ElderOrbit
Terms of ServicePrivacy Policy & Data HandlingField Test / Beta ConsentHIPAA & Health Data Notice

Version: privacy@2026-07-27

Effective: July 27, 2026

This page is maintained by the app operator. It is not legal advice and not independently verified by Lovable. Confirm all terms with qualified counsel before relying on them.

Privacy Policy & Data Handling Practices

This Privacy Notice describes how ElderOrbit, Inc. ("ElderOrbit," "we," "us," or "our") collects, uses, discloses, and protects information about you — including health-related information you and your care team choose to record — and explains the legal rights you have over that information. Please review it carefully.

1. Scope & Legal Frameworks

ElderOrbit is an AI-enabled care coordination platform designed to help families, paid caregivers, community programs, and healthcare providers collaborate on the care of an elderly or dependent loved one. Depending on where you live and how your care circle utilizes the platform, one or more of the following regulatory frameworks govern our handling of your data:

  • HIPAA (Health Insurance Portability and Accountability Act):
    • Institutional / B2B Use: When ElderOrbit partners with healthcare providers, health systems, home health agencies, or covered entities, ElderOrbit acts as a Business Associate under a signed Business Associate Agreement (BAA).
    • Direct-to-Consumer / Family Use: For direct family and consumer accounts, ElderOrbit voluntarily applies HIPAA-aligned technical, administrative, and physical safeguards (e.g., encryption-at-rest, strict RBAC, row-level data isolation) to all health records, vitals, medications, and care logs.
  • GDPR (General Data Protection Regulation): For users in the EU/EEA or UK, ElderOrbit acts as a Data Controller for account setup, identity management, and platform administration, and as a Data Processor for care-coordination data entered by your care team (including health data defined as "Special Category Data" under Article 9).
  • SOC 2 Type 2 & ISO Standards: Our underlying cloud architecture is operated under enterprise controls addressing Security, Availability, Processing Integrity, Confidentiality, and Privacy.
  • State Medical Records & Retention Laws: Retention and disclosure of care logs, triage notes, and clinical records comply with federal guidelines and applicable state medical records statutes (e.g., Vermont state healthcare retention requirements).

2. Data Ownership & Entity Roles

  • You Own Your Data: You, your family coordinator, and your care circle retain full ownership of all personal details, care logs, vitals, medications, and operational records uploaded to ElderOrbit.
  • De-Identified Data: ElderOrbit may retain aggregated, de-identified, or anonymized metadata — derived using recognized standards such as the HIPAA Safe Harbor method (45 CFR § 164.514(b)) or GDPR Recital 26 — to analyze platform performance and improve system reliability. De-identified data strips all 18 HIPAA personal identifiers (e.g., names, dates, IP addresses, device identifiers) and cannot be re-identified.

3. Information We Collect

We collect only the minimum necessary information required to facilitate effective care coordination:

  • Identity & Contact Details: Full name, email address, physical address, phone number, and account credentials.
  • Care & Operational Logs: Daily notes, shift handoffs, completed tasks, schedules, and caregiver observations.
  • Vitals & Health Metrics: Biometric measurements such as blood pressure, glucose, temperature, heart rate, and weight tracked by you or your care circle.
  • Medications & Schedules: Medication names, dosages, administration schedules, and adherence logs.
  • Care Team Data: Contact details and assigned roles for family members, professional caregivers, clinicians, and informal neighbors or volunteers invited to the workspace.
  • Technical & Telemetry Data: IP addresses, mobile device identifiers, operating system versions, access timestamps, and immutable audit logs used for security monitoring and session integrity.

Consent & Tracking Standards

  • Explicit Opt-In: We enforce un-checked, explicit opt-in confirmation for both this Privacy Policy and our Terms of Service.
  • Zero Advertising Trackers: We do not deploy third-party advertising pixels, cross-site analytics scripts, or behavioral tracking algorithms anywhere within the application or behind authenticated screens.
  • Separate Communications Opt-In: Notifications (e.g., SMS task alerts) require separate consent and can be adjusted independently.

4. How We Use Your Information & AI Processing

We use personal and health information solely for care coordination purposes within ElderOrbit. Specifically, to:

  • Enable multi-party scheduling, task delegation, and communication across the circle of care.
  • Generate daily handoff reports, care summaries, and status updates.
  • Deliver proactive task reminders, care alerts, and system notifications.
  • Maintain an immutable audit log of system activities for safety and compliance accountability.
  • Support internal CISO security monitoring, intrusion detection, and vulnerability mitigation.

AI & Automated Coordination Layers

  • Support Capacity Only: ElderOrbit utilizes artificial intelligence algorithms for scheduling coordination, task routing, pattern flagging, and handoff summarization.
  • No Medical Diagnoses: AI features operate strictly in a supportive administrative capacity. ElderOrbit does not provide medical advice, clinical diagnoses, or autonomous treatment choices; all care decisions remain strictly under human control.
  • No Public Model Training: Personal health information and care logs processed by automated workflows are processed through isolated, secure enterprise pipelines and are never submitted to public AI models for general model training.

5. Multi-Party Access Controls & Information Sharing

ElderOrbit connects diverse stakeholders — including family members, agency caregivers, physicians, and informal neighbors. To prevent unauthorized exposure:

  • Role-Based Access Control (RBAC): Access permissions are strictly partitioned based on role. Detailed clinical notes or sensitive health metrics are accessible only to authorized health roles and family coordinators, while informal helpers or volunteers see only assigned non-clinical tasks.
  • Row-Level Database Security: Technical data perimeters enforce row-level isolation so that users can only view records belonging specifically to their authorized care circle.
  • Subprocessor Governance: Cloud storage, database, and messaging vendors (e.g., AWS, GCP, Twilio) act as subprocessors under strict contractual obligations. Every subprocessor with access to health-related data must execute a Business Associate Agreement (BAA) and undergo enterprise security verification.

We do not sell, rent, monetise, or trade your personal or health data to any third party under any circumstances.

6. Mobile & Infrastructure Security Safeguards

  • Encryption Standards: All data is encrypted in transit using modern TLS 1.3 and at rest using AES-256.
  • Mobile Ecosystem & Biometrics: Mobile applications support secure local authentication controls, including Multi-Factor Authentication (MFA) and native system biometrics (Apple FaceID / TouchID, Android Biometric Prompt).
  • Push Notification Safeguards: Push notifications sent to mobile devices contain generic alerts (e.g., "You have a new care update in ElderOrbit") and never expose sensitive health details or patient names on lock screens.
  • Device Integrity Requirements: To ensure encryption perimeters remain uncompromised, ElderOrbit software is strictly prohibited from running on modified, rooted, or jailbroken mobile devices.
  • Immutable Audit Logging: Every read, write, edit, or deletion of a care record generates a tamper-evident audit log capturing user identity, timestamp, and action performed.

7. Data Retention & Account Deletion

  • Active Retention: Data is retained for as long as your account is active or as configured by your care team administrator.
  • In-App Account & Record Deletion: Users may request or initiate account and record deletion at any time directly within the application (Settings → Privacy → Delete Account). Associated operational data is soft-deleted immediately and purged permanently within 90 days.
  • Legally Mandatory Holds: Where mandated by HIPAA rules (45 CFR § 164.316) or state medical records laws, specific clinical records, triage notes, and medication logs are archived in secure, isolated cold storage for a mandatory hold period of 6 years from the last date of service.
  • Cryptographic Destruction: Upon the expiration of mandatory hold periods, data is permanently destroyed via cryptographic key deletion or multi-pass secure overwrite.

8. Your Legal Rights

Regardless of your geographic location, ElderOrbit extends the following privacy rights:

  • Access & Data Export: Request a machine-readable export of all personal health records, vitals, and logs maintained in your account.
  • Correction & Rectification: Request correction of inaccurate demographic, medication, or care record details.
  • Deletion & Erasure: Request full deletion of your account and records, subject to Section 7 statutory holds.
  • Restriction of Disclosures: Request restrictions on data sharing with specific care circle members or third parties.
  • Withdrawal of Consent: Revoke consent for optional communications (such as SMS alerts) at any time.
  • Breach Notification: If an unpermitted acquisition or security breach affecting your Protected Health Information occurs, ElderOrbit will notify you and relevant authorities without unreasonable delay and well within statutory deadlines (such as the federal HIPAA 60-day maximum requirement).

9. SMS & Mobile Communications

By providing your phone number and opting in, you consent to receive transactional SMS notifications regarding care updates, shift reminders, and task alerts. Message frequency depends on your account activity. Standard message and data rates may apply. You can opt out at any time by updating your preferences in Settings → Notifications or by replying STOP to any SMS message.

10. Changes to This Notice

We may update this Privacy Policy to reflect technical, operational, or legal developments. Material updates will be communicated via in-app banner announcements, direct email notifications, and an updated "Last Updated" date at the top of this document prior to taking effect.

11. Contact Information & Complaints

If you have questions regarding this policy, wish to exercise your data privacy rights, or need to raise a security concern, please contact our privacy office:

  • Privacy Officer & Legal Counsel: ElderOrbit, Inc. — privacy@elderorbit.ai
  • Email: support@elderorbit.ai / legal@elderorbit.ai
  • Address: ElderOrbit Corporate Headquarters, Vermont, USA

If you are located in the United States and believe your health data privacy rights have been violated under HIPAA, you also have the right to file a formal complaint directly with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR).

© 2026 ElderOrbit. All rights reserved.
Legal & Trust CenterTerms of ServicePrivacy NoticeHIPAA NoticeBeta ConsentSecurity & Compliance