District Behavioral Health Privacy Policy

Distric Behavioral HealthPrivacy Policy
Marketing Console Platform
Effective date: August 20, 2026 (previously August 4, 2026)
Contact: admin@districtbehavioralhealth.com
Who we are and who this applies to
District Behavioral Health (“we,” “us,” or “our”), including our operating
brands, provides an internal Marketing Analytics Platform (the “Platform”) for
authorized staff to review and manage marketing performance for our own
advertising accounts and social media pages.
This Platform is for internal staff only. It is not a patient portal, is not
intended for patients or the public, and is not used to deliver treatment or
health care services.
Purpose of the Platform
We use the Platform for internal marketing reporting and optimization of
advertising accounts, websites, and social media pages that we own or control.
This includes performance analysis, conversion tracking, search visibility
reporting, audience and creative analysis, and publishing organic social media
content on our own pages.
Services we connect
Depending on configuration and staff permissions, the Platform may connect to:
Google Ads — currently used for read-only reporting. In the future, we may also
use the Google Ads API to create and manage campaigns, ad groups, keywords, and
ads for our own accounts.
Meta Ads — advertising performance data via the Meta Marketing API.
Facebook Pages and Instagram — organic publishing to Pages and Instagram
professional accounts we own or control, and retrieval of public comments on our
ads and posts, via the Meta Graph API and Instagram API.
Meta Ad Library — publicly available advertising creative, used for market and
creative research.
LinkedIn — organic publishing to LinkedIn company Pages we own or control, via
the LinkedIn Community Management API. Authorized staff connect a LinkedIn
account that holds an administrator role on our Page, and the Platform publishes
posts and images to that Page on our behalf.
Google Analytics 4 (GA4) — analytics and conversion-related reporting via the
Google Analytics API.
Google Search Console and PageSpeed Insights — organic search performance and
page health reporting for websites we own.
Clerk — authentication and login for authorized users of the Platform.
Supabase — hosted database where Platform data is stored.
Information we access and store
When authorized staff connect accounts, we may access and store:
Ad account, property, website, and social media page identifiers and names
Campaign, ad set, ad, keyword, search-term, geographic, city, device,
demographic, time-of-day, placement, and impression-share performance metrics
Conversion action counts and related marketing conversion metrics (for example,
Offline: VOB, Qualified Out of Network, Call Tracking Metrics / CTM call leads,
and website form submission conversions)
Organic search queries, page URLs, click and impression counts, average
position, and page performance measurements for websites we own
Advertising creative we or other advertisers have published publicly, including
images, video thumbnails, and ad copy
Social media content our staff create in the Platform, including post text,
uploaded images, scheduling information, and the identifiers of posts we publish
OAuth access and refresh tokens for connected services (stored encrypted)
The LinkedIn member ID and display name of the staff member who authorizes a
LinkedIn connection, used to attribute and troubleshoot publishing
App user identity information from Clerk needed for login and access control
(such as user ID and email)
Public comments on our ads and posts
To understand audience response, the Platform retrieves publicly visible
comments on our own ads, Page posts, and Instagram content. For each comment we
may store the comment text, the commenter’s public display name, the comment
identifier, the like count, and the time it was posted, along with a sentiment
label and topic themes generated as described below.
We collect this information only from comments left publicly on our own
advertising and social media content. We do not collect private messages, and we
do not build profiles of individual commenters, contact them based on their
comments, or use their comments for advertising targeting. We do not treat these
comments as protected health information, and we ask that no one share personal
health details in public comments. Comments may be deleted from the Platform on
request to the contact address above.
AI-assisted features
Where enabled, the Platform uses third-party AI providers to draft marketing
content and summarize marketing performance:
OpenAI — used to classify the sentiment and themes of public comments described
above, to draft captions from images and slide text, and to generate marketing
performance summaries and recommendations from the metrics described above.
Anthropic (Claude) — used to draft organic social media content and propose
content ideas.
Information sent to these providers is limited to marketing content and
performance data, plus the public comment text described above. We do not send
patient records or protected health information to these providers.
What we do not do
We do not use the Platform for patient treatment or to collect, store, or
process protected health information (PHI) for care delivery.
We do not sell Google user data, Meta user data, or LinkedIn data.
We do not collect or store information about people who follow, view, or
interact with our pages beyond the public comment information described above.
We do not use Google Ads, Meta Ads, GA4, Search Console, or LinkedIn data to
train unrelated AI models, and we do not sell that data to data brokers.
We use connected advertising, analytics, and social media access only to operate
and improve our own marketing operations for accounts and pages we own or
control.
Current Google Ads permissions and planned changes
Today, Google Ads access is used for reporting and analysis. We plan to expand
use of the Google Ads API so authorized staff can also create and edit
campaigns, ad groups, keywords, and ads. Any such write access will remain
limited to our own advertising accounts and authorized internal users.
Where information is stored and how it is protected
Platform data is stored in a hosted database provided by Supabase. OAuth tokens
are encrypted at rest. Access to the Platform is limited to authorized internal
users through Clerk authentication and our access controls.
Third-party service providers
The Platform relies on the following third parties to provide authentication,
data storage, advertising, analytics, and social media APIs, and (where enabled)
AI-assisted features. Their handling of information is also governed by their own
policies:
Google (Google Ads, Google Analytics, Search Console, PageSpeed Insights, and
Google OAuth): https://policies.google.com/privacy
Meta (Meta Ads, Facebook Pages, Instagram, and Ad Library):
https://www.facebook.com/privacy/policy
LinkedIn (Community Management API and LinkedIn OAuth):
https://www.linkedin.com/legal/privacy-policy
Clerk (authentication): https://clerk.com/legal/privacy
Supabase (database hosting): https://supabase.com/privacy
OpenAI: https://openai.com/policies/privacy-policy
Anthropic: https://www.anthropic.com/legal/privacy
Your choices and controls
Authorized users may disconnect connected advertising, analytics, and social
media accounts in the Platform Settings. Disconnecting LinkedIn deletes the
stored LinkedIn tokens and Page selection.
You can revoke Google access for this application at any time at:
https://myaccount.google.com/permissions
You can revoke Meta access at any time at:
https://www.facebook.com/settings?tab=applications
You can revoke LinkedIn access at any time at:
https://www.linkedin.com/psettings/permitted-services
To request deletion of Platform-related account connection data or stored
comment data, or for privacy questions about the Platform, contact
admin@districtbehavioralhealth.com.
Relationship to our other notices
This section applies specifically to the Marketing Analytics Platform used by
internal staff. It does not replace our website privacy practices or our HIPAA
Notice of Privacy Practices for patient health information.

Thomas daniel
Senior Doctor


Mathew
Senior Doctor


