Peer Support Studio (the “Platform”) is operated by MADe180, LLC (“MADe180,” “we,” “us”), Louisville, Kentucky. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices available to you.
1. Scope and how this policy fits with your BAA
This policy covers three different groups, and the rules differ for each:
- Website visitors — people who visit peersupportstudio.com.
- Account holders — peer support specialists, supervisors and administrators who log in to the Platform on behalf of an organization.
- Participants — individuals receiving peer support services, whose records are entered into the Platform by an organization.
Where an organization uses the Platform to store protected health information (“PHI”), that organization is the covered entity or its business associate, and MADe180 acts as its business associate under the Health Insurance Portability and Accountability Act (“HIPAA”). For that information, the Business Associate Agreement (“BAA”) between us and the organization controls, and it prevails over this policy to the extent of any conflict. We do not use or disclose PHI except as permitted by the BAA, as required by law, or as directed by the organization.
Participants who want to exercise rights over their records should contact the organization that provides their services. We will assist that organization in responding.
2. Information we collect
Website visitors
Basic technical information such as IP address, browser type and pages viewed, plus anything you voluntarily send us (for example, an email to our contact address). We do not require an account to browse the marketing site.
Account holders
- Name, work email address, role, and the organization you belong to
- Authentication data managed through Amazon Cognito (we do not store your password)
- Preferences, such as your selected organization and display settings
- Audit records of actions taken in the Platform, including access to participant records
Participant records (PHI)
Organizations decide what to enter. Depending on how an organization configures its use, records may include identifiers and contact details, intake information, recovery goals and plans, session notes, assessment results, service and attendance logs, uploaded documents, messages, and — where the organization uses those features — session audio recordings and transcripts.
Some organizations serve minors. Where that is the case, participant records may include information about minors, and that information is handled under the organization’s BAA and applicable law. The Platform is not directed to children and minors cannot create their own accounts.
3. How we use information
- To provide, secure, support and improve the Platform
- To authenticate users and enforce organization-level access controls
- To generate the drafts and summaries that Platform features produce (see Section 4)
- To communicate about the service, including security and availability notices
- To meet legal, regulatory and contractual obligations
We do not sell personal information, and we do not share it for cross-context behavioral advertising. We do not use participant records for marketing.
4. How AI features use data
The Platform uses AI to draft documentation and summaries — for example, turning a session transcript or a completed form into a draft note, scoring a note against a documentation rubric, or summarizing a participant’s recorded progress. The following commitments apply:
- Every AI feature that processes participant information runs on infrastructure covered by a signed BAA. AI text generation runs on Amazon Bedrock within Amazon Web Services. Session audio transcription runs on AssemblyAI under a BAA and Qualified Service Organization Agreement.
- Customer data is not used to train AI models. We do not permit our AI providers to use participant information to train, retrain or fine-tune their models.
- AI output is a draft, not a record. Generated text is presented to the peer support specialist for review and editing. Nothing is filed as documentation without a person reviewing it.
- AI processing is logged. When a feature sends participant information for AI processing, we record an audit entry identifying the user, the organization, the feature and the model used.
- AI features that do not involve participant information — such as brainstorming lesson content — may use other providers. These features are not designed to receive participant information, and users are instructed not to enter it.
AI-generated content can be inaccurate or incomplete. It does not constitute clinical, medical, legal or billing advice. See our Terms of Service for the responsibilities that come with using these features.
5. Service providers and subprocessors
We use the following providers to operate the Platform. Providers that may handle PHI do so under a signed BAA.
| Provider | Purpose | May handle PHI |
|---|---|---|
| Amazon Web Services | Hosting, storage, authentication, AI processing (Bedrock), speech synthesis | Yes — under BAA |
| Neon | Managed PostgreSQL database | Yes — under BAA |
| AssemblyAI | Session audio transcription | Yes — under BAA and Part 2 QSOA |
| Twilio | SMS notifications and assessment invitations | Yes — where an organization enables SMS |
| Resend | Transactional email | Yes — where an organization enables email |
We maintain a current subprocessor list and will provide it on request. We will give customers advance notice of a new subprocessor that will handle PHI.
We may also disclose information where required by law, to protect rights and safety, or in connection with a merger or acquisition — in which case the receiving party remains bound by commitments no less protective than these.
6. Security
Safeguards we implement include:
- Encryption of data in transit using TLS, and encryption at rest using AES-256
- Segregation of every participant record by organization, enforced on every request, so one organization cannot access another’s data
- Role-based access control (owner, administrator, supervisor, peer specialist)
- Audit logging of access to and changes affecting participant records
- Time-limited authenticated sessions
- Data hosted in the United States
A note on terminology: the Platform encrypts data in transit and at rest. It is not “end-to-end encrypted,” because the Platform must process record content in order to provide features such as search and documentation drafting. We describe our security this way deliberately, so that customers can evaluate it accurately.
No system is perfectly secure. If we become aware of a breach of unsecured PHI, we will notify the affected organization in accordance with the BAA and applicable law.
7. Data retention and deletion
We retain participant records for as long as the organization maintains its account, because the organization — not MADe180 — determines the retention schedule its own legal and professional obligations require.
Records deleted within the Platform are generally archived rather than destroyed immediately, so that organizations can recover from mistakes and preserve documentation integrity. On termination of an agreement, we will, at the organization’s direction, return or destroy the PHI we hold, or extend these protections to information that cannot feasibly be returned or destroyed, as provided in the BAA.
Audit records are retained to support the compliance obligations they exist to serve. Backups are purged on a rolling schedule.
8. Your rights
Participants
HIPAA gives individuals rights over their health information, including rights of access, amendment and an accounting of disclosures. Because your records belong to the organization providing your services, please direct those requests to that organization. If you contact us directly, we will refer you to them and assist them in responding.
Records relating to substance use disorder treatment may also be protected by 42 C.F.R. Part 2, which restricts redisclosure more strictly than HIPAA.
California residents
Under the California Consumer Privacy Act, as amended, California residents have rights to know, delete, correct, and to opt out of sale or sharing of personal information. We do not sell or share personal information as those terms are defined. Medical information governed by HIPAA or the California Confidentiality of Medical Information Act is exempt from the CCPA, so for participant records the rights described above under HIPAA apply instead. To exercise a CCPA right regarding information we control, email contact@made180.org. We will not discriminate against you for exercising a right.
Account holders
You may request access to or correction of your account information by contacting us or your organization’s administrator.
9. Cookies
The Platform uses cookies that are strictly necessary to keep you signed in and to maintain your session. The marketing site uses minimal analytics. We do not use advertising cookies.
10. Changes to this policy
We will update this policy as the Platform changes and will revise the “Last updated” date above. For material changes affecting customer organizations, we will provide notice as required by the applicable agreement.
11. Contact
MADe180, LLC
Louisville, Kentucky
contact@made180.org
To request our current subprocessor list, security overview, or a Business Associate Agreement, email us at the address above.