SeraCare SeraCare
Download
App
🏥 SeraCare Home
Legal
🔒 Privacy Policy 📋 Terms of Use
Download on App Store

Legal

Privacy Policy

Last updated: January 1, 2026  ·  Effective immediately

Table of Contents
  1. Overview
  2. Information We Collect
  3. How Your Data Is Stored
  4. Data Sharing & Disclosure
  5. HIPAA Compliance
  6. Security Measures
  7. Your Rights
  8. Children's Privacy
  9. Changes to This Policy
  10. Contact Us

1 Overview

SeraCare ("we," "our," or "us") is a HIPAA-compliant patient care management application designed exclusively for licensed healthcare professionals. This Privacy Policy explains how we collect, use, and protect information when you use the SeraCare iOS app.

The short version: SeraCare stores all patient data locally on your device. We do not operate a backend server, we do not collect patient health information, and we do not sell any data to third parties — ever.

2 Information We Collect

SeraCare is designed to minimize data collection. Here is exactly what the app collects and why:

Account registration data (stored locally on-device only):

  • Username and hashed password (PBKDF2 — we never store plaintext passwords)
  • HIPAA acknowledgment timestamp
  • Session tokens for authentication

Patient care data (stored locally on-device only):

  • Patient room assignments and identifiers you enter
  • Care notes, task records, and schedule entries you create
  • Audit log entries recording data access events

We do not collect:

  • Names, dates of birth, or Social Security numbers of patients
  • Insurance or billing information
  • Device identifiers, analytics, or crash reports sent to our servers
  • Location data

3 How Your Data Is Stored

All data entered into SeraCare is encrypted and stored exclusively on your iOS device using AES-GCM encryption. No data is transmitted to SeraCare servers or any third-party cloud service.

When you perform a patient handoff, data is transferred directly between devices over a local peer-to-peer network connection using Apple's MultipeerConnectivity framework. This transfer is encrypted end-to-end and does not route through the internet or any intermediary server.

If you delete the SeraCare app, all locally stored data is permanently removed from your device. We have no copy of your data and cannot recover it.

4 Data Sharing & Disclosure

SeraCare does not share, sell, rent, or trade any user data or patient information with third parties. Because all data is stored locally on your device, there is no data for us to share.

The only scenario in which data leaves your device is a voluntary handoff transfer initiated by you to a specific colleague on the same local network. That transfer goes directly to their device — not through our systems.

We may disclose information only if required by law, such as in response to a valid court order, but as we hold no user data on our servers, any such request would yield nothing.

5 HIPAA Compliance

SeraCare is built to support the operational requirements of HIPAA-covered healthcare professionals. The following safeguards are implemented:

  • Access controls: Rate-limited login with strong password enforcement prevents unauthorized access.
  • Audit controls: All data access events are logged locally with timestamps for compliance review.
  • Integrity controls: AES-GCM encryption ensures data has not been altered or destroyed without detection.
  • Automatic logoff: Sessions automatically terminate after a configurable period of inactivity.
  • Transmission security: All peer-to-peer data transfers use encrypted connections.

SeraCare is a software tool to assist healthcare professionals with workflow organization. It is not a covered entity or business associate under HIPAA. Users who are covered entities are responsible for ensuring their use of SeraCare aligns with their own HIPAA compliance obligations.

6 Security Measures

SeraCare implements the following technical safeguards to protect your data:

  • AES-GCM 256-bit encryption for all locally stored patient data
  • PBKDF2 password hashing — passwords are never stored in plaintext
  • Rate-limited login to prevent brute-force attacks
  • Automatic session timeout after inactivity
  • Encrypted peer-to-peer transfers via MultipeerConnectivity
  • Full on-device audit logging of all data access events

7 Your Rights

Because all data is stored locally on your device, you have complete control over it at all times:

  • Access: All data you have entered is visible within the app at any time.
  • Deletion: You can delete individual records within the app, or delete the app entirely to remove all data.
  • Portability: Patient data can be transferred to a colleague via the secure handoff feature.
  • Correction: All records can be edited at any time within the app.

8 Children's Privacy

SeraCare is intended solely for use by licensed healthcare professionals who are at least 18 years of age. We do not knowingly collect any information from persons under 18. If you believe a minor has used the app, please contact us immediately.

9 Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. Continued use of SeraCare after any changes constitutes your acceptance of the revised policy. We encourage you to review this policy periodically.

10 Contact Us

If you have any questions about this Privacy Policy or how SeraCare handles data, please contact us:

Questions about your privacy?

We're committed to transparency. Reach out any time.

✉ support@seracare.app

© 2026 SeraCare. All rights reserved.

Privacy Policy Terms of Use