SHS Wellness Passport: Privacy & Data-Handling Notice
Vendor: Greater Angels Software, LLC Product: SHS Wellness Passport Effective date: 2026-07-26 Last updated: 2026-07-26
1. Scope
This notice describes how the SHS Wellness Passport application handles data.
It covers the product wherever it runs: the public demo at
demo.greaterangelssoftware.com, the pilot deployment for California State
University, Bakersfield (CSUB) Student Health Services (SHS), and any subsequent
customer deployment. Our corporate marketing website is covered by a separate
website privacy policy.
Where a signed Data Handling Addendum (DHA) or data processing agreement is in place with an institution, that agreement controls if it conflicts with this notice. This notice is the public summary; the DHA is the binding contract.
2. Our role and the data we process
Greater Angels Software operates the Wellness Passport as a service provider acting on the institution's behalf and under its direction. The institution (CSUB SHS) owns the campaign data. For records that constitute student education records, we handle them consistent with FERPA under the institution's direction and do not re-disclose them. The institution's designation of Greater Angels Software for FERPA purposes, and the associated use and re-disclosure limits, are established in the DHA.
2.1 Data we collect
- Opaque, per-campus account identifier and an affiliation string
- Event check-ins (timestamp, event, capture method)
- Campaign enrollment
- Student-authored free-text reflections (reviewed by SHS staff)
- Content-view records
- Staff audit log of any manual check-in correction
2.2 Data we deliberately do not collect or store
- Student names
- 9-digit campus IDs
- Password hashes (in the pilot's local-account mode, authentication is via short-lived QR-based credentials)
- Protected Health Information (PHI)
This is enforced by the database schema itself: there are no columns for the above. The schema is the control, not merely a policy promise.
3. How we use the data
Data is used solely to operate the wellness campaign for the institution: recording event attendance, enabling the passport and progress experience for students, and presenting attendance and learning-outcome information to SHS staff. We do not use it for any other purpose.
4. How we share data, and how we do not
- We do not sell data. Ever.
- We do not use data for advertising or marketing.
- We do not use student data to train any AI model, ours or a third party's.
- Campaign data belongs to the institution and is siloed to that institution's use.
4.1 Artificial intelligence
The application makes no call to any AI model provider. No student-authored text, and no other institutional data, is sent to an external model for scoring, generation, or any other processing.
Reflection responses are stored for SHS staff to read and review directly; they are never machine-scored. The in-app wellness guide (disabled for the pilot) answers from a fixed, human-authored corpus and does not read what a student types. The application ships with no AI vendor SDK installed.
4.2 Sub-processors
| Sub-processor | Purpose | Data exposed |
|---|---|---|
| Amazon Web Services | Cloud hosting and managed PostgreSQL | All product data, encrypted |
We use no analytics SDKs, no advertising trackers, and no third-party session recording.
5. Security
- In transit: TLS 1.2+ for all traffic; plain-HTTP requests are redirected to HTTPS.
- At rest: production data will be held on managed, AES-256-encrypted PostgreSQL storage before any student is onboarded. The current pre-pilot environment holds synthetic demonstration data only.
- Access control: role-based; staff and student routes are authorization-gated server-side. Aggregate reports suppress small-group counts to prevent re-identification.
- Secure development: automated dependency scanning on every change and a baseline dynamic (DAST) scan of the running application.
- Vulnerability reporting: see our published security contact at https://greaterangelssoftware.com/.well-known/security.txt
6. Data retention and destruction
Data is retained only for the duration of the pilot term, and any period required by law or the DHA. At the conclusion of the pilot term, campaign data is returned to the institution and/or destroyed, per the DHA. A signed DHA is executed before any student is onboarded.
7. Individual rights
Students and the institution may request access to, correction of, or deletion of the limited data we hold. Requests are routed through SHS or directly to us; given how little we collect, these are typically simple to honor.
8. Security and privacy contact
Anthony Graca, Founder & Principal Engineer Greater Angels Software, LLC [email protected] (626) 202-6299
9. Changes to this notice
We will update this notice as the product changes and revise the "Last updated" date above. Material changes affecting an active institutional deployment will be communicated to that institution under the DHA.