User Agreement

Who may use the Care Console, what belongs in it, what it is not — and the separate rules for organizations that hold people's health information.

Drafted 9 September 2026 · version ua-2026-09

Status. This is the full text, in review. The agreement currently in force is the shorter participation agreement an administrator accepts on the join page, and it stays in force until this text is approved and put in its place. Nothing on this page changes what any organization has already accepted.

The short version, before the long one.

The Care Console is free coordination software given away by a nonprofit. It is built to run on organization-level facts — specialty, insurance, age range, format, availability — rather than on who a client is.

This is not a Business Associate Agreement, and the console is not a HIPAA-covered channel. If your organization needs a covered channel, it brings its own and we hold a place for it — your account, your provider, your agreement. See §5.

It is not for emergencies. If someone is in danger, call or text 988, or call 911.

What is in here
  1. Who this agreement is between
  2. What the Care Console is, and what it is not
  3. Accounts and sign-in
  4. What belongs in the console, and what does not
  5. Organizations that hold health information
  6. Your organization's data
  7. When our staff can open your console
  8. Where an assistant takes part
  9. Fair use, and when we would suspend an account
  10. What we promise, and what we do not
  11. Changes, leaving, and ending
  12. Emergencies, and how to reach us

1. Who this agreement is between every organization

Three parties, and it is worth being exact about which is which.

There are two moments of agreement, and they are different. An administrator accepts on behalf of the organization when the organization joins; that is the one we record, with the name and role of the person who accepted, the date, and the version. Each individual then agrees to this by signing in and using the console.

Whoever accepts on an organization's behalf is confirming they are authorized to do so. If you are not, please pass it to someone who is rather than accepting on the strength of being the person who happened to open the page.

2. What the Care Console is, and what it is not every organization

What it is. A coordination tool. It holds a directory of participating organizations, a matching engine that finds an appropriate clinician or service, a way to pass a referral, a way for organizations to message each other, and a set of self-service tools for running your own listing, roster and content.

What it is not, said plainly, because each of these has been assumed by someone at least once:

3. Accounts and sign-in every organization

4. What belongs in the console, and what does not every organization

The rule, in one sentence: the console carries facts about organizations and openings, not facts about people being served.

So a referral or a message here is meant to read like "adult client, mid-thirties, PTSD, looking for EMDR, Aetna, evenings — any capacity this month?" and never like a name, a date of birth, a phone number, an address, an insurance ID, a photograph, a document, or a clinical record.

Please do not enter, anywhere in the console: a client's name or initials, contact details, date of birth, address, insurance or member number, chart or record, uploaded documents or images of them, or any combination of details specific enough that a person could be picked out from it.

Where this depends on your team rather than on our software — and we would rather you knew exactly where.

Most of the console structurally cannot take a client's identity. The matching engine only accepts category values, and an automated check fails our build if anything else could reach it.

But several fields are free text, and free text stores whatever is typed into it: the note attached to a referral, a message to another organization, peer feedback about another organization, your own call scripts, and your organization's own notes. We do not filter them. There is a gentle prompt when a message looks like it contains an email address, phone number or name, and it never blocks sending — a filter that quietly missed things would be worse than an honest rule, so we tell you the rule instead of pretending to enforce it.

Keeping identity out of those fields is therefore something your team does, and we ask for it here so that nobody assumes the software is holding a line it is not.

How long we keep it. Referral notes and messages between organizations are deleted after 90 days. Your own content — call scripts, links, organization notes, your directory listing — is kept until you change or remove it, because it is yours rather than a message.

Peer feedback is published inside the network. A comment your team writes about another organization is visible to the network's shared record, not just to you and them. Write it as something you would be content to have read aloud.

5. Organizations that hold health information clinical & PHI-handling orgs

This section applies if your organization is a covered entity or otherwise holds protected health information — a therapy practice, a psychiatric group, a clinic. It does not apply to a coaching ministry, a referral office, a classroom or a small business, and we are not going to hand any of them a compliance regime they do not need.

5.1 Three places, three different rules

Almost every misunderstanding in this area comes from treating "the platform" as one thing. It is three, and knowing which one you are looking at tells you what may go in it.

WhereWhat it isClient identity?Whose agreement covers it
The coordination layer This console, our servers, the directory, the matcher, the browser extension No. Keep it out — see §4 Nobody's, and it does not need one, because it is not meant to hold identity
Your records system Your own GoHighLevel account: contacts, your referral pipeline, your notes Yes — deliberately. This is where a person's name belongs Your own agreement with your provider, under their HIPAA add-on
Your messaging surfaces Your chat widget, your forms, your texts and calls — including the widget shown inside this console Yes. This is the surface identity is supposed to enter through Your own agreement, same as above. The conversation goes from the browser to your provider, not through us

One sentence to carry: we do the matching without the name, and we hand off into a system that is allowed to know it.

5.2 The console itself cannot be your covered channel, and here is the honest reason

Not because we have not got round to it, and not as a policy we could waive. Two structural reasons:

What that means for you, concretely. To discuss a client you and another organization have both already identified, use the channels you already have. In the console, keep the conversation about fit, availability and scheduling.

The console says this to your team at the moment it matters rather than only here: the message box carries the line "Standard channel — keep it de-identified: no client names, dates of birth, or health details." If we ever have a covered channel, we will say so on the day it is real and not before.

5.3 What we give you instead: a place for your own widget

Any website can hold a chat widget. That is all the console does here, and it is the whole design.

At the top of your Messages screen there is a placeholder for a secure chat. Your administrator fills it from your own account, under Organization → Resources & links → Team chat. Then:

Where TheraSaaS fits. TheraSaaS is the GoHighLevel agency that signs the business associate agreement with each clinical organization, and in many cases donates the widget and the account setup. That agreement is between your organization and them. We are glad it exists and we are not a party to it: we cannot promise anything on their behalf, we cannot extend their coverage to our own software, and their signature is not ours.

5.4 Where we do hold access to your account, and what we do with it

If we set up or support your records account, we hold credentials that can reach it — and since that account is where identity lives, we would rather write this down than let §5.1 imply we are nowhere near it.

5.5 Your own obligations stay yours

Nothing here transfers any part of your compliance to us. Your organization remains responsible for its licensure, its own privacy notices and consents, the minimum-necessary judgment about what to share, its own breach obligations, and the clinical decisions it makes with what the console shows it. Using this network does not move any of that.

6. Your organization's data every organization

7. When our staff can open your console every organization

We operate this platform, so a small number of named Love Is A Habit staff can open your console to answer a support question or diagnose a problem. Rather than let §6 imply otherwise:

8. Where an assistant takes part every organization

Some parts of the console can include an AI assistant — for example as a participant in a shared room. Where that happens:

9. Fair use, and when we would suspend an account every organization

We would rather explain this than have a clause nobody reads. We may suspend or remove an account for:

Where we can, we will ask first. Where something is putting a person's information at risk, we may act first and explain immediately after.

10. What we promise, and what we do not every organization

This is free software given away by a nonprofit, and we will not dress that up.

11. Changes, leaving, and ending every organization

If this agreement changes materially, we will ask administrators to review and accept it again rather than quietly updating the date. Small clarifications we will simply date.

Your organization can leave at any time, take its data, and ask us to delete what we hold. We can end an organization's participation too — for the reasons in §9, or if we stop running the platform, in which case we will give notice and time to export.

12. Emergencies, and how to reach us every organization

The console is not for emergencies. If someone is in immediate danger, call 911. For a mental-health crisis, call or text 988, or text 741741 to reach the Crisis Text Line. Do not route an urgent situation through a referral or a message here, where nobody may see it for hours.

Questions about this agreement, requests, or concerns: drew.s@loveisahabit.org. If your organization has an attorney reviewing this, we would genuinely rather hear the question than have it go unasked.

← Back to Care Console