Who we are and what this policy covers
Annalog, Inc. (“Annalog,” “we,” “us”) provides software that home care agencies use to schedule caregivers, coordinate shift coverage, verify visit attendance, and communicate with their staff.
This policy describes how Annalog handles personal information in two distinct capacities, and the distinction determines your rights:
As a service provider to agencies.When a home care agency uses Annalog to manage its workforce and clients, the agency decides what data is collected and why. Annalog processes that data under contract with the agency and on the agency’s instructions. If you are a caregiver or a client of an agency, the agency, not Annalog, is the party that determines how your information is used, and the agency’s own privacy notice governs that relationship. Requests to access, correct, or delete data should ordinarily go to your agency first.
On our own behalf. When you visit our website, contact us directly, or apply for a job with us, Annalog determines the purposes of that processing itself, and this policy governs directly.
What this policy is not.This is not a HIPAA Notice of Privacy Practices. Where Annalog handles protected health information, it does so as a business associate under a Business Associate Agreement with the agency, and the agency issues its own Notice of Privacy Practices to clients. This policy is also not a substitute for your employment agreement or your agency’s employee handbook.
Whose information we handle
The Service touches three populations with materially different data profiles. We describe them separately because collapsing them would obscure what actually happens to each.
| Attribute | Caregivers | Clients and their families | Agency administrators |
|---|---|---|---|
| Relationship | Employee or contractor of the agency | Recipient of care services | Staff of the agency |
| Data character | Employment and workforce data | Care and scheduling data | Account and administrative data |
| Primary sensitivity | Location, availability, messaging | Home address, care schedule, care needs | Access credentials, audit trail |
Information we collect
3.1 Information you or your agency provides
- Identity and contact information: name, phone number, email address, mailing address.
- Employment information (caregivers): role, credentials and certification numbers, certification expiration dates, employment or contractor status, assigned clients, availability and scheduling preferences, language proficiency, and any restrictions on assignment.
- Client and visit information: client name, service address, scheduled visit times, care plan tasks assigned to a shift, and access instructions for the residence.
- Account credentials: authentication tokens, device enrollment records, and session identifiers.
3.2 Information generated by your use of the Service
- Shift and attendance records: clock-in and clock-out events, shift acceptance and release, no-shows, schedule changes, and the identity of the person who made each change.
- Location information.When you clock in or out of a visit, the Service records the device’s approximate or precise location at that moment in order to verify that the visit occurred at the correct address. That location is stored on the visit record as part of the verified attendance trail, because an electronic visit verification record must remain auditable for as long as the record itself is retained. If you choose to share your location before a shift to signal that you are en route, that location is retained for up to 30 days and then expires. Location is not collected in the background, and it is not collected when you are off shift and have not shared it.
- Messaging content and metadata: the content of messages exchanged through the Service, together with sender, recipient, timestamps, delivery status, and the channel used (for example, iMessage, SMS/RCS, or another supported messaging platform).
- Device and technical information: device model and operating system, application version, IP address, push notification tokens, and device compliance and enrollment status.
- Diagnostic information: error reports, crash logs, and performance telemetry.
3.3 Information we do not collect
We do not collect biometric identifiers. The Service does not use fingerprint, facial geometry, or voiceprint recognition for clock-in verification.
We do not sell personal information, and we do not share personal information for cross-context behavioral advertising.
Health information and the messaging channel
Home care generates health information. Annalog’s home care product is deliberately designed so that the messaging channel is not a channel for clinical documentation.
Messages exchanged through iMessage, SMS/RCS, and other consumer messaging platforms are limited to scheduling, shift offers and coverage, logistical information, and communication between caregivers and agency administrators. These channels traverse infrastructure operated by Apple, mobile carriers, and our messaging vendors, and Annalog does not control end-to-end encryption or message retention on those platforms.
Clinical documentation, care notes, and any information about a client’s health condition are handled inside authenticated Annalog surfaces subject to our HIPAA safeguards, not over consumer messaging channels.
We ask that you not send clinical or health information over messaging channels. Because messages are free text, we cannot guarantee that others will follow this rule, and we treat any message content that arrives at our systems with the same technical safeguards we apply to health information regardless of channel.
How we use information
We use personal information to:
- Build, publish, and modify schedules, and to match open shifts to available caregivers.
- Deliver shift offers, reminders, and coverage requests, and to process acceptances and releases.
- Record and verify visit attendance, including location-based verification of clock-in and clock-out.
- Route messages between caregivers, agency administrators, and clients and family members.
- Authenticate users and devices, maintain sessions, and enforce access controls.
- Maintain audit logs sufficient to reconstruct who accessed or changed what, and when.
- Provide support, diagnose failures, and monitor the reliability and performance of the Service.
- Detect and prevent fraud, unauthorized access, and abuse.
- Comply with legal obligations, including labor, wage-and-hour, and healthcare recordkeeping requirements.
- Improve the Service, using aggregated or de-identified data that cannot reasonably be linked back to an individual.
We do not train general-purpose AI models on your data. Where the Service uses machine learning to interpret voice or text, models operate on data only to produce a result for the agency that supplied it, and outputs are confirmed by a human before being written to a care record.
Retention
We retain personal information for as long as the agency’s account is active and as required afterward for legal, regulatory, and audit purposes.
| Data category | Retention |
|---|---|
| Scheduling and attendance records | Four years |
| Messaging content | Two years |
| Audit and access logs | Six years |
| Diagnostic and crash logs | 30 days |
When an agency terminates its account, we return or delete agency data as specified in our agreement with the agency, subject to any legal obligation to retain it. Deletion timelines and backup expiry are described in that agreement.
Security
We maintain administrative, physical, and technical safeguards designed to protect personal information, including encryption of data in transit and at rest, role-based access control, tenant isolation, network-level access restriction to internal systems, mandatory device enrollment for managed devices, audit logging of access to sensitive records, vulnerability scanning and dependency monitoring, and periodic review of our security practices.
Some data is cached on your device so the Service continues to work without connectivity. That data is encrypted on the device and is cleared when you sign out or when the agency removes your access.
No system is perfectly secure. If we become aware of a breach affecting your personal information, we will notify affected parties as required by applicable law and by our agreement with the agency.
Your rights
Rights depend on where you live and on whether you are dealing with Annalog as a service provider to your agency or in our own right. In most cases, direct your request to your agency, which controls the data. We will assist the agency in responding.
- California residents, including employees and contractors, have the right to know what personal information is collected and how it is used, to request correction or deletion, to limit the use of sensitive personal information, and to be free from retaliation for exercising these rights.
- Residents of other US stateswith comprehensive privacy laws — including Colorado, Connecticut, Virginia, Texas, Oregon, and others — have rights of access, correction, deletion, and portability. Most of these laws exempt employment data; California does not.
Everyone may contact us at the address in Section 12. We will not discriminate against you for exercising a privacy right.
To exercise a right, contact your agency, or contact us at support@annalogcare.com. We may need to verify your identity before acting on a request.
Children
The Service is not directed to children and is not intended for use by anyone under 18. We do not knowingly collect personal information from children. Clients receiving care are adults, and where a family member accesses the Service on a client’s behalf, that person must be an adult authorized by the agency.
Changes to this policy
We will update this policy when our practices change. Material changes will be communicated to agencies in advance through the Service or by email, and the effective date above will be revised. Continued use of the Service after a change takes effect constitutes acceptance of the updated policy.
Contact
Annalog, Inc.
Privacy inquiries: support@annalogcare.com
If you are a caregiver or client of an agency that uses Annalog, please contact your agency first. We will work with them to respond.