Marrow Sanctuary
Marrow Privacy Policy
Marrow is the mobile app for Marrow Sanctuary, a community led by Charon Normand-Widmer, LMSW, in Livonia, Michigan. This policy explains what the app holds about you, why it holds it, who else can see it, and what you can ask us to do with it.
It is written to be read. Nothing here is hidden in a longer document somewhere else, and nothing here is meant to be hard to follow. If a line is unclear, write to us and we will say it a different way.
This version takes effect on September 20, 2026, and covers the Marrow app. Psychotherapy records from clinical work with Charon are held apart from everything described here, under HIPAA and Michigan law, and are governed by the practice's own Notice of Privacy Practices.
01 Who this policy comes from
Marrow Sanctuary is run by Luminous Ground, led by Charon Normand-Widmer, LMSW, in Livonia, Michigan, United States. Luminous Ground decides what the app collects and what becomes of it, which makes us responsible for the information described here.
For anything in this policy, write to [email protected]. A person reads that address.
02 What the app is, and what it is not
The app is a door into the community. It signs you in to what you already have access to, and from there you can read the rooms, post, reply, listen to the recorded practices, and see what is coming up.
Your place in the community is arranged separately on the website, under the separate agreement you accepted when you joined. The app itself handles none of that, so it holds nothing about it.
Using the app does not make you Charon's client. She is a licensed therapist, and in Marrow she is the host of a community, not your therapist. Nothing in the app is assessment, diagnosis, treatment, or clinical advice, and no one in the community is acting as your clinician.
Because of that, what you write in the app is not a clinical record and is not protected health information. If you are also a client of the practice, that work and its records stay apart from anything here. Please keep clinical detail you would want held under HIPAA out of the community rooms.
03 Urgent matters, and where to take them
The app is not watched around the clock, and no one is sitting on the other side of it waiting. A post can go hours without being seen. It is not a way to reach anyone quickly, and it is not a place for a crisis.
If you are in danger, thinking about harming yourself, or worried that you cannot stay safe, use one of these instead:
If we learn that someone is at serious risk, we may contact emergency services or the people who can reach them, and we may share what we know for that purpose. We would rather be wrong about the urgency than silent about it.
One more thing you should know before you write anything in the rooms. Charon is a licensed social worker, and Michigan law makes her a mandated reporter. If something in the app gives her reasonable cause to suspect that a child or a vulnerable adult is being abused or neglected, she is required to report it to the state, and she will. That duty follows her into the community, and it is not something we can hold in confidence.
- Call or text 988, the 988 Suicide and Crisis Lifeline. Someone answers at any hour, every day.
- Call 911.
- Go to the nearest emergency room.
04 What the app collects
Only what the app needs to work. Most of it you hand us. Some of it your device sends on its own.
The app does not reach for your precise location, your contacts, your calendar, your health data, or your microphone. Your camera and photo library open only when you choose to add a picture, and only the picture you choose comes across.
There is no advertising identifier in the app, and no third-party advertising or tracking software inside it. Nothing here follows you around other apps or other websites.
- Account identity. Your name, your email address, and the sign-in credentials tied to your account. Your password is stored scrambled, and nobody here can read it.
- Profile details you choose to add. A photo, pronouns, where you are in general terms, a short line about yourself, and links you want other members to see. All of it is optional, and you can change or remove it whenever you want.
- What you post. Posts, comments, replies, reactions, any images or files you attach, and direct messages you send inside the community. These are stored so the conversations hold together.
- Sensitive things you choose to write. Marrow is a community about inner work, so a post may touch on your health, your beliefs, or your history. You decide what goes in. Where the law asks for your clear agreement before anyone handles information of that kind, choosing to post it in a shared room is that agreement, and you can take it back by removing the post or asking us to.
- Device and usage information. Device model, operating system version, app version, language, time zone, the general region your connection comes from, which screens you open, which recordings you play, and when you sign in.
- Crash logs. When the app stops working, it sends a technical report: what the app was doing at the moment it failed, the state of the device, and the version involved. These are read to fix the problem and nothing else.
- Notification identifiers. If you turn notifications on, your device gives us an identifier so a message can reach it. Turning notifications off ends that.
- What you write to support. If you email us, we keep the thread so we can follow what happened and answer you properly.
05 How that information is used
What you post is not used to build an advertising profile, and it is not handed to anyone who builds them. Nothing in the app makes an important decision about you automatically.
- To sign you in and keep your access working across your devices.
- To put your posts in front of the right rooms, and to bring other members' posts to you.
- To send the notifications you asked for, and nothing you did not ask for.
- To answer you when you write to us with a question or a problem.
- To keep the space safe: acting on reports, removing content that breaks the community guidelines, and stopping anyone misusing an account.
- To fix what breaks, and to understand which parts of the app members actually use, so the work improves.
- To meet obligations the law puts on us.
06 What other members can see
The community rooms are shared rooms. Anything you post in one is visible to every other member, along with your name and your profile photo. Write as though you are saying it out loud with people in the room, because that is what is happening.
Members can screenshot, copy, or quote what they read. We can take a post out of the app, and we will if you ask, but nothing brings it back from someone who already read it.
Direct messages go to the person you send them to. We do not read them as a habit. We may look at a thread if it is reported to us for safety, and we may act on what we find.
Two small requests. Share what you want to share and keep the rest. And when your story includes somebody else, leave out the details that would let a reader identify them.
07 Who else handles it, and who never does
A small number of companies handle this information for us, under written agreements, only for the purposes above, and only on our instructions.
Beyond those, your information stays with us. Nobody outside Marrow is given your information in return for anything, and nobody ever has been. It does not go to advertisers, and it does not go to anyone who gathers personal information to build profiles of people. Other members see only what you posted yourself.
Two things would make us disclose more: a valid legal demand we are required to answer, and a serious risk to someone's safety. Where the law allows us to tell you about a demand, we will.
Luminous Ground and these companies are in the United States, and that is where the information lives. If you are in the United Kingdom, the European Union, or anywhere outside the United States, using the app moves your information to the United States, where it is held under United States law. Where the law asks for a safeguard around that move, we rely on the standard data protection clauses our providers make available, and you can ask us which ones apply.
- HighLevel and LeadConnector. The platform the community and the app are built on. It holds accounts, profiles, and posted content.
- Apple and Google. They distribute the app and pass along crash and diagnostic reports. What they collect themselves when you install and run an app from their platforms is governed by their own policies.
- Google Workspace. Email correspondence between you and us.
- Acuity Scheduling. Used only if you follow a scheduling link to arrange a time, and only the details that the scheduling needs.
08 How long it is kept
Nothing is held longer than it is useful. The periods below are the outside limits, and asking us to close your account brings them forward.
Deleted information leaves the live systems straight away and works its way out of encrypted backups within thirty days. A few records are kept longer where the law requires us to keep them, and we keep only the part the law asks for.
- Account identity and profile: while your access is live, and for up to twelve months after it ends, so nothing is lost if you are away for a while.
- What you posted: it stays in its thread so the conversation still reads, unless you ask us to take it out.
- Direct messages: until either person deletes them, and up to twelve months after an account closes.
- Device and usage information: up to twenty-four months, and after that only in a form that no longer points at a person.
- Crash logs: up to twelve months.
- Support email: up to twenty-four months after the thread ends.
09 How it is kept secure
Information travels encrypted between your device and our providers, and it sits encrypted on their infrastructure.
Inside Marrow, access to member information is limited to Charon and the small number of people who help run the community. Each of them signs in as themselves, and access is removed when someone stops helping. Passwords are stored scrambled, so nobody here can read yours or tell you what it is.
Your part is small. Keep your sign-in details to yourself, and write to us if you think somebody else has them.
Security is never absolute, and we would rather say that plainly than pretend. If a breach ever puts your information at risk, we will tell the members affected promptly, say what happened, and tell you what to do about it.
10 Your rights over your information
Write to [email protected] and we will answer within thirty days. We may ask you one question to confirm you are who you say you are, and then we get on with it. Asking changes nothing about how you are treated in the community.
Where you live may give you more than this. The California Consumer Privacy Act, the UK and EU GDPR, and similar laws elsewhere carry further rights, and we will meet them. For members in the UK and the EU, we handle your information to carry out our agreement with you, to meet legal obligations, on our legitimate interest in running a safe community, and on your consent where you gave it. Where a post touches on health, beliefs, or anything else the law treats as special, we rely on your explicit consent, given by choosing to write it in a room you know other members can read. You can withdraw consent at any time, and you can complain to your data protection authority, which in the United Kingdom is the Information Commissioner's Office.
- Access. Ask for a copy of what we hold about you, and we will send it.
- Correction. Tell us anything that is wrong and we will put it right. Most profile details you can edit yourself in the app.
- Deletion. Ask us to close your account and remove your information, subject to the limits in the section above. We will not send you around in circles to do it.
- Export. Ask for your profile and your posts in a machine-readable file, emailed to you, so you can take them elsewhere.
- Objection. Tell us to stop handling your information for one of the purposes above, and we will stop unless the law requires us to carry on. If it does, we will tell you which one and why.
- Notifications. Turn them off in the app or in your device settings at any time.
- Community email. Tell us to stop, and we stop.
11 Adults only
Marrow is for adults, eighteen and over. The app is not built for children, and we do not knowingly collect information from anyone under eighteen.
If we learn that a child holds an account, we will close it and delete what we have. If you are a parent or guardian and you think your child gave us information, write to [email protected] and we will handle it quickly, without making you chase us.
12 Changes to this policy
This policy will change as the app changes. When it does, we will post the new version with a new effective date at the top.
If a change matters to you, meaning it alters what we collect, what we do with it, or who else sees it, we will tell members in the app or by email before it takes effect. Continuing to use the app after that means the current version applies to you.
Earlier versions are kept. You can ask us for the one that applied when you joined.
Questions, requests, or a line in here that reads wrong to you: [email protected]. A person reads that address, and a person writes back.
By post: Luminous Ground, 19620 Milburn Street, Livonia, MI 48152, United States.
If you are in danger right now, we are not the right place to send it. Call or text 988, call 911, or go to the nearest emergency room.