Your safety here

Your Privacy & Security

We built this place for people who have already had enough taken from them. The way we handle your information reflects that. This page explains, in plain language, exactly what we protect, how we protect it, and what we will never do.

Your identity here is yours to define

When you join Bridge of Hope Recovery, you choose a name. That name is the only identity you carry here, in meetings, on the calendar, in every interaction. Your real name is never collected, never stored, and never required.

The only personal information we hold is the email address you use to verify your account. That email is encrypted the moment it reaches us, scrambled into a form that cannot be read without a key that never leaves our server. It exists only to let you recover access to your account if you ever need it.

In plain terms: If someone broke into our database, they would find scrambled data they cannot read: not your email address, not your name, not anything you have written here.

Your journal and personal writing are locked, literally

Everything you write here is encrypted with a key that belongs only to you: your journal entries, your workbook and worksheet answers, your assessments, and every experience you share.

Here is how it works: when you create your account, we generate a unique encryption key just for you. That key is then locked using your password, so only you can unlock it. We store the locked version. We never store the unlocked version. When you log in, your password unlocks your key. When you log out, the unlocked key disappears from memory entirely.

Nobody here can read what you have written.

In plain terms: Your writing here is like a diary in a locked box. Your password is the key. Your email works as a carefully guarded spare key, kept so a forgotten password never costs you your words. Nobody opens the box except you.

The encryption we use

We use AES-256-GCM to encrypt your personal content. This is the same encryption standard used by banks, government agencies, and security researchers worldwide. The "256" refers to key length. It would take longer than the age of the universe to break by brute force with current technology.

GCM adds something important beyond basic encryption: it detects tampering. If anyone were to modify your encrypted data, the system would know immediately and refuse to decrypt it. Your content cannot be silently altered.

Your encryption key is derived from your password using PBKDF2-SHA256 with 600,000 iterations, the current recommendation from the National Institute of Standards and Technology (NIST). This process deliberately takes a fraction of a second, making automated attacks hundreds of thousands of times harder.

What happens if you reset your password

Resetting your password does not affect anything you have written here. Everything stays exactly as you left it.

Here is how that works: when you click the reset link in your email, you have proven to us that you own that email address. That proof, combined with a secret we hold that is never stored in our database, is enough to safely hand your encryption key back to you, locked with your new password. Your content never moves. Your key never changes. Only the lock on your key changes.

This was designed specifically so that people going through difficult times, who may forget passwords, lose devices, or simply need a fresh start, never lose access to what they have written and worked through here.

The one situation where content becomes inaccessible: if you permanently lose access to your email address. Your email is the key to account recovery. Keep it current in your profile, and make sure you can always access it.

What we never do

  • We never sell your data

    Your information is not a product. We do not sell it, license it, share it with advertisers, or use it to build profiles for anyone outside this platform.

  • We never read what you write

    Your writing is encrypted with your personal key. Someone with database access alone sees only scrambled bytes; no administrator or staff member can browse, search, or read your entries. The only theoretical path to your content is the password-recovery machinery described above, which exists for you and is never used for anything else.

  • We never require your real identity

    Your chosen name is your identity here. We will never ask for your legal name, address, phone number, or any identifying information beyond an email address for account recovery.

  • We never share your story without your permission

    What you share in meetings, in your journal, or in any part of this platform belongs to you. Anonymity is a founding value of this community, not an afterthought.

What we do collect, and why

  • Your encrypted email address

    Stored encrypted. Used only for account verification and password recovery. Never used for marketing. Never shared.

  • Your chosen community name

    Your anonymous identity here. Not your real name. Visible to other members in the context of meetings and community interaction, because connection is part of healing.

  • Your activity within the platform

    Login dates (for your streak), which meetings you attend, which prompts you respond to. This data is used only to personalize your experience and is never shared externally.

  • The writing and experiences you choose to share

    Encrypted with your personal key before it touches our database. The experiences and assessments you share are used only to personalize your prompts, meeting recommendations, and resources. Invisible to everyone except you.

  • Your approximate location, only if you choose to set one

    If you save a location to find in-person meetings near you, we store the town-level coordinates of what you typed (never your device's GPS) in your profile, along with the search radius you chose. It is used for one thing: filtering the meeting calendar by distance. Leave it empty and nothing is stored; clear it any time from your profile. Guests' location searches stay in their own browser and never reach our database.

  • A scrambled fingerprint of your network connection

    To keep this community safe, when you register or log in we store a one-way scrambled version (a cryptographic hash) of your network address, never the address itself. We can't reverse it, and it identifies no one. Its only purpose is to help us notice when someone who was removed for harming members tries to come back under a new name.

A note on signing in

There is no "remember me" here, on purpose. Your private writing is locked with a key that only your password can open, so a cookie that skips the password could never unlock your content. Every sign-in asks for your password, and every sign-in fully unlocks what's yours.

If something feels wrong

If you ever believe your account has been accessed without your permission, contact us immediately. Changing your password signs you out everywhere. You can also delete your account yourself from your profile. Everything you've written is erased permanently, no questions asked.

A significant amount of thought, research, and care went into building the security architecture of this platform. The people here deserve nothing less. This is not a legal document designed to protect us. It is a plain-language commitment designed to protect you. If you have questions about anything on this page, Report or Ask Something.