Pendlark early family beta
Privacy Policy
This plain-language policy explains what Pendlark handles while families test the product and what happens when an account deletion is requested.
Information you choose to provide
Pendlark may receive voluntarily provided account information such as your name, email address, and authentication details. If you choose to use them, this also includes your Support Profile, family and child support-needs information, consent choices, Family Care Calendar entries, Care Queue and saved-provider information, supported uploads and their document metadata, and feedback or support reports.
Technical and diagnostic information may be generated when the service runs, including bounded provider-search diagnostics, error details, device or request context, and security records needed to operate the product. Please do not upload information that you do not want Pendlark to handle.
How Pendlark uses information
We use information to operate Pendlark, provide the family organization features you request, secure accounts, troubleshoot failures, support users, and improve the beta. Necessary infrastructure and service providers may process information for those functions under their service boundaries.
Pendlark does not sell sensitive family information to advertisers. Access to account and family information is controlled through authentication and authorization. Shared provider catalog data and unrelated family records are kept separate from your account.
Your choices and deletion requests
You may request deletion from Account Settings. Pendlark verifies the signed-in account and current password, requires an explicit confirmation, resolves any recurring billing question before destructive work, and removes family content in an ownership-scoped sequence. Critical failures stop the process and create a recoverable Admin state rather than claiming completion.
A small amount of information may remain for payment or accounting, security or fraud prevention, audit, disputes, or support history. Where practical, retained records are anonymized or detached from the active family profile. No fixed legal retention period is stated here; unverified durations remain owner-reviewable.
Beta boundaries
Pendlark is an early beta and may change as the product is tested. Pendlark does not claim HIPAA compliance, a certification, or another regulatory certification in this policy.
Retention matrix
The current beta treatment is summarized below. “No fixed period set; owner review required” is intentionally not a statutory duration.
| Data class | Deleted immediately | Retained minimally | Reason | Anonymized/detached |
|---|---|---|---|---|
| Auth user, credential account, sessions | Delete after verified cleanup | None in the active account | No active sign-in after completion; Better Auth owns final removal. | Recovery evidence is detached after completion. |
| Support Profile, child/family support-needs, onboarding | Yes | None | Active family profile content is removed. | No user link retained. |
| Calendar events, exceptions, reminders | Yes | None | Family-specific organization state is removed. | Not retained. |
| Care Queue/saved-provider relationships | Yes | Shared provider catalog remains. | The family relationship is removed without deleting shared providers. | No user link retained. |
| Supported upload objects and document metadata/proposals | Yes, including R2 object keys | None after successful object deletion | Family content and storage exposure are removed; cleanup stops safely on failure. | No storage URL or key is returned to the user. |
| User-scoped provider diagnostics | Yes | Only an explicitly approved detached aggregate, if later adopted | Family search criteria must not remain attached to the user. | Current beta deletes the user-scoped rows. |
| Feedback/support content | Yes unless an owner-approved minimal support-history rule exists | None under the current beta rule | Reports may contain sensitive family content. | Current beta deletes the user-owned issue and its actions. |
| Subscription grants/local entitlement | Revoke/delete after billing resolution | None in the active account | Access must not continue after deletion. | Billing evidence is detached where practical. |
| Payment/accounting event evidence | No | No fixed period set; owner review required | Only minimal detached evidence may remain for accounting/payment review when owner-approved. | Customer email and direct customer linkage are removed where practical. |
| Security/fraud/audit/dispute/deletion recovery record | No | No fixed period set; owner review required | Explain the outcome, resolve disputes, and recover critical failures. | Detached after successful completion where practical. |
| Shared provider catalog and unrelated family rows | No | Preserved | Product data and strict family isolation must remain intact. | Never attached to the deleted family by cleanup. |
Auth user, credential account, sessions
- Deleted immediately
- Delete after verified cleanup
- Retained minimally
- None in the active account
- Reason
- No active sign-in after completion; Better Auth owns final removal.
- Anonymized/detached
- Recovery evidence is detached after completion.
Support Profile, child/family support-needs, onboarding
- Deleted immediately
- Yes
- Retained minimally
- None
- Reason
- Active family profile content is removed.
- Anonymized/detached
- No user link retained.
Calendar events, exceptions, reminders
- Deleted immediately
- Yes
- Retained minimally
- None
- Reason
- Family-specific organization state is removed.
- Anonymized/detached
- Not retained.
Care Queue/saved-provider relationships
- Deleted immediately
- Yes
- Retained minimally
- Shared provider catalog remains.
- Reason
- The family relationship is removed without deleting shared providers.
- Anonymized/detached
- No user link retained.
Supported upload objects and document metadata/proposals
- Deleted immediately
- Yes, including R2 object keys
- Retained minimally
- None after successful object deletion
- Reason
- Family content and storage exposure are removed; cleanup stops safely on failure.
- Anonymized/detached
- No storage URL or key is returned to the user.
User-scoped provider diagnostics
- Deleted immediately
- Yes
- Retained minimally
- Only an explicitly approved detached aggregate, if later adopted
- Reason
- Family search criteria must not remain attached to the user.
- Anonymized/detached
- Current beta deletes the user-scoped rows.
Feedback/support content
- Deleted immediately
- Yes unless an owner-approved minimal support-history rule exists
- Retained minimally
- None under the current beta rule
- Reason
- Reports may contain sensitive family content.
- Anonymized/detached
- Current beta deletes the user-owned issue and its actions.
Subscription grants/local entitlement
- Deleted immediately
- Revoke/delete after billing resolution
- Retained minimally
- None in the active account
- Reason
- Access must not continue after deletion.
- Anonymized/detached
- Billing evidence is detached where practical.
Payment/accounting event evidence
- Deleted immediately
- No
- Retained minimally
- No fixed period set; owner review required
- Reason
- Only minimal detached evidence may remain for accounting/payment review when owner-approved.
- Anonymized/detached
- Customer email and direct customer linkage are removed where practical.
Security/fraud/audit/dispute/deletion recovery record
- Deleted immediately
- No
- Retained minimally
- No fixed period set; owner review required
- Reason
- Explain the outcome, resolve disputes, and recover critical failures.
- Anonymized/detached
- Detached after successful completion where practical.
Shared provider catalog and unrelated family rows
- Deleted immediately
- No
- Retained minimally
- Preserved
- Reason
- Product data and strict family isolation must remain intact.
- Anonymized/detached
- Never attached to the deleted family by cleanup.