Last updated September 13, 2026
HealthBase (“we”, “us”) helps families coordinate care for the people they look after — appointments, bills, insurance, documents and medications. This policy explains what we collect, why, and how it's protected.
Care data is used only to power the features you use — showing your family's timeline, sending reminders, generating shareable emergency cards, and so on. We do not sell your data or use it for advertising.
Only members you explicitly invite to a family care space can see that family's data, scoped to the role you assign them (Owner, Editor, or Viewer). Emergency-card and invite links are protected by unguessable tokens and expire automatically. Anyone holding a live link before it expires can view what it shares, so treat links like you would a spare key.
Data is stored with row-level access controls so a family's records are only reachable by its own members and the automated systems that serve them. Documents are kept in a private storage bucket and served only via short-lived signed links. Passwords are never stored in plain text, and you can add two-factor authentication in Security settings.
Family Owners can schedule deletion of a care recipient, documents, or a family workspace. After the configured grace period, HealthBase removes the affected active database records and private-storage objects. Provider-managed backups may retain encrypted copies until their retention period expires. AI, email, fax, and other downstream providers follow their own contractual retention and deletion processes and may require manual confirmation.
You can edit or delete most records directly in the app. You can request a full export or schedule supported deletion scopes from Security settings. Contact support for account-authentication deletion or help with a downstream-provider erasure request.
Questions about this policy? Reach us through the Help & support page in the app.
This policy is a general template. Because HealthBase handles health-adjacent information, have it reviewed by counsel for HIPAA and applicable state-law compliance before relying on it in production.