Privacy Policy
Effective July 22, 2026
This Privacy Policy explains how APDHQ (“APDHQ,” “we,” “us”) collects, uses, protects, and shares information when you use our web application and our iOS application (together, the “Service”). APDHQ is a compliance and electronic-record tool for Florida Agency for Persons with Disabilities (APD) iBudget home-care agencies. It is used by agencies to manage their own records and is not directed to the general public or to children.
Because the Service is used to manage health-related records, some information you enter may be protected health information (PHI) about the individuals an agency serves and employs. We handle that information as described below and only on behalf of the agency (our customer).
1. Who controls your data
For the records an agency stores in the Service (consumer records, employee records, documents, notes, and related data), the agency is the data controller and APDHQ acts as a service provider / business associatethat processes that data on the agency’s behalf. For account and billing information about the agency and its users, APDHQ is the controller.
2. Information we collect
Account information
- Your name, email address, and role, and the agency you belong to.
- Authentication data managed by our identity provider, including a hashed password and, if you enable it, two-factor authentication settings.
Agency records you enter (may include PHI)
- Consumer and employee records, APD identifiers, documents you upload, expiration dates, session notes, incident reports, and related compliance data.
Usage, device, and log data
- Standard server logs (such as IP address, timestamps, and requests), audit records of document views and changes, and app diagnostics needed to operate and secure the Service.
- On iOS, the app stores your session securely on the device (Keychain) and, if you enable it, a Face ID / passcode app lock. Optional local reminders about expiring documents are generated on your device.
Voice input (optional)
- If voice-to-text is enabled and you use it, a short audio recording is sent for transcription and the resulting text is placed in your message. See sub-processors below.
We do not collect analytics for advertising, and we do not sell personal information.
3. How we use information
- To provide, secure, and maintain the Service.
- To power features you invoke — including Coworker, our AI assistant, which answers questions and drafts documents from your agency’s data at your direction.
- To keep an audit trail of document access and changes for compliance.
- To process subscription billing.
- To communicate with you about the Service and respond to support requests.
- To meet legal, regulatory, and security obligations.
4. How information is shared (sub-processors)
We share information only with the vendors that help us run the Service, under contracts that require appropriate confidentiality and security, and — where PHI is involved — a Business Associate Agreement (BAA) where applicable:
- Supabase — hosting, database, authentication, and file storage for the Service.
- Anthropic — powers the Coworker AI assistant. Content you send to Coworker is processed to generate responses.
- OpenAI — used only for optional voice-to-text transcription, and only if that feature is enabled and you use it. Audio you record for transcription is sent to this vendor. If your agency has not enabled voice input, no audio is sent.
- Stripe — processes subscription payments. Card details are handled by Stripe, not stored by APDHQ.
We may also disclose information if required by law, to protect rights and safety, or in connection with a business transfer, subject to the protections in this Policy.
5. Data security
- Data is encrypted in transit using industry-standard TLS/HTTPS.
- Access to agency data is enforced at the database layer with row-level security, so each agency can reach only its own records.
- Document files are served only through an audited, access-checked path that records who viewed each file.
- Optional two-factor authentication and an iOS app lock provide additional account protection.
No method of transmission or storage is completely secure, but we work to protect your information using appropriate technical and organizational measures.
6. Data retention and account deletion
We retain information for as long as your agency’s account is active and as needed to provide the Service. Health and compliance records may be subject to legal retention requirements, so we may retain certain records for the period required by law even after an account closes.
You can request deletion of your account at any time — in the iOS app, open Agency → Account → Delete account, or contact us at privacy@apdhq.com. When you request deletion, we will delete or de-identify your personal account information and, at the agency’s direction, the agency’s records, generally within 30 days, except where we are legally required to retain specific records. You may cancel a pending deletion request during that window by contacting us.
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete personal information, and to object to or restrict certain processing. Because agency records are controlled by the agency, we will refer requests about those records to the agency and assist as its service provider. To exercise a right, contact us at privacy@apdhq.com.
8. Children’s privacy
The Service is intended for use by agency staff, not by children, and we do not knowingly collect personal information directly from children through the Service. Records an agency maintains about the individuals it serves are entered and controlled by the agency.
9. Changes to this Policy
We may update this Policy from time to time. When we make material changes, we will update the effective date above and, where appropriate, provide additional notice.
10. Contact us
Questions about this Policy or our privacy practices? Contact us at privacy@apdhq.com.