Privacy at ElPulseChart
How we handle information across the ElPulseChart platform.
Privacy Policy for Elpulse
Last Updated: August 21, 2026
Introduction
Elpulse ("we," "our," or "us") provides a comprehensive care management platform for residential group homes, foster homes, and Residential Treatment Homes (RTH). This Privacy Policy explains how we collect, use, disclose, and safeguard information when you use our mobile application, native iOS app, and website (elpulsechart.com), collectively referred to as the "Service."
By using Elpulse, you agree to the collection and use of information in accordance with this policy.
Information We Collect
Account & Identity Information
- Name, email address, phone number, job title/role, and organization/facility affiliation
- Login credentials and authentication data
- Role designation (Admin, Manager, Caregiver, Family) and facility-level access grants
Resident/Patient Information
- Demographic and identifying information (name, room, date of birth, MRN)
- Medication administration records (MAR): medications, dosages, schedules, administration status, controlled substance tracking, witness records, and correction history
- Individual Support Plan (ISP) data: desired outcomes, implementation strategies, measurable criteria, baseline data, and daily activity tracking
- Individually-Based Limitations: documented restrictions on protected freedoms (e.g., food access, visitors, schedule), the health/safety justification for each, and signed consent records
- Clinical flowsheet data: vital signs, weight, bowel movement tracking, intake/output, blood glucose, and pain assessments
- Progress notes: daily caregiver documentation across mood, meals, sleep, hygiene, behavior, and other care domains
- Incident reports and related documentation
- Photos or documents attached to a resident's record, where applicable
Staff & Facility Operations Information
- Time clock and scheduling data: clock-in/out times, breaks, shift assignments, and timesheet approvals
- Payroll-related information: hourly rates and calculated labor costs (used for facility-internal reporting, not for processing payments)
- Staff credentials, certifications, and delegation records
- Facility configuration, regulatory profile, and compliance policy settings
Information Collected Automatically
- Usage data: features accessed, timestamps of key actions, login activity
- Device information: device type, operating system, and app version
How We Use Information
We use collected information to:
- Provide, operate, and maintain the Elpulse platform, including medication tracking, ISP/PBSP documentation, clinical flowsheets, and staff scheduling
- Enable accurate, auditable documentation of care delivery, including corrections with a preserved audit trail
- Authenticate users and enforce role-based and facility-based access controls
- Support required consent, review, and co-signature workflows for sensitive clinical actions
- Improve the Service, troubleshoot issues, and develop new features
- Communicate with you about updates, support, or service-related notices
- Comply with legal, regulatory, and recordkeeping obligations applicable to residential care and healthcare settings
Health Information & HIPAA
Elpulse is designed to support licensed care facilities in maintaining accurate, complete clinical and behavioral health records. Information entered into Elpulse — including medication records, ISP/PBSP data, individually-based limitations, clinical flowsheets, and progress notes — may constitute Protected Health Information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA). Facilities and organizations using Elpulse are responsible for ensuring their own compliance with applicable healthcare privacy laws, and we will enter into a Business Associate Agreement (BAA) with covered entities upon request.
We implement administrative, technical, and physical safeguards designed to protect health information consistent with HIPAA Security Rule requirements, including role-based access controls, facility-level data isolation, encryption, and detailed audit logging of clinical actions (including corrections, reviews, and co-signatures).
Individually-Based Limitations & Consent Records
Where a facility documents a limitation on a resident's protected freedoms (such as access to food, visitors, or personal schedule) due to an assessed health or safety need, Elpulse stores the documented justification and any signed consent record uploaded by the facility. This is among the most sensitive categories of information in the Service, and access is restricted to authorized facility staff (Admins and, where the facility permits, RNs) involved in that resident's care.
Data Sharing and Disclosure
We do not sell personal or health information. We may share information:
- With your facility's authorized administrators, managers, and staff, as configured within the platform's role- and facility-based access controls
- With service providers who perform functions on our behalf (e.g., cloud infrastructure, hosting, notification delivery), under contractual confidentiality obligations
- When required by law, subpoena, or legal process
- To protect the rights, safety, or property of Elpulse, our users, or others
- In connection with a merger, acquisition, or sale of assets, with notice to affected users where required
Subscriptions & Payment
Elpulse offers subscription plans billed at the organization level through our website. We do not process or store full payment card information ourselves; payment processing is handled by our payment processor. On the native iOS app, subscription management is handled through your organization's web account at elpulsechart.com, consistent with Apple App Store guidelines for business-to-business applications.
Data Retention
We retain resident, staff, and facility data for as long as your account is active or as needed to provide the Service, comply with legal obligations, resolve disputes, and enforce our agreements. Certain clinical record types (including ISP/PBSP tracking and individually-based limitation records) are retained for extended periods consistent with applicable state recordkeeping requirements for residential care providers. Facilities may request deletion of their data, subject to these requirements.
Data Security
We use industry-standard safeguards — including encryption in transit and at rest, role-based and facility-scoped access controls, and audit logging of clinical and administrative actions — to protect information from unauthorized access, alteration, disclosure, or destruction. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
Your Rights and Choices
Depending on your role and applicable law, you may have the right to:
- Access, correct, or request deletion of your personal information
- Object to or restrict certain processing of your information
- Request a copy of your data in a portable format
To exercise these rights, contact us using the information below. Requests involving resident health data must typically be made through your facility's designated administrator, consistent with recordkeeping obligations that apply to the facility as the data controller for resident records.
Children's Privacy
Elpulse is intended for use by professional caregivers and administrative staff at licensed care facilities. It is not directed at children, and we do not knowingly collect personal information from individuals under 18 as app users. Where Elpulse is used by a facility serving minor residents (e.g., certain foster care or RTH settings), the facility itself is responsible for the appropriate handling of that resident's information under applicable law, and Elpulse's role is limited to providing the documentation platform used by facility staff.
Third-Party Links
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices of those third parties, and we encourage you to review their privacy policies separately.
Account Deletion
You may request deletion of your account at any time from inside the app: Settings → Privacy & Data → Schedule Account Deletion. You can also request deletion by emailing elpulsechart@gmail.com from the address on your account.
What happens: your access is deactivated immediately and a 7-day recovery window starts, during which you can cancel the request from the pending-deletion screen. After the window, a separate final purge permanently removes your login and personal profile (name, email, phone, credentials).
Organization owners: scheduling deletion as the owner of an organization schedules the whole organization. After the recovery window, confirming the final purge permanently erases all of the organization's records — including resident clinical records and the audit trail — and cancels the subscription. Before confirming, the facility must export and keep any records it is legally required to retain; ElPulseChart keeps no copy afterwards.
What may be retained: clinical and audit records that a licensed residential care provider is legally or operationally required to keep — for example medication administration records, incident reports, progress notes, resident documents and the audit trail — are retained by the facility for the period required by applicable law and are not erased by an individual account deletion. Where such a record references you (for example as the staff member who charted a dose), the record is kept but your login is removed. Not every clinical record is erased immediately or automatically.
Changes to This Policy
We may update this Privacy Policy from time to time as the Service evolves. We will notify users of material changes by updating the "Last Updated" date above and, where appropriate, through in-app or email notice. Continued use of the Service after changes take effect constitutes acceptance of the updated policy.
Contact Us
If you have questions or concerns about this Privacy Policy or our data practices, please contact us at:
Email: elpulsechart@gmail.com Website: https://elpulsechart.com