Privacy Policy

Family Elder Planning is designed to help families organize practical elder-care tasks without asking for sensitive medical details.

Last updated: September 19, 2026

Privacy at a glance

No planner-note storage

Your custom planner notes run in your browser. They are not saved to Family Elder Planning servers.

No card-number storage

Paid checkout is handled by Stripe. Family Elder Planning does not collect or store payment card numbers.

Planner notes stay on your device

The custom planner runs in your browser. We do not save your planner notes, loved-one names, medication names, symptoms, family notes, or other free-text planning details on our servers.

Family Care Coordination System

The Family Care System uses IndexedDB to autosave care-plan information in this browser on this device. Family Elder Planning does not receive the names, notes, medication information, appointments, tasks, coverage details, handoffs, or other free text entered in the local plan. There is no cloud care profile or live cloud collaboration. Another person using the same browser profile may be able to see local information, and clearing site data can erase it.

A Family File is an optional portable backup/export containing the full plan. It is created and checked in the browser and should be handled like a sensitive document. Sponsor branding, entitlement records, checkout metadata, and partner reporting identifiers are not stored in the Family File.

Contact and care-interest notice

Free resources and tools work without an email address. When you explicitly request a resource, we privately store your email, optional first name, requested purpose, source form, and consent record to provide it. Requesting a resource does not subscribe you to continuing emails. A separate unchecked option asks for practical FEP emails about organizing care, tools, and relevant offers. New subscriptions require email confirmation; past resource recipients are not automatically enrolled.

If you submit a help-at-home request, we additionally collect only the broad preference, timeframe and optional ZIP you visibly choose. ZIP is for area-relevant resources. A phone number is collected only in an explicitly requested FEP callback flow, when enabled. These preferences can reveal an interest in health or care services; we treat them as private operational information. Do not submit someone else’s contact details, diagnoses, medications, insurance identifiers, medical documents or free-text care plans. We do not attach assessment answers or calculator values to your record.

We use this information for the resource or FEP assistance you requested, private request management and, only with separate consent and confirmation, continuing FEP emails. This is first-party collection: we do not sell these records or share them with care providers. Any later named-provider introduction needs separate permission identifying the recipient, fields, purpose and expected contact. A newsletter checkbox is not permission for such a transfer.

Provider-interest records contain the submitted business email, optional contact name, organization, website, broad service type and service area, plus permission to discuss future appropriate inquiries. Registration does not create a partnership or public listing.

Our service infrastructure processes these records: private PostgreSQL database storage, Vercel hosting and server functions, and Resend email delivery. Access to contact records and exports requires server-verified operator authentication. We keep private care plans in your browser as described above. Contact-management and email-token pages do not load marketing analytics. Resource links do not carry contact information.

Requests are flagged for review after 30 days and unnecessary request details are removed after 90 days. An active opted-in subscription is kept for its stated purpose, with periodic inactivity review. Minimum suppression records may remain to prevent unwanted future email. Delivery queues, verification and consent records are used to honor permissions and prevent duplicate sends. Short-lived abuse controls use keyed fingerprints, not raw email addresses as public identifiers.

You may unsubscribe from continuing emails using the link in each marketing email. To withdraw request-contact permission, ask about your record, or request deletion, use the contact page and identify the email you submitted. Withdrawal stops future use for that purpose; it does not make earlier processing retroactively unauthorized. We do not expand the purposes of historical records merely because this notice changes. An analytics opt-out does not block a resource or request you explicitly submit.

Support messages

If you contact support, we collect the information you choose to send, such as your name, email, order email, issue type, and message. Please do not include medical details, diagnosis details, medication names, Social Security numbers, payment card numbers, or other sensitive information in a support message.

Home Kit suggestions

If you suggest an addition to the First 14 Days Home Kit, we store only a generalized topic for review and may send that topic to the site operator by email. We do not store or email your exact suggestion text. Public voting is limited to approved request categories. New suggestion topics are not posted publicly unless they are reviewed, normalized, and added as a general category. Please do not include names, diagnoses, medication names, urgent symptoms, phone numbers, email addresses, or other sensitive details in a suggestion.

Analytics

We use privacy-safe event tracking to understand whether visitors use the checklist, planner, Quick Sheet, professional sharing handout, print/copy buttons, feedback buttons, paid-kit links, topic chooser, and next-step assessment. Analytics events are limited to allowlisted metadata such as page path, source, counts, booleans, selected care phase, selected scenario type, selected planning category, urgency band, destination type, recommendation rank, feedback context, delivery-provider configuration status, and a random anonymous browser-session ID.

Our first-party analytics also retain only the referring hostname and approved UTM source/medium, campaign and content values for the first landing in an anonymous browser visit. Full referring URLs and arbitrary campaign text are discarded. First-party analytics events do not include emails, names, consent text or selections, form bodies, loved-one names, symptoms, medication names, free-text notes, family notes, IP addresses, query strings, full referrer URLs, or user-agent logs.

On public information and product pages, we also use Google Analytics 4 to measure page views, traffic sources, engagement, calculator starts and completed calculations, deliberate next steps, saved resource requests, and a limited set of resource or purchase-interest clicks. These actions carry no calculator values or form fields. It uses analytics cookies and technical information such as browser/device information and approximate location. We send canonical page paths and referring origins, with query strings and fragments removed. Advertising signals and personalization are disabled. Google Analytics is not loaded in the private care-plan app, access pages, admin pages, demos, or marked internal/test visits, and it honors Global Privacy Control and Do Not Track. We do not send form answers, care-plan content, identities, or purchase records to Google Analytics. See how Google uses information from sites that use its services.

Partner-sponsored activity

Real partner activity collection is currently disabled. If a legally reviewed sponsored pilot is later activated, the system may count only eight allowlisted operational activity events plus authoritative successful activation exchanges and separately aggregated support records. These counts contain no family identity, care-plan value, free text, Family File, URL, IP address, persistent visitor identifier, or raw token. Test, demo, owner, and professional-evaluation traffic is excluded. Partner-visible values 1–4 are suppressed, raw accepted events are limited to 120 days, and aggregate briefs are limited to 24 months unless reviewed terms or law require a different period.

A sponsor cannot see a family’s local plan. Optional sponsor contact actions leave Family Elder Planning, do not attach plan information, and are then governed by the sponsor’s own privacy practices.

Payments

Payments are handled by Stripe. Family Elder Planning does not collect or store payment card numbers. Stripe may process your payment and receipt information according to Stripe's own privacy and security practices. Family Elder Planning entitlement records contain product/payment-state metadata needed to provide or revoke access, not care-plan information. Care details and Family Files are not sent to Stripe metadata or email.

Cookies and local storage

The site may use browser features needed for normal page behavior, local IndexedDB autosave, signed HttpOnly product-access cookies, payment checkout through Stripe, the Home Kit request voting control, or internal testing controls. Product access metadata is separate from care-plan content. We do not use the planner to store your health notes on our servers.

Contact

For privacy or support questions, use the contact page. For medical and editorial boundaries, read the medical disclaimer and editorial policy.