Privacy

Your data, handled with care.

CareFlowAI works with sensitive conversations between families and the communities they trust with their loved ones. This page explains what we collect, why, and how to ask us to delete it.

What we collect

When a family member chats with the AI assistant on your website, we capture the message text, a session reference, and any structured answers they provide through our intake wizard (care level, relationship, timeline).

When a prospective family books a tour, we collect their name, email, phone, party size, and an optional short note. We do not collect medical records, diagnoses, dates of birth, or any of the eighteen HIPAA Safe-Harbor identifiers in any form field.

When a facility owner signs up, we collect the data needed to provision their account: facility identity, primary contact, and any notes submitted through the onboarding intake form.

How we handle health information

CareFlowAI was designed for the tooling layer of senior-care operations, not for clinical record-keeping. We never store Protected Health Information (PHI) in any chat or intake field.

If a family message contains something that looks like a medical detail (a diagnosis, a date of birth, a phone number that matches a resident), the AI redirects the conversation to a phone call rather than recording it. Our intake forms explicitly tell families not to type medical information, and our backend rejects it before it reaches the database.

The tour-booking flow captures no medical data — only scheduling logistics. Booking records are retained for the period required to operate the service and then archived according to the published retention schedule.

What we never do

We never sell facility, family, or visitor data. We never share it with third-party advertisers. We never use family inquiry content to train AI models.

We never connect CareFlowAI data to a social network, advertising identifier, or any ad network — anywhere, at any tier.

How we store and protect data

Data is stored in an encrypted database behind private network access. Access is limited to the small team operating the platform for your facility, and to operators of your own facility through the dashboard.

All traffic is encrypted in transit (HTTPS). Internal access to family inquiry records uses single-factor-protected staff sessions with full audit logging.

We use the same HIPAA-aware posture as a Business Associate context, even though our written BAA is offered selectively — please contact us if your organization requires one.

Your rights

Facilities can export their full data set at any time through the operator dashboard. Facilities can request deletion of their entire record, and we will honor a verified deletion request within thirty days.

Families who have interacted with a facility chatbot can request deletion of their inquiry conversation by contacting the facility directly. We will process verified deletion requests from facility operators within thirty days.

If you are a family member and your inquiry was directed to a phone call (and therefore never recorded) but want us to confirm its absence in our system, you can contact us and we will confirm from our audit log.

Changes to this policy

We may revise this document as our service evolves. Material changes (anything that expands what we collect, lengthens retention, or weakens deletion rights) will be announced through the operator dashboard at least thirty days before they take effect, and the in-product effective date at the bottom of this page will be updated.

For questions about this policy — or to request a deletion, ask about a Business Associate Agreement, or flag a privacy concern — please use our contact form and we will route it to the right person.

Want to talk to us about this policy?

Send us a note →

Effective July 2026 · CareFlowAI · Los Angeles, California