Security & privacy
This page holds information about someone who isn’t the account holder — your mom or dad. That deserves a plain explanation of what happens to it, not eight pages a lawyer wrote for other lawyers.
What we collect
Only what the features you use actually need: names, medications, the notes you write, documents you choose to upload, and the people you invite into a family’s file. Nothing is collected that isn’t visibly tied to a feature in the app.
How it’s protected
Everything is encrypted in transit and at rest. Passwords are handled entirely by our authentication provider — we never see or store one in plain text.
Every family’s file is isolated from every other family’s file at the database level, not just hidden by the app’s screens. That isolation is enforced by the database itself, so a bug in the app’s code can’t accidentally show one family’s information to another.
Who can see what
A family’s file has three kinds of access: the primary caregiver who owns it, family members who can see and add to the medical record, and helpers — a paid aide, a neighbor — who see only schedule and logistics, never the clinical history. No one outside a family’s own circle can see anything in it, ever.
About AI
This product doesn’t use AI to generate anything yet. When it does — a visit summary, a letter draft — every AI-generated output will say so clearly on the screen, be logged so it can be checked later, and require your review before it changes anything in the record. It will never diagnose, recommend a treatment, or give medical advice on its own authority — it will always point back to your care team.
Your data, your control
Export everything you have access to, at any time, as a file you can keep — no asking, no waiting. Delete your account and the underlying data is actually removed, not just hidden from view. Both of those are one click, from your account page.
What we don’t do
We don’t sell your data. We don’t share it with anyone outside a family’s own circle, other than the infrastructure it takes to run the app itself — hosting, the database, and delivering email. We don’t use your family’s information to train any AI model.
One honest note
We are not a HIPAA-covered entity, and we don’t claim HIPAA compliance. We built this with the same seriousness — encryption, strict access control, and data isolation enforced at the database level — because it’s the right way to handle someone else’s health information, not because a regulation requires it of us. If that status ever changes, this page will say so plainly.
Questions
If any of this is unclear, or you want something explained further, reach out directly at bernard@truenorth-inc.com.