Skip to document
app2care
For CliniciansApp LibraryFor DevelopersSign inRequest Early Access
Privacy PolicyTerms of Service

Privacy Policy

One privacy policy for the app2care website, platform, developer integrations, and CareFlow.

Last updated: September 19, 2026

On this page

  1. Services covered and our role
  2. Website, account, and organization information
  3. Developer and platform information
  4. CareFlow information
  5. Purposes and health-data boundaries
  6. Recipients and connected services
  7. Technical data, cookies, and storage
  8. Retention and safeguards
  9. Your choices and privacy requests
  10. Children’s information
  11. Updates and contact

1. Services covered and our role

This policy describes how app2care, inc. (app2care, we, us) handles information in the public app2care website, app2care platform and its developer integration services, and CareFlow when operated by app2care. These are the services covered by this policy. Contact us at support@app2care.com.

We handle business and account information to operate our relationship with visitors, users, developers, and customer organizations. When a healthcare organization uses our services to process patient information on its behalf, our handling of that information is also governed by its instructions, applicable agreements, and law, including a business associate agreement (BAA) where required. Our role depends on the service and relationship involved.

This policy does not replace a healthcare provider’s Notice of Privacy Practices, a required patient authorization, or a BAA. Independently operated marketplace apps and other services have their own privacy policies, even when accessed through app2care. A product not named here is not automatically covered by this policy.

2. Website, account, and organization information

Website access requests include your name, company or practice, role, email address or phone number, and any optional website or developer app name you provide. We retain associated submission, review, and follow-up records.

Platform accounts and onboarding may also include login identifiers, password hashes or identity-provider identifiers, contact details, organization membership and permissions, business addresses, clinician identifiers, integration descriptions, verification correspondence, and access decisions. We receive information from you, your organization’s authorized administrators, and connected sign-in providers.

Please use business contact information for inquiries. Do not send patient records, passwords, or API credentials through the public access-request form or ordinary support email.

3. Developer and platform information

Developer services handle app registrations, integration settings, API credential records, webhook destinations, declared data uses, app listings and media, security and privacy documentation, review submissions, and publication history. Information submitted for a public listing may be displayed publicly when published. Do not put secrets or patient information in listing content.

Depending on the integrations enabled, the platform receives information from connected apps, customer systems, and electronic health records. This may include patient identifiers, clinical orders, health-related events, FHIR information, event payloads, routing and delivery records, and audit information. Some information is stored to support routing, retries, troubleshooting, and service records; it is not necessarily processed only in transit.

4. CareFlow information

CareFlow supports healthcare organizations’ clinical, remote monitoring, and billing workflows. Depending on the features and integrations used, it processes staff accounts and roles, patient identifiers and demographics, clinical orders, enrollment and consent records, monitoring periods and activity, time entries, communications and notes, device assignments, and related audit records.

Billing and eligibility workflows may process insurance and subscriber details, provider information, diagnoses, claim service lines, charges, claim submissions, payer responses, and remittance information. Information may come from authorized staff, the app2care platform, connected patient apps, electronic health records, and configured billing or eligibility services.

These records may contain protected health information. The healthcare organization’s permissions and applicable agreements govern their use; this policy does not give app2care permission to use them for unrelated purposes.

5. Purposes and health-data boundaries

We use business, account, and technical information to respond to inquiries, verify and manage access, administer organizations, support integrations and app publication, communicate about services, maintain service records, troubleshoot, protect services, and meet legal obligations.

When processing health information for a customer, we use it to perform the authorized service: for example, route an event to a configured recipient, display a patient’s monitoring activity to authorized staff, or transmit a claim through a configured billing integration. Use and disclosure must remain within applicable customer instructions, agreements, and legal requirements.

Sharing an app2care account or brand does not authorize unrestricted sharing between products or organizations. This policy is not consent to patient-data marketing, sale, or unrelated model training. Any additional use requiring authorization, consent, or a contractual basis must be addressed separately before that use occurs.

6. Recipients and connected services

Information may be accessible to authorized app2care personnel and providers supporting hosting, storage, communications, security, and service operations. Customer administrators and authorized users can access information according to their roles and service configuration.

Configured integrations may send information to healthcare organizations, electronic health records, app developers, identity providers, and billing or eligibility providers. CareFlow includes integrations with Stedi for supported eligibility and claims workflows when configured. The recipients and information involved depend on the services enabled and the applicable permissions and agreements.

We may disclose information as required by law or as permitted by applicable agreements and law to protect people, address misuse, or protect legal rights. A business transfer may involve transferring information, subject to applicable restrictions. These provisions do not override restrictions on protected health information. Third-party operators remain responsible for their own services and privacy practices.

7. Technical data, cookies, and storage

Our services and technical providers may process IP addresses, browser and device information, request times, service activity, and diagnostic or security logs to deliver, maintain, and protect the services.

The public website uses browser session storage to restore scroll position and loads fonts from Google Fonts. Font requests send technical information, including your IP address, to Google; see Google’s Privacy Policy. Platform and CareFlow sign-in use authentication cookies, browser storage, or identity-provider sessions, depending on the sign-in method. Browser settings can clear or restrict storage, but doing so may interrupt sign-in or other features.

Providers and connected services may process information in locations different from yours. Applicable service agreements and legal requirements govern any restrictions on processing location or transfers. Contact us for information relevant to your organization’s configuration.

8. Retention and safeguards

Retention depends on the type of information, service configuration, request or account status, customer instructions, contractual commitments, operational needs, and legal requirements. Event payloads, delivery records, clinical and billing records, audit logs, correspondence, and backups may have different retention periods. We do not apply one universal deletion deadline to all data.

Closing an account does not necessarily erase records held for a healthcare organization or remove records from connected systems. Health-data return or deletion is governed by the applicable service agreement or BAA and legal requirements. Contact us or the responsible healthcare organization to discuss a specific request.

Our services use safeguards including authentication, role-based access controls, and audit records. No system can be guaranteed completely secure. Security responsibilities are shared with customer organizations and connected providers, including managing authorized users, devices, and integration credentials.

9. Your choices and privacy requests

Contact support@app2care.com about access to, correction of, or deletion of business/account information, or to stop optional business communications. We may need to verify your identity and authority, and some records may need to be retained. Your rights and our response obligations depend on applicable law; you may also contact the relevant privacy regulator where applicable.

For patient records processed on behalf of a healthcare organization, contact that organization first. We support its handling of requests as required by our agreements and law; we may need to refer your request to it rather than independently change or delete a clinical record. Contact the relevant third-party operator for information held in its own service.

Customers can manage authorized users and integrations through the available controls. Removing access does not itself revoke a legally required record-retention obligation or delete information previously delivered to another authorized recipient.

10. Children’s information

The public website and professional platform/CareFlow accounts are intended for adult business users and authorized healthcare staff. They are not offered as accounts for children. Healthcare organizations may use the services to process records about minors when authorized and subject to applicable requirements; a professional-user service may therefore still contain children’s health information.

A patient-facing app has its own operator, age requirements, and applicable privacy notices. If you believe information about a child was provided improperly, contact us or the healthcare organization responsible for the records so the concern can be addressed.

11. Updates and contact

We may update this policy as the covered services and practices change. The last-updated date identifies this revision. We will provide additional notice or obtain consent where required; changing this policy does not override an existing BAA or authorize a previously impermissible use of health information.

Questions or privacy requests: support@app2care.com. Please describe the service and your relationship to the account or organization without including patient records in your initial email.

See also: Terms of Service.

The connective tissue between digital health apps, clinical practices, and backend services.

app2care
Product
  • App Library
  • For Developers
  • How it Works
Legal
  • Privacy Policy
  • Terms of Service
© 2026 app2care, inc. all rights reserved.support@app2care.com