Security and Data Retention
This page summarizes current safeguards and operational limits. It is not a certification or guarantee of absolute security.
Current safeguards
HTTPS in production; salted password hashing; secure cookie settings; tenant-separated SQLite databases; encrypted Google refresh tokens; short-lived one-time portal links; filename controls; limited demo capabilities; and application logging.
User responsibilities
Therapists must protect credentials and devices, use unique passwords, keep contact details current, grant access only to authorized people, review exported information, and promptly report suspected unauthorized access.
Retention and deletion
Active tenant information is retained while the account is active. Danger Zone requests suspend access and provide 24 hours to restore. At or after expiry, CareIL removes the tenant database and tenant upload directory during lifecycle cleanup. Legal, fraud-prevention or narrowly limited provider records may have different retention periods.
Incident reporting
Suspected security issues should be sent to the security contact without including client clinical information. CareIL will investigate and make notifications required by applicable law according to its role.
Operator and contact
CareIL
Privacy: privacy@careil.net
Support: support@careil.net
Accessibility: support@careil.net
These are general product documents and do not replace legal advice tailored to the operator or therapist’s specific activities.