Privacy Policy
This policy explains what information Careinflux collects, how we use and protect it, and the choices and rights you have. We take the privacy of your data — and the health information of those you serve — seriously.
Last updated: June 24, 2026
1. Overview
Careinflux ("Careinflux," "we," "us," or "our") provides a cloud-based clinical operations platform for therapy agencies, schools, and the clinicians who serve students and clients (the "Service"). This Privacy Policy describes how we handle information when you visit our website, create an account, or use the Service.
By using our website or the Service, you agree to the practices described in this policy. If you do not agree, please do not use the Service. This policy works alongside our Terms of Service.
2. Who We Are
Careinflux is a United States–based software provider. Depending on how you use the Service, we may act in two different roles:
- As a data controller for information we collect directly from website visitors and account administrators — for example, marketing contacts, billing details, and account credentials.
- As a service provider and HIPAA Business Associate for the clinical data that our customers (the therapy agencies and schools who license the Service) store in the platform. In that role, our customer is the data controller, and we process data on their behalf and under their instructions.
3. Information We Collect
Information you provide
- Account information — name, work email, phone number, organization name, and role.
- Billing information — billing contact and payment details processed securely by our payment provider (we do not store full card numbers on our servers).
- Clinical and operational data — records that customers and their authorized users enter into the platform, such as student and client profiles, schedules, session notes, documentation, contracts, and reports.
- Support and communications — messages, requests, and feedback you send us.
Information we collect automatically
- Usage data — pages viewed, features used, actions taken, and timestamps.
- Device and log data — IP address, browser type, operating system, and referring pages.
- Cookies and similar technologies — see Cookies & Tracking below.
4. Protected Health Information & HIPAA
Some information stored in Careinflux may constitute Protected Health Information ("PHI") under the Health Insurance Portability and Accountability Act ("HIPAA"). When we handle PHI on behalf of a customer who is a covered entity or business associate, we act as a HIPAA Business Associate.
- We provide a signed Business Associate Agreement (BAA) to every customer at no additional cost.
- We only use and disclose PHI as permitted by the BAA, this policy, and applicable law.
- We maintain administrative, physical, and technical safeguards designed to protect PHI, including encryption, access controls, and audit logging.
- We do not sell PHI, and we do not use PHI for advertising.
If you are an individual whose PHI is stored in the platform (for example, a student, client, or parent), your rights regarding that information are generally exercised through the agency or school that provides your care. Please contact them directly, or see Your Privacy Rights.
5. How We Use Information
We use the information we collect to:
- Provide, operate, secure, and maintain the Service.
- Authenticate users and enforce role-based access controls.
- Process billing and manage subscriptions.
- Respond to support requests and communicate about your account.
- Monitor, troubleshoot, and improve performance and reliability.
- Detect, prevent, and respond to fraud, abuse, and security incidents.
- Send service updates and, where permitted, relevant product information (you can opt out of marketing at any time).
- Comply with legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use PHI for marketing or advertising.
6. How We Share Information
We share information only as described here:
- With your organization — administrators and authorized users in your account can access data according to their assigned roles and permissions.
- With service providers — vetted vendors who help us operate the Service (such as cloud hosting, payment processing, and email delivery) under contracts that require appropriate safeguards. Vendors handling PHI sign a BAA with us.
- For legal reasons — when required by law, subpoena, or other legal process, or to protect the rights, safety, and security of users and the public.
- In a business transfer — in connection with a merger, acquisition, or sale of assets, subject to the protections in this policy.
We never sell personal information or PHI to third parties.
8. Data Security
We apply enterprise-grade safeguards to protect your data, including:
- Encryption in transit (TLS 1.3) and at rest (AES-256).
- Role-based access control and the principle of least privilege.
- Detailed audit logging of activity within the platform.
- Soft-delete architecture so records are not immediately destroyed.
- Automated, encrypted backups with point-in-time recovery.
- Hosting in SOC-2 certified data centers in the United States.
No method of transmission or storage is completely secure, but we work continuously to protect your information and to meet the requirements of healthcare data protection. Learn more on our Security & Compliance page.
9. Data Retention
We retain account and clinical data for as long as your organization maintains an active account, and afterward only as needed to comply with legal, regulatory, or contractual obligations. Customers can export their data at any time in standard formats. When data is no longer required, we delete or de-identify it in accordance with our retention schedule and applicable law.
10. Your Privacy Rights
Depending on where you live, you may have rights to access, correct, delete, or restrict the use of your personal information, to receive a copy of it, or to object to certain processing. These rights include protections under laws such as the California Consumer Privacy Act (CCPA/CPRA) and similar state laws.
- If you have a Careinflux account, you can review and update much of your information directly in the app.
- For requests we control, contact us at [email protected] and we will respond within the time required by applicable law.
- For data stored on behalf of an agency or school (including PHI), please direct your request to that organization; we will assist them as their Business Associate.
We will not discriminate against you for exercising any of your privacy rights.
11. Children's Privacy
The Service is intended for use by therapy agencies, schools, and clinicians — not by children directly. Records about minors are entered and managed by authorized professionals on behalf of those minors and their guardians, consistent with HIPAA, FERPA where applicable, and our customers' obligations. We do not knowingly allow children to create accounts or use the Service on their own.
12. International Users
Careinflux is operated in the United States, and our infrastructure is hosted in the United States. If you access the Service from outside the United States, you understand that your information will be processed and stored in the United States, where data protection laws may differ from those in your country.
13. Third-Party Services
Our website and the Service may link to or integrate with third-party services (for example, payment processing). This policy does not cover the practices of those third parties. We encourage you to review their privacy policies. We select vendors carefully and require appropriate safeguards, including a BAA where PHI is involved.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will revise the "Last updated" date above and, where appropriate, notify you through the Service or by email. Your continued use of the Service after an update means you accept the revised policy.
15. Contact Us
If you have questions about this Privacy Policy or how we handle your information, contact us:
- Email: [email protected]
- Or use our contact page.
Questions about our policies?
Our team is happy to clarify anything in these documents or walk you through how we handle your data.