Legal
Privacy Policy
Effective date: September 2026
This is your information, not ours. We collect it to help you get housing, work, a clear record and benefits, and for nothing else.
We do not sell it. We do not run ads. We do not use tracking tools to follow you around the internet. The only analytics on this website is a single tool that turns on only if you say yes, and it never runs on the page where someone refers another person to the program. We never share your information with another organization unless you say yes first, and you can delete your account from inside the app at any time.
The short version
This page explains what Amanda's House does with information about you. The rest of it is the detail. Here is the whole idea in six lines:
- We collect what we need to run your account and help you with services: your name and how to reach you, your appointments, your messages with your care team, the answers you give on intake forms, and documents you upload.
- Your information belongs to you and to the organization you work with. We do not sell it, rent it, or hand it to data brokers or advertisers.
- If you are referred to another organization, we ask you first and record your answer. Nothing goes to them unless you say yes.
- A small number of companies help us run the app (a database, a notification service). They work for us under contract and cannot use your information for their own purposes.
- Health-related answers are never used for advertising or marketing. Ever. Not by us, not by anyone.
- You can delete your account in the app. See Delete your account for what is removed and what has to be kept.
Who we are and what this covers
Amanda's House is made and run by Autonomous User Rehabilitation Agent (“AURA”), a company in Los Angeles County, California. Our legal name is Autonomous User Rehabilitation Agent LLC and our mailing address is 8033 W Sunset Blvd, Ste 353, Los Angeles, CA 90046. In this policy, “we”, “us”, “AURA” and “Amanda's House” all mean that company.
We run a platform called Amanda's House powered by AURA. It has three parts, and this policy covers all of them:
- The phone app for clients: people across LA County working toward housing, work, a clear record and benefits.
- The phone app for care staff: the people at partner organizations who work alongside those clients.
- This website, and the web tool Amanda's House headquarters uses to run the platform.
One thing this policy does not cover. The organization you work with has its own privacy practices for everything it does outside this app: its paper files, its other systems, its own staff. If you have a question about how your organization handles your information, ask that organization directly.
What information we collect
Here is every category of personal information the platform handles. Not all of it applies to every person: a client and a staff member use the app for different things.
Who you are and how to reach you
- Your name, email address and phone number.
- Your account sign-in details. Your password is never stored as readable text. It is stored scrambled, in a way that cannot be turned back into your password, and nobody at Amanda's House can read it.
- The language you choose for the app, English or Spanish.
Your work with your care team
- Appointments, and the reminders we send you about them.
- Messages between you and your care team inside the app.
- Your answers to intake and screening questions. Some of these are health-related, for example, questions about your health, a disability, or the kind of help you need.
- Case notes written about your situation by staff at the organization working with you.
- Records of referrals between partner organizations, including whether you agreed to the referral and when.
Documents you upload
- Identity and eligibility documents, for example a photo ID, a Medi-Cal card, proof of income, or proof of address.
- Consent forms you sign in the app.
Points and rewards
- The points you earn for taking part, and the record of rewards you redeem them for. See the Terms of Use for how the rewards program works.
Your device
- A push notification token, an anonymous code your phone gives us so we can send you a notification. It identifies your phone, not you, and it changes if you reinstall the app.
- Basic technical information every app and website receives, such as your device type and app version, used to keep the app working and to fix problems.
Face ID, Touch ID and fingerprint unlock never leave your phone. If you turn on biometric unlock, your phone checks your face or fingerprint and tells the app yes or no. We never receive, see or store your face or fingerprint.
Where the information comes from
- From you: what you type, choose, upload and sign in the app.
- From the organization working with you: a staff member may set up your account, record a service, write a case note, or book an appointment with you.
- From another partner organization, if you agreed to be referred to or from them.
- From your phone: the technical details above, and only the permissions you grant.
How we use the information
These are all the uses. There are no others.
- To run your account: signing you in, keeping you signed in securely, and showing you your own information.
- To help you get services: matching you with programs, working through intake, tracking what has happened and what is next.
- To let you and your care team talk: messages, and video visits where your organization offers them.
- To remind you: appointment reminders and other notifications you have turned on.
- To pass a referral on, when and only when you have agreed to it.
- To run the points and rewards program: awarding points and recording what you redeem.
- To keep the platform safe and working: preventing abuse, fixing bugs, protecting accounts.
- To meet legal and program requirements: the records an organization has to keep to run a funded program, and anything the law requires of us.
- To understand how the platform is doing as a whole: counts and totals, such as how many people a program served. We do this with grouped numbers, not by studying any one person's file.
What the app asks your phone for
The app asks your permission before using any of these, and you can say no or change your mind later in your phone's settings. Saying no to any of them does not lock you out of the app; it only turns off the feature that needs it.
- Camera: to scan the QR code on an invitation, and to photograph a document you want to upload.
- Microphone: for video visits with your care team.
- Calendar: only when you ask us to add an appointment to your own calendar. We do not read what is already in it.
- Notifications: to send reminders and messages. Turning these off in your phone's settings stops them.
- Face ID, Touch ID or fingerprint: to unlock the app. As explained above, this happens entirely on your phone.
Referrals: sharing with another organization
We ask you first, every time. Your information is shared with a receiving organization only after you agree, and the app records that you agreed and when.
Partner organizations in the network refer people to each other. For example, if the organization you are working with cannot help with housing but another one can. When that happens:
- The app asks you to agree to the referral before anything is sent.
- If you say no, nothing about you goes to the other organization, and you can keep using the app exactly as before.
- Your agreement is recorded in the app, with the date.
- The receiving organization then sees the information it needs to pick up your case, and becomes responsible for it under its own privacy practices as well as this policy.
- You can tell your care team you no longer want to work with a receiving organization. That stops future sharing; it cannot un-send what was already sent, and the receiving organization may have to keep its own records of the services it provided.
The companies that help us run the app
We do not build everything ourselves. A small number of companies provide the plumbing. Each one works for us under a written contract that limits them to doing what we ask, requires them to protect the information, and forbids them from using it for their own purposes or selling it.
- Supabase: stores the database, handles sign-in, and holds the documents you upload. The servers are in the United States.
- Expo: relays push notifications from us to Apple and Google.
- Apple and Google: deliver those notifications to your phone. Because of how phone notifications work, the text of a notification passes through them; we keep that text short and general for this reason.
- The video visit provider chosen by your organization, if you have a video visit. Your organization can tell you which one it uses.
- Vercel: hosts this website. It does not hold any of the information described above.
The information is stored and processed in the United States. If you use the app from outside the United States, that is where your information goes.
Other times we might share information
Apart from referrals and the service providers above, information leaves us only:
- To the organization working with you. Its staff see the clients on their own caseload. Amanda's House headquarters can see platform records to support organizations and keep the service running.
- When you ask us to: for example, you ask us to send a document somewhere.
- When the law requires it: a valid court order, subpoena or legal obligation. We check that a request is valid before we answer it.
- To stop serious harm: where someone's life or safety is at risk, or the law obliges a staff member to report something.
- If Amanda's House ever merges with or transfers its programs to another organization, in which case the information moves with the program, the receiving organization is bound by this policy, and we will tell you before anything changes.
What we never do
- We do not sell your personal information. Not for money, not in exchange for anything else.
- We do not share it with data brokers or list companies.
- We do not run advertising in the app or on this site, and we do not let anyone else advertise to you based on what we know about you.
- We run no advertising, on the app or on this website, and this website's own usage analytics only turns on if you agree to it. See “Cookies, tracking and Do Not Track” below. The app itself carries no analytics or tracking tool at all: no Google Analytics, no Facebook pixel, no advertising software development kit.
- We never use health-related information for advertising or marketing, or share it with anyone for that purpose.
- We do not use your information to train artificial intelligence models for anyone else.
- Taking part in the rewards program is never required, and your points never affect the services you receive.
Cookies, tracking and Do Not Track
This website does not track you unless you say yes. The first time you visit, a banner at the bottom asks whether we can turn on basic usage analytics. If you tap Decline, or leave without choosing, nothing loads and no analytics script or cookie ever runs. Either way, your choice is remembered in your own browser (a value called ah-cookie-choice, saved to your browser's local storage, not a tracking cookie, and not something we can read from our side) so we don't ask again. You can change your mind at any time: Cookie settings in the footer of every page brings this choice back up.
If you tap Accept, we load a single analytics tool, PostHog, to see which pages people open and roughly how long they spend on them. It does not build an advertising profile of you, does not run ads, and we do not let anyone else use it to advertise to you. This website has no other analytics or advertising tool of any kind: no Google Analytics, no Facebook pixel, nothing that follows you to other websites.
Refer someone is the one page that never tracks, even if you already said yes elsewhere: Refer someone loads no analytics at all, so referring another person to the program is never recorded as your activity.
Aside from that, the only cookies that can appear on this website are the ordinary technical ones the website software (Next.js) may need to serve a page and keep it secure, and, if you sign up for early access, the request that saves your email address. PostHog itself sets no cookie at all. It keeps its own memory of you in your browser's local storage, the same as the cookie choice above.
The app does not track you across other apps or websites either. It has no advertising identifier and no tracking software inside it.
Do Not Track
Some browsers can send a “Do Not Track” signal. There is no agreed standard for what a website must do when it receives one, so we do not respond to it differently, but only because we already do not track anyone, with or without the signal. We also allow no third party to collect personal information about you across other websites through this site or the app.
How we protect your information
No system is perfect, and anyone who tells you otherwise is selling something. Here is what we actually do:
- Information travels encrypted between your phone and our servers, and is stored encrypted.
- Passwords are stored scrambled in a way that cannot be reversed. Nobody at Amanda's House can see your password.
- The database itself enforces who can see what, row by row. A staff member at one organization cannot reach another organization's clients, even by accident.
- Staff and headquarters accounts get only the access their job needs, and headquarters sign-in requires a second step beyond a password.
- Sensitive actions are recorded, so we can see who did what.
- You can lock the app behind your phone's Face ID, Touch ID or fingerprint.
If you think someone else has got into your account, email support@amandashouse.com or tell your care team straight away.
How long we keep your information
Three different rules apply, depending on the kind of record.
- Your contact details and your account: your name, email, phone number, language preference, push notification token and sign-in details. Removed when you delete your account.
- Documents you uploaded: your ID, your Medi-Cal card, proof of income or address. Deleted when you delete your account.
- Care records the organization has to keep by law: the services you received, case notes, referrals, appointment history, consents you signed and the points ledger. These are kept for as long as the organization's program rules and California law require, because a funded program has to be able to show what it did. When you delete your account, these records are separated from your login, so they are no longer connected to a person who can sign in.
We also keep information for longer if we have to, for example, if it is needed for a legal claim or an investigation that is already under way.
Deleting your account and taking back consent
You can delete your account yourself, from inside the app, at any time. You do not have to ask us, and you do not have to give a reason. Open More and choose Delete my account.
Our Delete your account page walks through the steps, says exactly what is deleted and what has to be kept, and explains what to do if you cannot sign in.
Taking back a consent
- A referral consent: tell your care team, or use the consent record in the app. Future sharing stops. Information already sent cannot be recalled, and the receiving organization may have its own records to keep.
- Notifications: turn them off in the app or in your phone's settings.
- Camera, microphone, calendar or biometrics: turn any of them off in your phone's settings.
- Everything at once: delete your account.
Your choices and your California rights
California law gives people rights over their personal information. Some of those laws apply only to large companies, and Amanda's House is almost certainly too small to be covered by them today. We are not going to hide behind that. We offer these rights to everyone who uses the platform, by choice.
- Know: ask us what personal information we hold about you, where it came from, what we use it for, and who we have shared it with.
- Get a copy: ask for a copy of it.
- Correct: ask us to fix anything that is wrong. Much of it you can edit yourself in the app.
- Delete: delete your account, or ask us to delete your information. See the retention rules above for the records a program must keep.
- Limit how sensitive information is used: your health-related answers and your documents are only ever used to provide the service you asked for, which is already the limit the law describes. We will never use them for anything else.
- No sale, no sharing for ads: we do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of. The “Do Not Sell or Share My Personal Information” link in the cookie banner leads here, to this answer.
- No retaliation: using any of these rights will never affect the services you receive, your points, or how you are treated.
How to ask
Email privacy@amandashouse.com or write to us at 8033 W Sunset Blvd, Ste 353, Los Angeles, CA 90046. Tell us what you want and which account it concerns.
We will confirm who you are before we act, usually by contacting you at the email address or phone number already on your account. That is protection for you: it stops somebody else asking for your file. We aim to answer within 45 days. If somebody is acting for you, we will ask for proof that you authorized them.
Reviewing and changing what we hold
Most of your information can be seen and changed in the app itself: your profile, your notification settings, your language, your consents and your documents. For anything you cannot reach there, ask your care team, or use the email address above.
Health information, HIPAA and breaches
Where HIPAA fits
HIPAA is the federal health privacy law. It applies to certain health care providers, health plans and their contractors, not to every organization that handles health-related information.
- AURA is not itself a covered entity under HIPAA, and this policy is not a HIPAA Notice of Privacy Practices.
- Where a partner organization is covered by HIPAA, AURA acts as that organization's business associate under a written agreement, handles the information on its instructions, and follows the safeguards that agreement requires. In that case, the organization's own Notice of Privacy Practices governs your health information, and questions about it go to that organization.
- Where an organization is not covered by HIPAA, HIPAA does not govern the information, but we apply the same protections described in this policy anyway.
If there is ever a breach
If health-related information held in the platform is ever exposed, lost or taken without authorization, we will:
- tell the people affected without unreasonable delay, and in any case within 60 days of finding out;
- tell the Federal Trade Commission; and
- where 500 or more people are affected, also notify the media, as the FTC's Health Breach Notification Rule requires.
Where a partner organization is a HIPAA covered entity, we will also notify that organization so it can meet its own obligations.
Children
The platform is for adults. It is not directed at children under 18, and we do not knowingly collect information from anyone under 18. If you believe a child has created an account, email privacy@amandashouse.com and we will remove it.
Language
The app is available in English and Spanish. This website, including this policy, is currently in English only; a Spanish version is being prepared. If you would find this policy easier to understand in Spanish, ask your care team or email support@amandashouse.com and someone will go through it with you.
Changes to this policy
We will update this page when the platform changes. The effective date at the top always tells you which version you are reading.
If we make a material change (a change to what we collect, how we use it, or who we share it with), we will:
- change the effective date at the top of this page;
- post a notice on this page describing what changed, and keep it up for at least 30 days; and
- tell you in the app, and by email where we have your address, before the change takes effect.
We will never apply a material change backwards to information we already hold without asking you first.
How to reach us
- Privacy questions, or a request about your information: privacy@amandashouse.com
- Help with the app: support@amandashouse.com, or see our Support page.
- By post: Autonomous User Rehabilitation Agent LLC, 8033 W Sunset Blvd, Ste 353, Los Angeles, CA 90046
In an emergency, do not email us. Call 911. If you are in crisis, call or text 988. The app's Crisis help button is available at any time, whether or not you are signed in.