What Aidepost holds, and what leaves it.
Written in the same words as the product. If a sentence here and a screen in the application disagree, the screen is the bug.
One table: assignments, where a named caregiver is paired with a resident who needs one-to-one support. Nothing else in the product can reference a resident.
Ten tables — staff, credentials and their dates, onboarding, shifts, clock events, timesheets, applications and caregiver profiles.
Two tables: published job posts, and the reference data behind them.
Where it lives
Records are held in Convex, in the United States, under an executed business associate agreement. Payment is taken by Stripe, and Stripe holds the card — we never see a card number. Transactional email is sent through Resend. Those three, and nothing else, are the processors this product depends on.
Because this product holds protected health information, you accept a Customer business associate agreement at signup, before the trial starts. It is part of the signup and it is presented in full, not linked from a checkbox.
What leaves the product
Egress is the part of a privacy notice that usually goes unwritten. Here it is, channel by channel.
- Email says
- “WH-1: 2 shifts open within 24 hours.” That is the whole rendering of the uncovered-shift event, and it is one of sixteen messages that may be sent at all. The send function takes an event key and references; there is no body parameter, so there is nothing to write free text into.
- Push says
- “Your CPR expires in 7 days.” A credential name may appear to its own holder, and nowhere else; your version of the same event carries a count. Where a message names a time it renders as a day and a shift name — “Sat night” — never a date and time, because a precise time identifies a person’s routine to anyone holding the phone.
- Public
- One thing: a live job posting, reachable without an account, at an opaque address that carries no organisation, house or sequence — so nobody can enumerate the listings or work out how many customers we have. That endpoint reads the posts table only, filtered to live, and cannot read any table holding personal or protected information. Applying requires an account. Relief shifts never appear there, and a shift is never public at all.
- Analytics
- Open shifts filled within twenty-four hours, by house. Nothing we measure is ever shown to a caregiver as a score about herself. That is a constraint on the product, not a note about reporting.
- Logs
- The Convex dashboard only. No third-party log destination.
- URLs
- Opaque short-codes. A link cannot be read for a name.
This website
If you join the early-access list, this site stores the email address you typed, the licence track and the house count you picked, the product you were reading about, and the time you sent it. Nothing else — there is no analytics script, no advertising pixel, no third-party tag and no cookie on this page. We write to you once, when the product opens. Reply to that message and we delete the row.
Your rights
You can export everything the product holds for your organisation, at any time, from inside the product — and after a cancellation you can still sign in to export before anything is purged. Ask us to delete a record and we delete it; the audit log of who did what is retained, because a record that can be quietly removed is not an audit log.
The full Terms of Service and, where one applies, the Customer business associate agreement are presented at signup, in full, and a copy is kept in your account. This page summarises what the product does; it does not replace those documents.
Bareeda LLC, doing business as Providerhub Oregon. Oregon, USA.