Privacy Policy
Effective August 25, 2026
Alongside helps families and care teams coordinate care. This policy explains what information the service processes, why it is used, when it is disclosed, and the controls available to you.
1. What this policy covers
This Privacy Policy applies to the Alongside mobile application, this website, support communications, and related services (together, the “Service”). “Alongside,” “we,” “us,” and “our” refer to the operator of the Alongside Service. For privacy questions or requests, email support@alongsidefamily.com.
Alongside is a family care-coordination tool. It is not a healthcare provider, health plan, pharmacy, emergency service, electronic health record, or medical device, and it does not provide medical advice. The Service may hold health-related information that users choose to enter, so we treat that information as sensitive.
This policy does not govern the independent practices of Apple, Google, PostHog, RevenueCat, an app store, an identity provider, or a website linked from the Service. Their own terms and privacy notices apply to their services.
Back to top2. Information we collect
Account and profile information
We process your name, email address, password authentication record, verification status, profile photo if provided, locale, timezone, account status, and identifiers assigned by Alongside. If you sign in with Apple or Google, we receive the provider identifier and account details that provider makes available with your permission, such as a verified email address and name.
Care Circle and recipient information
Users may enter Care Circle names, member roles, invitation details, recipient names, photos, date of birth, timezone, care summaries, emergency information, medications, instructions, schedules, tasks, appointments, provider or location text, observations, comments, outcomes, assignments, completion records, handoff acknowledgements, and attachments. This can include sensitive health and care information about a user or another person.
Activity and accountability records
The Service records actions such as creating or changing care items, claiming work, completing or skipping an occurrence, accepting an invitation, changing a role, and requesting deletion. These records include the responsible account, relevant record, server timestamp, and a limited snapshot needed to explain the historical event.
Device, notification, and reliability information
We process device platform, app version, device identifier, push token, notification preferences, quiet hours, delivery status, network and realtime state, and support identifiers. Security audit records may include a one-way hash derived from an IP address, user-agent information, a correlation identifier, and the action performed.
Purchase information
For Plus subscriptions, we process an Alongside account identifier, plan and entitlement status, purchase and renewal events, product identifiers, store transaction information, expiration status, and webhook event identifiers. Apple or Google processes payment details; Alongside does not receive your full payment-card number.
Usage analytics
When analytics is enabled, Alongside sends PostHog an opaque Alongside user ID and a restricted set of product events, such as a screen category, care-item type, plan, platform, result, count, or network state. We do not send names, email addresses, invitation tokens, record IDs from dynamic routes, free-text notes, medication instructions, provider or location text, notification content, or other care content. Automatic touch capture and session replay are disabled.
Support and website information
If you contact us, we process your name, email address, selected topic, message, and the time and technical metadata needed to deliver and protect the form. Please do not include medical details, passwords, authentication codes, or urgent care requests in support messages. This legal website does not use advertising cookies or website analytics.
Back to top3. Where information comes from
- From you, when you create an account, enter care information, change settings, subscribe, or contact support.
- From other Care Circle members, when they invite you, add recipient information, assign work, or record care activity involving you.
- From your device, including platform, app version, push token, permission state, and reliability events.
- From Apple or Google, when you use provider sign-in, app distribution, purchases, or push delivery.
- From RevenueCat, which reconciles subscription and entitlement status.
If you provide information about another person, you must be authorized to do so and should make this policy available to that person when appropriate.
Back to top4. How we use information
- Provide accounts, Care Circles, scheduling, assignments, history, handoffs, exports, realtime updates, and other requested features.
- Authenticate users, verify email addresses, deliver invitations, and enforce Care Circle permissions.
- Generate and deliver reminders and care notifications according to user settings.
- Process subscriptions, restore purchases, reconcile entitlements, enforce plan limits, and prevent billing fraud.
- Protect the Service, investigate abuse, prevent duplicate actions, maintain audit records, and troubleshoot failures.
- Understand feature use and reliability through privacy-restricted analytics and improve the Service.
- Answer support requests and communicate material service or policy changes.
- Comply with legal obligations and establish, exercise, or defend legal claims.
Where data-protection law requires a legal basis, we process information as needed to perform our agreement with you; for our legitimate interests in operating, securing, and improving the Service; to comply with law; and with consent where we specifically request it. You may withdraw a consent through the relevant device or Service setting, but doing so does not affect earlier lawful processing.
Alongside does not use care information for targeted advertising or automated clinical decision-making.
Back to top6. Your choices and rights
- Access and correction: review or update profile and care information in the app, subject to role permissions and historical audit requirements.
- Export: a Care Circle organizer can prepare a structured Care Circle export. The signed download link expires after five minutes and the file is removed after download.
- Notifications: change category preferences and quiet hours in the app and device permissions in the operating system. Some service or security messages are not promotional and may still be sent.
- Analytics: analytics is used only when configured by Alongside. You may request that we address an analytics identifier associated with your account.
- Correction, deletion, restriction, objection, and portability: these rights may apply depending on where you live. We will honor applicable requests and explain any lawful limitation.
- Appeal or complain: contact us if you disagree with our response. You may also complain to the privacy or data-protection authority where applicable.
Send requests to support@alongsidefamily.com. We may need to verify your identity and authority over a Care Circle before acting. An authorized agent must provide proof of authority. We do not discriminate against users for exercising applicable privacy rights.
Back to top7. Retention and deletion
- Active account and Care Circle data is retained while needed to provide the Service.
- Invitations expire after seven days. Expired invitation tokens are cleaned by scheduled server maintenance.
- A requested Care Circle deletion immediately stops future care and removes other members' access. The current production default is a 30-day recovery period, after which the Circle and its scoped records are permanently deleted by a scheduled process.
- Account deletion requires the user first to transfer or delete owned Care Circles. The account is then disabled and its direct identity fields are replaced; historical activity may retain the neutral label “Former member” to preserve care accountability.
- Export links expire after five minutes. An export file is removed after download, and a scheduled job removes an undownloaded temporary export after it is at least 15 minutes old.
- Support correspondence is kept only as long as reasonably needed to answer the request, protect the Service, maintain a support history, or meet legal obligations.
- Production backup staging files are configured for a 30-day retention period. Off-site backup retention is controlled by the deployed backup provider and is limited to disaster recovery; deleted data can persist in protected backups until those backups expire.
- Security, billing, and legal records may be retained longer when reasonably necessary for fraud prevention, accounting, dispute resolution, or legal compliance.
Ordinary care-history records are archived rather than silently rewritten or hard-deleted. This preserves an accurate record of what happened. Retention settings may change for a deployment, but we will not describe a shorter period than the Service actually uses.
Back to top8. Security
Alongside uses HTTPS in production, server-enforced Care Circle authorization, secure platform storage for mobile authentication tokens, restricted server secrets, rate limits, opaque push payloads, immutable or archive-oriented history, encrypted or protected backups, and logging and analytics rules designed to exclude care-note bodies and medication instructions. Access to care data is based on active Care Circle membership, not only on what the app interface displays.
No system can guarantee absolute security. Use a unique password, protect access to your device and email account, review Care Circle membership, and contact us promptly if you believe an account or Circle has been accessed without permission.
Back to top9. International processing
Alongside and its providers may process information in countries other than the country where you live. For example, RevenueCat states that it stores customer data in the United States, and the configured PostHog region determines where analytics events are ingested. Privacy protections and lawful government access rules can differ by country. Where required, we use recognized transfer mechanisms and contractual safeguards for transfers of personal information.
Back to top10. Children's privacy
Alongside accounts are intended for adults who are at least 18 years old or the age of legal majority where they live. The Service is not directed to children, and we do not knowingly allow a child to create an account. An adult may enter information about a child as a care recipient only when legally authorized to do so. If you believe a child created an account or personal information was provided without proper authority, contact us so we can investigate and take appropriate action.
Back to top11. Health information and breach notice
Alongside is not automatically subject to the U.S. Health Insurance Portability and Accountability Act (HIPAA) merely because users enter health-related information. Do not interpret this policy as a representation that Alongside is a HIPAA covered entity, business associate, or certified as HIPAA compliant.
Other privacy and breach-notification laws may apply to consumer health information, including the U.S. Federal Trade Commission Health Breach Notification Rule when its coverage requirements are met. If a legally reportable breach occurs, we will provide notices to affected individuals and regulators in the timing and form required by applicable law.
Back to top12. Changes to this policy
We may update this policy as the Service, providers, or legal requirements change. The effective date at the top identifies the current version. If a change materially affects how we use previously collected information, we will provide notice in the app, by email, or through another appropriate channel before the change takes effect when required.
Back to top13. Contact us
Email privacy questions and requests to support@alongsidefamily.comor use the contact form. Do not send medical details, passwords, authentication codes, or emergency requests. Alongside is not monitored as an emergency channel; contact local emergency services for urgent help.
Back to top