Back to sign in

Privacy Policy

Effective: February 1, 2026 Version: 1.0

Afyanex Care ("Afyanex", "we", "us") provides documentation software for home-care agencies. This Privacy Policy explains what data we collect, why, and how we protect it.

1. What information we collect

  • Agency profile: agency name, contact info, branding assets.
  • Workforce data: caregivers' name, email, phone, credentials, certifications.
  • Patient (client) data: name, date of birth, address, diagnoses, allergies,

medications, care plan, contacts, and shift-by-shift documentation. This is Protected Health Information (PHI) under HIPAA.

  • Usage data: pages viewed, voice-event counts, error logs, IP addresses,

and timestamps. We use this to operate, secure, and improve the service.

  • Payment data: handled exclusively by Stripe — we never store card

numbers on our servers.

2. Why we collect it

  • To provide the documentation, scheduling, billing, and care-coordination

features your agency uses.

  • To enable AI-assisted voice transcription and note formatting.
  • To meet electronic-visit-verification (EVV) and other regulatory

requirements your agency reports to its state Medicaid program.

  • To improve product quality, detect abuse, and provide customer support.

3. Who we share it with

We share PHI only with:

  • Your agency's authorized users (admins and caregivers you've granted

access to specific clients).

  • Family members you've explicitly invited via the Family Portal.
  • Sub-processors under a HIPAA Business Associate Agreement:

- MongoDB Atlas (database hosting) - Stripe (payments, no PHI) - OpenAI (voice transcription — under DPA, no training on your data) - Anthropic (AI note formatting — under DPA, no training on your data) - Resend (transactional email) - Sentry (error logs, PHI scrubbed) - PostHog (product analytics, PHI scrubbed)

We do NOT sell PHI under any circumstance.

4. How we protect it

  • TLS 1.2+ for all data in transit
  • AES-256 encryption at rest (MongoDB Atlas)
  • Role-based access control (caregivers see only assigned clients)
  • httpOnly session cookies, 2FA available for admins
  • Brute-force login lockout, audit logging of every PHI access
  • Quarterly penetration testing
  • Vendor BAAs with every sub-processor that touches PHI

5. Your rights

You can request a copy of your data, correct errors, restrict processing, or delete your account at any time by emailing privacy@afyanex.com. We honor requests within 30 days.

6. Data retention

Active client records are retained for the length of your subscription plus 7 years thereafter (the HIPAA minimum). Audit logs are retained for 6 years after the event. On account closure, you may export your data; we then permanently delete or de-identify it within 60 days of the retention window ending.

7. Children

Afyanex does not knowingly collect data on individuals under 18 unless they are minor clients of a participating agency, in which case the agency's HIPAA authorization governs the relationship.

8. Changes to this policy

We will notify agency administrators by email at least 30 days before any material change takes effect. Continued use of the service constitutes acceptance of the updated policy.

9. Contact

Afyanex Care — Privacy Office privacy@afyanex.com

Version 1.0 · Effective 2026-02-01