← Back to M3MentalHealth.org

M3 Review — Privacy Policy

M3MentalHealth.org · Effective / Last Modified: July 8, 2026

M3 Review — Privacy Policy

M3MentalHealth.org

M-3 Information, LLC · 155 Gibbs Street, Rockville, MD 20850

Effective Date / Last Modified: July 8, 2026

1. Overview and Scope

This Privacy Policy describes how M-3 Information, LLC and its parents, subsidiaries, affiliates, and operating ventures (“M3,” “we,” “us,” or “our”) collect, use, disclose, and protect information in connection with M3MentalHealth.org and any related websites, applications, and services we operate (the “Services”), including the M3 Review, the M3 Checklist, and other M3 Assessments. This Privacy Policy is incorporated into and forms part of our Terms and Conditions. By using the Services, you agree to this Privacy Policy as it may be amended from time to time in our sole discretion; the current version is always posted on the Services.

Related notices. When we act as a healthcare provider or otherwise handle protected health information (“PHI”) subject to the Health Insurance Portability and Accountability Act of 1996 and its implementing regulations at 45 C.F.R. Parts 160 and 164 (“HIPAA”), including the Privacy, Security, and Breach Notification Rules, our Notice of Privacy Practices governs that information and controls over this Policy in the event of a conflict. Consumer health data of Washington and Nevada residents is additionally addressed in our Washington Consumer Health Data Privacy Policy. Both documents are posted at M3MentalHealth.org.

2. Information We Collect

2.1 Information You Provide

2.2 Information Collected Automatically

2.3 Information from Third Parties

We may receive information from service providers that support the Services, such as payment processors, insurance or Medicare eligibility verification services, analytics providers, and identity or fraud-prevention services.

3. How We Use Information

We do not use or disclose personal information for purposes materially different from those described in this Policy without providing notice or obtaining any legally required consent. We collect personal information only when you voluntarily provide it or as described in this Policy, and we use each category of information only as described here or as stated on the page where it is collected.

4. Deidentified Data; Research and AI Training

To advance mental health research and improve our services, we may deidentify and aggregate information collected through the Services, including Assessment responses and scores. Deidentification is performed in accordance with recognized standards, including the HIPAA deidentification standard at 45 C.F.R. § 164.514 (the “safe harbor” method or expert determination), so that the data cannot reasonably be used to identify you or be linked back to you.

Deidentified and aggregated data may be used, alone or with collaborators, for the following purposes:

We commit that: (a) we will not attempt to re-identify deidentified data; (b) we contractually require any recipient of deidentified data to refrain from attempting re-identification; and (c) no personally identifiable information will be shared or disclosed as part of these research or AI-training activities. Where state privacy laws (such as the California Consumer Privacy Act, as amended) impose requirements on the use of deidentified data, we maintain and use such data in compliance with those requirements.

5. How We Share Information

We do not share personal identifying information, or information at the individual level, except as described in this Policy. We may share information as follows:

We do not sell your personal information for monetary consideration, and we do not sell or share consumer health data or use it for targeted advertising without any consent or authorization required by applicable law, including the Washington My Health My Data Act and Nevada Senate Bill 370. If our practices change, we will update this Policy and provide any legally required notice and opt-out or consent mechanisms before doing so.

6. Applicable Standards and Legal Frameworks

We maintain our privacy program with reference to the federal and state standards currently applicable to online mental health screening services, including:

Because our principal place of business is in Maryland, we give particular attention to the Maryland Online Data Privacy Act, which among other things imposes data-minimization requirements and restricts the sale of sensitive data, including health data.

7. Your Privacy Rights

7.1 State Privacy Rights

Depending on your state of residence, you may have some or all of the following rights with respect to your personal information:

To exercise these rights, email privacy@m3information.com or call 301-641-8045. We will verify your identity before acting on a request and will respond within the time required by your state’s law (generally 45 days, extendable once where permitted). You may authorize an agent to submit requests on your behalf where your state’s law allows. We will not discriminate or retaliate against you for exercising your rights.

7.2 Consumer Health Data Rights (Washington, Nevada, Connecticut)

If you are a resident of Washington or Nevada, or your consumer health data is collected in those states, you have additional rights under the Washington My Health My Data Act and Nevada SB 370, including the rights to confirm collection and sharing of consumer health data, to withdraw consent, and to have consumer health data deleted, and the right not to have your health data sold without valid authorization. These rights, and our related practices, are described in our Washington Consumer Health Data Privacy Policy posted at M3MentalHealth.org. Connecticut residents have analogous protections for consumer health data under the Connecticut Data Privacy Act.

7.3 HIPAA Rights

Where your information is PHI subject to HIPAA, you have the rights described in our Notice of Privacy Practices, including rights of access, amendment, accounting of disclosures, restriction requests, and confidential communications.

8. Cookie Policy

We and our partners use cookies and similar technologies. There are generally four categories of cookies, and we may use each on the Services:

Strictly Necessary Cookies. Essential to enable you to move around the Services and use their features, such as accessing secure areas. Because they are essential, they cannot be disabled through our cookie controls.

Performance Cookies. Collect information about how you use the Services, such as which pages you visit, to help us operate our infrastructure efficiently, serve fresher content, measure aggregate usage in an anonymized fashion, and test new features.

Functionality Cookies. Remember choices you make, such as login state and preferences, so we can tailor and enhance the Services. Information collected by these cookies does not track your browsing on other sites.

Targeting Cookies. We, our advertising partners, or other third parties may use these cookies to deliver advertising relevant to your interests and to measure campaign effectiveness. These cookies may recognize your device across sites, and related information may be shared with advertising networks and other partners. Because Assessment responses are sensitive health information, we do not permit targeting cookies to collect or receive your Assessment responses or scores, and where consumer health data laws apply we obtain any required consent before using advertising technologies with such data.

Managing cookies. Most browsers let you refuse or delete cookies through browser settings. Disabling cookies may affect the functioning of the Services.

8.1 Opt-Out Preference Signals and Do Not Track

Where required by applicable state law (including California and Colorado), we honor browser-based universal opt-out preference signals, such as the Global Privacy Control (GPC), as a valid request to opt out of sale or targeted advertising for the browser or device sending the signal. Except for such recognized signals, the Services do not currently respond to “Do Not Track” browser settings.

9. Data Security

We maintain administrative, technical, and physical safeguards designed to protect information against unauthorized access, use, alteration, and disclosure, appropriate to the sensitivity of the data, with reference to recognized frameworks such as the HIPAA Security Rule and the NIST Cybersecurity Framework. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for maintaining the confidentiality of your credentials.

10. Breach Notification

If we experience a breach of unsecured health information, we will notify affected individuals, and regulators and media where required, in accordance with applicable law, including the HIPAA Breach Notification Rule (where PHI is involved), the FTC Health Breach Notification Rule (16 C.F.R. Part 318) (which requires notice without unreasonable delay and no later than 60 calendar days after discovery), and applicable state breach notification statutes, including the Maryland Personal Information Protection Act.

11. Data Retention

We retain personal information only as long as reasonably necessary for the purposes described in this Policy, to comply with legal, regulatory, tax, accounting, or reporting obligations, to resolve disputes, and to enforce our agreements. Retention periods vary by data category and legal requirement. When personal information is no longer needed, we delete it or deidentify it in accordance with Section 4.

12. Children

The Services are intended solely for individuals 18 years of age or older. We do not knowingly collect personal information from anyone under 18, and we do not knowingly collect personal information from children under 13 within the meaning of COPPA. If you believe a person under 18 has provided personal information to us, contact privacy@m3information.com and we will delete it.

13. Third-Party Sites and Services

The Services may contain links to third-party websites and services that we do not control. This Policy does not apply to those third parties, and we are not responsible for their privacy practices. Review the privacy policies of any third-party service before providing information to it.

14. Changes to This Privacy Policy

We may revise this Privacy Policy from time to time in our sole discretion. The Effective Date above reflects the most recent revision. Material changes will be posted on the Services, and where required by law we will provide additional notice or obtain consent. Your continued use of the Services after a revision constitutes acceptance of the revised Policy.

15. Contact Us

Privacy Officer, M-3 Information, LLC · 155 Gibbs Street, Rockville, MD 20850 · 301-641-8045 · privacy@m3information.com

See also our Notice of Privacy Practices, Washington Consumer Health Data Privacy Policy, and Terms and Conditions, each posted at M3MentalHealth.org.