Privacy Policy
HIPAA CompliantLast updated: March 23, 2026
CaretakerHelp.ai ("we," "us," or "our") is committed to protecting the privacy and security of your personal information and Protected Health Information (PHI). This Privacy Policy describes how we collect, use, disclose, and safeguard your information in compliance with the Health Insurance Portability and Accountability Act (HIPAA), the HITECH Act, and applicable state privacy laws.
1. Information We Collect
Account Information
- Full name, email address, and phone number
- Account credentials (passwords are hashed and never stored in plaintext)
- Subscription and billing information
Protected Health Information (PHI)
We may collect the following categories of PHI about you or your care recipient:
- Demographic information (name, date of birth, address, relationship)
- Health conditions and diagnoses
- Medication names, dosages, and schedules
- Insurance and benefits enrollment information
- Financial information related to benefits eligibility (income, assets)
- Care plans and task assignments
- Uploaded documents (advance directives, insurance cards, medical records)
- Communication logs between care team members
Technical Information
- IP address and approximate location (for security purposes only)
- Browser type, device information, and operating system
- Session data, access timestamps, and audit logs
2. How We Use Your Information
We use your information to:
- Provide and operate the CaretakerHelp.ai platform
- Screen benefits eligibility based on information you provide
- Generate AI-assisted care guidance and recommendations
- Track medications and check for potential interactions
- Securely store and organize your documents
- Facilitate care team coordination and communication
- Send transactional emails (account verification, password resets, alerts)
- Maintain security, detect fraud, and comply with legal obligations
- Improve our services through de-identified, aggregated analytics
3. AI Processing Disclosure
All AI processing occurs locally on our own infrastructure. We do NOT send your personal information or Protected Health Information to any external AI services, third-party APIs, or cloud-based language models. Our AI models run entirely within our HIPAA-compliant environment, ensuring your data never leaves our secured systems for AI processing.
AI-generated guidance is based on publicly available benefits program criteria and the information you provide. AI outputs are informational only and do not constitute professional advice.
4. Who We Share Information With
We do not sell your information. We may share information only as follows:
Care Team Members
Information about a care recipient is shared with care team members you explicitly invite. You control who has access and can revoke access at any time.
Business Associates
We may share PHI with service providers who perform functions on our behalf (e.g., hosting, email delivery). All such providers are bound by HIPAA Business Associate Agreements (BAAs) that require them to safeguard PHI to the same standards we maintain.
Legal Requirements
We may disclose information when required by law, subpoena, court order, or to protect the rights, safety, or property of our users or the public, in accordance with HIPAA's permitted disclosures.
5. Security Measures
We implement administrative, physical, and technical safeguards as required by the HIPAA Security Rule, including:
- AES-256 encryption for all data at rest
- TLS 1.3 encryption for all data in transit
- Bcrypt password hashing with appropriate work factors
- CSRF protection on all state-changing operations
- Strict Content Security Policy headers
- Multi-factor authentication support
- Automatic session timeout after 20 minutes of inactivity
- Comprehensive audit logging of all PHI access
- Role-based access control with principle of least privilege
- Regular security assessments and penetration testing
- Encrypted database backups with tested restoration procedures
6. Your HIPAA Rights
Under HIPAA, you have the right to:
- Access - Request a copy of the PHI we maintain about you or your care recipient
- Amendment - Request correction of PHI you believe is inaccurate or incomplete
- Accounting of Disclosures - Request a list of certain disclosures we have made of your PHI
- Restriction - Request restrictions on certain uses and disclosures of your PHI
- Confidential Communications - Request that we communicate with you through specific means or at specific locations
- Breach Notification - Be notified in the event of a breach of unsecured PHI, as required by the HITECH Act
- Complaint - File a complaint with us or with the U.S. Department of Health and Human Services if you believe your privacy rights have been violated
To exercise any of these rights, contact our Privacy Officer using the information below. We will respond to all requests within 30 days.
7. Cookies and Tracking
We use only essential cookies required for the operation of the Service:
- Session cookies - Maintain your authenticated session (httpOnly, Secure, SameSite=Strict)
- CSRF token - Protect against cross-site request forgery attacks
- Cookie consent - Remember your cookie preferences
We do NOT use advertising cookies, analytics trackers, or any third-party tracking technologies. We do not participate in cross-site tracking or data broker networks.
8. Data Retention and Deletion
We retain your data for as long as your account is active, plus the following retention periods after account closure:
- PHI and personal data - Deleted within 30 days of account closure, unless a longer retention period is required by law
- Audit logs - Retained for 6 years as required by HIPAA
- Billing records - Retained for 7 years as required by tax law
- De-identified data - May be retained indefinitely for service improvement
You may request deletion of your data at any time by contacting our Privacy Officer or through your account settings. We will process deletion requests within 30 days, subject to legal retention requirements.
9. Children's Privacy
CaretakerHelp.ai is intended for users aged 18 and older. We do not knowingly collect information from children under 18. If we become aware that we have collected personal information from a child under 18, we will delete it promptly. Care recipients may be minors, but account holders must be adults with legal authority to manage the minor's information.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email and by posting the updated policy on this page with a new "Last updated" date. We encourage you to review this policy periodically. Your continued use of the Service after changes constitutes acceptance of the updated policy.
Contact Our Privacy Officer
If you have questions about this Privacy Policy, wish to exercise your HIPAA rights, or have a privacy concern, please contact:
You may also file a complaint with the U.S. Department of Health and Human Services Office for Civil Rights at hhs.gov/hipaa.