John Teasdale Appverse

Appverse legal

Privacy Policy

This policy explains what information the Appverse handles, why it is used, when it is shared, and the choices available to you.

Effective and last updated August 29, 2026

Terms of Use Privacy Policy Consumer Health Data Policy

1. Scope and operator

This Privacy Policy applies to the John Teasdale Appverse websites, applications, APIs, messages, experiments, and related services listed in the Terms of Use, as well as any other service that links to this policy (collectively, the “Services”). It describes personal information handled by John Teasdale (“we,” “us,” or “our”) through the Services.

Some Services are offered for or with an employer, staffing company, clinician, practice, or other organization that may independently decide how to use information. A Service-specific notice identifies that organization and its role where applicable.

Some Services provide a more specific notice or consent, such as Kelstar’s applicant notice or a connected provider’s terms. The more specific notice controls for that workflow. The separate Consumer Health Data Privacy Policy applies to consumer health data and is part of this Privacy Policy by reference, but it is published separately to keep the health disclosure clear and distinct.

This policy does not govern a third-party website, platform, employer, clinician, or other organization that independently decides how to use information.

2. A short summary

  • A single Appverse account can identify you across participating johnteasdale.com Services.
  • We collect the information you submit, information created when you use a feature, and limited device, security, and usage information.
  • Some Services process sensitive information, including health, employment, relationship, message, location, credential, and identity information.
  • Some features send submitted content to AI providers or connected services to perform the action you request.
  • We do not sell personal information and do not use it for cross-context behavioral advertising.
  • You can request access, correction, export, or deletion by contacting us. Some information must be retained for security, legal, employment, transaction, or audit reasons.

3. Information we collect

Personal information handled by the Services
CategoryExamplesWhy we use it
Account and identityName, email, verification status, password hash, account identifiers, linked Google or Apple account identifiers, administrator status, session and one-time-code records.Create and secure accounts, sign you in across participating Services, prevent abuse, recover accounts, and issue short-lived access tokens.
Contact and communicationsEmail, phone number, Telegram or other channel identifier, messages, prompts, replies, audio/video room display name, reminders, support requests, and delivery metadata.Deliver requested conversations, notifications, login codes, support, real-time rooms, and connected-assistant actions.
Profiles, relationships, and assessmentsProfile text, birthday, location labels or coordinates, images, testimonials, introductions, messages, values-assessment selections, structured interpretations, scores, reports, share links, and administrative feedback.Create profiles and reports, operate dating and values experiences, personalize questions, facilitate conversations, and administer the Services.
Health and wellnessSymptoms, severity, food, water, meal photos and estimated nutrition, health concerns, lab reports, biomarkers, clinical documents, and AI-derived health interpretations.Provide health logs, food analysis, clinical decision support, and requested health-coaching workflows. See the separate health-data policy.
Employment and staffingApplication answers, contact details, work history, professional licenses and credentials, resume and supporting documents, shift information, region, work authorization, Social Security number, payroll and tax identifiers, I-9 identity and work-authorization documents, vaccination status, background-check authorization, and onboarding activity.Accept and assess applications, verify credentials, administer offers and onboarding, schedule work, communicate with applicants and staff, and meet employment obligations. Sensitive onboarding values such as a Social Security number are stored encrypted where the Service collects them.
User content and filesDocuments, photos, media, QR payloads, redirect destinations, questions and answers, instructions, uploaded files, and content you ask an AI or connected service to process.Provide the feature you request, store or share content according to your settings, and detect misuse.
Lookup and public-record resultsPhone numbers submitted for lookup and provider results such as carrier, approximate location, associated names or addresses, validation, and spam signals.Return authenticated lookup results and cache successful results for reliability and cost control.
Transactions and connectionsSubscription or purchase status, transaction identifiers, billing contact information, OAuth permissions, connected-service tokens, and actions performed through connected accounts.Provide paid features and integrations. Payment card details are ordinarily collected directly by the payment processor, not stored by us.
Device, security, and usageIP address, user agent, timestamps, requested route, session activity, rate-limit records, error and diagnostic logs, feature events, referring link, and aggregate scan or visit counts.Operate, secure, debug, measure, and improve the Services; prevent fraud and abuse; and understand reliability.

We do not collect every category from every person. What we collect depends on which Service and feature you use.

Data-minimizing features. Ordinary QR creation and saved presets remain in your browser unless you create an optional shortlink. Chat audio and video are relayed through the real-time meeting provider and are not recorded by us as an Appverse feature. Trace/Track does not store a submitted food image as the resulting health entry. Values does not persist raw assessment-response prose, although it retains structured interpretations, scores, and limited audit information.

4. Sources of information

We collect information:

  • from you, when you create an account, submit a form or file, answer a question, send a message, join a room, create a link, request a lookup, connect an account, or contact us;
  • automatically, from your browser, device, cookies, local storage, server logs, and your interaction with a Service;
  • from people you involve, such as a clinician, staffing administrator, testimonial author, room host, other participant, or person sending a message;
  • from connected services, such as Google, Apple, Telegram, Twilio, email, a payment provider, or another account you choose to connect; and
  • from service providers and public or commercial data sources, such as phone validation, carrier, spam, public-record, and address-data providers used by the authenticated lookup utility.

5. How we use information

We use personal information to:

  • provide, personalize, and maintain the Services and fulfill your requests;
  • authenticate accounts, maintain shared sessions, authorize access, and recover accounts;
  • process content with AI, generate reports or estimates, and perform connected actions you request;
  • communicate with you, deliver codes and notifications, and respond to support or privacy requests;
  • process applications, credentials, onboarding, staffing, transactions, and Service administration;
  • protect users, investigate abuse, enforce terms, and secure systems;
  • debug, analyze, and improve performance, usability, and feature quality; and
  • comply with law, legal process, and recordkeeping requirements.

Where law requires a legal basis, we process information to perform a contract with you, based on your consent, for our legitimate interests in operating and securing the Services, or to comply with law. You may withdraw consent for future processing, but that does not make earlier processing unlawful.

6. AI processing

AI-enabled features may send the prompt, answer, message, image, document, profile context, conversation history, health entry, or other content needed for the requested feature to Cloudflare’s AI services or a model provider available through an AI gateway. Depending on the Service and current configuration, model providers may include OpenAI, Anthropic, Meta, or another provider identified by the feature.

We use AI to interpret answers, generate questions or conversational replies, analyze food photos or documents, summarize information, draft actions, and support other features described in the Service. We may store the submitted content, structured result, model identifier, evaluation or feedback, and operational metadata. A Service may choose not to retain raw inputs while retaining derived signals; for example, Values does not persist raw response prose but does retain structured assessment state and an administrative decision audit.

We configure providers and prompts to support the requested Service. We do not authorize providers to use sensitive personal information for their own advertising. Provider retention and model-training treatment depend on the service arrangement and configuration in effect when a request is processed.

7. When we disclose information

We disclose information only as reasonably needed in these circumstances:

  • Infrastructure and operations. Cloudflare provides hosting, network security, D1/KV/R2/Durable Object storage, real-time media infrastructure, email delivery, and AI gateway or inference services. Neon and Supabase provide managed database, authentication, or storage infrastructure to Services that use them. Other configured database, storage, observability, and deployment providers may process data for the Services they support.
  • Communications and connected services. Twilio, Telegram, Google, Apple, Amazon Web Services/SES, SendGrid, and similar providers process information when their channel or connection is enabled. We disclose the content and identifiers needed to deliver the requested action.
  • AI providers. Cloudflare and enabled model providers process feature inputs and return model output as described above.
  • Payments and analytics. Stripe or another disclosed payment processor handles payments. PostHog or other configured operational analytics may receive device, page, event, and interaction information, including metadata showing use of a health-related feature when analytics is enabled for that Service. We do not authorize analytics providers to use this information for advertising, and we do not use third-party advertising networks for cross-site behavioral advertising.
  • Phone lookup providers. Twilio Lookup and enabled marketplace providers, which may include Trestle, Nomorobo, Icehook, TrueCNAM, and RealPhoneValidation, process submitted phone numbers and return validation, carrier, identity, address, or spam data.
  • People you direct us to involve. Information may be shared with a room host or participant, profile visitor, report recipient, clinician or practice, staffing administrator or employer, message recipient, or anyone who receives a link or content at your direction.
  • Safety and legal reasons. We may preserve or disclose information when reasonably necessary to comply with law or legal process, protect rights and safety, investigate fraud or abuse, or secure the Services.
  • Business changes. Information may transfer as part of a financing, reorganization, sale, merger, acquisition, or transfer of a Service, subject to applicable law and appropriate confidentiality protections.
No sale or behavioral advertising. We do not sell personal information for money, share it for cross-context behavioral advertising, or use sensitive information to infer characteristics for advertising.

8. Public and shared features

Information you publish or share can leave your control. Published dating profiles, locations, testimonials, and media may be public. A Values report, Reveal question, Chat room, QR code, redirect, or similar link may be viewed by anyone who receives its address. Reveal questions and named answers normally expire from its store after about 24 hours, but participants can copy or capture them before then.

Do not place confidential, regulated, or highly sensitive information into a public field or shareable link. Search engines, recipients, or other users may retain copies even after the original is removed.

9. Retention

We retain information for the time reasonably needed to provide the applicable Service, honor your settings, secure and troubleshoot it, comply with law, resolve disputes, and enforce agreements. Retention differs by feature:

  • Appverse sessions normally expire after about seven days unless refreshed or revoked; access tokens are short-lived and one-time login codes expire within minutes. Account records remain until deletion or as otherwise necessary.
  • Reveal content is configured to expire after approximately 24 hours.
  • Snoop caches successful lookup results and formatted summaries for up to 30 days.
  • QR presets remain in the browser until cleared. Optional shortlink destinations and aggregate scan information remain until the link is removed, expires, or the Service is discontinued.
  • Trace/Track health entries remain until the user deletes them or the account or Service is deleted. A food image is sent for analysis but is not stored as the health entry.
  • Values retains structured session state, reports, opaque response signals, and limited administrative audits; it does not persist raw response prose as part of the assessment record.
  • Employment, onboarding, transaction, clinical, profile, message, and connected-assistant records may be retained for the active relationship and afterward for applicable legal, employment, professional, safety, audit, or dispute periods.

Deletion from active systems may not immediately remove encrypted backups, security logs, records held by an independent recipient, or information we must retain by law. Those copies remain protected and are deleted or rendered inaccessible under their normal schedules.

10. Cookies, local storage, and analytics

Appverse Identity uses a necessary authentication cookie that can operate across participating johnteasdale.com subdomains. Services may use browser storage for security state, a pseudonymous browser or session identifier, draft data, local QR presets, interface preferences, or offline functionality. You can clear these through your browser, but doing so may sign you out or remove locally saved data.

We may use first-party or configured operational analytics to understand feature usage, errors, and performance. We do not currently use personal information for cross-site behavioral advertising. Because of that, the Services do not respond differently to a browser’s “Do Not Track” signal. We treat a legally recognized opt-out preference signal, including Global Privacy Control, as an opt-out where applicable; our current practice is already not to sell or share personal information for behavioral advertising.

11. Security

We use administrative, technical, and organizational safeguards designed for the nature of the information, including access controls, short-lived authorization tokens, rate limits, restricted storage, encrypted transport, hashed passwords and verification values, encryption of certain provider credentials, and row- or account-level data separation where supported.

No system is completely secure. You are responsible for protecting devices, email and messaging accounts, and credentials. Contact us promptly if you believe an account or sensitive record has been compromised.

12. Your choices and rights

Depending on the Service and where you live, you may be able to:

  • view or correct your Appverse name and email, set or change a password, and manage linked providers through your profile;
  • access, correct, export, or delete Service records through an in-product control;
  • disconnect a linked account or revoke its permissions at the provider;
  • unsubscribe from optional email or messaging communications;
  • request confirmation, access, correction, deletion, or a portable copy of personal information;
  • object to or restrict certain processing, withdraw consent, or appeal a refused privacy request where applicable; and
  • receive equal service and pricing without unlawful discrimination for exercising a privacy right.

Send a request to jpteasdale@gmail.com and identify the Service involved. We may need to verify your identity and authority. An authorized agent may submit a request where law permits, but we may request proof of authorization. We may deny or limit a request where an exception applies, such as protecting another person, preserving security logs, complying with employment or legal duties, or completing a transaction.

13. California privacy disclosures

California residents may have rights under the California Consumer Privacy Act (CCPA) when it applies to a Service. The categories collected during the preceding 12 months, depending on the Service used, are: identifiers; customer-record information; protected classification information you provide; commercial and transaction information; internet or electronic network activity; geolocation, including coordinates you choose to submit; audio, visual, and similar information; professional or employment information; education and credential information; sensitive personal information; and inferences drawn from submitted information.

The sources, business purposes, retention approach, and categories of recipients are described in Sections 3 through 10. We do not sell these categories or share them for cross-context behavioral advertising. We do not knowingly sell or share personal information of people under 16. If the CCPA applies, you may request to know, access, correct, delete, or obtain a portable copy of covered information and may limit certain uses of sensitive personal information. Our current use of sensitive information is limited to providing requested features, security, legal compliance, and other purposes permitted without a right-to-limit notice.

California’s “Shine the Light” law permits certain requests about disclosure for third parties’ own direct marketing. We do not disclose personal information to third parties for their own direct marketing purposes.

14. Children

The Services are not directed to children under 13, and we do not knowingly collect their personal information. Dating, employment or staffing, clinical-record, and paid Services are for adults. If you believe a child has submitted personal information, contact us so we can investigate and delete it where appropriate.

15. International use

The Services are operated from the United States. If you use them elsewhere, information may be transferred to and processed in the United States and other countries where providers operate. Those countries may have different privacy laws. Where required, we use an available lawful transfer mechanism and apply the rights described in this policy.

16. Changes to this policy

We may update this policy as Services, providers, or laws change. We will revise the date above and provide additional notice or seek consent when required. Material changes apply prospectively from the stated effective date.

17. Contact

Privacy questions, requests, and appeals may be sent to John Teasdale at jpteasdale@gmail.com. Include the relevant Service and the right you want to exercise.

Questions or privacy requests: jpteasdale@gmail.com