SeniorThrive Privacy & Data Sharing Policy
Last Updated and Effective Date: April 20, 2026
This policy replaces all previous versions.
Your Privacy at a Glance (Key Takeaways)
We know privacy policies can be long, so here's a quick overview:
- We Collect Your Info: To provide and improve SeniorThrive, and to keep it secure.
- Your Health Info is Special (PHI): It gets extra protection and is only shared with your explicit consent through ThriveCircle.
- You're in Control: You can see, change, or ask us to delete your information. You also control marketing communications.
- Strong Security: We use robust measures to protect your data.
- ThriveCircle Sharing: You decide what PHI is shared with whom in your care circle.
- Our Full Terms: This policy works together with our Terms of Service, which has more legal details.
Questions? We're here to help. Contact us at [email protected].
Respecting Your Privacy: Secure & Trustworthy
In the digital age, privacy is vital, especially when it involves your home and health. At SeniorThrive, we place your privacy and security at the core of our service. We're not just creating a platform; we're building a trusted environment where we are deeply committed to protecting your safety and confidentiality.
Our Commitment to Health Data Privacy
SeniorThrive is committed to protecting the privacy and security of your health-related information. While SeniorThrive is not a HIPAA covered entity or business associate, we voluntarily apply strong privacy and security standards to all health-related information you share with us, including encryption, access controls, and audit logging. If we enter into arrangements with healthcare providers or other HIPAA-covered entities that require us to act as a Business Associate, we will enter into appropriate Business Associate Agreements and comply with the applicable requirements of HIPAA.
Scope & Acceptance
By creating an account or using the SeniorThrive web app or any ThriveCircle feature ("Services"), you confirm that you have read, understood, and agree to this entire Privacy & Data Sharing Policy and our Terms of Service (which are incorporated herein by reference and govern your use of our Services). You are also responsible for taking reasonable steps to protect your account, such as using a strong password and keeping your login credentials confidential.
Who's Covered: All users, including Focus Older Adults (OAs), Circle Administrators, Professional Caregivers, and Family Members, whenever you access any SeniorThrive feature.
Information We Collect
We collect and process the following categories of information:
Account & Contact:
Name, email, phone number, password.
Device & Usage:
Device type, operating system, IP address, browser type, features used, errors encountered.
Location (with your consent):
Precise or coarse GPS data to enable location-based services.
Profile & User-Generated:
Photos you upload, free-text entries, support requests.
Health & Fitness (if you opt in):
- PHI: Activities of Daily Living (ADL), Instrumental ADL, BMI, medication logs, fall incidents, wellness check-ins, mood/symptom tracking, vital signs.
- Non-PHI: Aggregate metrics (ThriveScore), general activity counts.
Household & Environmental:
Room Check photos, pet information, household to-do lists.
Financial (if you transact):
Payment details collected via secure third-party processors (we never store full card numbers).
Cookies & Tracking:
- We use cookies, beacons, and similar technologies for analytics and personalization.
- Marketing Cookies (Optional): If you opt in, we and selected third parties may use these to measure ad performance and serve relevant ads.
De-Identification:
When processing data for analytics or research, we strip direct identifiers (name, email, device ID) and employ methods consistent with recognized de-identification standards (such as those outlined under HIPAA) to prevent re-identification. We avoid combining this de-identified data with other datasets that could lead to re-identification unless you explicitly opt in.
Tracking & Third-Party Analytics
We and selected third-party partners may link your SeniorThrive web-app usage with activity on other websites for analytics, advertising measurement, or retargeting. For a detailed list of all cookies and tracking technologies we use, please see our Cookie Policy.
Product Analytics (SeniorThrive Web Application):
Within the SeniorThrive web application, we use PostHog (PostHog, Inc., 2261 Market Street #4008, San Francisco, CA 94114, United States) to understand how our service is used and to improve the experience. PostHog acts as our data processor under a Data Processing Agreement and stores data in the United States. PostHog receives a pseudonymous user ID and event data describing your interactions with the platform (such as page views and sign-in events). PostHog does not receive your name, email address, home address, phone number, date of birth, medications, home safety photos, assessment results, care plan, role (senior, family member, or caregiver), or any information about your health or care relationships. Session recording is disabled. We load PostHog only after you grant Tier 3 (Marketing & Analytics) consent, and we honor the Global Privacy Control (GPC) browser signal as a universal opt-out.
Cookie Banner Controls:
Our cookie banner offers at least three tiers, Necessary, Functional, and Marketing. You choose which to allow.
Browser Settings:
You can disable or block third-party cookies in your browser (Chrome, Safari, Firefox, etc.).
Do-Not-Track:
While browsers may send a "Do Not Track" signal, enforcement varies. Use your cookie banner choices and browser settings for reliable control.
How We Use & Share Your Information
App Functionality & Security:
To provide, maintain, and secure our Services, including authentication, fraud prevention, uptime monitoring, customer support.
Personalization & Analytics:
Content recommendations, troubleshooting, feature testing, service improvement.
Care Collaboration (ThriveCircle):
With your explicit approval, share precise data categories with caregivers and family as detailed in the ThriveCircle Addendum.
Communication:
Notifications, onboarding emails, product updates, service announcements (you control marketing opt-in/out).
Third-Party Services & Advertising:
We share information with third-party service providers who assist us in operating our Services, only under strict confidentiality agreements (including Business Associate Agreements where PHI is involved). Advertising data is shared only with your opt-in.
Legal Compliance:
Responding to lawful requests from public and government authorities, complying with legal processes, enforcing our terms and conditions, protecting our operations or those of any of our affiliates, protecting our rights, privacy, safety or property, and/or that of our affiliates, you or others; and allowing us to pursue available remedies or limit the damages that we may sustain.
Business Transfers:
In a merger, acquisition, financing, reorganization, bankruptcy, or sale of all or a portion of our assets, your information may be sold or transferred as part of that transaction. Your rights and protections regarding your PHI will travel with it.
Referral Introductions:
If you request a referral through SeniorThrive, we may collect details you provide (such as your name, contact information, and general description of your home safety or accessibility needs) to help identify an appropriate service provider. We may share only the necessary details with potential providers to facilitate an introduction. We do not sell or rent this information, and we encourage you to review the privacy practices of any provider you choose to engage.
Artificial Intelligence and Automated Processing
Several SeniorThrive features use artificial intelligence (AI) and automated processing to provide you with personalized information and recommendations. We believe in full transparency about how your data is processed by AI systems.
AI-Powered Features:
The following features use Google's Gemini AI models, which we access through Google Cloud's Vertex AI platform provided by Google LLC under enterprise data processing terms. References to "Google Gemini" below refer to processing through this platform:
- Room Check: Photos you upload of your home rooms are sent to Google Gemini for analysis to identify potential safety considerations.
- AI Companions: Messages you send to AI companions (Clarity, Riley, Luigi, Buddy, Sage, Harper, Morgan, Navigator) are processed by Google Gemini. With your consent, companions may also access specific data categories (such as Room Check results, wellness logs, daily check-ins, or care plans) to personalize their responses.
- Health Information Finder: Search queries you enter about health topics are sent to Google Gemini to generate informational content.
- Medication Label Reader: Photos of medication labels you upload are sent to Google Gemini to extract medication details such as name, dosage, and instructions.
- Scam Checker: Text you submit for scam analysis is sent to Google Gemini to assess whether it may be fraudulent.
- Plant Identification: Photos of plants you upload are sent to Google Gemini for identification.
- Hobby Explorer: Hobby-related content is generated using Google Gemini based on topics you select.
- Voice Notes: Audio recordings submitted by caregivers are processed for transcription.
- Questionnaire Analysis: Your responses to profile questionnaires may be processed to generate personalized recommendations.
- Care Plan Generation: Assessment data (including ADL and IADL scores) may be processed by AI to help generate care plan recommendations.
- Care Pack Insights: Care pack information may be processed by AI to generate contextual insights for caregivers.
AI Data Handling:
We process your data through Google Cloud's Vertex AI platform under Google's enterprise data processing terms and Data Processing Addendum. Under these terms: (1) Google does not use your data, prompts, or AI outputs to train or improve Google's foundation AI models; (2) Google acts as our data processor with respect to your data, not as an independent controller; (3) Google may retain input and output data for up to 30 days solely for abuse and safety monitoring, after which it is deleted; and (4) data is processed within Google Cloud regions we select. We do not permit any AI sub-processor to use your data for purposes beyond providing the service to SeniorThrive.
AI Limitations:
AI-generated content is provided for informational purposes only and may contain errors, omissions, or inaccuracies. AI outputs do not constitute medical advice, professional home safety assessments, or clinical recommendations. You should not rely solely on AI-generated information and should always consult qualified professionals for medical, safety, or care decisions.
Automated Decision-Making:
SeniorThrive uses automated processing to compute your ThriveScore (a composite wellness, safety, and connection metric) and to assess medication risk profiles based on FDA data. These computations are performed on our own servers and do not involve external AI services. No automated decision has binding legal or similarly significant effects on you. You may contact us at [email protected] to request information about how automated processing applies to your account.
Integration with Third-Party Services
In addition to the AI services described above, SeniorThrive integrates with the following third-party services that may receive your data:
Google Services:
- Google Calendar: If you connect your calendar, appointment details (event titles, times, locations, and attendees) are synced with Google Calendar via their API.
- Google Photos: If you connect Google Photos, we access your photos and albums with your OAuth authorization. We request read-only access.
- Google Maps: Address and location data may be sent to Google Maps for geocoding and location-based features.
- YouTube API: Enables video features (e.g., embedded tutorials, SeniorThrive Explores series). Search queries are sent to YouTube.
Health Data Services:
- FDA openFDA API: Medication names (without any personal identifiers) are sent to the U.S. Food and Drug Administration's public API to retrieve drug label information and recall data.
- MyHealthFinder (HHS): Demographic information (age and sex, without personal identifiers) may be sent to the U.S. Department of Health and Human Services to retrieve personalized health recommendations.
Product and Content Services:
- Book Search: Book search queries are sent to Google Books, Open Library, and the New York Times Bestseller API.
- Product Search: Product search queries may be sent to SerpAPI for product discovery.
Other Integrations:
Fitness trackers (such as Oura, Fitbit, and Withings), analytics platforms, and other third-party services we integrate with are vetted for appropriate privacy and security standards, including data processing agreements where applicable.
Third-Party Privacy Policies:
By using SeniorThrive features that interact with Google services, you also agree to Google's Terms of Service and Privacy Policy. We encourage you to review the privacy practices of all third-party services you connect through SeniorThrive.
Your Rights & Choices
Access & Correction:
View or edit your account details and PHI entries at any time through your account settings.
Export & Deletion:
Download your data (e.g., in CSV/JSON format) or request permanent deletion of your account and associated data, subject to legal retention requirements and our data retention policies.
Consent Management:
Toggle data-sharing settings in Settings → Privacy, especially for ThriveCircle features.
Cookie Controls:
Adjust cookie preferences via our cookie banner or your browser settings.
Email Opt-Out:
Every marketing email footer has an "Unsubscribe" link; you can also adjust preferences under Settings → Notifications.
Children's Privacy:
We do not knowingly collect personal information from children under 13 (or a higher age threshold where applicable by law). Our services are not directed to children. If we learn we have collected a child's personal information, we will promptly delete it.
State-Specific Privacy Rights
Depending on where you live, you may have additional rights under state privacy laws. Below is a summary of key rights by state. To exercise any of these rights, contact us at [email protected]. We will respond within the timeframe required by applicable law. We will not discriminate against you for exercising your rights.
California (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know: Request the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Delete: Request deletion of your personal information, subject to certain exceptions.
- Correct: Request correction of inaccurate personal information.
- Opt Out of Sale/Sharing: SeniorThrive does not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Limit Use of Sensitive Personal Information: You may limit our use of sensitive personal information (including health data) to purposes necessary to provide the Services.
- Non-Discrimination: We will not deny you services, charge different prices, or provide a different quality of service because you exercised your privacy rights.
You may designate an authorized agent to make a request on your behalf. We may require verification of your identity before fulfilling any request.
Washington (My Health My Data Act)
If you are a Washington resident, the My Health My Data Act provides you with specific rights regarding consumer health data, which includes information SeniorThrive collects such as medication information, wellness check-ins, vital signs, Room Check results, and any health-related search or symptom entries. These rights do not extend to our product-analytics telemetry (page views and sign-in events sent to PostHog), which does not identify your health status, conditions, role, or care relationships. Your rights with respect to your consumer health data include:
- Consent: We will obtain your consent before collecting or sharing your consumer health data, except as necessary to provide the Services you requested.
- Access: You may request confirmation of whether we are collecting or sharing your consumer health data.
- Deletion: You may request deletion of your consumer health data.
- Withdrawal: You may withdraw consent for future collection or sharing of your consumer health data.
Colorado, Connecticut, Virginia, and Texas
If you reside in Colorado, Connecticut, Virginia, or Texas, you generally have the right to:
- Confirm whether we are processing your personal data and access that data.
- Correct inaccuracies in your personal data.
- Delete your personal data.
- Obtain a portable copy of your personal data.
- Opt out of targeted advertising, sale of personal data, and profiling that produces legal or similarly significant effects.
- Automated Decision-Making (Colorado, Connecticut): You have the right to opt out of profiling in furtherance of decisions that produce legal or similarly significant effects. You may also request information about the logic used in automated processing that affects you.
If we decline your request, you may appeal by contacting us at [email protected] with the subject line "Privacy Rights Appeal."
Email Communication & Consent
Opt-In Required:
During signup, you explicitly consent to receive emails, each opt-in is logged with a timestamp.
Confirmation Email:
After you opt in, we send a verification link before any regular communications begin.
Types of Messages:
Welcome/onboarding, wellness reminders, product updates, community news, legal/security notices.
Withdraw Consent:
Use the "Unsubscribe" link in any email or adjust in Settings → Notifications.
Third-Party Delivery:
We use trusted providers (e.g., Dreamlit, OneSignal) under strict confidentiality; we never sell your email address.
Security Measures
We employ robust technical, administrative, and physical safeguards designed to protect your information from unauthorized access, use, alteration, and disclosure. These include:
- Encryption: AES-256 at rest; TLS 1.2+ in transit.
- Access Controls: Role-based permission checks on every PHI request.
- Audit & Breach Monitoring: Immutable logs of all PHI actions; automated alerts for suspicious activity.
- Business Associate Agreements (BAAs): We enter into BAAs with any third party handling PHI on our behalf, as required by HIPAA.
- Regular Security Assessments: We conduct periodic security reviews and vulnerability assessments.
While we take significant measures to protect your data, no security system is impenetrable. We cannot guarantee the absolute security of your information. In the event of a data breach involving your personal information where notification is required by law, we will notify you in accordance with applicable legal requirements.
Changes to This Policy & Contact
We'll post updates to this Privacy Policy here and notify you (e.g., via email or in-app notification) at least 30 days before material changes take effect. Your continued use of SeniorThrive after such notice constitutes your acceptance of the revised policy.
Questions or Complaints: [email protected]
Accessibility: We are committed to making this policy accessible. If you need it in an alternative format, please contact us.
Contact Us
Privacy questions, data requests, or notices under applicable state privacy laws may be sent to:
SeniorThrive LLC
Attn: Privacy Officer
5436 Via Carrizo, Laguna Woods, CA 92637
Email: [email protected]
Acknowledgement
By continuing to use SeniorThrive, via the web app or ThriveCircle features, you confirm you've read, understood, and accepted this Privacy & Data Sharing Policy and our Terms of Service in their entirety.
Governing Law & Our Terms of Service
This Privacy Policy and any disputes related to it or your use of SeniorThrive Services will be governed by and construed in accordance with the laws of the State of California, without regard to its conflict of law principles.
Our Terms of Service contain important provisions regarding dispute resolution (which may include arbitration and a class action waiver), limitations on liability, and other terms that govern your use of our Services. Please review them carefully.
International Data Transfers
SeniorThrive is based in the United States. If you are accessing our Services from outside the United States, please be aware that your information, including personal data and PHI, may be transferred to, stored, and processed in the United States, where our servers are located and our central database is operated. The data protection and other laws of the United States might not be as comprehensive as those in your country. By using our Services, you consent to your information being transferred to our facilities and to the facilities of those third parties with whom we share it as described in this Privacy Policy.
ThriveCircle Data-Sharing Addendum
This Addendum applies only when you use any ThriveCircle features centered on a Focus Older Adult's (OA's) care. It details how data, especially Protected Health Information (PHI), is shared within a ThriveCircle.
Key Definitions
PHI (Protected Health Information):
Information that relates to your past, present, or future physical or mental health or condition, the provision of health care to you, or the past, present, or future payment for the provision of health care to you, and that identifies you or for which there is a reasonable basis to believe it can be used to identify you. Examples include medication logs, fall incidents, vital signs, and mood/symptom entries.
Non-PHI:
Other data that is not PHI. Examples include room checks (unless they incidentally contain PHI), general appointments, and to-do lists.
Roles:
- Focus OA: The older adult whose data lies at the heart of the Circle.
- Circle Admin: Manages membership & shared household information.
- Professional Caregiver: Enters and views clinical PHI necessary for care, often operating under a BAA with SeniorThrive or their employing agency.
- Family Member: Views approved data categories, adds non-PHI entries, and may sync calendars.
Role-Based Permissions & PHI
| Action / Category | Focus OA | Circle Admin | Professional Caregiver | Family Member | PHI? |
|---|---|---|---|---|---|
| Medications | ✓ | With Consent | With Consent | With Consent | PHI |
| Fall Incident Reports | ✓ | With Consent | With Consent | With Consent | PHI |
| Wellness Check-Ins & Mood Logs | ✓ | With Consent | With Consent | With Consent | PHI |
| Vital Signs & Clinical Notes | ✓ | With Consent | With Consent | With Consent | PHI |
| Medical Appointments | ✓ | With Consent | With Consent | With Consent | PHI |
| General Appointments | ✓ | ✓ | ✓ | ✓ | Non-PHI |
| Household / Room Checks | ✓ | ✓ | With Approval | With Approval | Non-PHI |
| Calendar Sync (External Apps) | ✓ | ✓ | ✓ | ✓ | Non-PHI |
Footnotes:
- Explicit OA consent required before any access.
- Sensitive household items (e.g., room check photos) require OA/Admin approval for sharing.
- Only non-PHI metadata (e.g., event time, title, location for general appointments) syncs unless you expressly opt in to share more details that might constitute PHI.
Consent Workflows & Modals
We use clear, step-by-step consent processes:
PHI Category Toggle:
Location: Settings → Privacy → individual toggles with [Learn More] links (e.g., to a relevant FAQ or section explaining PHI sharing medications).
Modal #1 ("Share PHI Data?"):
- Title: "Share Your [Category] with [Role Name]?"
- Body: "You're about to share your [Category], sensitive health information, with [Role Name]. This data is encrypted, and you can revoke access at any time in Settings."
- Buttons: [Cancel] [Confirm & Share]
- Learn More: Links back to this Addendum's Role-Based Permissions table.
Invite Member:
- Trigger: "Invite Caregiver" or "Invite Family" in ThriveCircle.
- Modal #2 ("Inviting [Role Name]"):
- Title: "Invite [Role Name] to Your ThriveCircle"
- Body: "They'll view your shared categories and, for caregivers, may enter clinical updates. You control every permission in Settings."
- Buttons: [Back] [Send Invite]
- Learn More: Anchors to "Role-Based Permissions" above.
Connect External Calendar:
- Trigger: "Connect Calendar" for Admins or Family.
- Modal #3 ("Connect External Calendar?"):
- Title: "Sync ThriveCircle with Your Calendar"
- Body: "You'll sync appointment events (typically non-medical unless specified) to [Google/Apple Calendar]. No sensitive health data leaves SeniorThrive unless you explicitly opt in to share more."
- Buttons: [Cancel] [Allow Sync]
- Learn More: Points to the Integration section under "Non-PHI Calendar Sync."
Audit & Revocation
Immediate Enforcement:
Revoking consent via Settings → Privacy instantly hides all affected PHI from the relevant Circle member(s).
Notifications:
In-app toasts and optional email alerts to impacted members:
Example: "Access to [Focus OA Name]'s [Category] data was revoked by [Focus OA Name/Circle Admin Name] on May 20, 2025."
Data Retention & Portability
Active PHI:
Remains accessible within an active ThriveCircle according to the permissions you've set.
Post-Circle/Account Closure:
Upon ThriveCircle deletion or Focus OA account closure (including in the event of death), PHI is archived for a period of six months. This retention period supports data recovery needs and allows legally designated representatives to request data export. After this period, PHI is securely purged from our active systems, subject to any overriding legal or regulatory retention obligations.
Export:
You or your legally designated representative can request an export of your data.