Legal
Privacy Policy
Effective Date: August 16, 2026 · Last Updated: August 16, 2026
White Owl Rising is an unincorporated project operated by Lance Taylor in Texas. It publishes the White Owl Rising Recovery Guide, a free recovery resource directory and personal recovery toolkit.
White Owl Rising is currently in free beta. Features and resource information are being tested and improved and may contain errors, change, or occasionally be unavailable. White Owl Rising is a recovery-resource and personal self-help tool and is not medical treatment, counseling, emergency care, or professional advice.
This policy describes what the app actually does today, feature by feature. Features that are built but not currently available to the public are marked as not active rather than described as if they were running.
Scope
This policy covers the White Owl Rising Recovery Guide website and installed app, at whiteowlrising.app and related addresses. The legacy address soberguide.app is no longer the site's name and simply redirects here. It does not cover other organizations we link to — treatment centers, meeting groups, employers, clinics, government sites, maps, or phone services all have their own practices.
Browsing without an account
You can read every resource directory — emergency numbers, meetings, treatment and detox, recovery housing, food, transportation, benefits, employment, faith, community, healthy living — with no account and no personal information.
We do not call this “anonymous.” Like any website, requests reach our hosting and database provider, and routine technical data such as your IP address, browser type, and the pages requested may be processed and appear in their operational server logs. We do not use that data to build a profile of you, and we do not run advertising or profiling trackers.
Where your information is stored
Three things matter: whether something stays on your device, whether it reaches our database, and whether it is ever sent to an AI service. Here is the honest breakdown.
On your device only — encrypted, and we cannot read it
These are the private Toolkit features behind your 6-digit Toolkit PIN. Their contents are encrypted in your browser with AES-256-GCM and stored only on that device. They are never uploaded to us, never included in error reports, and never sent to any AI service.
- Morning routine and nighttime check-in entries.
- Weekly reflection answers.
- Gratitude entries written inside the Toolkit.
- Past journal entries and journal history.
- Your private Prayer List.
- Habit tracker, habit notes, and completion history.
- Your To-Do List items — there is one To-Do List and it lives inside the encrypted Toolkit.
- Private recovery details you keep in the Toolkit, such as sponsor, home group, meetings, and chip dates.
On your device only — stored without encryption
- Your public sobriety date and the home-screen counter, so the counter works with no PIN and no account.
- Reminder and notification preferences, and app display preferences.
- Near Me coordinates, kept in session storage and cleared when you close the tab.
- If you are signed in, your sign-in session token, kept in browser storage rather than a cookie.
Anyone with access to your unlocked device may be able to read the unencrypted items. Clearing browser, site, or app data can permanently remove locally stored Toolkit information, and so can private browsing or switching devices. What an uninstall or app removal leaves behind varies by browser, device, and operating system, so do not rely on uninstalling alone as a secure way to delete your data. Once local content is gone, we cannot recover it.
In our cloud database
- Account email address and a password hash held by our authentication provider. We never see your password.
- Profile details for existing accounts: display name and, if entered there, a sobriety date.
- Saved favorites, if you are signed in and tap the heart on a listing.
- Anything you type into a public submission form (see below).
- Aggregate directory usage counters: how many searches ran on a page and how long they took. These contain no user identifier, no IP address, and no search text.
- Email delivery logs for messages the app sends, and a mailing list of addresses collected earlier or given to us directly.
Publicly submitted for review
- Employer experience submissions: what you type, including employer name, city, state, your interview experience, tips, and rating. These are saved for admin review and may be published in the directory. Do not include your name or anything you would not want shown publicly.
- Organization interest enquiries, where that form is available: organization name, contact name, email, phone, location, and message.
- Resource, event, and correction submissions from Help Grow the Guide: the resource or event name, category, location, address, website, phone, your notes, and your name and email. These are stored for admin review and emailed to us. Nothing is published automatically, and we may email you to confirm details. Please do not include private health information.
Built but not active
- Public account registration is turned off. Existing accounts can still sign in.
- Voluntary financial support is available through Help Us Grow, and card payments there are processed by Stripe; we do not receive or store your full payment-card number. Subscriptions, merchandise checkout, paid provider profiles, and other commercial payment features remain inactive.
- The AI assistant, AI coach, and the older cloud-synced journals and member tools are not reachable by the public.
- There is no file or screenshot upload anywhere in the public app.
How we use information
- To show and search the resource directories.
- To sign existing users in and keep them signed in.
- To store the small amount of account and favorite data those users choose to save.
- To review submissions and corrections so directory listings stay accurate.
- To answer emails you send us.
- To understand overall directory load and speed, using counters that identify no one.
- To fix crashes, using automatic JavaScript error reports containing the error message, stack trace, and page path.
- To meet legal obligations, protect the safety and integrity of the service, and respond to valid legal process.
We do not use your information for advertising, profiling, scoring, or automated decisions about you.
AI processing
Nothing in your private Toolkit is ever sent to an AI service. Journals, gratitude, weekly reflection, habits, prayer list, to-dos, and recovery details make no network call at all — they never leave your device, so there is nothing for an AI provider to receive.
AI assistant and planning features exist in the code but are not available to the public today. If they are switched on later, they would run only when you deliberately start a request, the text you choose to send would be transmitted to a third-party AI provider to generate a reply, and this policy would be updated before that happens. Encrypted Toolkit content would remain excluded.
Some published reading content in the app is drafted with AI assistance by an administrator. That process uses no member data.
AI output can be wrong or out of date and is never medical, clinical, legal, or treatment advice.
Location
We ask for your location only when you tap a “Near Me” control. It is a single one-time reading — no background tracking, no continuous monitoring. The coordinates stay in your browser for that session and are used only to sort listings by distance. They are not sent to our servers and are not stored by us. You can decline and still search by ZIP, city, or county.
Accounts and authentication
New public account creation is currently turned off. People who already have an account can sign in with email and password through our authentication provider; the password is stored by that provider in hashed form and we never see it. Your sign-in session is kept in your browser’s local storage. Access to account records is restricted by database rules to the account that created them.
Your Toolkit PIN and encryption
Your 6-digit Toolkit PIN is separate from any account password. It is used on your device to derive the key that encrypts your private Toolkit. The PIN itself is never stored in readable form, never transmitted, and never known to us. Only the encrypted data is written to your device.
Because of that, we cannot read, reset, or recover your Toolkit. If you forget the PIN, the only option is to reset the Toolkit, which permanently deletes the encrypted contents. This is on-device privacy protection. It is not a certification, not a HIPAA or 42 CFR Part 2 compliance claim, and no system is perfectly secure.
Device Reminders
Reminders are off until you turn them on. Turning them on only enables reminders inside the app while it is open. Notifications from your device are a separate, explicit choice: permission is requested only when you tap “Allow device notifications” yourself — never on page load — and if you decline or your browser blocks them, we do not ask again and in-app reminders keep working. Everything is per browser installation: your reminders do not follow you to another phone, tablet, or computer.
Full reminder details — what a reminder is about, and the task, prayer, journal entry, or resource it points at — stay encrypted in your Toolkit on your device. Your delivery preferences themselves (whether reminders are on, which features, times, days, quiet hours, and this installation’s anonymous code) are stored unencrypted in ordinary browser storage on this device. They contain no reminder content.
If you allow device notifications, our server receives only the minimum needed to deliver one: an anonymous code generated by your browser for this installation, a private management credential stored only as a one-way hash, the push address and keys your browser issues, your time zone, a send time, an opaque reminder code, and an internal screen to open. It never receives task text, journal text, prayer text, provider or treatment names, or any encrypted Toolkit content. Every notification reads the same generic line: “You have a White Owl Rising reminder.”
So the same reminder never reaches you twice, this device keeps a small private record of which reminders have already been shown. It holds only an anonymous code for each shown reminder and the time it appeared — never any reminder content, feature name, or screen. It is stored on your device, shared between the app and the notification helper, cleaned up automatically after a week, and erased by a Toolkit reset.
Turning device notifications off, turning reminders off, or resetting the Toolkit deletes that record and unsubscribes this device. A full Toolkit reset also erases your reminder preferences, this record of shown reminders, and this installation’s code; simply turning reminders off keeps your times and days on this device so you do not have to set them up again. A notification-only service worker is used for delivery; it never caches pages and is registered only after you allow device notifications.
While your Toolkit is locked, we never rewrite your scheduled reminders. Locked, the app cannot read your private reminders, and rewriting the schedule from what it could see would quietly cancel them. Your existing schedule is left untouched until the next time you unlock.
Limits we will not overstate: your device and operating system control sound, Focus / Do Not Disturb, battery behavior, exact timing, and whether a notification is delivered at all. iPhone and iPad only allow notifications once the app is added to the Home Screen. Delivery while the app is closed also requires the delivery service to be configured for this deployment; that setup is not complete and has not been tested, so today reminders appear in the app while it is open and nothing is sent while it is closed. The Settings screen always states which of these is true for you.
Cookies, analytics, and trackers
We do not run Google Analytics, Meta Pixel, or any advertising, retargeting, or profiling tracker, and we do not use advertising cookies. We do not sell or rent your information, and we do not share it with advertisers or data brokers.
What is used instead: browser local storage and IndexedDB for on-device features and the sign-in session, session storage for Near Me, aggregate directory counters that identify no one, and automatic JavaScript error reports through our hosting platform. Our hosting provider may set cookies or similar identifiers necessary to deliver and protect the site. Device Reminders use a notification-only service worker; it never caches pages and is registered only after you allow device notifications.
Our hosting platform also provides limited operational analytics about the site: visitor and pageview counts, which pages were viewed, general traffic source or referrer, device category, country or approximate region, aggregate session and engagement metrics, and technical or error information. In providing these, the platform may process routine technical data such as IP addresses in its operational logs. We use this information to understand how the service is running and how the public pages are used — not to build advertising profiles, target ads, or track you across other sites.
Service providers
We share information only with the providers needed to run the app:
- Our hosting, database, and authentication provider, which stores accounts, favorites, submissions, and operational logs.
- Our email infrastructure, which sends account and update emails and keeps a delivery log.
- An error-monitoring integration built into our hosting platform, which receives JavaScript error reports.
- Map, phone, and email apps you open from a listing, which are operated by others.
Voluntary support payments on Help Grow the Guide are handled by our payment processor, Stripe, which receives your card and billing details directly and shares only the payment result with us. We never see or store your card number. Every other payment feature, including subscriptions and merchandise checkout, remains inactive.
Links, maps, calls, and emails
Tapping Call, Directions, Website, or Email hands off to your phone, map, browser, or mail app and to the organization you are contacting. We do not see or record those calls, messages, or the pages you visit afterwards, and we are not responsible for those organizations’ privacy practices.
Health and recovery information
Recovery, mental-health, and spiritual information is sensitive. White Owl Rising is designed as a consumer recovery-resource and personal self-help tool. It is not a healthcare provider, treatment program, clinic, electronic medical or health record, clinical chart, or clinical documentation system, and we do not claim HIPAA or 42 CFR Part 2 compliance or certification.
The private Toolkit is intended for an individual’s own personal use. Counselors, treatment providers, sober-living operators, and organizations should not use White Owl Rising to create, store, transmit, or manage identifiable patient or client treatment records, clinical notes, or protected treatment information on behalf of a healthcare or substance-use treatment provider.
Privacy-law obligations can depend on how a service is used, what information is involved, and the relationship between the parties, so nothing here is a guarantee about the legal status of what you write. The strongest protection we offer is architectural: the private Toolkit stays encrypted on your device where we cannot see it. Please do not store anything in this app that would seriously harm you if it were disclosed.
Children and minors
The public directory is general-audience safety information anyone who needs help can read. Accounts, private Toolkit features, and any future AI or payment features are intended for adults 18 and older. We do not knowingly collect personal information from children under 13, and we have no parental-consent process, so children under 13 must not submit personal information through forms or create accounts. We do not ask for your age. If you believe a child has provided personal information to us, email us and we will delete it.
Retention, deletion, correction, and export
On-device content is retained until you delete it or clear your browser or app data. That deletion is immediate on that device and cannot be undone or recovered by us.
Cloud records are kept while they are needed for the purpose they were collected for. There is no self-service delete-my-account or export button, so both are handled by hand. Email whiteowlrisingofficial@gmail.com from the address on the account to request deletion, a correction, or a copy of what we hold. We aim to respond within 45 days.
Deletion is not instant everywhere. Backups, email delivery logs, and operational server logs held by our providers roll off on their own schedules, and we may keep limited records where the law, accounting, or security requires it.
Security
Cloud records are protected by database access rules that restrict user data to the account that created it, and traffic is encrypted in transit. Private Toolkit content is additionally encrypted on your device with a key we never receive. No system is perfectly secure, and we cannot promise that any transmission or storage is impenetrable. If we learn of a breach affecting personal information, we will notify affected people and any regulator as required by Texas and other applicable law, without unreasonable delay.
Texas privacy rights
If you are a Texas resident, state law may give you the right to confirm whether we process your personal data, obtain a copy, correct it, delete it, and opt out of targeted advertising, sale, or profiling. We do not conduct targeted advertising, sale of personal data, or profiling, so there is nothing to opt out of. To exercise any other right, email whiteowlrisingofficial@gmail.com with “Privacy request” in the subject. If we decline a request, you may reply to appeal, and we will respond in writing with our reasoning. We may need to verify that the request comes from you. We cannot fulfil a request for encrypted Toolkit content because we have no access to it.
Where information is processed
White Owl Rising is operated from Texas for a mainly Texas audience. Our hosting, database, email, and error-reporting providers operate in the United States and may use infrastructure in other regions to deliver the service.
Changes and contact
If this policy changes materially, we will update the Effective and Last Updated dates at the top of this page. For any privacy question or request, email whiteowlrisingofficial@gmail.com. See also our Terms of Use and Legal & Safety page.