Operator: Nickelsense Inc. (dba Parachute, Tether, Tandem)
Applies to: Parachute, Tether, and Tandem websites at https://myparachute.live, https://mytether.live, and https://mytandem.live, the Parachute, Tether, and Tandem apps for iOS and Android, and related services
Effective: October 2, 2026
Last updated: October 2, 2026
Version: 1.0
This Notice is part of the Privacy and Consumer Health Data Policy. "Cookie" here includes cookies, SDKs, local storage, pixels, tags, device identifiers, embedded players, and similar technologies on the web and in the mobile apps.
Because Parachute | Tether | Tandem handles sensitive recovery and mental-health information, we use essential technologies to sign you in, secure the Service, remember your privacy choices, and deliver features you request. We use optional first-party analytics only after you opt in. We do not use advertising pixels, cross-context behavioral advertising, data-broker enrichment, or session replay.
| Technology / provider | Type | Data | Purpose | Duration | Your choice |
|---|---|---|---|---|---|
| Session cookie / secure sign-in token | First-party essential | Random session token | Sign-in and security | 14 days | Required |
| Privacy-choice record | First-party essential | Consent version and preferences | Remember your choices | 12 months | Required |
| Rate-limit and CSRF tokens | First-party essential | Random token, IP security signal | Prevent abuse | Up to 24 hours | Required |
| PostHog product analytics (self-hosted by Nickelsense) | Optional | Screen and event names, coarse device, random analytics token | Product improvement | 12 months | Opt-in |
| Sentry error and crash reporting | Third-party | Error type, app and device, redacted stack and logs | Reliability | 90 days | Essential: needed to detect and fix crashes and security errors; text, URLs, and identifiers are redacted before sending |
| LiveKit (voice and video) | Functional | Media stream, IP, device and quality metadata | The live call you start or join | The call; connection logs up to 30 days | You start or join the call |
| OneSignal push notifications (mobile) | Functional | Push token, device type, notification delivery status | Deliver notifications you allow | Until you disable notifications or delete your account | Device notification permission |
| Embedded media players (for example, video or podcast hosts) | Functional | IP, device, content ID | Play media you request | Provider's policy | Prior notice and consent |
The following surfaces never load an advertising tracker or session-replay tool: signup, intake, recovery or mental-health profile, check-ins, sobriety date, search, Hubb and meeting and provider pages when signed in, support requests, AI chat, direct messages, journal, groups, live sessions, crisis resources, billing, and privacy requests. Diagnostic tools on these surfaces redact text fields, URLs and query strings, health attributes, contact data, message bodies, screenshots, and stable account identifiers before transmission.
With your separate permission, we collect events such as screen opened, feature used, response time, failure, and coarse journey completion under a random, revocable analytics token. We do not include post, message, or journal text, health answers, search terms, exact location, advertising identifiers, or direct account or contact identifiers. Turning analytics off stops future optional events and severs (deletes) the token map. Essential aggregate counts needed to operate and secure the Service continue and contain only the feature or event name, count, success or error status, app version, platform, and date — with no account token, health content, or free text.
Use Settings → Privacy → Cookies and tracking (or the cookie banner on the website) to allow or reject:
Rejecting optional technologies does not block core features. We honor legally required browser and device preference signals, including the Global Privacy Control (GPC) signal.
We do not currently use session replay anywhere in the Service, and we will not use it unless we first identify the specific feature, obtain prior all-party consent, apply a redaction scheme, and publish the purpose, provider, and retention in this Notice. Live-session recording is turned off by default; a host may turn it on only after every participant sees a clear notice and gives any prior consent the law requires.
We do not send a member's identity or a persistent account or device identifier together with video or audio titles to a third party unless it is necessary to play content you requested and is supported by a stand-alone consent where the Video Privacy Protection Act applies. We audit embedded players before each release.
Questions and requests: privacy@nickelsense.com or Settings → Privacy (in the App or on the web).
Other legal documents
Nickelsense Inc. · Louisville, Kentucky · legal@nickelsense.com · (502) 354-8105