Security & data

Your parent’s data stays encrypted, on our cloud — not a third party’s.

What Helpmate collects, how it is stored, who can access it, how long it is kept, and how a caregiver can delete it. Written for the family member who needs to read the answer before they sign up.

End-to-end encrypted wearable to caregiver appNo third-party resellers, brokers, or ad networksOne-tap caregiver-driven deletion

What we collect

Three streams of data, and nothing else.

The wearable is built around three categories of sensor output that actually matter to a caregiver. We do not collect ambient audio, we do not collect step counts for an insurer dashboard, and we do not collect anything else that is not on this page.

Location pings

Cell-tower assisted GPS fixes written when the wearable detects a fall, when the wearer presses SOS, and when the wearer crosses a geofence in or out. The wearable does not stream a continuous location trail. It writes a fix on the events that matter and otherwise stays quiet.

Alerts

Detected fall events, geofence crossings, and SOS presses. Each alert carries a timestamp, a coarse location, and the sensor fingerprint that caused the trigger. Raw sensor streams stay on the device — once the wearable has decided whether an event was real, the underlying samples are not transmitted anywhere.

Senior profile

The caregiver inputs the wearer’s nickname, an optional photo, an age bracket, the caregiver’s own contact info, and the name and email of any other caregivers they invite. We never require a date of birth, a Social Security number, a street address, or a Medicare ID — and the app does not collect one.

How it’s stored

Encrypted in transit, encrypted at rest, and not for sale.

Location and biometric data travel end-to-end encrypted between the wearable and the caregiver app. Inside Helpmate, the data is held in an encrypted PostgreSQL store with TLS in transit and AES-256 at rest. Encryption keys are rotated on a fixed cadence, separate keys back up the audit log, and access to the production store is gated by short-lived credentials that engineers request by name every time they need to look.

We do not maintain any relationship with third-party data resellers, data brokers, or advertising networks. We do not embed analytics SDKs that follow wearers across the web. We do not sell — and have never sold — a record, a cohort, or an aggregate to anyone outside the caregiver app the family is using. That posture is checked at every vendor review and stated plainly here so a reading family member does not have to ask twice.

Every caregiver view of the wearer’s data is recorded in an append-only audit log with a timestamp, the caregiver’s account, and the field that was read. The primary caregiver sees this audit log from inside the app, and the log itself is retained longer than the operational data so the deletion event is itself auditable.

Who can access it

Only the care circle you invite. No strangers, no call centers.

The wearer’s primary caregiver invites every other caregiver by sending a tokenized email link from inside the app. There are no shared passwords and no separate logins — each caregiver has their own account tied to their own email, and each link expires the moment it is accepted or after seven days, whichever comes first.

Up to six caregivers per wearer

A care circle holds a primary caregiver and up to five additional caregivers — the spouse at work, the adult daughter in another state, a sibling, a home aide, a neighbor who is around during the day. Everyone invited sees the same quiet timeline the moment an alert fires.

Adding and removing a caregiver is a tap in the app; the removed caregiver immediately loses access to the timeline, and the removal is itself written to the audit log.

Invites only, never shared credentials

Family-member onboarding takes the form of tokenized invite links delivered by email. No call center representative can log into the caregiver app, no support engineer can read a wearer’s location log without a named request-and-approve, and the primary caregiver is always the one who invited the rest of the circle.

Audit log of every caregiver view

Every time any caregiver opens the wearer’s profile, reads a fall alert, or pulls a location history, the read is recorded with a timestamp and the caregiver’s account. We maintain audit logs for every caregiver view so the primary caregiver can see who looked at what and when — not just trust that no one did.

Retention, cancellation, deletion

How long things stick around, and how to make them stop.

Retention windows

Location pings and fall alerts are held in the caregiver timeline for ninety days, which is long enough for a caregiver to look back across a fall-event and a recovery without scrolling through a deluge. SOS presses and their acknowledgements are held for one year so a dispute or a follow-up call has the data to anchor to.

The senior profile fields a caregiver entered — the nickname, photo, age bracket, and contact info for the care circle — are held for as long as the caregiver account is active, and sit behind the deletion control described below. The audit log itself is held for three years so the deletion event is itself auditable to anyone reviewing the file on a later date.

Cancellation

Subscription pause or cancel stops new data capture immediately — no new location pings, no new alerts, no new senior-profile fields. The wearable keeps its last-known-location SOS over Wi-Fi for thirty days so the wearer is not stranded while billing sorts itself out, the same thirty-day grace described on the FAQ and the pricing page.

After the thirty-day grace the device falls back to local-only SOS — the one-press button still works at the wearable, but the caregiver timeline stops receiving events. The wearer is never cut off mid-fall while the subscription is in dispute.

Caregiver-driven deletion

A single in-app control, available to any invited caregiver in the care circle, invokes a full deletion: location pings, alerts, the senior profile, and the subscription association all go. The wearable is unpaired, the care circle is removed, and the primary caregiver sees a confirmation card.

The audit log entry that the deletion occurred is the one record that survives the wipe, and it survives for the audit retention window described above — so the act of deletion is itself auditable. Past that window every record tied to this wearer is gone.

How we’re different

Helpmate vs. the medical-alert industry default.

A plain-English ladder of the privacy choices that distinguish the Helpmate posture from the pendant-and-call-center pattern most families have been offered before.

  • On-device raw signals

    Helpmate — Raw accelerometer and barometer samples stay on the wearable — only the inference that matters leaves the wrist.

    Industry default — Raw sensor streams are streamed to the vendor’s cloud for inference.

  • End-to-end encryption wearable → caregiver app

    Helpmate — Location and biometric data end-to-end encrypted between wearable and caregiver app.

    Industry default — TLS to a vendor portal, then stored in plaintext at rest.

  • Care circle scoped through explicit invites

    Helpmate — A primary caregiver invites caregivers individually with a tokenized email link; no shared passwords.

    Industry default — A central call center routes alerts to whoever answers the phone first.

  • Audit log of every caregiver view

    Helpmate — Every caregiver view is logged and visible to the primary caregiver from inside the app.

    Industry default — Vendor portals are opaque; the family does not see who looked at what.

  • No data resale, no advertising SDKs

    Helpmate — No third-party resellers, brokers, or advertising networks — checked at every vendor review.

    Industry default — Ad-supported wellness bundles and broker relationships behind the device.

Still have a question?

Ask the people who built it.

If something on this page is unclear, or your parent’s situation has a wrinkle we have not covered, write to us. A founder reads every note and replies within two business days.

No drip campaign, no auto-dialerReplies from the team that built the device

You can also write directly to helpmate@polsia.app.

A founder reads every note and replies within two business days.