Privacy
Privacy Policy
The Better Place AI ("we," "us," "our") provides a caregiving management platform used by families, home care agencies, and healthcare facilities (our "Customers") to coordinate care. This Privacy Policy explains what we collect, how we use it, who we share it with, and the rights you have over your information.
This policy applies to our website (www.thebetterplaceforseniors.com), our web application (app.thebetterplaceforseniors.com), and our iOS and Android mobile apps (collectively, the "Service").
1. How We Act in Relation to Your Data
When a Customer organization signs up (for example, a home care agency), that organization controls the information it puts into the Service, including information about its patients, caregivers, and staff. We process that information on the organization's behalf as a service provider under California law and a business associate under HIPAA where applicable.
If you are a patient, family member, or caregiver, please also refer to the privacy practices of the organization that invited you to use the Service. The organization remains responsible for the information it enters about you.
2. Information We Collect
2.1 Information you provide directly
- Account information — name, email address, phone number, password, role, organization.
- Caregiver profile — home address, skills, certifications, languages spoken, years of experience, hourly rate, weekly availability.
- Patient profile — name, date of birth, address, emergency contacts, primary and secondary diagnoses, medications, allergies, care needs, preferred language and care preferences. This is typically entered by a coordinator on the patient's behalf.
- Care documentation — care notes, vital sign readings, shift tasks and their completion status, incident reports.
- E-signature PIN — a 4- to 6-digit PIN chosen by caregivers to sign shift reports. We store only a one-way hash; the raw PIN is never saved.
2.2 Information we collect automatically
- Device and usage data — IP address, device type, operating system, browser, and app version.
- Location data — when a caregiver checks in or out of a shift, the mobile app records GPS latitude and longitude and, where available, the reverse-geocoded address. This is used to verify shift presence and is only collected at check-in and check-out events, not continuously.
- Push notification tokens — if you enable notifications, we store an anonymous device token to deliver messages about shift reminders and new care activity.
- Audit log entries — every create, update, and sensitive view within the Service is logged with the acting user, timestamp, and a description of the action.
2.3 Information we do not collect
- We do not record audio or video.
- We do not track location continuously, only at explicit check-in and check-out events.
- We do not use third-party advertising trackers.
- We do not sell personal information to third parties.
3. Protected Health Information (HIPAA)
Much of the information our Customers enter qualifies as Protected Health Information (PHI) under the U.S. Health Insurance Portability and Accountability Act (HIPAA). When a Customer organization is a HIPAA Covered Entity, we act as its Business Associate and sign a Business Associate Agreement (BAA) that governs how we may use and protect PHI.
Consistent with HIPAA and our BAAs, we will:
- Use PHI only to provide the Service and improve its quality;
- Implement administrative, physical, and technical safeguards to protect PHI;
- Report any security incidents or breaches in accordance with our BAA obligations;
- Return or securely destroy PHI upon termination of the underlying service agreement.
If you are a Customer and need a signed BAA before adding PHI to the Service, contact us at admin@thebetterplaceforseniors.com.
4. How We Use Information
We use the information we collect only for the following purposes:
- Deliver the Service — run scheduling, care documentation, caregiver matching, and reporting features.
- AI-assisted features — our caregiver matching algorithm ranks caregivers against patients based on the skills, availability, location, language, experience, and reliability data each Customer has entered. Our AI writing assistant helps caregivers improve and summarize care notes.
- Communications — send transactional emails (password resets, caregiver invites, shift notifications) and important service announcements.
- Security and fraud prevention — detect abuse, protect against unauthorized access, and investigate violations of our terms.
- Compliance and legal obligations — comply with applicable laws, respond to valid legal requests, and enforce our agreements.
- Product improvement — in aggregated and de-identified form only, to understand usage patterns and improve the Service. We do not use PHI for model training.
5. AI Features and Third-Party Model Providers
Our AI writing assistant sends the content of a care note you are editing to a large language model provider (currently OpenAI and/or Anthropic) to improve grammar, summarize, or convert tone. We configure these providers so that your data:
- Is transmitted over encrypted connections;
- Is processed only to generate the requested output;
- Is not used to train the provider's general-purpose AI models;
- Is retained by the provider only for the minimum period required to deliver the response and to satisfy their legal and abuse-monitoring obligations.
Our caregiver matching algorithm runs entirely on our own servers and does not send data to any external AI provider.
6. How We Share Information
We share information only in these limited cases:
- Within your organization — information entered by one authorized user of a Customer organization is visible to other authorized users of the same organization, subject to the role-based permissions configured by that organization.
- Service providers — trusted vendors that help us operate the Service, including our cloud hosting provider (Amazon Web Services), email delivery provider, push notification provider, and AI writing-assistant providers listed in Section 5. These vendors are contractually bound to use information only on our behalf.
- Legal requirements — if required by law, subpoena, or court order, or to protect the rights, safety, or property of The Better Place AI, our Customers, or the public.
- Corporate transactions — in connection with a merger, acquisition, financing, or sale of assets, subject to continued protection of your information.
We do not sell personal information. We do not share personal information with advertisers. We do not allow any third party to access PHI except as explicitly permitted in a signed BAA.
7. Data Retention
We retain Customer data for as long as the Customer's account is active. After a Customer ends its subscription, we retain account data for up to 90 days to allow for reactivation and export, after which it is securely deleted or de-identified. Audit log entries may be retained for up to 6 years to meet HIPAA and other regulatory obligations.
If you are a caregiver, patient, or family member invited by a Customer organization, your data lifecycle is tied to that organization's account and its configured retention settings. Contact the organization directly for deletion requests tied to their account.
8. Security
We protect your information with multiple layers of safeguards:
- Encryption — all data is encrypted in transit (TLS 1.2+) and at rest (AES-256).
- Role-based access — each user sees only the patients, caregivers, and records permitted by their role in their organization.
- Tenant isolation — database queries are filtered by organization ID; data from one Customer organization is never accessible to another.
- Audit logging — we log every create, update, and sensitive view with user, timestamp, and entity.
- Authentication — passwords are hashed with bcrypt and never stored in plain text. E-signature PINs are stored as one-way hashes.
- Automated backups — we take regular database backups with point-in-time recovery.
- Least privilege — production system access is limited to a small number of authorized personnel and reviewed regularly.
No system is perfect. We encourage you to choose a strong password, keep it confidential, and notify us at admin@thebetterplaceforseniors.com immediately if you believe your account has been compromised.
9. Your Rights (California Residents — CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA) give you the right to:
- Know what personal information we have collected about you and how it has been used and shared.
- Access a copy of your personal information in a portable format.
- Correct inaccurate personal information.
- Delete personal information we have collected, subject to certain exceptions (for example, records we must retain for legal compliance).
- Limit the use of sensitive personal information (including health data).
- Opt out of sale or sharing — we do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- Non-discrimination — we will not deny service, charge different prices, or provide a different level of service because you exercised a privacy right.
To exercise these rights, email admin@thebetterplaceforseniors.com with the subject line "Privacy Request." We will verify your identity and respond within 45 days. If you are a patient, caregiver, or family member whose records were entered by a Customer organization, please direct your request to that organization; we will support it in responding.
10. Mobile App Permissions
Our mobile app requests the following permissions, each for a single, disclosed purpose:
- Location — to record GPS coordinates at shift check-in and check-out only. Not tracked continuously.
- Camera — to attach photos to care notes or upload profile pictures (optional).
- Photo library — to select an existing photo for your profile or a care note (optional).
- Notifications — to send shift reminders and alerts for new care activity.
You can revoke any of these permissions at any time in your device settings. The Service will continue to work with reduced functionality.
11. Children's Privacy
The Service is designed for professional use by adults (caregivers, coordinators, admins, and adult family members). We do not knowingly collect personal information directly from children under 13. If a Customer organization enters information about a patient under 13 (for example, a pediatric care client), that information is treated as sensitive PHI and receives the same HIPAA-level protections described in Section 3.
12. International Users
The Service is hosted in the United States (AWS us-west-1). If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have data-protection laws different from those in your country. By using the Service, you consent to this transfer.
We do not currently market the Service to residents of the European Union or United Kingdom. If you are a resident of those regions and have questions, contact us at admin@thebetterplaceforseniors.com.
13. Cookies
Our marketing website (www.thebetterplaceforseniors.com) uses only strictly necessary cookies for navigation and anonymous usage analytics. We do not use advertising cookies, cross-site tracking, or third-party marketing pixels. Our web application uses standard session cookies and browser storage to keep you logged in; these are required for the Service to function.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Effective Date" at the top of this page. For material changes, we will also provide a more prominent notice — for example, via an in-app banner or email to account administrators — at least 30 days before the change takes effect.
15. Contact Us
Questions, privacy requests, or concerns about this Policy:
The Better Place AI
Email: admin@thebetterplaceforseniors.com
Website: www.thebetterplaceforseniors.com
Location: California, United States