Gray Matters Alliance, LLC — Mobile App & Platform Privacy Policy
Effective Date: August 15, 2025 · Version 3.1 · Last Updated: July 19, 2026
Applies to:
- MyCompass App, Apple App Store (End Users)
- Compass Care Calling App, Apple App Store & Google Play (Authorized Users)
- Compass Care Alerts App, Apple App Store & Google Play (Authorized Users)
- MyCompass Web Portal, secure browser-based access (Authorized Users)
- Compass Care Command Center, secure web-based administration platform for provider organizations (Organizational Users)
- Nora Caregiver Intelligence, AI-enabled caregiver support feature (see Section 6)
Our Promise: We Will Never Sell or Market Your Information
The people we serve trust us with some of their most sensitive information. We treat that trust as the foundation of everything we do. We make this promise plainly:
- We will never sell, rent, or trade your information, including your PHI and any de-identified data derived from it, to anyone, for any price.
- We will never share your information with advertisers or data brokers, and we will never use it for advertising or marketing.
- We will never let a third party use your information for that third party’s own purposes.
- We will never use your information to train advertising or commercial AI models.
We use information only to provide your services, keep you safe, obtain payment from your health plan for services we actually delivered, run our organization responsibly, and comply with the law. We use de-identified data only for our own quality improvement, safety, accessibility, and non-commercial research, never for sale, licensing, or advertising.
This promise binds not only GMA today but anyone who may operate the Services in the future. If GMA is ever part of a merger, acquisition, financing, reorganization, or sale of assets, your information will remain protected under this same commitment, and any successor will be contractually required to honor it.
This is not a marketing statement. It is a commitment we intend to be held to.
1. Purpose and Scope
This Privacy Policy (“Policy”) describes how Gray Matters Alliance, LLC (“GMA,” “we,” “our,” or “us”) collects, uses, discloses, and protects personally identifiable information (“PII”) and protected health information (“PHI”) when you use any of GMA’s mobile applications, the MyCompass Web Portal, the Compass Care Command Center, and the connected services that make up the MyCompass System (collectively, the “Services”).
The Services include the MyCompass App, used by individuals receiving services (“End Users”) under GMA’s support programs; the Compass Care Calling App, used by guardians, legal representatives, and authorized professionals (“Authorized Users”) to communicate with End Users; the Compass Care Alerts App, used by Authorized Users to receive safety-related notifications; the MyCompass Web Portal, secure browser-based access used by Authorized Users; the Compass Care Command Center, a secure, web-based administration platform used by provider agencies and other organizations (“Customer Organizations”) and their workforce members (“Organizational Users”) to manage the delivery of remote support services to the End Users they serve; and Nora Caregiver Intelligence, GMA’s AI-enabled caregiver support feature (see Section 6).
These applications and services are part of GMA’s MyCompass System, a comprehensive, HIPAA-compliant remote support and assistive-technology platform that includes the mobile and web apps; the Compass Care Command Center; secure cloud storage and APIs; Nora Caregiver Intelligence; on-premises home-support hardware; Apple HealthKit and HomeKit integrations (where enabled); approved third-party Internet-of-Things (IoT) devices and sensors; Mobile Device Management (MDM); and optional content-filtering and monitoring tools. The administrative, physical, and technical safeguards described in Section 8 apply to every component of the MyCompass System, including any on-premises hardware.
1.1 GMA’s Regulatory Status and Role
GMA is an enrolled government-healthcare provider (including Medicaid and, where applicable, other government health programs) and a Covered Entity under the Health Insurance Portability and Accountability Act (“HIPAA”). GMA acts as a Covered Entity for the services it furnishes directly to End Users. In certain arrangements, GMA may instead perform functions on behalf of another covered entity (for example, a provider agency, managed-care organization, or health plan), in which case GMA acts as a Business Associate and the applicable Business Associate Agreement (“BAA”) governs GMA’s use and disclosure of information for those functions. Where GMA acts as a Business Associate, this Policy applies only to the extent consistent with that BAA and the direction of the responsible covered entity.
Command Center deployments. The most common arrangement of this kind is a Customer Organization’s use of the Compass Care Command Center to serve the organization’s own clients. In those deployments, the Customer Organization is the covered entity responsible for its clients’ PHI; GMA processes that PHI as the organization’s Business Associate, uses and discloses it only as permitted by the governing BAA and HIPAA (45 CFR Section 164.504(e)), and GMA’s vendors supporting those deployments (including AWS for Nora) act as subcontractor Business Associates under downstream agreements as required by 45 CFR Section 164.502(e)(1)(ii). GMA executes a BAA with every Customer Organization before that organization’s client data is onboarded to the Command Center.
1.2 Relationship to the Notice of Privacy Practices and Other Terms
This Policy is a general notice of GMA’s privacy practices and operates alongside GMA’s Notice of Privacy Practices (“NPP”), which is provided separately as required by 45 CFR Section 164.520. Where this Policy and the NPP address the same subject, the NPP governs GMA’s formal HIPAA obligations. For End Users served through a Customer Organization, that organization’s own Notice of Privacy Practices applies to the organization’s use of their information. This Policy is also subject to GMA’s End User Agreement and any applicable service or Terms of Use agreement; where those agreements address matters such as liability, dispute resolution, and acceptable use, those agreements govern those topics. See Section 14.
1.3 Acceptance of This Policy
Where an End User has the legal capacity to do so, that End User may review and accept this Policy. Where an End User is a minor or an adult who lacks legal capacity, this Policy is reviewed and accepted on the End User’s behalf by the End User’s legally authorized representative, and use of the Services by such an End User is not, by itself, acceptance of these terms by that End User. Organizational Users accept this Policy in their individual capacity, and their organization’s use of the Command Center is additionally governed by the organization’s service agreement and BAA with GMA. By accepting this Policy, or by accepting it on behalf of an End User you are legally authorized to represent, you acknowledge that you have read, understood, and agreed to it.
2. Definitions
The following definitions apply throughout this Policy and govern all interactions with the Services.
2.1 “Services,” “Apps,” or “Applications.” The MyCompass App, the Compass Care Calling App, the Compass Care Alerts App, the MyCompass Web Portal, the Compass Care Command Center, Nora Caregiver Intelligence, and the connected components of the MyCompass System owned and operated by Gray Matters Alliance, LLC.
2.2 “MyCompass System.” The integrated, HIPAA-compliant infrastructure operated by GMA, including mobile and web apps, the Compass Care Command Center, cloud-based backend, secure APIs, Nora Caregiver Intelligence, MDM tools, on-premises home-support hardware, Apple HealthKit/HomeKit integrations where enabled, and approved third-party IoT devices. This system supports remote support services, care planning, device management, alerting, and communications for individuals served by GMA and by Customer Organizations.
2.3 “Gray Matters Alliance” or “GMA.” Gray Matters Alliance, LLC, the legal entity responsible for developing, maintaining, and operating the Services, and the primary data steward for information processed through the Services. GMA’s regulatory role is described in Section 1.1.
2.4 “Protected Health Information” (PHI). As defined by HIPAA (45 CFR Section 160.103), individually identifiable health information transmitted or maintained in any form that relates to an individual’s health or condition, the provision of health care, or payment for health care, and that identifies the individual or can reasonably be used to identify them.
2.5 “Personally Identifiable Information” (PII). Information that can be used on its own or with other information to identify, contact, or locate a person, including (but not limited to) full name, address, email, phone number, date of birth, IP address, and device identifier.
2.6 “End User.” The individual receiving remote support services through the MyCompass System, whether served directly by GMA or by a Customer Organization, typically using the MyCompass App directly. End Users may include persons with intellectual, developmental, or physical disabilities, aging adults, or others receiving waiver or clinical services. An End User may require or authorize a legally authorized representative to manage access on their behalf.
2.7 “Authorized User.” An individual legally authorized to access information about an End User, including legal guardians; parents or spouses with power of attorney; and case managers, clinicians, or care providers with documented consent or contract authority. An Authorized User’s access is limited to the scope of that documented legal authority. Authorized Users may use the Compass Care Calling App, the Compass Care Alerts App, or the Web Portal to fulfill caregiving or professional duties under HIPAA-compliant agreements.
2.8 “Legally Authorized Representative.” A legal guardian, conservator, parent or custodian (where permitted by law), health-care power of attorney, agent under a supported-decision-making agreement, or other person or entity authorized under applicable state law to make decisions or grant authorizations on behalf of an End User, within the scope of that authority.
2.9 “Customer Organization” and “Organizational User.” A “Customer Organization” is a provider agency or other entity that contracts with GMA to use the Compass Care Command Center and the MyCompass System to deliver or manage remote support services for its own clients. An “Organizational User” is an individual member of a Customer Organization’s workforce (e.g., administrators, program directors, direct support professionals) granted role-based access to the Command Center under the organization’s agreement with GMA. Organizational Users may access only the End Users assigned to their organization and role.
2.10 “Consent” or “Authorization.” Documented permission by the End User or their Legally Authorized Representative, as required under 45 CFR Section 164.508, for the collection, use, or disclosure of PHI or PII by GMA and its Business Associates.
2.11 “Business Associate.” Any individual or entity that performs functions involving PHI on behalf of a covered entity, pursuant to a formal Business Associate Agreement (BAA) under HIPAA. GMA’s Business Associates may include cloud-hosting providers, AI infrastructure providers, communication vendors, IoT integration partners, billing and revenue-cycle vendors, clearinghouses, and customer-support services. GMA itself acts as a Business Associate of Customer Organizations with respect to their clients’ PHI (see Section 1.1).
2.12 “Device Metadata.” Automatically collected technical data related to app or device use, which may include IP address, device operating system, device ID (Apple IDFA or Android AAID), crash logs, and app version and usage patterns.
2.13 “De-Identified Data.” Data stripped of identifiers such that it cannot reasonably be used to identify an individual, in accordance with HIPAA’s de-identification standards (45 CFR Section 164.514), using either the Safe Harbor or Expert Determination method.
2.14 “Mobile Device Management (MDM).” Administrative and technical tools used by GMA to secure and support GMA-provided tablets or phones issued to End Users, which may include app-usage restriction, location features (only if authorized), internet filtering, and device-health and compliance monitoring, configured as described in Section 8.5.
2.15 “Emergency Event.” A system-defined incident or condition that may include boundary breaches, periods of inactivity, fall detection, or any safety-related event that triggers an alert within the Compass Care Alerts App or Command Center, or initiates contact through Compass Care Calling. The limitations in the Important Safety Notice above apply to all Emergency Events.
2.16 “Nora Caregiver Intelligence” (“Nora”). GMA’s AI-enabled caregiver support feature, operated by GMA on Amazon Web Services using AWS Bedrock under a Business Associate Agreement. Nora provides decision support only, operates under human oversight, and does not make autonomous clinical or safety determinations. See Section 6.
2.17 “Biometric or Biometric-Derived Data.” Data generated from measurements of an individual’s biological or behavioral characteristics that can be used to identify the individual, and data derived from such measurements, to the extent any such data is processed by the Services. See Section 3.8.
2.18 “Payment and Billing Information.” Information used to verify eligibility, obtain authorization, and submit, document, and adjudicate claims for the Services, including payer and plan identifiers, claim and service records, and related financial information.
2.19 “Connected Platforms and IoT Integrations.” Approved third-party platforms, devices, and sensors that exchange data with the MyCompass System, including Apple HealthKit and HomeKit (where enabled) and approved IoT devices such as medication dispensers, fall sensors, and environmental sensors. Data exchanged with these platforms is governed by Section 11.
3. Information We Collect
GMA collects limited, purpose-driven information to support individualized services, promote safety, and comply with healthcare obligations. Information is collected only when necessary for service delivery or client protection, authorized by the End User or their Legally Authorized Representative, required by law or regulatory contract, or (for Customer Organization deployments) directed by the Customer Organization under its agreement with GMA. Information may be submitted directly by the user, passively collected via system use, or received from Connected Platforms and third-party integrations under Business Associate Agreements.
3.1 MyCompass App (Apple App Store, End Users)
Designed for individuals receiving remote support services, the MyCompass App collects information to facilitate daily routines, goals, wellness monitoring, and communication. Data collected includes:
- PII: full name, date of birth, contact information, client ID (if used)
- Service-Related Data (PHI): support schedules, goal tracking, check-in notes, reminders, emergency contacts and custom alert preferences, and self-notes or feedback
- App Interaction Data: page visits, clicks, frequency of logins, and timestamped activities
- Device Metadata (via MDM): device type, OS version, IP address, and crash reports
- Health Data via Apple HealthKit (only where enabled and authorized): see Section 11
Sensitive Data Handling. GPS location and microphone/camera access are not collected unless a specific feature requires it and it is explicitly enabled and authorized. Biometric or biometric-derived data is handled only as described in Section 3.9. Except for Nora Caregiver Intelligence (which operates as a care-support feature under Section 6) and security/diagnostic tooling, the MyCompass App does not use tracking cookies, advertising IDs, or analytics SDKs unrelated to medical or care support.
3.2 Compass Care Calling App (Apple + Google, Authorized Users)
Allows Authorized Users to initiate or respond to calls with the End User. Data collected includes caller/recipient identity (display name, linked client ID, authorized-user role); communication metadata, not content (call timestamps, duration, direction, error codes); device metadata (IP address, device ID, OS); and user authentication tokens (secured session IDs).
Note: No call audio or video is recorded or stored. GMA does not access call content. If recording functionality is implemented in the future, it will be enabled only with express authorization, advance notice, a Policy update, and compliance with applicable federal and state wiretap and two-party/all-party consent laws.
3.3 Compass Care Alerts App (Apple + Google, Authorized Users)
Provides real-time event notifications and logs concerning End User safety, based on thresholds defined in the support plan. Data collected includes alert metadata (alert type, timestamp, status, recipient log); authorized-user information (name, role, contact, linked clients); device metadata (push token, OS version, device type); limited HealthKit-derived context where a HealthKit integration is enabled and relevant to an alert; and optional approximate geolocation of the End User only when alert-location monitoring is explicitly enabled by the End User’s Legally Authorized Representative.
Note: Alerts are based on rules configured by authorized parties. No continuous location tracking is performed unless explicitly configured and consented to where legally appropriate. The limitations in the Important Safety Notice apply.
3.4 MyCompass Web Portal (Authorized Users)
The Web Portal provides browser-based access for Authorized Users and may process the same categories of PII, PHI, and authentication data described above, together with browser session data, IP address, and access logs. The same role-based access controls, encryption, and audit logging that apply to the mobile apps apply to the Web Portal.
3.5 Compass Care Command Center (Web, Organizational Users)
The Compass Care Command Center is a secure, web-based administration platform through which Customer Organizations manage the delivery of remote support services to their clients. Data processed through the Command Center includes:
- Organizational User account data: name, work contact information, role, organization affiliation, and credentials
- Client (End User) records managed by the organization (PHI): client profiles, support plans, schedules, alert configurations, service documentation, and caseload assignments
- Operational and audit data: alert response records, service-delivery logs, dashboards, and reporting
- Access and session data: login events, IP address, browser session data, and audit logs of every access to client records
Role of the parties. For End User PHI managed by a Customer Organization through the Command Center, the Customer Organization directs the use of that information and GMA processes it as the organization’s Business Associate under the governing BAA (see Section 1.1). Organizational Users may access only the clients assigned to their organization and role; strict tenant-level segregation prevents any organization from accessing another organization’s data.
3.6 Shared System-Level Data (All Services)
The following technical and security-related data may be collected across all Services: user authentication logs and timestamps; password resets or session expirations; MDM status; app, portal, and Command Center version, usage health, and error reporting; and consent-acknowledgment logs (e.g., EULAs and authorization forms).
3.7 Payment and Billing Information
To deliver and obtain payment for the Services, GMA collects and maintains Payment and Billing Information, including payer and plan identifiers, eligibility and authorization data, service and claim records, and related financial information. GMA uses and discloses this information for payment purposes as permitted by HIPAA (see Sections 4.1 and 7.3), and protects it with the safeguards described in Section 8. GMA does not use Payment and Billing Information for advertising, marketing, or profiling.
3.8 Connected Platforms and IoT Integrations
Where the MyCompass System is connected to approved platforms and devices (e.g., Apple HealthKit/HomeKit, smart medication dispensers, wearable or fall sensors), GMA may receive device readings (e.g., medication events, fall detection), status reports (e.g., device disconnected, low battery), and usage or alert history. All such data is received under HIPAA-compliant agreements (or, for Apple HealthKit/HomeKit, handled under Apple’s platform requirements as described in Section 11) and handled in accordance with this Policy.
3.9 Biometric and Biometric-Derived Data
Some assistive features may, where enabled and authorized, process biometric or biometric-derived data (for example, certain access methods or physiologic or behavioral measurements). GMA collects such data only where a feature the End User or their Legally Authorized Representative has enabled requires it, limits it to the minimum necessary, and does not use it for advertising, marketing, or profiling. Where GMA processes biometric or biometric-derived data, GMA: provides notice of the categories collected and the purpose; obtains consent where required by applicable law; protects the data under Section 8; and retains it only as long as needed for the authorized purpose or as required by law, after which it is securely destroyed or de-identified. If a feature that processes biometric data is not enabled, GMA does not collect biometric data through that feature.
3.10 Data Minimization and Least-Privilege Access
GMA enforces HIPAA’s “minimum necessary” standard. No employee, Authorized User, Organizational User, or system administrator may access more data than is required for the delivery of services. All access is logged and monitored.
4. HIPAA Permitted Uses and Basis for Processing
GMA collects, uses, and discloses information only as permitted or required by HIPAA, the HITECH Act, and other applicable U.S. federal and state laws. Where GMA acts as a Covered Entity, the permitted uses below apply directly; where GMA acts as a Business Associate of a Customer Organization or other covered entity (Section 1.1), GMA’s uses and disclosures are further limited to those permitted by the governing Business Associate Agreement.
4.1 Treatment, Payment, and Health Care Operations
Under 45 CFR Section 164.506, GMA may use and disclose PHI without separate authorization as necessary for treatment, payment, and health care operations, including providing, coordinating, or managing remote support services; facilitating care communication between End Users and Authorized Users; verifying eligibility, obtaining authorization, and submitting and adjudicating claims with payers and their agents; responding to safety events, alerts, or wellness checks; and personalizing the MyCompass experience (e.g., goal tracking, schedule configuration). This is the primary basis for most processing within the Services.
4.2 Authorization and Consent
Where an intended use or disclosure is not otherwise permitted by HIPAA, GMA relies on a signed HIPAA Authorization (45 CFR Section 164.508) or other legal documentation provided by the End User (if legally competent) or the End User’s Legally Authorized Representative. These authorizations are logged in accordance with federal retention requirements.
4.3 Required by Law and Contractual Obligations
GMA may process data as required under federal, state, or local law, including compliance with Medicaid waiver programs, TRICARE and other government health programs, aging services, or state disability-service contracts; documentation of remote support service delivery; incident or audit reporting; and retention requirements mandated by funding agencies.
4.4 Uses Permitted by HIPAA for Health and Safety
As permitted under HIPAA (including 45 CFR Section 164.512), GMA may use and disclose PHI to address serious threats to health or safety, for example, sending system alerts to authorized parties in the event of a fall, elopement, or inactivity; using app-based metadata to detect potential risks or failures; and managing emergency contact lists, device rules, or alert escalation. All such uses are governed by the minimum-necessary standard and user-role permissions.
4.5 Business Associate Agreements
Any vendor, contractor, or integrated service provider that processes or accesses PHI on behalf of GMA is subject to a Business Associate Agreement in compliance with 45 CFR Section 164.502(e). These partners may use PHI/PII only to support service delivery and must maintain privacy and security controls at least as protective as GMA’s. Conversely, GMA executes a Business Associate Agreement with every Customer Organization before the organization’s client data is onboarded to the Compass Care Command Center, and GMA’s vendors serving those deployments operate as subcontractor Business Associates under downstream agreements as required by 45 CFR Section 164.502(e)(1)(ii).
4.6 De-Identified and Aggregated Use
GMA may use de-identified data, stripped of identifiers under 45 CFR Section 164.514, for quality assurance, product improvement, system analytics, and non-commercial research. For Customer Organization data, de-identification and aggregation occur only as permitted by the governing BAA. No such use is traceable to any individual, and no marketing or advertising profiling is conducted with this data.
5. How We Use Information
GMA uses information solely to provide lawful, consented, and necessary services. All data handling is governed by the principles of privacy (access limited to authorized roles), security (data encrypted, access-controlled, and monitored), and confidentiality (minimum-necessary use). GMA does not sell, lease, or monetize user data, and does not use collected information for advertising or profiling.
5.1 Day-to-Day Remote Services (MyCompass App). To present schedules, reminders, and goal prompts; enable End Users to log progress and communicate needs; notify End Users of updates and achievements; tailor experiences to support plans; and help authorized personnel understand engagement or inactivity patterns. All interactions are encrypted and stored in HIPAA-compliant environments.
5.2 Secure Communication (Compass Care Calling App). To facilitate live interactions between End Users and their support network; track whether wellness or safety check-ins were attempted or completed; identify service gaps (e.g., repeated missed calls); log connection issues; and authenticate calling parties to protect against unauthorized access. No audio or video content is recorded or retained unless a future feature is explicitly enabled with legal authorization, user notice, and compliance with applicable recording-consent laws.
5.3 Alerts and Safety Events (Compass Care Alerts App). To notify Authorized Users of boundary exits, inactivity, potential falls, or system-status events; timestamp alert responses; maintain alert logs for quality assurance; assist with emergency communication under pre-authorized protocols; and identify false positives or optimize alert parameters. Location data is accessed only where explicitly enabled with appropriate consent; no continuous background tracking is performed.
5.4 Organizational Service Management (Compass Care Command Center). To enable Customer Organizations to onboard and manage their clients’ profiles and support plans; configure alerts, schedules, and caseload assignments; monitor and document service delivery and alert responses; generate operational and compliance reporting for the organization’s own clients; and administer Organizational User accounts and role-based permissions. GMA uses Command Center data on behalf of and at the direction of the Customer Organization, consistent with the governing BAA, and for GMA’s own permitted purposes of system administration, security, legal compliance, and proper management of the platform.
5.5 Payment and Billing. To verify eligibility and benefits, obtain prior authorizations, document service delivery, and submit and reconcile claims with Medicaid, TRICARE, and other payers and their authorized agents, consistent with Sections 4.1 and 7.3.
5.6 System Integrity and Technical Support. To detect software bugs and crashes; maintain uptime, speed, and compatibility; track login activity and authorization to prevent unauthorized access; enforce MDM policies; and deliver technical support. No unrelated analytics, user profiling, or advertising frameworks are implemented.
5.7 Legal, Clinical, and Contractual Requirements. To satisfy required documentation for waiver-funded or publicly contracted services; reporting for incident management or support-plan outcomes; state or federal audit requests; and legally mandated disclosures (e.g., abuse, neglect, or imminent harm). All such uses are subject to the minimum-necessary standard, logged in audit trails, and reviewed by compliance staff.
5.8 Internal Quality Improvement and Risk Mitigation. Using de-identified or aggregated data, GMA may improve accessibility and usability, analyze response times and system health, develop training materials and internal controls, and proactively resolve safety risks or device issues. These uses do not involve identifiable user data unless permission is granted through a formal authorization process, and for Customer Organization data occur only as permitted by the governing BAA.
5.9 Strict No-Use Clauses. GMA does not use any data collected through the Services for behavioral advertising or marketing; sale or licensing to third parties; unconsented research; or personal profiling beyond necessary safety configurations.
6. Nora Caregiver Intelligence (Artificial Intelligence)
Nora Caregiver Intelligence (“Nora”) is an AI-enabled caregiver support feature available within the MyCompass App, the Compass Care apps, the MyCompass Web Portal, and the Compass Care Command Center. This section describes how Nora processes information and the safeguards that apply.
6.1 Purpose and Function. Nora assists Authorized Users and Organizational Users in delivering services by surfacing relevant context, organizing care information, and supporting caregiving tasks. Nora processes information, which may include PHI, solely for these caregiving-support purposes. Nora is a care-support feature and is not used for advertising, marketing, or profiling.
6.2 Infrastructure and Business Associate Coverage. Nora is operated by GMA on Amazon Web Services using AWS Bedrock, which is covered by GMA’s Business Associate Agreement with AWS. Model inference runs within GMA’s AWS environment. The underlying model provider does not receive GMA data as a separate party and does not retain GMA inputs or outputs to train its models. Where Nora processes a Customer Organization’s client data, AWS operates as a subcontractor Business Associate consistent with the downstream-agreement requirements of HIPAA.
6.3 No Training on PHI. PHI is never used to train any artificial-intelligence or machine-learning model. No model provider retains GMA data for training purposes.
6.4 Safeguards and Data Minimization. GMA applies layered safeguards to Nora, including encryption in transit and at rest, strict data minimization, role-based access, tenant-level segregation of Customer Organization data, audit logging, and de-identification or tokenization of information where it does not impair the caregiving-support function. GMA limits the information made available to Nora to what is reasonably necessary for caregiving support.
6.5 Human Oversight. Nora provides decision support only. Nora does not make autonomous clinical, care, or safety determinations. Outputs from Nora that may affect an End User’s care or safety are reviewed by a qualified human before any action is taken. GMA maintains a human-in-the-loop approach for all care-affecting Nora functionality.
6.6 Accuracy and Limitations. AI-generated output may be incomplete or inaccurate and is intended to assist, not replace, the judgment of qualified caregivers and clinicians. Authorized Users and Organizational Users remain responsible for care decisions.
6.7 Nondiscrimination. Consistent with Section 1557 of the Affordable Care Act and GMA’s nondiscrimination commitments, GMA evaluates Nora to guard against discriminatory outcomes based on race, color, national origin, sex, age, or disability, applies bias-mitigation and human-oversight controls, and does not use Nora to make or support decisions in a manner that unlawfully discriminates against End Users.
7. Disclosure of Information
GMA treats all personal and health-related information with the highest degree of confidentiality. GMA does not sell, lease, or monetize user data, and does not permit any third party to use the data for the third party’s own purposes. GMA discloses information only to deliver services, comply with the law, protect the safety of End Users, or fulfill authorized care agreements, and, when it does, only the minimum necessary information, to vetted recipients, under appropriate agreements.
7.1 Disclosures With Authorization
GMA will disclose PHI or PII to a third party when the End User has provided a HIPAA-compliant written authorization; the End User’s Legally Authorized Representative has authorized disclosure within the scope of their authority; or a contractual party (e.g., a Medicaid or other government-program provider or case manager) has legal standing under a state or federal program. Such disclosures may include information necessary for coordination of care, emergency contacts, or authorized clinical teams.
7.2 Disclosures Without Authorization (As Permitted by Law)
Under 45 CFR Section 164.512, GMA may disclose information without authorization in limited, legally permissible situations: to avert a serious threat to health or safety; to public-health or social-services authorities as part of mandated reporting; to comply with a court order, subpoena, or legal investigation; to regulatory agencies conducting audits or licensing; to law enforcement under narrowly defined conditions (e.g., locating a missing vulnerable adult); to a medical examiner or coroner if required by law; and to government authorities where necessary to comply with national-security or protective-services laws. Such disclosures are tightly scoped to the minimum data required and documented under HIPAA’s accounting-of-disclosures rules (see Section 9.6).
7.3 Disclosures to Payers for Payment
GMA discloses PHI and Payment and Billing Information to government and commercial payers (including Medicaid, TRICARE, and other programs), their administrators, and clearinghouses, as necessary to verify eligibility, obtain authorization, and submit, document, and adjudicate claims for the Services. Payers act as independent covered entities or government agencies subject to their own legal obligations and are not GMA’s Business Associates when they receive information for their own payment, audit, or program-administration purposes.
7.4 Disclosures to Business Associates
GMA may share limited PHI or PII with Business Associates who perform services on GMA’s behalf, such as cloud storage, AI infrastructure (AWS Bedrock for Nora), notification infrastructure, MDM platforms, billing and revenue-cycle services, clearinghouses, and customer-support tools. All such entities are bound by a Business Associate Agreement under 45 CFR Section 164.502(e) requiring them to use the information only for authorized services, protect it with industry-standard safeguards, and report any breach or unauthorized use immediately.
7.5 Disclosures Within Customer Organization Deployments
Where a Customer Organization uses the Compass Care Command Center, GMA discloses that organization’s client information to the organization’s own Organizational Users in accordance with the roles and permissions the organization configures, and as directed by the organization under the governing BAA. GMA does not disclose one Customer Organization’s data to any other organization or customer, and strict tenant-level segregation enforces that boundary. The Customer Organization is responsible for the lawfulness of its own workforce’s access to and use of its clients’ information.
7.6 Internal Access Controls
Only GMA personnel with a legitimate “need to know” may access user data, e.g., support staff, administrators managing configurations, authorized clinicians or coordinators, and compliance or legal staff. Every access event is logged and monitored using secure audit controls.
7.7 Guardian and Authorized User Disclosures
Authorized Users may receive information only about End Users for whom they have documented legal or clinical authority, only within the scope of that authority, and only consistent with the limits of their access (e.g., read-only vs. full interaction). GMA honors court-ordered or statutory limits on a representative’s access, and End Users retain privacy rights where applicable law provides. No Authorized User or Organizational User may access PHI or system information outside their assigned role or permission scope. Misuse may result in immediate access suspension and legal action.
7.8 De-Identified and Aggregated Disclosures
GMA may share de-identified or aggregated information for quality improvement, research (only if not involving PHI), grant reporting, and public-health or education initiatives. Such information is scrubbed of all 18 HIPAA-defined identifiers and validated using the Safe Harbor or Expert Determination method.
7.9 No Sale and No Third-Party Monetization
GMA does not sell, rent, trade, or otherwise monetize your information, including PHI and any de-identified data derived from it, does not share it with advertisers or data brokers, and does not use it for advertising or marketing. GMA does not authorize any third party to use your information for the third party’s own purposes. This commitment is stated as Our Promise at the front of this Policy and is binding on GMA.
7.10 Business Transfers and Successor Obligations
GMA does not treat your information as a commercial asset to be sold. In the event of a merger, acquisition, investment, reorganization, bankruptcy, or sale or transfer of all or part of GMA’s business or assets, any PHI or other personal information will continue to be protected in accordance with this Policy and applicable law, and GMA will require any successor or acquirer to assume these obligations, including Our Promise, in writing. GMA will provide notice as required by law before any such information becomes subject to a materially different privacy practice and, where required, will offer the opportunity to consent or object.
8. Data Security and Retention
GMA implements rigorous administrative, physical, and technical safeguards designed to meet or exceed the standards of HIPAA, the HITECH Act, applicable state privacy and cybersecurity statutes, and industry best practices for mobile health and assistive technologies.
8.1 Data Encryption
All information is encrypted in transit using TLS 1.2 or higher, at rest using AES-256, and on devices under MDM controls where applicable. Encryption applies to personal identifiers and PHI across app, portal, and Command Center interactions, cloud storage, alert payloads, AI processing, and administrative tools.
8.2 Access Controls and Tenant Segregation
Access is strictly role-based and limited to individuals with verified credentials and a documented need-to-know. GMA enforces multi-factor authentication for administrative, backend, and Command Center users; device-level security policies for managed devices; time-based session expiration and automatic logout; audit logging of every login and data-access event; and strict tenant-level segregation so that each Customer Organization can access only its own clients’ data.
8.3 Breach Detection and Notification
In accordance with HIPAA’s Breach Notification Rule (45 CFR Sections 164.400 to 414), GMA maintains a formal breach-response policy. In the event of a breach of unsecured PHI, GMA will investigate and contain the incident promptly; notify affected individuals (and their Legally Authorized Representatives, as appropriate) in writing without unreasonable delay and no later than 60 calendar days after discovery, unless an exception applies; notify the U.S. Department of Health and Human Services (HHS) and any relevant state agencies as required by law; and document the incident and take corrective action. Where GMA acts as a Business Associate of a Customer Organization or other covered entity, GMA will notify that covered entity of any breach of its unsecured PHI in accordance with 45 CFR Section 164.410 and the governing BAA. All Business Associates and vendors must agree in writing to report suspected breaches immediately.
8.4 Data Retention
GMA retains PHI and PII for a minimum of seven (7) years from the date of last use, or longer as required by federal or state Medicaid, TRICARE, or other program documentation rules, managed-care contract provisions, waiver-program recordkeeping laws, or legal holds. Where retention timelines conflict, the longer duration applies. Records for minors may be retained for longer periods as required by applicable state law (e.g., until the age of majority plus a statutory period). For Customer Organization data, retention and return-or-destruction on termination are governed by the applicable BAA and service agreement. Once retention obligations expire, data is securely destroyed or permanently de-identified using NIST 800-88-compliant methods.
8.5 Mobile Device Management and Monitoring
For GMA-issued or MDM-controlled devices, additional security and support features may apply: remote lock and wipe; prohibition of unauthorized applications; location features (only if explicitly authorized and enabled); usage-restriction and content-filtering policies; and regular device-health scans and update enforcement. No MDM software is installed without the consent of the End User or their Legally Authorized Representative, and MDM data is not used for advertising or non-service analytics.
GMA distinguishes safety-supportive monitoring from control of the End User. Any monitoring, filtering, or location feature is tied to a documented need in the End User’s support plan, configured to the least-intrusive setting that meets that need, reviewed periodically, and, where the End User has the capacity to participate, configured with the End User’s input. GMA discloses to the End User and their Legally Authorized Representative what is and is not monitored on a managed device.
8.6 Infrastructure and Hosting
All data is stored in secure, HIPAA-compliant cloud environments hosted in the United States. GMA’s infrastructure includes redundant backups, intrusion-detection systems, role-based administrative dashboards with least-privilege design, periodic penetration testing and vulnerability scans, and 24/7 uptime monitoring. The same safeguards extend to any on-premises home-support hardware that is part of the MyCompass System.
8.7 User and Organizational Responsibility
All users are expected to keep login credentials confidential; immediately report lost or stolen devices; refrain from sharing app/portal screenshots or personal data externally; and use only authorized devices and app stores. Customer Organizations are additionally responsible for promptly deactivating Organizational User accounts when workforce members separate or change roles, and for maintaining the accuracy of their role and permission configurations. GMA provides training and support for safe usage.
9. Your Rights and Choices
GMA respects the rights of all users to control their personal information and protected health data under HIPAA, the HITECH Act, and applicable state privacy and disability-service laws. The following rights apply subject to legal authority and verification of identity. A right held by an End User may be exercised by the End User’s Legally Authorized Representative within the scope of their authority. For End Users served through a Customer Organization, HIPAA rights requests (access, amendment, restriction, accounting) are generally directed to and administered by that organization as the covered entity; GMA will support and facilitate the organization’s response as required by the governing BAA, and will promptly forward any such request it receives to the appropriate organization.
9.1 Right to Access
You may request access to PII or PHI collected or stored through the Services, including service or support-plan records, logged activities or goals, alert and call history (if applicable), and device metadata. Requests may be made in writing to privacy@graymattersalliance.com. GMA will respond within 30 calendar days, with one 30-day extension where permitted under 45 CFR Section 164.524, and may require verification of identity or authority.
9.2 Right to Correct or Amend Information
You may request corrections to inaccurate, incomplete, or outdated information, including personal identifiers, assigned caregivers or emergency contacts, support goals or communication preferences, and technical records with verifiable errors. Requests must be in writing; GMA will respond within the timelines required by HIPAA (45 CFR Section 164.526), generally within 60 calendar days, with one 30-day extension where permitted, and where feasible will respond sooner. Certain clinical records may require documented justification for amendment, and GMA may deny an amendment in the limited circumstances HIPAA permits, with a written explanation and your right to submit a statement of disagreement.
9.3 Right to Revoke Consent or Authorization
An End User or their Legally Authorized Representative may revoke a previously granted HIPAA Authorization or consent at any time, in writing. Upon revocation, GMA will discontinue future uses or disclosures based on that Authorization; the revocation will not apply retroactively to uses or disclosures already made; and certain ongoing services may be limited or suspended if revocation prevents essential care coordination. GMA will not retaliate against any person for exercising a privacy right, and where a revocation results in a change to or end of services, GMA will support a safe transition, including the timely transfer of records as authorized. A representative revoking app access for an Authorized User must submit a written request with legal documentation of authority.
9.4 Right to Request Restrictions
You may request restrictions on how GMA uses or discloses your PHI. While GMA is not required to agree to every requested restriction, it will review each request individually, honor any restriction it agrees to in writing (unless required by law to override it), and provide a written response with its decision and, if denied, a justification. As required by 45 CFR Section 164.522(a)(1)(vi), GMA will honor a request to restrict disclosure of PHI to a health plan for payment or health-care-operations purposes where the item or service involved has been paid for in full, out of pocket, by you or on your behalf, except where the disclosure is otherwise required by law.
9.5 Right to a Copy in an Electronic Format
Consistent with HIPAA’s right of access (45 CFR Section 164.524), upon request GMA will provide a copy of your PHI in a readable electronic format and, where readily producible, deliver it to you or to a third party you designate in writing. Any fee charged will be limited to a reasonable, cost-based fee as permitted by 45 CFR Section 164.524(c)(4). Only data collected by GMA directly is included; data obtained from third-party services is excluded unless legally transferable.
9.6 Right to an Accounting of Disclosures
Consistent with 45 CFR Section 164.528, you may request an accounting of certain disclosures of your PHI made by GMA. The accounting does not include disclosures for treatment, payment, or health care operations; disclosures made to you or pursuant to your authorization; and other categories excluded by law. Requests may be made in writing to the Privacy Officer (Section 16).
9.7 Right to File a Complaint
If you believe your privacy rights have been violated, you may file a complaint with GMA’s HIPAA Privacy Officer or with the U.S. Department of Health and Human Services, Office for Civil Rights (OCR). GMA prohibits retaliation against anyone who exercises this right.
9.8 Right to Deletion (Limited by HIPAA Retention Rules)
Medical or service-related data must be retained for the periods described in Section 8.4 and cannot be deleted on request during that period. However, non-clinical or auxiliary records (e.g., app notes, preferences) may be deleted on request; Authorized User accounts may be deleted when the user is no longer responsible for the End User; and full account deletion may occur after services terminate and records are no longer required for legal, billing, or compliance purposes. GMA will communicate the deletion timeline and any legal exceptions in its response.
9.9 Request Procedures
To make a request related to any of the rights above, contact GMA’s HIPAA Privacy Officer (Section 16). All requests will be acknowledged within 10 business days and completed within the timelines required by applicable law.
10. Accessibility, Effective Communication, and Language Access
GMA is committed to ensuring that this Policy and the consents and notices that accompany the Services are understandable and accessible to the people they serve, consistent with Section 1557 of the Affordable Care Act, the Americans with Disabilities Act, and Section 504 of the Rehabilitation Act.
- Plain-language and accessible formats. GMA provides this Policy and key consent materials in plain language and, on request and at no cost, in accessible formats (such as large print, screen-reader-compatible electronic formats, or other auxiliary aids and services) to support effective communication with individuals with disabilities.
- Language access. GMA provides language-assistance services, including translation or interpretation, to individuals with limited English proficiency, on request and at no cost, where required by applicable law.
- How to request. To request this Policy or related materials in an accessible format or another language, contact the Privacy Officer (Section 16).
11. Third-Party Services, Integrations, and Connected Platforms
GMA uses select third-party service providers and connected platforms to operate the Services securely. These providers and platforms do not own, sell, or independently exploit your data. Except for Apple HealthKit/HomeKit (governed by Apple’s platform requirements described below), all third-party relationships involving PHI are governed by Business Associate Agreements, and no third party may use PHI or PII outside the scope of its engagement with GMA.
11.1 Categories of Third-Party Services
- Cloud Hosting: encrypted, HIPAA-compliant U.S.-based environments (e.g., AWS)
- AI Infrastructure: AWS Bedrock, used to operate Nora Caregiver Intelligence under BAA (see Section 6)
- Mobile/Web App Infrastructure: push notifications, device updates, app distribution, and crash diagnostics, configured for HIPAA safety
- Secure Communication Tools: voice, video, or alert-based communication between End Users and Authorized Users (e.g., Agora)
- Mobile Device Management: to configure, monitor, and secure GMA-issued devices
- Billing, Revenue-Cycle, and Clearinghouse Services: to verify eligibility, submit and adjudicate claims, and support payment operations under BAA
- Customer Support Systems: for support-ticket tracking and secure correspondence
- IoT and Hardware Integrations: approved devices such as medication dispensers, fall sensors, and environmental sensors, exchanging data through secure APIs under the same HIPAA standards as in-app data
11.2 Apple HealthKit and HomeKit
Where enabled and authorized, the MyCompass System integrates with Apple HealthKit (health and fitness data) and Apple HomeKit (connected home/accessory data). Consistent with Apple’s requirements, GMA: uses HealthKit and HomeKit data solely to provide health, care, and safety functionality; does not use HealthKit or HomeKit data for advertising, marketing, data-mining, or sale; does not disclose HealthKit or HomeKit data to third parties except as needed to provide a health or service purpose with the user’s consent; and does not use this data for any purpose unrelated to the Services. Apple does not act as GMA’s Business Associate for HealthKit/HomeKit; once HealthKit/HomeKit data is received into the MyCompass System, GMA protects it as PHI under this Policy and the safeguards in Section 8.
11.3 Restrictions on Third Parties
All third-party service providers are prohibited from selling, reusing, or disclosing user data; using app data for marketing, advertising, analytics, or profiling; retaining data beyond what is required for contractual compliance; accessing audio, video, or location data unless technically necessary and contractually permitted; and subcontracting without GMA’s written consent and a downstream HIPAA-compliant agreement.
11.4 IoT Vendor Diligence and BAA Requirement
Before integrating any IoT device or platform that may transmit PHI, GMA requires a signed Business Associate Agreement or comparable HIPAA-compliant data-protection contract. Where a device or vendor cannot or will not enter a BAA, GMA will either de-identify data before transmission, limit the integration so that no PHI is exchanged, or decline the integration. GMA does not expose identifiable client data to vendors that have not contractually agreed to HIPAA-level protections.
11.5 Guardian and Client Awareness
When a third-party tool or device is involved in delivering care, GMA will identify the tool in onboarding materials or device guides, provide instructions regarding configuration and consent, offer training or support for approved integrations, and ensure data remains within the boundaries of authorized use.
11.6 Public App Store Requirements
To comply with Apple App Store and Google Play policies, any third-party SDKs or APIs embedded in the apps are configured to disable advertising-tracking features, analytics not required for security or bug resolution, and device fingerprinting or app-based profiling. GMA does not share Apple or Android device identifiers (e.g., IDFA, AAID) with third parties for commercial purposes.
12. Children’s and Incapacitated Adults’ Privacy
The Services may be used by or on behalf of individuals who are minors, incapacitated adults, or individuals under guardianship or supported-decision-making agreements. GMA takes extra precautions to ensure all such data is handled in compliance with HIPAA, applicable state laws regarding minors and guardianship, and best practices for vulnerable populations.
12.1 Age Restrictions and Guardian Access
An End User may use the MyCompass App regardless of age, provided the individual is a recipient of GMA services and the app is configured appropriately. For End Users under 18, or those declared legally incapacitated or requiring substituted or supported decision-making, a Legally Authorized Representative must act on their behalf for authorization of data access, consent to terms, configuration of app settings, and activation of safety or communication features. GMA requires documentation of legal authority (e.g., guardianship orders, power of attorney, supported-decision-making agreement) before enabling access by an Authorized User acting on behalf of another person, and limits that access to the scope of the documented authority.
12.2 Collection of Information from Minors
GMA obtains verifiable guardian or parental consent before collecting PHI or PII from a minor, and does not knowingly collect such information from minors without it. Where services are provided to a person under 18, or an adult lacking legal capacity, data collection is limited to the minimum necessary and directed solely to support care delivery under the authorization of a Legally Authorized Representative. GMA does not engage in behavioral tracking, targeted advertising, or profiling of minors.
12.3 Role of Guardians and Authorized Representatives
Within the scope of their documented legal authority, Legally Authorized Representatives may set up and manage user profiles, determine who may access the Compass Care Calling or Alerts apps, enable or restrict alert thresholds and notifications, and revoke access or request updates on behalf of the End User. GMA honors court-ordered or statutory limits on a representative’s access. All representative activities are logged and stored in accordance with HIPAA audit requirements.
12.4 Supported Decision-Making and Retained Rights
GMA presumes that an End User has capacity except to the extent a court order or applicable law provides otherwise, and supports supported-decision-making arrangements. For End Users with partial capacity who require assistance, GMA configures the Services to default toward End-User participation where possible, including shared access, tailored interface configurations, and prompting mechanisms that allow participation with guidance. GMA recognizes that capacity is contextual and may change over time; changes to a person’s access following a change in capacity require appropriate documentation. End Users retain the privacy rights afforded to them under applicable law, including as against a representative where the law or a court order so provides.
12.5 Heightened Protection of Sensitive Status
GMA recognizes that an individual’s status as an End User, and related data, may reveal disability or health conditions that are highly sensitive. GMA treats this information with heightened protection, limits access to those with a need to know, and does not use it to discriminate against or otherwise disadvantage an End User.
12.6 COPPA Compliance
GMA’s apps are not directed to the general public or to children under 13 for independent use. In any case where a child under 13 may use an app, verifiable guardian consent and oversight are required, and all collection is solely for service delivery and protection, consistent with the Children’s Online Privacy Protection Act (COPPA).
13. Information Not Governed by HIPAA; State Privacy Rights
13.1 Information Not Governed by HIPAA
Most information processed through the Services is PHI governed by HIPAA. Some information, for example, analytics from GMA’s public website, account information created before any health context exists, or certain device diagnostics, may fall outside HIPAA. GMA handles that information consistent with this Policy and applicable consumer-privacy law: GMA does not sell it, does not use it for cross-context behavioral advertising, and applies reasonable security safeguards to it.
13.2 State Privacy Rights
Depending on where you live, state law may give you additional rights with respect to personal data or consumer health data that is not otherwise exempt as PHI or covered-entity data, for example, under the Washington My Health My Data Act, Nevada’s consumer-health-data law, and comprehensive privacy laws in states such as California, Virginia, Colorado, and Connecticut. These rights may include the right to access, correct, delete, or obtain a copy of certain personal data, and to opt out of certain processing. Many of these laws exempt PHI and information handled by HIPAA-covered entities; where an exemption applies, that information continues to be governed by HIPAA and this Policy. To exercise any state-law right that applies to you, contact the Privacy Officer (Section 16); GMA will respond as required by the applicable law and will not discriminate against you for exercising a right.
14. Governing Law and Relationship to Other Agreements
This Policy is governed by the laws of the State of Missouri and applicable U.S. federal law, without regard to conflict-of-laws principles, except where the law of another state mandatorily applies to a particular individual or category of data. The Services are intended for use in the United States, and information is processed and stored in the United States.
This Policy addresses privacy practices. It is part of, and is supplemented by, GMA’s End User License Agreement and any applicable Terms of Use or service agreement, which govern matters such as permitted use, limitations of liability, warranties, and dispute resolution. For Customer Organizations, the organization’s service agreement and BAA with GMA additionally govern the Command Center. Where this Policy and the NPP address the same HIPAA subject, the NPP governs GMA’s formal HIPAA obligations (see Section 1.2). Nothing in any agreement purports to waive rights that cannot be waived under applicable law, including the privacy rights of End Users.
15. Other Applicable Laws
GMA complies with other federal and state laws that may apply to particular services or data. For example, where any service is delivered in an educational setting subject to the Family Educational Rights and Privacy Act (FERPA), where any records are subject to the federal confidentiality rules for substance-use-disorder treatment records (42 CFR Part 2), or where genetic information is involved under the Genetic Information Nondiscrimination Act (GINA), GMA handles that information in accordance with those laws in addition to this Policy. Where any such law imposes stricter requirements than this Policy, the stricter requirement applies.
16. Contact Information
GMA has designated a HIPAA Privacy Officer to oversee privacy-related matters, ensure compliance with federal and state data-protection laws, respond to inquiries, and handle concerns regarding the handling of personal or health information across the Services.
HIPAA Privacy Officer
Name: Kyle Dortch
Title: Chief Administrative Officer & HIPAA Privacy Officer
Organization: Gray Matters Alliance, LLC
Privacy & rights requests: privacy@graymattersalliance.com
Phone: 314-266-2678
Mailing Address: Gray Matters Alliance, 119 S Main Street, St. Charles, MO 63301, United States
Filing a Complaint
If you believe your privacy rights have been violated, you may file a complaint with Gray Matters Alliance (using the contact information above) or with the U.S. Department of Health and Human Services (HHS), Office for Civil Rights (OCR).
- OCR Website: hhs.gov/hipaa/filing-a-complaint
- OCR Phone: 1-800-368-1019
You will not be retaliated against for filing a complaint.
Response Timeframes. GMA will acknowledge all privacy-related inquiries within 10 business days and respond in full within the timelines required by HIPAA, state law, or relevant service agreements (generally within 30 calendar days for access requests and within the period described in Section 9.2 for amendment requests).
17. Changes to This Privacy Policy
GMA may update or modify this Policy at any time to reflect changes in applicable laws (including HIPAA, HITECH, or state rules); updates to the functionality, features, or integrations of the Services; enhancements to security or data-handling practices; or operational changes affecting how information is managed.
Any changes will be posted prominently within the apps, the Web Portal, and the Command Center; published on the official GMA website; and communicated directly to Authorized Users, Organizational Users, and End Users (or their Legally Authorized Representatives) when legally required or where changes involve material alterations to data use or user rights.
17.1 Effective Date of Revisions. Each updated version will include a clearly stated “Last Updated” date and version number at the top. Users are encouraged to review the Policy periodically.
17.2 Continued Use as Acceptance. By continuing to use the Services after an updated Policy is posted, you (or the Legally Authorized Representative who accepts on an End User’s behalf under Section 1.3) acknowledge and accept the revised terms. If you disagree with any material changes, you may discontinue use and request assistance with account closure.
17.3 Notification for Material Changes. For material changes (e.g., expanded use of PHI, new categories of data collected, or changes in legal rights), GMA will provide advance notice via in-app messaging or email to affected users; offer an opportunity to re-consent where required; and retain a historical record of prior versions.
Privacy Snapshot (for App Store & Google Play)
Developer: Gray Matters Alliance, LLC (GMA)
Apps covered: MyCompass (iOS only, End Users); Compass Care Calling (iOS & Android, Authorized Users); Compass Care Alerts (iOS & Android, Authorized Users)
The Compass Care Command Center is a web-based platform for provider organizations and is not distributed through the app stores; it is governed by the full Privacy Policy and each organization’s Business Associate Agreement with GMA.
Category: Medical / Health & Fitness
Region & Hosting: Data processed and stored in the United States (HIPAA-compliant).
Regulatory posture: HIPAA/HITECH compliant. The Services are not a medical device and not a personal emergency response system (PERS); they are part of GMA’s custom remote-support solution and are not a substitute for 911 or emergency services.
AI: Includes Nora Caregiver Intelligence, operated on AWS Bedrock under BAA, with human oversight and no use of PHI to train models.
Contact: privacy@graymattersalliance.com · 314-266-2678
Full Privacy Policy URL: /legal/privacy-policy/
We do not:
- Sell, rent, or trade your information, including de-identified data, ever; use behavioral ads; or share data with advertisers or data brokers.
- Transfer your information in a business deal without binding any successor to this same promise.
- Track you across apps or websites owned by other companies.
- Use HealthKit, HomeKit, or any care data for advertising, marketing, or data-mining.
- Use PHI to train AI models.
We do:
- Collect only what’s necessary for care, safety, and app functionality.
- Encrypt data in transit (TLS) and at rest (AES-256).
- Restrict access by role/authorization; all access is logged.
- Use Business Associates under HIPAA; no third-party monetization.
- Operate Nora Caregiver Intelligence on AWS Bedrock under BAA with human oversight.
- Honor user/representative rights (access, correction, restrictions, revocation, accounting), with medical-record retention of at least 7 years.
- Provide this notice in accessible formats and other languages on request.
Apple “App Privacy” Summary (App Store Connect)
Data Used to Track You: None.
Data Linked to You (for app functionality, account management, safety, customer support, security/compliance):
- Contact Info: name, email/phone (all apps)
- Identifiers: account ID, device token, IP/device info (all apps)
- Health & Fitness / Health Data (PHI): only where applicable to care, including Apple HealthKit data where enabled (MyCompass; limited alert context in Alerts)
- Home Data (Apple HomeKit): only where enabled, to support safety and care functionality
- Usage Data: app interactions, timestamps, login events (all apps)
- Location (approximate): Alerts only, and only if enabled by the End User’s Legally Authorized Representative
Data Not Linked to You: Diagnostics: crash logs, performance data (all apps)
We do not collect precise location, contacts, photos, microphone, or camera content unless a future feature explicitly requests it with clear in-app consent. HealthKit and HomeKit data are used solely for health, care, and safety purposes and are never used for advertising, marketing, data-mining, or sale.
Google Play “Data Safety” (Calling & Alerts)
- Data collected: Contact info, identifiers, usage data, diagnostics; Alerts may collect approximate location if enabled.
- Data shared: No data shared for advertising. GMA does not sell user data. Sharing is limited to HIPAA Business Associates for app operations.
- Security: Encrypted in transit and at rest; access is role-based and audited.
- Data deletion: Users/representatives may request account/data actions; medical records retained 7 years or more as required.
- AI: Nora Caregiver Intelligence runs on AWS Bedrock under BAA; PHI is not used to train models.
- Purpose of collection: App functionality, safety notifications, communications, security/compliance, customer support, diagnostics.
- Optional location: Alerts only, with explicit configuration by the End User’s Legally Authorized Representative.
Per-App Snapshots
1) MyCompass (iOS, End Users)
- Collects (Linked to You): Contact Info, Identifiers, Health/Service data (goals, schedules, support notes), Usage Data; Apple HealthKit data where enabled.
- Diagnostics (Not Linked): crash/performance logs.
- Location: Not collected.
- AI: Nora Caregiver Intelligence available, with human oversight; no PHI used for model training.
- Used for: app functionality, care coordination, safety reminders, account management, security/compliance, support.
- Does not: record audio/video, use advertising IDs, or profile for marketing.
- Typical Permissions: Notifications; Internet; HealthKit/HomeKit (only if enabled). No camera/mic/location required as currently designed.
2) Compass Care Calling (iOS & Android, Authorized Users)
- Collects (Linked to You): Contact Info, Identifiers, Usage Data, Call metadata (timestamps, duration, direction).
- Diagnostics (Not Linked): crash/performance logs.
- Location: Not collected.
- Used for: secure communication, verification/authentication, reliability/diagnostics, security/compliance.
- Does not: record or store call audio/video content.
- Typical Permissions: Notifications; Network; (Android) “Phone” for calls over data; foreground service for connectivity.
3) Compass Care Alerts (iOS & Android, Authorized Users)
- Collects (Linked to You): Contact Info, Identifiers, Usage Data, Alert metadata (type, time, status, recipient), Optional approximate location (only if enabled by the Legally Authorized Representative).
- Diagnostics (Not Linked): crash/performance logs.
- Used for: safety notifications, emergency workflows, audit trails, security/compliance.
- Location: Optional & event-based (no continuous background tracking unless explicitly configured).
- Typical Permissions: Notifications; (Optional) Location “When In Use” for alert workflows; foreground service on Android for timely alerts.
4) Compass Care Command Center (Web, Provider Organizations)
- Access: Secure web platform; not distributed via app stores.
- Collects: Organizational User account data, client records managed by the organization (PHI), operational/audit data, access and session logs.
- Governed by: this Privacy Policy and the organization’s Business Associate Agreement with GMA; strict tenant segregation between organizations.
- AI: Nora Caregiver Intelligence available, with human oversight; no PHI used for model training.
- Does not: use advertising IDs, sell data, or permit cross-organization access.
User Rights & Support (All Apps)
- Access / Corrections / Restrictions / Revocation / Accounting: Contact GMA’s HIPAA Privacy Officer (Section 16) or the privacy intake address. End Users served through a provider organization may also direct requests to that organization.
- Deletion: Available where legally permissible; clinical/service records retained 7 years or more per law.
- Accessibility & language: This notice is available in accessible formats and other languages on request.
- Complaints: Contact GMA’s Privacy Officer or HHS-OCR (no retaliation).