, coverage limits, and expiration; health clearance documentation where required by SFFC; training certificates and completion records;
- Interview notes, home safety checklist with required supporting documents and approval, denial, restriction, suspension, or termination decisions and their reasons;
- Service history, hours logged, families served, supervisory feedback, and any allegations, investigations, or corrective actions.
Document uploads are used only to determine and maintain your eligibility to serve, to satisfy SFFC certification, contract, funder, and insurance requirements, and to protect the safety of children and families. Uploaded credential documents are visible only to SFFC workforce users whose role includes volunteer screening or supervision. They are never visible to other volunteers, to Circle of Support team members, or to families.
4.4 Medical and behavioral health documents uploaded to the App
Who can upload: SFFC workforce users, volunteers, and families receiving services may upload medical and behavioral health documents through the App's secure upload feature.
What may be uploaded:
- Immunization records and vaccination histories, for children and for adults;
- Medication lists, prescriptions, dosing schedules, and medication administration instructions, including instructions a hosting-provider must follow while a child is in their care;
- Allergy and dietary restriction documentation, and emergency action plans such as asthma, seizure, anaphylaxis, or diabetes plans;
- Treatment plans and care plans issued by physicians, nurse practitioners, therapists, psychiatrists, counselors, behavioral health providers, and substance use disorder treatment programs, including behavior support plans, individualized education or health plans, and discharge and aftercare plans;
- Provider orders, referrals, appointment summaries, visit notes, after-visit summaries, lab and screening results, and letters from treating providers;
- Physical examination forms, immunization records, health clearances, and developmental or behavioral assessment reports;
- Insurance and Medicaid coverage documents where needed to coordinate services;
- The identity and contact information of treating providers, practices, clinics, and treatment programs;
- Power of Attorney for Health Care of a Minor, signed by participating parent when their child(ren) are receiving hosting service.
How this information is treated:
- Every document in this category is treated as protected health information and is governed by Section 8, regardless of who uploaded it. Documents that identify an individual as having or having had a substance use disorder — including behavioral health treatment plans, medication-assisted treatment records, and any document originating from a federally assisted SUD program — are additionally governed by the more restrictive Part 2 rules in Section 9, including the rule that use or disclosure for treatment, payment, or health care operations generally requires written consent.
- A family's upload of a document does not, by itself, authorize us to share it with anyone. Uploading is not consent to disclosure. Sharing beyond SFFC requires a separate written HIPAA authorization or Part 2 consent, or an independent legal basis.
- Volunteer access is strictly need-to-know and minimum necessary. A hosting-provider or family friends caring for a child sees only the specific safety-critical items required to care for that child safely during their assignment — typically allergies, current medications and administration, emergency action plans, and emergency contacts. Volunteers do not receive diagnoses, psychiatric or behavioral health treatment plans, SUD information, full medical histories, or a parent's health records unless the family gives a specific written authorization naming that volunteer and that information and the reason the volunteer is receiving that information. Volunteer access is time-limited to the assignment, is revoked at its conclusion, and is audit-logged.
- Volunteers uploading their own health documents — for example an immunization record, or physical exam form required for licensure — have that information used only to establish and maintain their own eligibility to serve. It is visible only to SFFC screening and supervisory staff, is never shown to families or other volunteers, and is not used for any employment or benefits decision beyond eligibility to serve.
- Documents in this category are stored encrypted, are excluded from group and direct chat unless the poster affirmatively overrides a warning within a care team channel, are never attached to material needs requests, are never included in push notification content, and are excluded from crash and diagnostic reporting.
- We use these documents only to deliver and coordinate services safely, to meet SFFC certification and funder requirements, and to respond to emergencies. We do not use them for research, marketing, fundraising, or artificial intelligence training.
4.5 Legal documents uploaded to the App
Who can upload: SFFC staff and volunteers may upload legal documents relevant to a referred family file or to a volunteer's file.
What may be uploaded:
- Court orders, including custody, visitation, guardianship, conservatorship, dependency, protective and no-contact orders, child support orders, orders authorizing or restricting services, and orders concerning the disclosure of records;
- Legal notices, including hearing notices, petitions, summonses, complaints, service-of-process documents, agency notices, appeal notices, and notices of case closure;
- Subpoenas, warrants, and other legal process, including subpoenas duces tecum, administrative demands, search warrants, and law enforcement requests;
- Case plans and service plans ordered or approved by a court, safety plans, and guardian ad litem or CASA reports;
- Powers of attorney, guardianship and custody letters, consent to treat authorizations, immigration and identity documents relevant to eligibility, and legal name change orders;
- Attorney correspondence, releases, settlements, and litigation hold notices.
How this information is treated:
- Legal documents routinely contain the names and details of children, health and behavioral health information, and substance use disorder information. They are therefore treated as among the most sensitive records in the App and are protected under Sections 8, 9, and 10 according to their contents. A court order that recites SUD treatment history is handled as a Part 2 record.
- Access is restricted to the assigned SFFC employee, an SFFC supervisor with a documented need, and SFFC's legal counsel and Privacy Officer. Volunteers may be shown only the operative terms they must follow — for example, that a named individual may have no contact, or that exchanges occur at a supervised location — and are not given the underlying order, petition, or report unless SFFC's counsel determines it is necessary and lawful.
- Uploading a subpoena, warrant, or demand into the App does not authorize SFFC to release anything, and it does not create consent. All legal process is routed immediately to the Privacy Officer and SFFC's legal counsel for review under Section 10 before any record is produced. The App contains no self-service export or production feature that responds to legal processes.
- A protective order or no-contact order uploaded by a family will be acted on for safety purposes — including restricting an individual's access, removing them from a team or channel, and reassigning a volunteer — and this may be done without the other party's consent where necessary to protect a person from harm.
- Legal documents are excluded from group chat, direct chat, notification content, material needs requests, and any volunteer-facing or community-facing screen. Uploading a legal document triggers an audit log entry and a notification to the assigned supervisor.
- We use legal documents only to comply with a court's directions, to determine who may lawfully receive information and who may have contact with a child, to protect safety, to meet SFFC certification and reporting duties, to preserve records under a litigation hold, and to obtain legal advice.
4.6 Community support team messaging information
Group chat and one-to-one direct chat content; message metadata including sender, recipients, team identifier, timestamps, read and delivery status; attachments you choose to send; reactions; and reports of abusive or inappropriate messages together with the reported content.
Messaging is not end-to-end encrypted. Messages are encrypted in transit and at rest and are stored on SFFC-controlled systems so that SFFC can meet its supervision, safety, mandatory reporting, licensing, records retention, and legal obligations. Authorized SFFC staff may access message content for those purposes, and the App displays a persistent in-channel notice stating so.
4.7 Material needs request information
Item requested; quantity; size; urgency; general delivery or pickup area; the requesting SFFC employee or volunteer; the program; responses, commitments, and fulfillment status; and delivery confirmation.
Material needs requests are de-identified as to the receiving family by design. The App does not permit family names, addresses, dates of birth, case identifiers, health information, SUD information, child welfare status, or the fact of enrollment in monitoring or treatment services to be broadcast to community members. Requests distributed outside the family's own care team reference a program and a general geographic area only. A field-level warning and a pre-send confirmation screen enforce this rule, and free-text fields are reviewed before broad distribution.
4.8 Device, technical, and usage information (automatically collected)
Device model and manufacturer; operating system and version; App version and build; language and locale; crash logs, diagnostic logs, and stack traces; IP address; push notification token; approximate general location derived from IP for security purposes only; session start and end times; feature usage and screen-view events tied to your account for audit purposes; and authentication and authorization events.
In future releases the App will generate and retain HIPAA-required audit logs recording who accessed which record, when, from what device, and what action was taken. Audit logs are a security and compliance control; they are not used for marketing or profiling.
4.9 Device permissions the App may request
Each permission is optional, is requested at the moment of use with a plain-language purpose string that immediately precedes the system prompt, is used only for the stated purpose, and can be revoked at any time in your device settings. Revoking a permission does not lock you out of the App; a manual alternative is provided wherever one is possible.
| Permission | Why we ask | If you decline |
|---|---|---|
| Camera | Photograph a reference letter, driver license, insurance card, or other credential document; capture a photo you choose to attach to a note or message | Upload an existing file from your device instead |
| Photos / Files | Attach an existing document or image. We use the system picker, so the App receives only the specific items you select and never reads your full photo library | Use the camera, or submit documents by secure email or in person |
| Notifications | Alert you to a new message, a request for materials, an assignment, credential expiring, or a required action | The App works normally; check the App for updates. Notifications are never required to use any feature |
| Precise location | Optional only, and only where a program requires geo-verified visit check-in | Enter the visit location and time manually |
| Microphone | Only if you choose to record a voice message. Off by default | Type your message |
| Contacts | Not requested. The App does not read your contacts, does not build a contact database, and offers no "select all" invite feature | — |
| Biometrics (Face ID / Touch ID / fingerprint) | Unlock the App locally. Biometric data never leaves your device and is never transmitted to us | Use your passcode or password |
The App does not collect an inventory of other apps installed on your device, does not collect SMS or call log data, and does not access Health Connect or Apple Health.
↑ Back to top5. How and Why We Use Information
We use information only for the following purposes:
- To deliver services. Coordinate and document Family Friends, hosting care and providing service referrals and material goods to families; maintain family notes and service records; schedule and staff visits; match volunteers to families; communicate with care teams.
- To screen, approve, and supervise volunteers. Verify identity, driving eligibility, insurance coverage, references, and criminal and child abuse registry history; make and document approval decisions; monitor credential expirations; supervise and, where necessary, restrict or terminate service.
- To protect the safety of children, families, and volunteers. Investigate incidents, allegations, and safety concerns; make mandated reports of suspected child abuse or neglect; respond to emergencies and serious threats.
- To operate community support teams. Enable group and direct messaging, moderate content, and respond to reports of abuse or misuse.
- To coordinate material goods donations for families receiving services, without exposing family identity or program details to community members.
- To administer medication, allergy, and emergency care instructions so that a hosting provider or family friends can safely follow a treating provider's directions for a child in their care, and to confirm required immunizations and health clearances.
- To comply with court orders and respond lawfully to legal process, to determine who may lawfully receive information, who holds custody or decision-making authority, and who may have contact with a child, and to preserve records under a litigation hold.
- To meet legal, licensing, accreditation, funder, and contractual obligations, including recordkeeping, audits, program monitoring, cost reporting, and grant reporting. Reports to funders and government agencies are made in aggregate or de-identified form unless the recipient is legally entitled to identifiable information and a lawful basis for disclosure exists.
- To secure the App, authenticate users, maintain audit logs, detect and prevent unauthorized access, fraud, and abuse, and investigate security incidents.
- To support and improve the App, diagnose crashes, fix defects, and provide technical support. Development, testing, and demonstration are performed with synthetic or de-identified data, never with live family records.
- To communicate with you about your account, your assignments, required training, credential renewals, and service-related notices.
We do not use information for behavioral advertising, cross-context behavioral profiling, automated decision-making that produces legal or similarly significant effects without human review, or the training of artificial intelligence models. We do not repurpose information collected for one of the above purposes for a materially different purpose without obtaining new consent or unless expressly permitted by law.
↑ Back to top6. Legal Bases and Consent
Depending on the user and the information, we rely on: your consent; your written HIPAA authorization or Part 2 consent; the performance of a SFFC service agreement or volunteer agreement; compliance with a legal obligation such as licensing, mandated reporting, or funder requirements; the vital interests of a child or other person where there is a serious and imminent threat; and our legitimate interests in operating a safe, accountable program, where those interests are not overridden by your rights.
Where we rely on consent, you may withdraw it at any time as described in Section 15. Withdrawal is effective going forward and does not affect actions already taken in reliance on the consent and does not require us to delete records we are legally obligated to retain.
↑ Back to top7. How We Share Information
We share information only as described below. Every recipient is bound by written contract to protect the information at a level equal to or greater than the protections in this Policy and as required by the Apple App Store Review Guidelines, the Google Play User Data policy, HIPAA, and 42 C.F.R. Part 2, and to use it only for the purpose we specify.
7.1 Inside SFFC
Access is role-based and least-privilege. SFFC employees see only their assigned families. Volunteers see only the families they are assigned to serve and only the information necessary to serve them safely. Circle of Support team members see only team messaging and de-identified material needs requests. Volunteer credential files are visible only to screening and supervisory staff. Every access is logged.
7.2 Service providers (business associates and subprocessors)
| Category | Purpose | Access to family notes / SUD data |
|---|---|---|
| Cloud hosting and database provider — [AWS / Azure / GCP], United States regions | Host the App, database, and encrypted document storage | No |
| Authentication and identity provider — [vendor] | Sign-in, multi-factor authentication | No |
| Push notification delivery — Apple Push Notification service and Firebase Cloud Messaging | Device alert only. Payloads are generic (e.g. "You have a new notification"). No family names, notes, clinical content or SUD data. Full content is loaded only after the user opens the App. | No |
| Crash and diagnostic reporting [vendor] | No third-party crash SDK. Optional Zendesk "Report a Problem" sends volunteer name, email, and user-written text only — not family notes or SUD records. | No |
| Transactional email and SMS — [vendor] | Accounts, security, and scheduling notices. Content limited to non-clinical operational text | No |
| Background screening and motor vehicle records — [vendor(s)] | Statutorily required volunteer screening, performed only with your separate written authorization | No |
| Document storage and e-signature [vendor] | Store credential documents and capture signatures | Credential documents only |
| Secure destruction / records vendor | Certified destruction at end of retention | Limited, under BAA |
Each service provider that may create, receive, maintain, or transmit protected health information on our behalf has executed a HIPAA Business Associate Agreement, and each that may handle Part 2 records has executed a Qualified Service Organization Agreement.
7.3 Other disclosures
- With your written authorization or Part 2 consent, to the person or entity you designate.
- To referring and partner agencies — child welfare agencies, courts, guardians ad litem, treatment providers, schools — only where a valid authorization, consent, court order, or specific legal authority permits it.
- To public authorities as required by law, including mandatory reports of suspected child abuse or neglect, reports required by professional licensure, and responses to valid legal process. Part 2 records are disclosed only as Section 9 permits.
- To prevent or lessen a serious and imminent threat to the health or safety of a person or the public, to the extent permitted by 45 C.F.R. § 164.512(j) and, for Part 2 records, only within the narrow bounds Part 2 allows.
- To funders, auditors, SFFC certification bodies, and accreditors for audit and program evaluation, using de-identified or aggregate data wherever the purpose can be achieved that way, and otherwise underwritten confidentiality and, where applicable, Part 2 audit and evaluation terms.
- In a merger, acquisition, asset transfer, or program transfer, only with legally adequate advance notice to affected individuals, and only where the successor agrees in writing to honor this Policy and all HIPAA and Part 2 obligations.
We do not disclose information to data brokers. We do not disclose information to third-party artificial intelligence services. We do not permit any recipient to use the information for its own marketing.
↑ Back to top8. HIPAA: Your Health Information Rights and Our Duties
Where SFFC acts as a HIPAA covered entity, or as a business associate of a covered entity, protected health information ("PHI") handled through the App is governed by the HIPAA Privacy, Security, and Breach Notification Rules (45 C.F.R. Parts 160 and 164) in addition to this Policy.
Uses and disclosures that may be made without your written authorization are limited to those permitted by 45 C.F.R. §§ 164.502 through 164.512, including treatment, payment, and health care operations; required disclosures to you and to HHS; public health and abuse reporting; health oversight; judicial and administrative proceedings; averting a serious threat to health or safety; workers' compensation; and disclosures to your personal representative. All other uses and disclosures will be made only with your written authorization, and you may revoke that authorization in writing at any time, except to the extent we have already acted in reliance on it.
Uses and disclosures that always require your written authorization include psychotherapy notes; SUD counseling notes; marketing communications; and any sale of PHI, which SFFC does not engage in.
You have the right to:
- Inspect and obtain a copy of your record, including an electronic copy, and direct us to transmit it to a person you designate (45 C.F.R. § 164.524);
- Request an amendment to your record (§ 164.526);
- Receive an accounting of disclosures (§ 164.528);
- Request restrictions on uses and disclosures, including a mandatory restriction on disclosure to a health plan for services you paid for in full out of pocket (§ 164.522);
- Request confidential communications by an alternative means or at an alternative location (§ 164.522(b));
- Receive notice of a breach of your unsecured PHI (Subpart D of Part 164);
- Obtain a paper copy of this notice on request; and
- File a complaint with us or with the HHS Office for Civil Rights without retaliation.
Notice regarding redisclosure. Information disclosed pursuant to the HIPAA Privacy Rule may be subject to redisclosure by the recipient and may no longer be protected by the HIPAA Privacy Rule (45 C.F.R. § 164.520(b)(1)(ii)(H)).
More protective law controls. Where state law, child welfare confidentiality law, 42 C.F.R. Part 2, or a funder requirement is more protective than HIPAA, the more protective standard governs, and this Policy is to be read accordingly.
SFFC is required by law to maintain the privacy and security of PHI, to give you this notice of our legal duties and privacy practices, to notify you following a breach of unsecured PHI, and to abide by the terms of this notice currently in effect. We reserve the right to change this notice and to make the new terms effective for all information we maintain, and we will make any revised notice available in the App, at the policy URL, and on request.
↑ Back to top9. 42 C.F.R. Part 2: Substance Use Disorder Records
The App may hold records that identify an individual, directly or indirectly, as having or having had a substance use disorder, and that were created by or received from a federally assisted SUD program. Those records are protected by 42 C.F.R. Part 2, which is more restrictive than HIPAA, and are handled as follows.
9.1 Consent is required for most uses and disclosures
Unlike other health information, use or disclosure of Part 2 records for treatment, payment, or health care operations generally requires the patient's written consent. A valid Part 2 consent must identify the patient, the recipient, the amount and kind of information to be disclosed, the purpose, the right to revoke, and an expiration event or date. You may give a single consent covering all future uses and disclosures for treatment, payment, and health care operations, and you may revoke that consent at any time, in writing or through the App, except to the extent action has already been taken in reliance on it.
Separate, specific written consent is required for the use or disclosure of SUD counseling notes, and for any use or disclosure of records for civil, criminal, administrative, or legislative proceedings. Consent for proceedings may not be combined with consent for any other purpose.
Each disclosure we make with your consent is accompanied by either a copy of the consent or a clear written explanation of the scope of the consent.
9.2 Prohibition on use in legal proceedings
Substance use disorder treatment records received from programs subject to 42 C.F.R. Part 2, or testimony relaying the content of such records, shall not be used or disclosed in civil, criminal, administrative, or legislative proceedings against the individual unless based on written consent, or a court order after notice and an opportunity to be heard is provided to the individual or the holder of the record, as provided in 42 C.F.R. Part 2. A court order authorizing use or disclosure must be accompanied by a subpoena or other legal requirement compelling disclosure before the requested record is used or disclosed.
A subpoena, warrant, or administrative demand alone is never sufficient authority for us to release a Part 2 record.
9.3 Redisclosure restriction and required notice
Part 2 records disclosed by SFFC are accompanied by the following notice:
This record was disclosed to you from records protected by federal confidentiality rules (42 C.F.R. Part 2). The federal rules prohibit you from making any further disclosure of information in this record that identifies a patient as having or having had a substance use disorder either directly, by reference to publicly available information, or through verification of such an identification by another person, unless further disclosure is expressly permitted by the written consent of the individual whose information is being disclosed or as otherwise permitted by 42 C.F.R. Part 2. A general authorization for the release of medical or other information is NOT sufficient for this purpose (see 42 C.F.R. § 2.31). The federal rules restrict any use of the information to investigate or prosecute with regard to a crime any patient with a substance use disorder, except as provided at 42 C.F.R. §§ 2.12(c)(5) and 2.65.
A HIPAA covered entity or business associate that receives Part 2 records under a TPO consent may redisclose them in accordance with HIPAA but may not use or disclose them in a legal proceeding against the patient absent specific consent or a qualifying court order.
9.4 Additional Part 2 protections and rights
- Disclosures without consent are permitted only in the narrow circumstances Part 2 allows: medical emergencies; scientific research; audit and evaluation; certain child abuse reporting as permitted by § 2.12(c)(6); crimes on program premises or against program personnel; de-identified disclosures to public health authorities; and pursuant to a qualifying court order.
- The App does not confirm or deny enrollment. No feature of the App reveals to any volunteer, community member, or outside party that an individual is or has been enrolled in SUD treatment. SUD information is never included in group chat, direct chat, push notification payloads, material needs requests, or volunteer-facing screens.
- Access controls. Part 2 records in the App are restricted to a named list of workforce users with a documented need, and every access is audit-logged. Part 2 records are flagged in the interface so that users know special rules apply. Consistent with the 2024 final rule, we are not required to segregate Part 2 records from other records, and we instead apply the Part 2 restrictions to the combined record.
- Your Part 2 rights include: the right to receive this Patient Notice; the right to revoke consent; the right to an accounting of disclosures; the right to request restrictions on certain disclosures; the right to opt out of fundraising communications; and the right to file a complaint directly with the Secretary of HHS and concurrently with SFFC, without retaliation.
- Breach notification. Breaches of Part 2 records are handled under the HIPAA Breach Notification Rule.
- Penalties. Violations of Part 2 are subject to the same civil and criminal enforcement authorities that apply to HIPAA violations (42 U.S.C. §§ 1320d-5, 1320d-6).
9.5 Fundraising
SFFC does not use App data for fundraising. If that ever changes, we will provide a clear opt-out in every fundraising communication and in the App, and we will honor opt-outs permanently. Part 2 patients and HIPAA individuals may opt out of fundraising communications at any time by contacting the Privacy Officer.
↑ Back to top10. Child Welfare Records, Legal Documents, and Legal Process
10.1 Child welfare and other confidential program records
Records relating to child protective services referrals, court involvement, safety plans, and dependency proceedings are confidential under state law and court rule and are disclosed only as those authorities permit. Nothing in this Policy limits SFFC's mandatory obligation to report suspected child abuse, neglect, or exploitation, or a serious and imminent threat to any person's safety, to the appropriate authorities. Mandated reports may be made regardless of consent, and Part 2 records are used in that process only as § 2.12(c)(6) and applicable state law allow.
10.2 Court orders, legal notices, and case documents
Court orders and legal notices uploaded to the App are used to comply with the court's directions, to identify who holds custody, guardianship, or decision-making authority, to determine who is a personal representative entitled to access a record, to enforce no-contact and supervised-contact requirements, and to document that SFFC met its obligations. Where a court order restricts our disclosure of information or restricts a parent's or other person's access to a child or to records, the order controls over any consent, authorization, or request to the contrary, and we will follow it.
Sealed records, records filed under seal, guardian ad litem and CASA reports, and juvenile court records are treated as confidential regardless of who uploaded them and are not redistributed inside or outside the App except as the court permits.
10.3 How we respond to subpoenas, warrants, and other legal process
A subpoena, warrant, or demand can be uploaded into the App so that it is preserved and routed for review. Uploading it does not trigger a disclosure and does not authorize one. Our process is:
- Immediate routing. The document is routed to the Privacy Officer and SFFC's legal counsel. No workforce user, volunteer, or family member may release a record in response to legal process on their own, and the App provides no self-service bulk export or production capability.
- Legal review. Counsel evaluates whether the process is valid, whether it was properly served, what it actually compels, whether a protective order or motion to quash is appropriate, and what narrower production would satisfy it.
- HIPAA analysis. Where the request reaches protected health information, we release it only as 45 C.F.R. § 164.512(e) and (f) permit — which, for a subpoena that is not accompanied by a court order, requires satisfactory assurance that the individual was notified or that a qualified protective order was sought — and we produce only the minimum necessary.
- Part 2 analysis. For any record subject to 42 C.F.R. Part 2, a subpoena, warrant, or administrative demand standing alone is never sufficient authority. Part 2 records may be released only with the patient's specific written consent for use in a proceeding, or under a court order issued after notice and an opportunity to be heard, and that court order must be accompanied by a subpoena or other compelling legal requirement before the record is disclosed. See Section 9.2. We will assert these protections on the patient's behalf.
- Child welfare and state law analysis. Confidential child welfare, juvenile court, and sealed records are withheld unless the issuing authority has jurisdiction over them and state law permits release.
- Notice to you. Except where we are legally prohibited from giving notice, where notice would be futile because the requester already holds the record, or where notice would create a risk to a person's safety or interfere with a lawful investigation, we will make reasonable efforts to notify the affected individual before we produce their record, so that they have an opportunity to object, and we will tell them what was requested and what we intend to produce.
- Documentation. Every request, our analysis, our objections, and every record produced are logged in our accounting of disclosures and are available to you under Section 8.
- Litigation hold. Once we receive legal process or reasonably anticipated litigation, the affected records are placed on hold and are exempt from routine deletion until the hold is released, as Sections 14 and 15.3 describe.
Emergency and exigent law enforcement requests are handled the same way, with counsel available on an urgent basis. We do not provide voluntary access to records for law enforcement absent a lawful basis, and we do not grant any third party direct or standing access to the App.
↑ Back to top11. Group Chat and Direct Messaging: What You Should Know
Because messaging carries the highest risk of accidental disclosure, the following rules apply and are displayed in the App:
- Anything you post in a group chat is visible to every member of that group. Membership changes over time and new members may be able to see message history from before they joined, unless the team is configured otherwise.
- Direct messages are visible to the sender, the recipient, and authorized SFFC staff for supervision, safety, mandatory reporting, licensing, records retention, and legal compliance. Messaging is not private from SFFC and is not end-to-end encrypted.
- Do not post protected health information, substance use disorder information, diagnoses, medications, treatment or recovery status, child welfare or court involvement, addresses, dates of birth, Social Security numbers, financial information, photographs of children, or any family's identity in any chat that includes anyone outside that family's authorized care team.
- Do not send medical documents or legal documents through chat. Immunization records, medication instructions, treatment plans, court orders, legal notices, subpoenas, and warrants must be submitted through the secure document upload feature, which applies the correct access controls, audit logging, and retention rules. Chat attachments do not. The App warns you and blocks distribution when it detects an attempted document upload to a channel that includes anyone outside the care team.
- Messages and attachments are retained under Section 14 and may be produced in response to lawful legal process, subject to the Part 2 limits in Section 9.2.
- You may report a message, mute a channel, leave a voluntary team, and delete a message you sent from other users' views. Deleting a message from view does not remove it from SFFC's audit and retention records where retention is legally required.
- SFFC does not read message content for advertising, profiling, or product analytics.
12. Material Needs Requests: Privacy by Design
When a SFFC workforce user or volunteer posts a request for material goods to community members:
- The request identifies the item, quantity, size, urgency, program, and a general geographic area only.
- It never identifies the family and never reveals that a family is enrolled in Family Friends, respite, SUD treatment, or child welfare services.
- Free-text fields display an inline warning, and a confirmation screen requires the poster to affirm that no identifying or health information is included before the request is distributed beyond the care team.
- Community members who respond see only the request and the SFFC staff coordination contact. Community members never receive a family's name, address, phone number, or any record. Delivery is coordinated through SFFC or through a family-approved drop point.
- Responder information — name, contact, and what was committed — is retained for in-kind donation acknowledgment, audit, and funder reporting.
13. Children's Privacy
The App is intended for use only by adults 18 and older. We do not knowingly permit anyone under 18 to create an account, and we do not knowingly collect personal information directly from children. The App is not directed to children, contains no advertising, and is not listed in a children's category.
Information about minor children — names, dates of birth, health and behavioral health needs, school information, visit observations, and photographs — is entered by authorized SFFC workforce users as part of the service record, under the authority of the parent or legal guardian's service agreement and consent, a court order, or a lawful child welfare referral, and is protected as described throughout this Policy. Where the Children's Online Privacy Protection Act applies to any collection of information from a child through the App, we obtain verifiable parental consent before that collection, collect no more than is reasonably necessary for the activity, do not condition participation on providing more information than is reasonably necessary, do not use it for advertising or profiling, retain it only as long as necessary for the purpose for which it was collected, and honor a parent's or guardian's request to review or delete it.
Parents and legal guardians may contact the Privacy Officer to review, request correction of, or request deletion of information about their child, subject to the legal retention obligations in Section 14 and to any court order or child welfare restriction.
If we learn that a person under 18 has created an account, we will disable the account and delete the associated account data promptly.
↑ Back to top14. Data Retention
We keep information only as long as necessary for the purpose it was collected, to meet legal, licensing, funder, accreditation, and insurance obligations, and to resolve disputes. Our schedule:
| Record | Retention period |
|---|---|
| Family notes and service records — adult participant | 10 years after case closure, or as required by state law, licensure, or funder terms, whichever is longer |
| Family notes and service records — where a minor is a subject | Until the child reaches age 18 or 10 years after case closure, whichever is later |
| Medical and behavioral health documents uploaded about a family — immunization records, medication instructions, provider treatment plans | Retained with the service record for that family, per the two rows above |
| Medical and behavioral health documents uploaded by a volunteer about themselves | Duration of service plus 7 years, or as licensure requires |
| Court orders, legal notices, and case legal documents | Life of the case plus the applicable service-record period above, and no shorter than the period any court order or state law specifies |
| Subpoenas, warrants, demands, our legal analysis, and records produced in response | 6 years as part of the accounting of disclosures under 45 C.F.R. § 164.528, or longer if a hold is in place |
| Substance use disorder records subject to Part 2 | 5 years, and no longer than required; destroyed by a method that renders them unreadable and unrecoverable |
| Volunteer applications — approved | Duration of service plus 7 years |
| Volunteer applications — withdrawn or denied | 7 years, then destroyed, unless a safety concern requires longer |
| Background check and motor vehicle results | Only as long as SFFC certification and contract terms require; results are not retained beyond the eligibility determination period where law permits shorter retention |
| Driver license and insurance images | Until 1 year after expiration or end of service, whichever is later |
| Group and direct chat messages | 7 years, unless subject to a legal hold or an active investigation |
| Material needs requests and fulfillment records | 7 years for in-kind donation and grant audit purposes |
| HIPAA and security audit logs | Not less than 6 years as required by 45 C.F.R. § 164.316(b)(2) |
| HIPAA Notice of Privacy Practices, Part 2 Patient Notice, consents, authorizations, and policy acknowledgments | 6 years from the later of creation or last effective date |
| Account and authentication records | Duration of account plus 2 years |
| Crash and diagnostic logs | 90 days |
| Backups | 30 days rolling, then overwritten |
When a retention period ends, records are securely destroyed or de-identified in accordance with the HIPAA de-identification standard. Records subject to a litigation hold, audit, open investigation, or court order are retained until the hold is released.
↑ Back to top15. Your Rights, Choices, Account Deletion, and Data Deletion
15.1 Rights available to all users
You may, at any time: access and review the information in your profile; correct inaccurate information; withdraw a consent or authorization; adjust or revoke any device permission; turn off notifications; leave a voluntary community team; export a copy of your own data; and ask a question or make a complaint without retaliation.
To exercise a right, contact the Privacy Officer at privacy@safefamilies.net. We verify your identity before acting, respond within 10 days, and will tell you if we need up to 30 additional days. There is no charge for these requests, and we do not discriminate or retaliate against anyone who exercises a privacy right.
15.2 How to revoke consent
Any consent, HIPAA authorization, or Part 2 consent may be revoked, by written notice to the Privacy Officer at privacy@safefamilies.net. Revocation is effective on receipt, going forward. It does not undo actions already taken in reliance on the consent and does not override records we are legally required to retain.
15.3 Account and data deletion
In the App: Menu → Settings → Account → Delete My Account. You will see, before you confirm, exactly what is deleted, what is retained, and why.
On the web, without the App: www.safe-families.org/app-privacy
By other means: privacy@safefamilies.net
When you request deletion, we delete or irreversibly de-identify: your profile and account credentials; your profile photo; device and push tokens; App usage and diagnostic data associated with you; message content you authored, subject to the limits below; and, for volunteer applicants who withdraw or are not approved, your application and uploaded documents. We complete deletion within 30 days of verifying your request, and we instruct our service providers and remove the data from backups within the backup cycle stated in Section 14.
What we must retain, and why. We cannot delete, and we will retain for the periods in Section 14: clinical and service records about families receiving services, which are legally mandated program records; records required by licensing, funders, insurers, or court order; medical and behavioral health documents that form part of a family's service record, and court orders, legal notices, and legal process together with our response to it; HIPAA and Part 2 audit logs and consent documentation; records of a safety incident, allegation, mandated report, or investigation; volunteer screening determinations where a safety concern was identified; financial and in-kind donation records; and records under a litigation hold. Retained records are locked to the minimum necessary access, are no longer used for any operational purpose relating to you and are destroyed at the end of their retention period. We will tell you in writing which categories were retained and the legal basis for each.
Deleting the App does not delete your account or your data. Use the in-app or web deletion path above.
15.4 Additional rights under state and international law
Depending on where you live, you may have additional rights, including the right to know the categories and specific pieces of personal information collected, the sources, the purposes, and the categories of recipients; the right to correction; the right to deletion; the right to portability; the right to opt out of sale, targeted advertising, and profiling — none of which we engage in; the right to limit the use of sensitive personal information; the right not to be discriminated against; and the right to appeal a denial of a request. To appeal, reply to our decision or write to appeals@safefamilies.net; we will respond within [45] days and will tell you how to contact your state attorney general if you remain dissatisfied. An authorized agent may submit a request on your behalf with written proof of authority.
↑ Back to top16. How We Protect Information
We maintain an information security program with administrative, physical, and technical safeguards designed to satisfy the HIPAA Security Rule (45 C.F.R. Part 164, Subpart C) and Part 2:
- Encryption of all data in transit using TLS 1.2 or higher with modern cipher suites and certificate pinning, and of all data at rest using AES-256, including document storage and backups;
- Access control by unique user ID, role-based least-privilege permissions, mandatory multi-factor authentication for all workforce and volunteer accounts, automatic session timeout, device-level passcode or biometric requirement, and remote wipe of App data on a lost device;
- Audit controls recording every record access and administrative action, with regular review for inappropriate access;
- Data minimization in notification payloads, logs, error reports, and analytics, none of which contain clinical content, uploaded document content, or SUD information;
- Upload-specific controls including virus and malware scanning of every uploaded file, file type and size restrictions, storage of documents in an encrypted object store separate from the application database with short-lived signed access URLs, document-level access control lists tied to role and assignment, a visible watermark and download log on documents viewed by volunteers, no caching of document content on the device beyond the active session, and blocked screenshots on document viewers where the operating system supports it;
- Workforce controls including background screening, HIPAA and Part 2 training before access is granted and annually thereafter, confidentiality agreements, and documented sanctions for violations;
- Vendor management including security review, executed Business Associate Agreements and Qualified Service Organization Agreements, and periodic reassessment;
- Risk analysis and risk management conducted at least annually and after any material change, plus penetration testing and vulnerability scanning;
- Contingency planning including encrypted backups, tested restoration, and a documented disaster recovery plan;
- Incident response with a written plan, defined roles, and forensic capability;
- No use of production family data in development, testing, training, or demonstration environments.
No system is perfectly secure. Please protect your device passcode and credentials, use a supported operating system, keep the App updated, and report any suspected compromise to security@SFFC.org immediately.
↑ Back to top17. Breach Notification
If we discover a breach of unsecured protected health information or of Part 2 records, we will notify affected individuals without unreasonable delay and in no case later than 60 days after discovery, and will notify the Secretary of HHS and, where required, prominent media, in accordance with 45 C.F.R. Part 164, Subpart D. We will also provide any notice required by applicable state breach notification law and by our funder and SFFC certification agreements. Notices describe what happened, what information was involved, what we are doing, and what you can do.
↑ Back to top18. Where Information Is Stored and Processed
All App data is stored and processed on servers located in the United States. We do not transfer App data outside the United States, and we do not permit our service providers to store or access it from outside the United States, without a documented lawful transfer mechanism, an executed data protection agreement, and, where required, your consent. If SFFC supports international programs, information collected through those programs is handled under a separate program-specific notice and is not commingled with United States clinical records in the App.
↑ Back to top19. Third-Party Services and Links
The App does not contain advertising SDKs, ad networks, social login, social sharing, or third-party analytics used for marketing. The only third-party code in the App is the operational service provider software described in Section 7.2, each of which is contractually limited to processing information solely on our instructions, is prohibited from using it for its own purposes, and is required to provide protection equal to or greater than this Policy and as required by the App Store Review Guidelines and the Google Play User Data policy. We do not share personal information with any third-party artificial intelligence service.
If the App links to an outside website, that site's own privacy policy governs, and we are not responsible for its practices.
↑ Back to top20. Accessibility and Language
This Policy is available in [English and Spanish] and in accessible formats on request. Contact privacy@safefamilies.net for a translated or accessible copy, or for help understanding it at no cost.
↑ Back to top21. Changes to This Policy
We may update this Policy. When we do, we will change the "Last updated" date, post the revised Policy at the policy URL and in the App, and maintain an archive of prior versions at www.safe-families.org/app-privacy. If a change is material — for example a new category of information, a new purpose, a new category of recipient, or a change to your rights — we will provide advance notice of at least [30] days by in-App notice and email, and where the change materially affects PHI or Part 2 records we will obtain a renewed acknowledgment or, where legally required, a new authorization or consent before the change takes effect as to you. We reserve the right to make revised terms effective for all information we maintain, as HIPAA permits, and will make the revised notice available in the App, at the policy URL, and in paper on request.
↑ Back to top22. Contact Us, and How to Complain
SFFC — Privacy Officer
Abel Ortiz
4300 W. Irving Park Road, Chicago, Illinois 60641
privacy@safefamilies.net · 773-653-2200
Security incidents: privacy@safefamilies.net · Requests and appeals: appeals@safefamilies.net
We will respond to any privacy question or complaint within [10] business days. You will never be retaliated against, penalized, or denied services for filing a complaint.
You may also complain to:
- U.S. Department of Health and Human Services, Office for Civil Rights — 200 Independence Avenue SW, Washington, DC 20201; 1-877-696-6775; hhs.gov/ocr/privacy/hipaa/complaints
- The Secretary of HHS, for an alleged violation of 42 C.F.R. Part 2, concurrently with a complaint to SFFC
- SAMHSA — for questions about substance use disorder confidentiality
- Your state Attorney General — for state privacy law concerns
- Your state child welfare SFFC certification authority — for program SFFC certification concerns
