Privacy Policy
1. Who we are and what this covers
Marrow ("Marrow", "we", "us") is a peer-support companion for the daily work of substance-use recovery, operated by SanctuaryApp, Inc. This Privacy Policy applies to the Marrow web application at marrows.io/app and the related marketing pages (the "Service"). It does not apply to third-party services we link to, such as 988, SAMHSA, AA, NA, SMART Recovery, or findtreatment.gov.
By using the Service, you acknowledge this Policy. If you do not agree, please do not use the Service.
2. Marrow and HIPAA
Marrow is not a HIPAA-covered entity, and using Marrow does not create a provider–patient relationship. The Health Insurance Portability and Accountability Act (HIPAA) generally applies to health-care providers, health plans, and clearinghouses, and their business associates. Marrow is a direct-to-consumer wellness tool. It is not a doctor, therapist, clinic, health plan, or substance-use treatment program, and it does not bill insurance. As a result, the information you put into Marrow is generally not "protected health information" (PHI) under HIPAA, and HIPAA's protections do not attach to it.
We tell you this plainly so you are not misled: information about recovery is sensitive, and we treat it carefully (see Consumer health data), but it does not carry HIPAA's specific legal protections. If you ever connect Marrow to a treatment provider in a way that would make us a business associate, we will put an appropriate agreement in place and update this Policy before doing so.
3. Information we process
a. Information that stays on your device (default)
By design, most of what you do in Marrow is stored only in your browser's local storage on the device you use. We do not receive it, and it does not leave your device unless you choose a feature that sends it (see below). This includes:
- Your honest record (days in practice, current stretch, cravings ridden, your daily check-ins);
- Your step work and written reflections, and your private inventory and amends lists;
- Walkthroughs you save, your display name if you set one, your settings, and any notes the companion keeps to be a steadier presence ("what Heron remembers").
You can export or permanently erase all of this at any time in the app under You → Your privacy, and your data. Clearing your browser data also removes it.
b. Information processed to answer the AI companion
When you talk with the companion (Heron), or use an AI-assisted feature, the text you send is transmitted to our AI provider to generate a response (see Section 4). We do not store these conversations on Marrow's servers.
c. Information if you use the community ("the Grove")
The Grove is an optional, anonymous peer space. If your version of Marrow has the Grove enabled and you post a message (a "stone"), that message is stored so others can read it. It is associated with an anonymous identifier only, used for moderation and to let you remove your own post; it is never shown to others and is not linked to your real identity, email, or name. We sign you in anonymously, with no email or password. Posts are screened for safety before they appear.
d. Optional account sync
If a future or optional version of Marrow offers cross-device sync, it stores your practice data under an anonymous account so you can carry it between devices. We will identify this clearly in the app before any such data leaves your device.
e. Technical and security information
Our hosting and serverless functions automatically process limited technical information to deliver and protect the Service, such as your IP address and request metadata, used for security, abuse-prevention, and rate-limiting. We do not use this to build advertising or marketing profiles.
4. How the AI companion handles your words
Marrow's companion and AI-assisted features are powered by a third-party large-language-model provider (currently Anthropic, the maker of Claude), accessed through our secure server function. Here is what that means for your privacy:
- Your message is sent to the AI provider to generate a reply, and a brief, on-device summary of context (for example, your day count) may be sent with it to make the reply more relevant. This summary is created on your device and is not stored by us.
- Marrow does not store your conversations. Our function is stateless; it relays your message, returns the reply, and keeps no transcript.
- Your conversations are not used to train AI models. Anthropic does not train its models on data submitted through its API.
- The AI provider may retain inputs briefly for trust-and-safety purposes under its own policies before deletion. Your use of the companion is also subject to the provider's terms and privacy practices. We encourage you not to enter information you would not want processed by a third-party AI service, such as full legal names of others or precise identifying details.
- Safety checks run on your device first. Language suggesting a crisis is detected in your browser, before any network request, so we can show you human help immediately.
5. How we use information
We use information only to:
- Provide the Service and its features, including generating companion responses;
- Keep people safe (for example, surfacing crisis resources and moderating community posts);
- Secure the Service and prevent abuse;
- Understand, in aggregate and de-identified form, how the Service is performing.
We do not sell your data, share it for cross-context behavioral advertising, use it to train AI models, or use the content of your recovery work for marketing.
6. When information is shared
We do not sell personal information. We share information only with:
| Recipient | Why |
|---|---|
| Hosting and infrastructure provider (e.g., Netlify) | To serve the application and run our secure functions. |
| AI provider (e.g., Anthropic) | To generate companion responses, as described in Section 4. |
| Community/database provider (e.g., Supabase), if the Grove or sync is enabled | To store and serve anonymous community posts or synced practice data. |
| Legal and safety | If required by law, or to protect the rights, safety, or property of users or the public. |
These providers act as our service providers/processors and are bound to use the information only to provide their services to us. If we are ever involved in a merger or acquisition, we will require the successor to honor this Policy.
7. Consumer health data
Even though Marrow is not covered by HIPAA, we recognize that recovery-related information is sensitive and may be treated as "consumer health data" under laws such as Washington's My Health My Data Act and similar state laws. For that category of information:
- We collect and process it only to provide features you ask for, and we keep it on your device by default;
- We do not sell it, and we do not share it for advertising;
- We do not require you to provide identifying information to use the core of the Service;
- You may withdraw consent and delete this data at any time by clearing it in the app (You → Your privacy, and your data) or by contacting us.
If you are a Washington resident or covered by a similar law, you have the right to confirm whether we process your consumer health data, to access it, to withdraw consent, and to request deletion. Because most of this data lives only on your device, deletion is usually immediate and in your control.
8. Your choices and rights
Depending on where you live (for example, under the California Consumer Privacy Act/CPRA, the Colorado Privacy Act, Washington's My Health My Data Act, Virginia's CDPA, or the EU/UK GDPR), you may have rights to access, correct, delete, or port your information, to opt out of sale or targeted advertising (we do neither), and to appeal a decision. To exercise these rights:
- In the app: use You → Your privacy, and your data to export or erase everything on your device, and You → What Heron remembers to remove individual notes;
- By email: contact us at hello@martori.studio. We will respond as required by applicable law.
We will not discriminate against you for exercising any privacy right.
9. Children and teens
Marrow is intended for adults 18 and older and is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has provided information to us, contact us at hello@martori.studio and we will address it.
10. Security and retention
We use reasonable technical and organizational measures to protect information, including keeping data on your device by default, transmitting over encrypted connections, and keeping secret keys on the server rather than in your browser. No method of storage or transmission is perfectly secure, and we cannot guarantee absolute security. We retain server-side information (such as community posts, if enabled) only as long as needed for the purpose described, and security logs for a limited period.
11. International users
Marrow is operated from the United States. If you access it from outside the United States, you understand that your information may be processed in the United States and other countries where we or our providers operate, which may have different data-protection laws than your own. Where required, we rely on appropriate safeguards for such transfers.
12. Changes and contact
We may update this Policy as the Service evolves or the law changes. When we do, we will revise the "Last updated" date and, for material changes, provide a more prominent notice. Your continued use after an update means you accept the revised Policy.
Questions, requests, or concerns: hello@martori.studio. Marrow is operated by SanctuaryApp, Inc.