What the Care Console platform and its Chrome extension store, what they never store, and who can see it.
Last updated 27 July 2026
Care Console is operated by Love Is A Habit, a nonprofit. It is a coordination tool for mental-health practices: it helps practices refer clients to each other and helps coordinators find an appropriate clinician quickly. It is free to join and donor-supported — we do not sell it, and we do not sell or share the data in it.
The short version. Coordinating care doesn't require knowing who the client is — it requires clinical fit, insurance, format and availability. So that is all this platform's structured records are built to hold, and an automated check fails our build if anything else could reach the matching engine. Identity itself belongs in the practice's own records system, under that practice's own compliance obligations. The honest exception is free text — a referral note, a message to another practice — which stores whatever is typed into it, which is why we ask teams not to type names there. The Chrome extension reads nothing about your browsing and never looks at the page behind it.
It helps to see the split, because it determines everything below:
The coordination layer is designed to hold no client identity, and most of it cannot. The matching engine only ever receives category values — specialty, insurance type, age band, format, region, availability — and an automated check fails our build if anything else could reach it.
A few fields are free text, and there we depend on your team rather than on software: the note attached to a referral, a message to another practice, a peer review comment, and your own call scripts. Nothing stops someone typing a name into those, so we ask teams not to. We describe this as a convention we hold together, not as a structural guarantee, because that is what it is — and telling you where a safeguard is not built in is more useful than a reassurance you cannot check.
Referral notes and messages between practices are deleted after 90 days. Your own call scripts and support content are kept until you change them, because they are your content rather than a message.
Our users are practice staff — clinicians, care coordinators, and administrators. For them we store:
Referrals passed between practices on this platform are de-identified. A referral carries information such as presenting concern, insurance type, preferred format, and an age range — not a name, date of birth, contact details, or clinical record.
The platform's structured records have no field for protected health information (PHI), and are not intended to carry it — with the free-text exception described above. Identified client content belongs in the practice's own records system — a GoHighLevel sub-account operated for that practice — and not in this platform's own application storage. Free-text fields a coordinator types (for example a referral note) are governed by policy and training rather than technical filtering, so staff are asked not to enter identifying details there.
The extension docks the console in Chrome's side panel next to whatever records system a practice already uses. Specifically:
Uninstalling the extension removes its local storage. Signing out clears the stored token.
We use no advertising networks, no analytics or tracking products, and no third-party session recording. There is no advertising anywhere in the product, and we do not sell, rent, or trade personal information.
No system is perfectly secure, and we would rather say that plainly than imply otherwise.
Practice-to-practice isolation is enforced on the server, as above. Separately from that: we operate this platform, so a small number of named Love Is A Habit staff can open a practice's console to answer a support question or diagnose a problem. We would rather write that down than let the sentence above imply otherwise.
None of this reaches your clients' records, which live in your own system rather than here — see “Two layers, and we only operate one” above. It can reach the free-text fields named there, which is the one reason we bothered to write this section down.
An administrator can export their organization's data at any time from the console's Data export tool. If a practice leaves the network and asks us to delete what we hold, we will do so, other than anything we are required to retain. Individual staff can ask their administrator, or us, to remove their profile.
This platform is not built to be a repository for protected health information — see the two layers above, including the free-text fields where that depends on your team rather than on our software. Where a practice needs an identified channel, that happens in their own records system, under their own agreements.
Today there is no BAA-covered channel between practices on this platform, and the product says so plainly in the message composer rather than reassuring anyone: it shows “Standard channel — keep it de-identified.” The agreement a practice accepts when it joins is a participation agreement, not a Business Associate Agreement, and accepting it does not change that claim. If a BAA-covered channel becomes available, we will say so when it is actually real — not before.
This is a tool for professional staff and is not directed to children. Practices serving minor clients coordinate about them using the same de-identified fields described above.
If this policy changes in a way that materially affects what we collect or who can see it, we will update the date above and tell practice administrators.
This page is about data. The rules for using the console — who may have an account, what belongs in it, and the separate section for practices that hold health information — are in the User Agreement.
Questions, requests, or concerns: drew.s@loveisahabit.org.
← Back to Care Console