Angel

Effective July 22, 2026 · Version 2026-07-22.1

Privacy Policy

This policy explains how [LEGAL_ENTITY_NAME] (“Angel,” “we”) collects, uses, shares, and protects information when providing the Angel service through a participating senior-living community. It covers residents who receive calls, family members, and community staff.

⚖️

Draft pending attorney review. Bracketed [VALUES] must be completed by the operating entity, and this document must be reviewed by a licensed attorney, including state-by-state call-recording-consent law, before it is relied on in production.

The short version

What a resident says on a call is private by default. What leaves that circle is a pattern, not a transcript, and safety always outranks privacy.

  • Angel’s companion calls are made by an AI, are recorded, and analyzed by an AI system, and we ask for that consent separately, before the first call, and record exactly which disclosure text was agreed to and when.
  • Family and staff normally see only consented trends and deliberately vague summaries, never transcripts or verbatim quotes. Staff can access more only through a logged, reason-required action.
  • The safety exception: explicit signs of self-harm, abuse, or immediate danger are shared with the care team in full, immediately, and that override is itself logged.
  • You can see, export, correct, or delete your information, review every consent you’ve given on the Privacy & consents page, and withdraw call-recording consent, which pauses the calling program, since analysis is the safety feature.
  • We use a small set of service providers (hosting, telephony, AI analysis) under contract. We don’t sell personal information, and we don’t use resident conversations for advertising.

This summary is for readability only. The numbered sections below are the binding text.

1Who we are2What we collect3Why we process it4Call recording & AI analysis5Privacy boundaries6Sharing & subprocessors7Retention & deletion8Your rights & choices9Security10Breach notification11Children12Changes to this policy13Contact

01Who we are & our role

The Angel service is operated by [LEGAL_ENTITY_NAME], a(n) [ENTITY_TYPE] organized under the laws of [STATE_OF_INCORPORATION], registered at [REGISTERED_ADDRESS]. Privacy contact: [PRIVACY_CONTACT_EMAIL].

Angel is business-to-business infrastructure: for resident and family records the participating Community decides who is enrolled, who may see what, and how long records are kept. Angel processes that information on the Community’s behalf under a service agreement. For account and usage data needed to operate and secure the platform itself, Angel acts on its own behalf.

02What we collect, and from whom

From residents: name, room, phone number, date of birth, intake details (interests, baseline wellbeing, preferred call times), consent choices; call audio recordings and transcripts; and AI-derived call metadata: mood signals, topics, distress flags, summaries, and wellbeing-zone assessments. Conversations may incidentally include health-adjacent information a resident chooses to share.

From family members: name, email, phone number, relationship to the resident, notification preferences, messages sent to the care team, and consent/acceptance records.

From staff: name, work email, phone, role, shift pattern, and actions taken in the applications (task updates, escalations, and, logged in detail, any access to sensitive resident records).

From everyone (device & usage data): authentication events, IP address, browser type, and security/audit logs generated as you use the applications. We do not run third-party advertising or cross-site tracking.

03Why we process it (purposes & legal bases)

(a) Providing the service: placing scheduled calls, coordinating care tasks, and delivering consented family updates (performance of the service relationship). (b) Call analysis: AI analysis of recordings and transcripts to surface wellbeing patterns (your explicit, separately captured consent, Section 4). (c) Safety: escalating explicit crisis disclosures to the care team (vital interests / protection of the resident). (d) Security & integrity: authentication, audit logging, abuse and incident investigation (legitimate interests in operating a safe service). (e) Legal compliance: retention, deletion, and disclosure obligations under applicable law. We do not sell personal information and do not use resident conversations for advertising or for training third-party foundation models.

04Call recording & AI-analysis consent

Consent to record is captured separately, never bundled

Recording laws differ by state and country: some require every party’s consent (“two-party” states such as California and Massachusetts), others one party’s. Angel therefore treats call-recording/AI-analysis consent as its own agreement, never folded into general Terms or Privacy acceptance, and does not assume any single jurisdiction’s rule is enough.

Before any call is recorded or analyzed, an explicit, timestamped consent is captured and stored with the specific disclosure text version agreed to. How the resident’s own consent is obtained, and who is responsible:

(1) Community intake: for residents enrolled by the Community, the Community is responsible for obtaining the resident’s (or their authorized decision-maker’s) recording consent during intake, before the first call is scheduled, and recording it in Angel’s consent records. (2) Resident self-signup: a resident creating their own portal account accepts the recording/analysis disclosure as a separate, unbundled step. (3) Audible disclosure: the AI companion states on the first call that calls are recorded and reviewed to support the resident’s care, answers honestly if ever asked whether calls are recorded, and each disclosure event is logged. A family member’s acceptance covers their own use of AI-derived updates; it is never treated as consent on the resident’s behalf.

Withdrawal has a real consequence, stated plainly: Angel has no “unrecorded call” mode. Analysis is the safety-monitoring feature. If a resident withdraws recording/AI-analysis consent, scheduled AI calls are paused entirely, the care team is notified to arrange human check-ins instead, and calls resume only if consent is given again. Withdrawal is available on the Privacy & consents page or through the Community.

05Privacy boundaries: who sees what

Anything a resident says is private by default. A single policy engine, not per-screen judgment, decides what leaves that boundary: (a) family members see only what the resident’s consent scope allows: trend direction and deliberately non-clinical summaries, never transcripts, never verbatim quotes, never raw numeric scores; (b) staff see consented trends, flags, and shareable summaries; raw transcripts and detailed private summaries require an explicit elevated-access action with a recorded reason, which is audit-logged; (c) managers see aggregate, facility-level views. Safety exception: explicit self-harm, suicidal-ideation, abuse, or immediate-danger disclosures are shared with authorized care staff in full detail immediately; the override itself is written to the audit log with its reason.

06Sharing & subprocessors

We share personal information only with: (a) the Community: your care team and its managers, per the boundaries above; (b) service providers processing on our behalf under contract; (c) authorities when required by law or to protect a person from serious harm; and (d) a successor entity in a merger or acquisition, with notice. Current subprocessors used by the deployed service:

Supabase (database, authentication, US hosting) · Vercel (application hosting) · Bland AI (telephony and voice AI for calls) · Anthropic or the configured language-model provider (transcript analysis) · ElevenLabs (voice synthesis, where enabled) · Twilio (SMS notifications, where enabled) · Typesense (search, where enabled) · the Community’s email delivery provider. The operator maintains the authoritative, current subprocessors list at [SUBPROCESSORS_LIST_URL] and will update this policy when it changes materially.

07Retention & deletion

Records are kept only as long as needed for the purposes above: (a) call recordings, transcripts, and analyses, for the period set in the Community Agreement, defaulting to [DEFAULT_RETENTION_PERIOD_E_G_24_MONTHS] after the call, then deleted or de-identified; (b) account and consent records, for the life of the account plus [CONSENT_RECORD_RETENTION_E_G_7_YEARS], because consent history is itself a compliance record; (c) audit logs, [AUDIT_LOG_RETENTION_PERIOD]; (d) safety-escalation records, per the Community’s incident-documentation obligations. When a resident’s record is deleted, resident-derived rows (calls, transcripts, analyses, trends) and orphaned portal identities are removed, and only a non-identifying deletion event remains in the audit log.

08Your rights & choices

Subject to applicable law, you (or a resident’s authorized decision-maker) may: access the personal information we hold; export a copy in a portable format; correct inaccurate details; delete your information (see Section 7 for what deletion covers); and withdraw consent, including recording/AI-analysis consent, with the operational consequence described in Section 4. You can review every agreement you’ve accepted, with version and timestamp, on the Privacy & consents page. Family members may adjust their own notification preferences but can never expand a resident’s consent scope. To exercise any right, use the in-app controls, contact your Community administrator, or email [PRIVACY_CONTACT_EMAIL]; we will verify identity before acting and respond within [RIGHTS_RESPONSE_PERIOD_E_G_30_DAYS]. We will not discriminate against you for exercising a right. Depending on where you live (e.g., California, the EU/UK), you may have additional statutory rights, including the right to complain to a supervisory authority.

09Security: what is actually in place

Honestly stated, as implemented today: all traffic is encrypted in transit (TLS); call transcripts are encrypted at rest at the column level in addition to provider disk encryption; role-based access control is enforced both in the application and at the database layer (Postgres row-level security); access to sensitive resident records requires an elevated, reason-recorded action; every access to resident-derived sensitive data is audit-logged; webhook traffic from the telephony provider is signature-verified; and the applications ship standard browser security headers. Angel is not currently HIPAA-certified or SOC 2-certified and makes no such claim. No system is perfectly secure; Section 10 describes what happens if we fail.

10Data breach notification

If we confirm a breach of security leading to unauthorized access to or disclosure of personal information, we will: (a) notify the affected Community’s designated administrator without undue delay, and no later than [BREACH_COMMUNITY_NOTICE_HOURS_E_G_72] hours after confirmation; (b) notify affected individuals (residents or their decision-makers, family members, staff) by email, or, where email is unsuitable for a resident, through the Community, without undue delay and within any timeline applicable law requires; (c) notify regulators and authorities where required; and (d) describe in plain language what happened, what information was involved, what we have done, and what those affected can do. Breach reports can be sent to [SECURITY_CONTACT_EMAIL].

11Children

The Service is built for older adults, their adult family members, and professional care staff. It is not directed at children, and you must be at least 18 to create an account including family accounts; a minor relative’s connection to a resident should be managed through an adult’s account. We do not knowingly collect personal information from anyone under 13 (or the higher age applicable law sets). If we learn we have, we will delete it promptly. Contact [PRIVACY_CONTACT_EMAIL].

12Changes to this policy

Each version of this policy carries a version number and effective date, with a change history at the bottom of this page. For material changes we post the updated policy in advance where practicable, notify signed-in users, and require review and re-acceptance before continued use. A new policy is never silently applied to existing users. Your acceptance of each version is stored with its version number and timestamp.

13Contact

Privacy questions and requests: [PRIVACY_CONTACT_EMAIL]. Legal notices: [LEGAL_CONTACT_EMAIL]. Mail: [LEGAL_ENTITY_NAME], [REGISTERED_ADDRESS]. Residents and families can always start with their Community administrator, who will coordinate with us.

Document version & history

Current version 2026-07-22.1, effective July 22, 2026. When this document changes materially, the version number changes, signed-in users are asked to review and re-accept before continuing, and prior acceptances remain on record with the version they applied to.

  • v2026-07-22.1 · July 22, 2026 First substantive Terms of Service and Privacy Policy: entity/jurisdiction placeholders, liability cap, warranty disclaimer, AI disclosure, recording-consent capture, retention, user rights, breach notification, and versioned consent records.
Terms of ServicePrivacy & consentsReturn home