Privacy & AI
Privacy, and how the AI is bounded.
Handoff is built around one rule: the caregiver is the authority. The AI structures your words — it never adds medical facts of its own, and nothing is shared until you review and approve every line.
The approval gate
Every brief is drafted from what you say, shown back to you in full, and held until you approve it. Whoever steps in only ever sees what you approved.
Our data commitments
- Storage. Handoff collects only what is needed to brief someone covering a shift. In the current prototype, a brief is created and held in your own browser — it is not stored on our servers. When Handoff handles real caregiver data, it will live in US-based infrastructure, and your profile stays exportable.
- Encryption. Data in transit is encrypted (TLS 1.3). When persistent storage is enabled, it will be encrypted at rest (AES-256) using our infrastructure provider's standard configuration. We claim nothing beyond that.
- Retention and deletion. A shared brief is scoped to a single shift and expires 72 hours after sharing. You can revoke a link at any time, and delete your profile and all briefs on demand.
- Third-party AI. The demo is an interactive prototype with a sample household — nothing you type in it is processed by a live AI model or stored by Handoff. Before any caregiver's information is processed by a third-party model, we will name the provider here and put the required data agreements in place.