Privacy Policy
GenCare Connect ("we," "our," or "us") operates the GenCare Connect mobile application and related services (collectively, the "Service"). This Privacy Policy explains how we collect, use, store, and share your information when you use the Service, and the rights you have over that information.
1. Who This Policy Applies To
This policy applies to all users of the GenCare Connect Service, including patients seeking hospice and palliative care, healthcare providers using the platform to deliver care, and administrative users of the web portal. By creating an account or using the Service you agree to the practices described here.
2. Information We Collect
2.1 Identity and Account Data
When you create an account we collect your first and last name, email address, and optionally your phone number. Healthcare providers also submit professional credentials including license number, license state, NPI number, board certifications, and educational background for credential verification purposes.
2.2 Location Data
We collect your precise location (latitude and longitude) once during onboarding or when you update your profile address to power provider proximity search. We request access to your device's GPS for this purpose only. We do not track your location continuously or in the background.
2.3 Health and Medical Data
The Service collects health-related information, including but not limited to:
- Self-reported medical conditions, allergies, and medications collected during patient onboarding
- Date of birth, gender, and insurance information
- Clinician-entered diagnoses (including ICD codes), medication prescriptions, care plans, and SOAP progress notes
- Visit records including chief complaint, notes, diagnosis, and treatment plan
- Clinical forms, consent documents, and patient-submitted documents such as lab results, imaging, and prescription uploads
- Audio recordings made by providers for note dictation via voice-to-text transcription
This data may constitute Protected Health Information (PHI) under HIPAA. Please see Section 7 for our HIPAA notice.
2.4 Financial Data
We record payment transaction identifiers, amounts, and statuses for consultation payments. Raw payment card numbers are never stored by us — card entry is handled entirely within the Stripe SDK on your device. Providers who receive payouts through the platform have a Stripe Connect account identifier stored. Insurance provider name and policy number may be stored on patient profiles.
2.5 Communications
Direct messages exchanged between patients and providers in the in-app chat, community group posts, notification records, and appointment notes (including reason for visit and cancellation reasons) are stored on our servers.
2.6 Files, Photos, and Audio
Profile photos, visit photos taken during in-person appointments, uploaded medical documents, credential files, and generated PDF reports are stored in our secure file storage. Audio recordings made by providers using the voice dictation feature are temporarily stored for transcription processing.
2.7 Device and Technical Data
We store your device's push notification token to deliver appointment reminders, medication alerts, and call notifications. We do not collect advertising identifiers, IP addresses, or user-agent strings in the ordinary course of service operation.
2.8 App Activity
We maintain an audit log of significant account events (sign-in, sign-out, profile changes, payment events, admin actions) for compliance and security monitoring. Appointment status history and call log records (start time, end time, duration, call type) are also stored. When Anonymous Analytics is enabled in Settings, we also record aggregate app-open and coarse screen-group events. These analytics events contain no user ID, route parameters, device identifier, free-form text, or health information.
2.9 What We Do Not Collect
We do not use advertising identifiers (IDFA, GAID), operate any third-party advertising or analytics SDK, or share your data for advertising purposes. Our privacy-controlled aggregate analytics are stored in our existing Convex backend. Our Apple App Privacy "Tracking" declaration is "No."
3. Device Permissions
The Service requests the following device permissions. You may revoke any permission in your device settings, though doing so may limit Service functionality:
| Permission | Purpose |
|---|---|
| Camera | Video consultations and document scanning |
| Microphone | Audio in video consultations and voice note dictation |
| Photo Library | Uploading profile photos and medical documents |
| Precise Location | Finding nearby healthcare providers during onboarding |
| Push Notifications | Appointment reminders, medication alerts, and incoming call alerts |
4. How We Use Your Information
- Delivering the Service — scheduling appointments, facilitating video and in-person consultations, managing care plans and clinical documentation, and processing payments.
- Provider matching — using your location and health conditions to surface relevant nearby providers.
- Communications — sending transactional email (OTP codes, account verification) via Resend, and push notifications via Expo.
- AI-assisted features — processing general FAQ queries through our AI model to generate answers; transcribing provider voice recordings to text for note dictation.
- Safety and compliance — maintaining audit logs to satisfy HIPAA audit-trail requirements, detecting misuse, and investigating safety reports.
- Product improvement — aggregate, non-identifying analysis of platform usage. No external analytics SDK is currently active.
5. Third-Party Processors
We share data with the following service providers solely to operate the Service. Each is bound by a data processing agreement or privacy policy governing their use of your information:
- Convex — all application data (user accounts, clinical records, messages, files, payment records); primary database, file storage, and serverless backend compute.
- Stripe — tokenized payment data (no raw card numbers stored), PaymentIntent IDs, doctor payout account metadata; processing consultation payments and provider payouts via Stripe Connect.
- LiveKit — user display name, user ID, real-time audio and video streams for the duration of a consultation call; real-time video and audio for virtual consultations.
- Expo Push Notification Service — push notification token, notification title, body, and deep-link reference; delivering push notifications to iOS and Android devices.
- Google Maps Platform (Places, Routes, Maps Static APIs) — address search queries, session tokens, coordinate pairs (no user identity is sent to Google); address autocomplete, travel time estimates, and map thumbnails. All calls are server-side proxied.
- OpenAI (GPT-4o-mini) — general FAQ questions submitted by users (prompt guards reject any patient-specific clinical queries); generating answers for the in-app FAQ assistant.
- OpenAI (Whisper) — audio recordings made by providers for note dictation (no patient identity included in the request); voice-to-text transcription of clinical notes.
- Resend — user email address and one-time password code; delivering account verification and password-reset emails.
We do not sell your personal information to third parties. We do not share your data with advertisers or data brokers.
6. Data Retention
We retain your personal information for as long as your account is active and for a period thereafter as required by applicable law and our contractual obligations. Clinical records, including diagnoses, medication records, care plans, and visit documentation, are subject to healthcare record retention requirements which may require retention for a minimum of seven to ten years for adult patients. Payment records are retained for the period required by applicable financial regulations.
When you request deletion of your account (see Section 9), we will remove or anonymize your personal data within thirty (30) days, except where retention is required by law or where data is contained in backup archives that are subject to our routine deletion schedule.
7. HIPAA Notice
GenCare Connect is designed for use by hospice and palliative care organizations. If the operator of the service is a covered entity or business associate under the Health Insurance Portability and Accountability Act (HIPAA), certain information you provide — including clinical notes, diagnoses, medications, visit records, and communications between patients and providers — may constitute Protected Health Information (PHI) subject to HIPAA protections.
The platform operator is responsible for executing Business Associate Agreements (BAAs) with all applicable service providers (including Convex, Stripe, LiveKit, and OpenAI) before handling PHI in production. Please contact your platform administrator or consult your healthcare attorney regarding HIPAA compliance obligations applicable to your organization.
8. Security
All data transmitted between the app and our servers is encrypted in transit using TLS. Data stored on our backend is protected by the access controls and encryption-at-rest measures provided by our infrastructure providers. We use role-based access control so that providers can access only the records of patients with whom they have an appointment relationship.
No method of electronic transmission or storage is 100% secure. If you believe your account has been compromised, please contact us immediately at support@gencareconnect.com.
9. Your Rights and Account Deletion
Depending on your jurisdiction, you may have rights to access, correct, port, or delete your personal information. To exercise these rights:
- In-app: Navigate to Settings → Account → Delete Account to initiate account and data deletion directly from the app.
- By email: Send a request to support@gencareconnect.com with "Data Deletion Request" in the subject line. We will respond within thirty (30) days.
See our Account Deletion page for full instructions. Residents of California may have additional rights under the California Consumer Privacy Act (CCPA). Residents of the European Economic Area may have additional rights under the General Data Protection Regulation (GDPR). Please contact us to exercise any applicable rights.
10. Children
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe we have collected information from a child under 13, please contact us so we can delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the app or by email at least fourteen (14) days before they take effect. Continued use of the Service after the effective date constitutes acceptance of the revised policy.
12. Contact Us
For privacy-related questions or to exercise your data rights, contact us at:
GenCare Connect — Privacy
Email: support@gencareconnect.com