App privacy
TheBridge Recovery App Privacy Notice
Effective September 20, 2026
This notice applies to the TheBridge Recovery mobile application. It is separate from Bridge Recovery’s website privacy policy.
Who operates the app
The app is published and technically operated by In My Pocket Labs LLC for Bridge Recovery. Bridge Recovery provides the programs and information shown in the app, and authorized Bridge Recovery staff use organization records to coordinate check-ins, events, and transportation requests. In My Pocket Labs LLC operates the app technology and hosted service.
What the app does
The app provides Bridge Recovery information and lets adults view meetings and published events, submit a private event RSVP, check in for a visit, and request transportation when Bridge has enabled ride availability. It provides recovery-community information and coordination. It does not provide diagnosis, medical advice, treatment recommendations, emergency response, or a guaranteed ride.
Information the app processes
Private guest session
The app creates an authenticated guest session with its hosted service. The service assigns a persistent guest identifier and uses request identifiers to associate your check-ins, RSVPs, ride requests, and privacy requests with your app session, prevent duplicates, limit abuse, and return only your own request status. You do not create a named public profile, but this identifier is still data associated with your use of the app.
Visit check-ins
A check-in can include the visit date and time, whether you chose an anonymous check-in, the reason selected for the visit, and optional name, email address, and phone number. If you choose an anonymous check-in, the app omits those optional contact fields from the submitted check-in. Authorized staff may use check-ins for Bridge operations and protected reporting.
Event RSVPs
An RSVP includes the event, whether you are interested, going, or cancelling, and optional name and email address. Your RSVP is private from other attendees. Authorized Bridge staff can view attendance information needed to operate the event.
Ride requests
A ride request can include your contact name; optional phone and email; selected contact method and consent; pickup and destination descriptions; requested date and arrival or return times; whether the request is round trip; passenger count; practical accessibility needs; app-push, text, and email notification preferences; request status; and coordination notes. The current app stores those notification preferences for staff visibility, but no external push, SMS, or email delivery provider is active and no external notification is delivered. A request is not a guaranteed ride. Authorized Bridge staff review requests and can approve, decline, cancel, or update them.
Published content and directions
The app downloads published event details and ride-availability settings from its hosted service. If you choose a directions button, the app passes the published destination address to the selected Apple Maps or Google Maps service in a secure web link. The app does not include your device coordinates in that link. The selected maps provider processes that interaction under its own terms and privacy policy.
One-time foreground location
The Android app includes foreground coarse and precise location permissions. It asks only after you choose a one-time meeting-search or optional check-in-location feature. Coordinates are processed in memory for that screen and are not sent to the hosted service, stored, used for ride requests, or used for background tracking.
How information is used
- Provide the check-in, RSVP, event, ride-request, privacy-request, and request-status features you choose.
- Let authorized staff coordinate events and transportation requests.
- Protect request ownership, prevent duplicate submissions, limit abuse, and maintain security.
- Operate protected Bridge reports and correct operational records.
- Meet a documented applicable legal or recordkeeping necessity.
Hosted services and exports
The app sends hosted application requests over HTTPS to Supabase infrastructure in the United States. Supabase provides authentication, application-service, database, and hosting functions. Supabase describes its data-processing role in its Data Processing Addendum.
The current app has no external SMS, email, push-delivery, calendar, dispatch, analytics, crash-reporting, advertising, payment, chat, or clinical-record service. Notification preferences are stored in the hosted ride record but are not sent to a delivery provider.
Authorized Bridge staff can download organization records as CSV files. Once downloaded, that copy is under the receiving organization’s control and may not follow the hosted database’s backup lifecycle. Requests concerning an exported copy are coordinated with Bridge Recovery.
Retention
Guest-session identifiers and member records are retained only for as long as reasonably needed to provide the requested feature, maintain accurate organization and security records, resolve disputes, prevent duplicate or abusive requests, and meet a documented applicable legal or recordkeeping necessity. When information is no longer needed for those purposes, authorized operators delete or anonymize it through the applicable operational process. Different records may be kept for different periods because active requests, completed records, and security records serve different purposes. This is not an indefinite blanket exception.
The hosted service uses daily physical database backups. The provider documents a seven-day accessible daily-backup window for the current plan, and point-in-time recovery is disabled. Deletion from the active database may not immediately remove a copy from an existing backup. Backup copies age out under the provider’s backup lifecycle unless a documented applicable necessity requires otherwise. Staff-downloaded CSV copies are separate and are addressed above.
Cancelling an RSVP or ride request changes its status; it does not itself delete the underlying record.
Your choices and requests
You may omit fields the app marks optional. Some information is required to submit and coordinate a ride request. You can cancel an RSVP or an eligible pending ride request from the app.
You can submit an access, correction, or deletion request in the app. The request creates a protected staff-review receipt; it does not erase records automatically. In My Pocket Labs coordinates verified requests through authorized tenant-scoped administration and with Bridge Recovery when organization records or exported copies are involved. Enough information may be required to locate the guest session or submitted record and verify that the requester is authorized to act on it.
A documented applicable security, dispute-resolution, legal, or recordkeeping necessity may limit deletion of a specific record. This is not an indefinite blanket exception. Backup copies may remain until they age out under the provider’s backup lifecycle.
Security
The app sends hosted requests over HTTPS/TLS and restricts member records by authenticated guest identity and staff records by staff authorization. No system can guarantee absolute security.
Children
The app is intended for adults age 18 and over and is not directed to children. A verified request concerning inadvertently submitted information uses the same coordinated handling process described above.
Changes
We may update this notice when app features, providers, or legal requirements change. The current effective date appears above.
Contact
For questions or requests to access, correct, or delete personal information, email daniel@inmypocketlabs.com. Please provide only the information reasonably needed to locate your request. Do not send passwords, access tokens, or unrelated sensitive information by email.