Privacy

Last updated: 2026-05-12

What we collect

How we use it

What we don't do

Retention & deletion

Account and message data persist until the caregiver removes the senior or the account. Consent timestamps are retained as required by SMS regulations.

Security

Sessions are server-side and never exposed in URLs. Cookies are HttpOnly + Secure + SameSite=Lax. All endpoints are HTTPS-only with HSTS. Mutating endpoints require same-origin requests. Rate limits protect signup, sign-in emails, and inbound SMS. The SMS webhook is authenticated with a shared secret.