Privacy Policy

Florence Care, Inc. · Last updated June 24, 2026

This privacy notice for Florence Care, Inc. (“Florence,” “Company,” “we,” “us,” or “our”) describes how and why we might collect, store, use, and/or share (“process”) your information when you use our services (“Services”), such as when you:

  • Visit our website at florence.care, or any website of ours that links to this privacy notice;
  • Download and use our application, or otherwise create an account to coordinate care through Florence;
  • Engage with us in other related ways, including any sales, marketing, partnership discussions, or events.

Questions or concerns? Reading this privacy notice will help you understand your privacy rights and choices. If you do not agree with our policies and practices, please do not use our Services. If you still have any questions or concerns, please contact us at info@florence.care.

Summary of Key Points

This summary provides key points from our privacy notice, but you can find out more details about any of these topics in the full document below.

What information do we process? When you visit, use, or navigate our Services, we may process personal information depending on how you interact with us, the choices you make, and the features you use. This includes information you provide directly — such as your name, contact details, and health and care information — as well as information you provide about another person whose care you are coordinating.

Do we process sensitive personal information? Yes. We process health and care information, and may process other sensitive information, when you provide it to us, with your consent or as otherwise permitted by applicable law.

Do we collect any information from third parties? We may receive information from third parties you direct us to interact with on your behalf — such as healthcare providers, schools, regional centers, or insurers — and from services or providers you choose to connect.

How do we process your information? We process your information to provide, improve, and administer our Services; to coordinate care on your behalf; to communicate with you; for security and fraud prevention; and to comply with law. We may also process your information for other purposes with your consent. We do not use your information for advertising, and we do not sell your information.

When and with whom do we share information? We share information with contracted service providers who help us operate the Services, with third parties you direct us to contact as part of your care coordination, where required by law, and in connection with a business transfer. We do not sell your personal information or share it with external marketers.

How do we keep your information safe? We use organizational and technical safeguards designed to protect your personal information, including encryption in transit and at rest. However, no electronic transmission or storage system can be guaranteed to be 100% secure.

What are your rights? Depending on where you live, applicable privacy law may give you rights to access, correct, delete, or limit the use of your personal information, and to opt out of marketing.

How do you exercise your rights? The easiest way to exercise your rights is by contacting us at info@florence.care. We will consider and act upon any request in accordance with applicable data protection laws.

Is Florence HIPAA compliant?

HIPAA mostly governs doctors, hospitals, and health plans. Florence is a tool you use directly, so HIPAA does not classify us as a “covered entity.” That does not mean your data is unprotected - it means these commitments do the protecting.

  • We process your health and care information only to provide Florence to you, never to advertise, and we never sell it.
  • Our cloud and AI providers (including Google Cloud and Google Workspace) act as subprocessors under written contract and are barred from training their models on your information.
  • Your information is encrypted in transit and at rest, and access is limited to a contractual duty of confidentiality.
  • You can review, correct, and delete your information at any time (see your rights below).
  • Where you live may give you additional protections - see the state-specific disclosures below (including consumer-health-data laws).

1. What Information Do We Collect?

1.1 Personal information you disclose to us

We collect personal information that you provide to us.

We collect personal information that you voluntarily provide when you register for the Services, set up or update a care profile, upload documents for us to act on, express interest in our products or Services, participate in activities within the Services, or otherwise contact us.

The personal information we collect depends on the context of your interactions with us and the choices and features you use. It may include:

  • Identity and contact data — your name, email address, phone number, and mailing address;
  • Account credentials — usernames, passwords, and similar authentication information;
  • Relationship and role data— your role in a person's care, such as parent, legal guardian, conservator, family member, or care recipient;
  • Health and care information — including diagnoses, conditions, care plans, benefits and eligibility documents, Individualized Education Programs (IEPs), regional-center records, provider correspondence, appointment and scheduling details, and similar information you or a connected provider supply at your direction;
  • Documents you upload for Florence to review or act on, such as forms, applications, letters, and other paperwork, together with their contents;
  • Communications — the contents of messages you send to us or that you direct us to send on your behalf, and records of our correspondence with you.

When you add, update, or delete care information, we may also record where the information originated, how it changed over time, and who made the change, so that the Services can maintain an accurate and accountable care record.

All personal information you provide must be true, complete, and accurate, and you must notify us of any changes.

1.2 Information automatically collected

Some information — such as your IP address and device characteristics — is collected automatically when you use our Services.

We automatically collect certain information when you visit, use, or navigate the Services. This information does not by itself reveal your specific identity, but may include device and usage information such as your IP address, browser and device characteristics, operating system, language preferences, referring URLs, device name, country, location, and information about how and when you use our Services. We collect this information primarily to maintain the security and operation of our Services and for internal analytics and reporting.

The information we collect includes:

  • Log and usage data — service-related, diagnostic, usage, and performance information our servers automatically collect when you access or use the Services. This may include your IP address, device information, browser type and settings, and information about your activity in the Services (such as date and time stamps, pages and features viewed, searches run, and actions taken), as well as device event information such as system activity and error reports.
  • Device data — information about the computer, phone, tablet, or other device you use to access the Services, which may include your IP address (or proxy server), device and application identification numbers, browser type, hardware model, internet service provider or mobile carrier, and operating system.

1.3 Information from other sources

We may receive information from third parties you direct us to engage, or from services you connect.

As part of coordinating your care, you may direct us to interact with third parties on your behalf — such as healthcare providers, schools, regional centers, government agencies, or insurers — and we may receive information from those third parties in the course of completing the tasks you have asked us to perform. We may also receive information from services or accounts you choose to connect to Florence. We process information received from these sources in accordance with this privacy notice.

1.4 Information about Care Recipients who are not the Account Holder

When you use Florence to coordinate someone else's care, you provide information about that person, and you confirm that you are authorized to do so.

Florence is often used by a parent, guardian, or other caregiver (the “Account Holder”) to coordinate care on behalf of another person — for example, a child or a dependent adult (the “Care Recipient”). In these cases, the Account Holder provides information about the Care Recipient to us, including the health and care information described above.

When you create an account or add a Care Recipient, you represent that you are the Care Recipient, or that you are the Care Recipient's parent, legal guardian, conservator, or are otherwise legally authorized to share their information with us and to use the Services on their behalf. We rely on this representation, and we are not able to independently verify the legal relationship between an Account Holder and a Care Recipient in every case. If you provide information about another person, you are responsible for ensuring you have the authority to do so and for the accuracy of that information.

We use information about a Care Recipient only to provide the Services to that Care Recipient and the Account Holder — such as managing care plans, handling paperwork, scheduling, and communicating with third parties at your direction. We do not use Care Recipient information for advertising, and we do not sell it.

Because care information may be shared between an Account Holder and a Care Recipient within the Services, a request or change made by one may affect information visible to the other. Where a Care Recipient has the legal capacity to act on their own behalf, they (or their authorized representative) may request access to, correction of, or deletion of their information as described in Section 9, and we will handle these requests in accordance with applicable law.

2. How Do We Process Your Information?

We process your information to provide and improve our Services, coordinate care on your behalf, communicate with you, ensure security and prevent fraud, and comply with law. We may process your information for other purposes with your consent.

We process your personal information for a variety of reasons, depending on how you interact with our Services, including:

  • To facilitate account creation and authentication and otherwise manage user accounts, so you can create and log in to your account and keep it in working order.
  • To deliver and facilitate delivery of the Services to you, including coordinating care — scheduling appointments, handling and submitting paperwork, navigating benefits and eligibility, and communicating with providers, schools, agencies, and other third parties on your behalf and at your direction.
  • To maintain longitudinal care memory, so that the Service can act with context over time, avoid asking you to repeat information, and provide continuity across the care process.
  • To respond to your inquiries and provide support, and to solve any issues you may have with the Services.
  • To send you administrative information, such as details about the Services, changes to our terms and policies, and other service-related messages.
  • To request feedback and to contact you about your use of the Services.
  • To send you marketing and promotional communications about our own Services, in accordance with your preferences. You can opt out at any time (see Section 9).
  • To protect our Services, including monitoring for and preventing fraud and maintaining the safety and security of the Services.
  • To evaluate and improve our Services, including identifying usage trends and assessing the effectiveness of our communications, so we can improve the Services and your experience.
  • To comply with our legal obligations, including responding to legal requests and exercising, establishing, or defending our legal rights.

We do not use your information to deliver advertising of any kind — including targeted, personalized, or behavioral advertising — and we do not sell your personal information.

2.1 How AI processing works

Florence uses AI systems, operated together with trusted providers under contract, to read documents, draft communications, and take care-coordination actions. We do not allow these providers to use your information to train their own models.

Florence is an AI-powered service. We use artificial-intelligence systems to read and interpret the documents and information you provide, to draft communications, and to take care-coordination actions on your behalf.

To provide these features, we use third-party cloud and AI/model providers as subprocessors under written contract, including Google Cloud and Google Workspace. These providers process information on our behalf and are contractually required to protect it and to use it only to provide services to us.

We do not permit our cloud or AI/model providers to use your information to train their own foundation models, except as necessary to provide the Services to us under our agreements with them. Where personnel or processors have access to consumer health data, they are subject to a contractual duty of confidentiality.

3. What You Can Do With the Information We Collect

Information you enter into the Services can generally be accessed, reviewed, edited, and deleted within the Services. For information that cannot be edited or deleted directly in the product, you may contact us at info@florence.care to request an update or deletion, and we will act on your request in accordance with applicable law.

4. When and With Whom Do We Share Your Personal Information?

We share information with contracted service providers, with third parties you direct us to contact, where required by law, and in connection with a business transfer. We do not sell your information or share it with external marketers.

We may share your personal information in the following situations:

  • Service providers and subprocessors. We share information with third-party vendors, service providers, and contractors who perform services for us or on our behalf and require access to such information to do that work. These include:
    • Google Cloud — cloud hosting and infrastructure;
    • Google Workspace — productivity and communications;
    • Analytics and error-monitoring providers — to help us maintain, secure, and improve the Services.
    Each service provider is bound by written contract to protect your information, to use it only to provide services to us, and to follow privacy protections consistent with this notice and applicable law.
  • Third parties you direct us to contact. As part of coordinating your care, we share information with third parties you ask us to contact on your behalf — such as healthcare providers, schools, regional centers, government agencies, and insurers — only to the extent necessary to perform the specific task you have requested.
  • Legal and compliance disclosures. We may disclose your information where we are legally required to do so, to respond to lawful requests from public authorities, to enforce our terms, or to protect the rights, property, or safety of Florence, our users, or others.
  • Business transfers. We may share or transfer your information in connection with, or during negotiations of, any merger, sale of company assets, financing, or acquisition of all or a portion of our business. We will notify affected account holders and, where applicable, provide an opportunity to close their account or request deletion of their information.

Except as described above, we do not share your personal information with outside parties without your consent. We do not sell your personal information, and we do not share it with external marketers.

5. What Is Our Stance on Third-Party Websites?

The Services may contain links to third-party websites, applications, or online services that are not operated or controlled by us. We are not responsible for the privacy or security practices of those third parties, and the inclusion of a link does not imply our endorsement. Any information you provide to a third party is governed by that third party's own privacy policy, not this one. We encourage you to review the privacy policies of any third-party websites or services you access.

6. How Long Do We Keep Your Information?

We keep your information for as long as necessary to provide the Services and to meet our legal obligations.

We will keep your personal information for as long as it is necessary for the purposes set out in this privacy notice, unless a longer retention period is required or permitted by law (such as tax, accounting, or other legal requirements). When we no longer have an ongoing legitimate need to process your personal information, we will either delete or de-identify it or, if deletion is not immediately possible (for example, because the information has been stored in backup archives), we will securely store your personal information and isolate it from further processing until deletion is possible.

You may request deletion of your information at any time by contacting info@florence.care, subject to the exceptions described in this notice.

7. How Do We Keep Your Information Safe?

We use organizational and technical safeguards to protect your information, but no system is perfectly secure.

We have implemented appropriate and reasonable technical and organizational security measures designed to protect the security of any personal information we process, including encryption of data in transit and at rest, access controls, and administrative safeguards. However, despite our safeguards, no electronic transmission over the internet or information storage technology can be guaranteed to be 100% secure, so we cannot promise or guarantee that unauthorized third parties will not be able to defeat our security and improperly collect, access, steal, or modify your information. Transmission of personal information to and from our Services is at your own risk, and you should access the Services only within a secure environment.

In the event of a data breach affecting your personal information, we will notify you and the appropriate authorities as required by applicable law. Where Massachusetts residents are affected, we will provide notice in accordance with Mass. Gen. Laws ch. 93H, including notice to the Massachusetts Attorney General and the Office of Consumer Affairs and Business Regulation as required.

8. Minors and Dependent Care Recipients

Florence may handle information about minors and dependent adults when an authorized caregiver provides it to coordinate their care. We do not allow children to use the Services on their own, and we do not market to children.

Unlike many consumer services, Florence may, by design, process information about Care Recipients who are minors or dependent adults — because coordinating care often involves a parent, guardian, or conservator acting on that person's behalf. When this occurs, the Account Holder provides the Care Recipient's information and represents that they are authorized to do so, as described in Section 1.4.

We do not knowingly permit children to create their own accounts or to use the Services independently, and we do not market or direct advertising to children. If you believe that a child has provided us personal information without the involvement of an authorized adult, please contact us at info@florence.care so we can take appropriate steps to address it.

9. Your Privacy Rights and Choices

You may review, update, or delete your information, withdraw consent, and opt out of marketing. Depending on where you live, you may have additional rights.

Reviewing and updating your information. You may review, change, or update the information in your account at any time within the Services, or by contacting us at info@florence.care.

Withdrawing your consent. Where we rely on your consent to process your personal information, you have the right to withdraw that consent at any time by contacting us. Withdrawing your consent will not affect the lawfulness of any processing carried out before the withdrawal, nor will it affect processing conducted in reliance on lawful grounds other than consent. We will stop the relevant processing within 30 days of your withdrawal.

Opting out of marketing. You can unsubscribe from our marketing communications at any time by clicking the unsubscribe link in our emails or by contacting us. Even after you opt out, we may still send you non-marketing, service-related messages necessary for the administration of your account.

Limiting the use of sensitive information. Where applicable law provides the right, you may direct us to limit the use and disclosure of your sensitive personal information to what is necessary to provide the Services.

Authorized agents and guardians. An authorized agent, parent, legal guardian, or conservator may exercise these rights on behalf of a Care Recipient. We may require proof of identity and of authority to act before fulfilling such a request.

Verifying your request. To protect your information, we will take steps to verify your identity before acting on a request — for example, by asking you to provide information we can match against our records, or by contacting you through a method you previously provided. We will use any information provided for verification only for that purpose.

9.1 Account termination

You may request to deactivate or terminate your account at any time by contacting info@florence.care. Upon your request, we will deactivate or delete your account and associated information from our active systems within 45 days, subject to legal exceptions — for example, where we must retain certain information to prevent fraud, resolve disputes, troubleshoot problems, assist with investigations, enforce our legal terms, or comply with applicable law.

10. State-Specific Privacy Disclosures

This section describes additional rights that may apply to residents of certain U.S. states. To exercise any of these rights, contact us at info@florence.care. We will verify your identity before responding and will respond within the time required by applicable law.

10.1 California Residents

“Shine the Light.” California Civil Code § 1798.83 permits California residents to request, once a year and free of charge, information about the categories of personal information (if any) we disclosed to third parties for their direct marketing purposes, and the identities of those third parties. Florence does not disclose personal information to third parties for their own direct marketing purposes.

California Consumer Privacy Act (CCPA/CPRA). If you are a California resident, you have specific rights regarding your personal information.

Categories of personal information we may have collected in the past twelve (12) months:

Categories of personal information collected in the past twelve months
CategoryCollected
Identifiers (name, email, IP address, account name)Yes
Contact details (phone number, mailing address)Yes
Protected classification characteristics (only as voluntarily provided or relevant to care)Yes, where provided
Commercial information (subscription or transaction records)Yes, for paid plans
Sensitive personal information (account login information; health and care information; precise geolocation, if collected)Yes
Internet or other network activity (usage and device data)Yes

Your California rights include: the right to know and access the personal information we collect, use, and disclose; the right to delete your personal information; the right to correct inaccurate information; the right to opt out of the sale or sharing of personal information (Florence does not use personal information for advertising, does not sell it, and does not share it for cross-context behavioral advertising); the right to limit the use and disclosure of sensitive personal information; and the right not to be discriminated against for exercising your rights.

You may use an authorized agent to submit a request, provided the agent gives proof of authorization.

10.2 Virginia Residents

Under the Virginia Consumer Data Protection Act (CDPA), Virginia residents acting in an individual or household context have the right to confirm whether we process their personal data and to access it; to correct inaccuracies; to delete personal data; to obtain a copy of their data in a portable format; and to opt out of targeted advertising, the sale of personal data, and certain profiling. Florence does not sell personal data and does not use it for advertising. We process sensitive data, including health information, only with your consent or as otherwise permitted by law.

We will respond to your request within 45 days, with one permitted extension where reasonably necessary.

Right to appeal. If we decline to take action on your request, we will inform you of our decision and the reasons for it. You may appeal by emailing info@florence.care. We will respond to an appeal within 60 days. If your appeal is denied, you may contact the Virginia Attorney General to submit a complaint.

10.3 Massachusetts Residents

Massachusetts does not currently have a comprehensive consumer-privacy law granting individual access, correction, and deletion rights. However, Massachusetts law imposes specific data-security and breach-notification obligations that apply to the personal information of Massachusetts residents, and we are committed to meeting them.

Data security (201 CMR 17.00). We maintain a Written Information Security Program (WISP) containing administrative, technical, and physical safeguards designed to protect the personal information of Massachusetts residents, consistent with the Massachusetts Standards for the Protection of Personal Information (201 CMR 17.00). These safeguards include encryption of personal information in transit and at rest, access controls that limit access to personal information to those who need it to perform their duties, secure user authentication and access-management practices, ongoing monitoring of our systems, and contractual requirements that our service providers maintain comparable safeguards.

Breach notification (Mass. Gen. Laws ch. 93H). If we discover a breach of security involving the personal information of a Massachusetts resident, we will notify the affected resident, the Massachusetts Attorney General, and the Office of Consumer Affairs and Business Regulation (OCABR) as required by Mass. Gen. Laws ch. 93H, without unreasonable delay. Consistent with the statute, our notice to you will not describe the nature of the breach or the number of residents affected, but will inform you of your rights and the steps you can take.

10.4 Maryland Residents

Under the Maryland Online Data Privacy Act (MODPA), Maryland residents acting in an individual or household context have the right to confirm whether we process their personal data and to access it; to correct inaccuracies; to delete personal data; to obtain a copy of their data in a portable format; and to opt out of targeted advertising, the sale of personal data, and profiling in furtherance of decisions that produce legal or similarly significant effects.

We apply the following practices consistent with MODPA:

  • Data minimization. We limit our collection of personal data to what is reasonably necessary and proportionate to provide the Services you have requested.
  • Sensitive data. We process sensitive data — including consumer health data — only as strictly necessary to provide the Services you have requested, or with your consent. We do not sell sensitive data.
  • No advertising or sale. We do not use personal data for targeted advertising and we do not sell personal data.
  • Consumer health data. Access to consumer health data is limited to personnel and processors who are subject to a contractual duty of confidentiality.
  • Minors. We do not process the personal data of a consumer we know or should know is under 18 for purposes of targeted advertising or sale.
  • Universal opt-out. We honor recognized universal opt-out mechanisms (such as the Global Privacy Control) where applicable.

Right to appeal. If we decline to take action on your request, you may appeal by emailing info@florence.care. We will respond to an appeal within 60 days. If your appeal is denied, you may contact the Maryland Office of the Attorney General, Division of Consumer Protection, to submit a complaint.

10.5 Other States and Consumer Health Data

Residents of other states may have additional rights under their state's privacy laws. In particular, residents of states with consumer health data laws — such as Washington's My Health My Data Act — may have specific rights regarding the collection, use, and sharing of their health data. To exercise any applicable right, or to ask which rights apply to you, contact us at info@florence.care.

11. Do We Make Updates to This Notice?

Yes, we will update this notice as necessary to stay compliant with relevant laws.

We may update this privacy notice from time to time. The updated version will be indicated by an updated “Last updated” date and will be effective as soon as it is accessible. If we make material changes, we may notify you either by prominently posting a notice of such changes or by sending you a direct notification. We encourage you to review this privacy notice periodically to stay informed about how we protect your information.

12. How Can You Contact Us About This Notice?

If you have questions or comments about this notice, you may contact our Privacy Officer, Jialin Chen, by email at info@florence.care, by phone at (978) 844-2860, or by mail to:

Florence Care, Inc.
Attn: Jialin Chen, Privacy Officer
2550 Turk Blvd
San Francisco, CA 94118
United States

13. How Can You Review, Update, or Delete the Data We Collect From You?

Based on the applicable laws of your jurisdiction, you may have the right to request access to the personal information we collect from you, to correct that information, or to delete it. To make such a request, please email us at info@florence.care. We will respond in accordance with applicable law.