# Privacy & Security: HIPAA-Compliant Behavioral Data Tracking

VillageMetrics provides comprehensive settings management with strong privacy controls to help you customize your experience while maintaining HIPAA compliance.

## Accessing Settings

- **Location**: Gear icon in upper right corner of any screen
- **Organization**: Settings are organized into logical sections for easy navigation
- **Context**: Some settings are global (apply to your account) while others are child-specific

## Manage Children Section

### Add or Modify Children

**Adding New Children**:

- **Parent Privilege**: Only parents can add children (requires checking "I am a parent or legal guardian")
- **Complete Profile Setup**: Same process as onboarding (name, nicknames, photo, conditions)
- **Automatic Setup**: New children get default behavior goals and settings
- **Village Management**: Each child has their own separate village

**Modifying Existing Children**:

- **Child Information**: Update name, preferred name, nicknames
- **Birth Date**: Add or modify date of birth
- **Photo**: Change or add child's photo
- **Conditions**: Update diagnostic information or add new conditions
- **Profile Picture**: Appears in child picker at top of app

**Deleting a Child**:

⚠️ **Permanent Action**: Deletes ALL data for the child including:

- All journal entries from all village members
- All analysis data and insights
- All medication information
- All village member associations
- Cannot be undone

**Deletion Process**:

1. Select "Delete Child" option
2. Read warning about permanent data loss
3. Type "delete" in confirmation field
4. Confirm deletion

### Join Another Village
- **For Existing Users**: If you already have a VillageMetrics account and want to join someone else's child's village
- **Requires Invitation Code**: Must have valid invitation code from child's parent
- **Same as Caregiver Signup**: Uses same process as new caregiver onboarding

## Child's Profile Section

*Settings in this section apply to currently selected child (shown in child picker at top)*

### Caregivers Management

**View All Caregivers**:

- **Active Caregivers**: Accepted invitations with full access
- **Pending Invitations**: Sent but not yet accepted
- **Expired Invitations**: Not accepted within time limit (approximately 30 days)

**Caregiver Information Displayed**:

- Name and email address
- Caregiver type (parent, family, therapist, etc.)
- Current permissions (which access types they have)
- Journal entry count (total contributions)
- Status and action options

**Managing Individual Caregivers**:

- **✏️ Edit Icon**: Change permissions, caregiver type, or contact information
- **✈️ Resend Icon**: Send new invitation if expired or not received
- **Delete Option**: Remove caregiver from village (their contributed data remains)

**Invitation Status Management**:

- **Pending**: Show resend option, can delete invitation
- **Expired**: Option to send fresh invitation with new expiration
- **Active**: Edit permissions, cannot delete invitation (must remove caregiver)

### Medication Management

**Current Medications**:

- Medications without end dates (child still taking)
- Full dosage information (AM/Midday/PM)
- Edit dosages, change timing, or discontinue

**Past Medications**:

- Historical medications with end dates
- View complete medication history
- Edit historical information if needed

**Adding Medications**:

- Search medication database for auto-completion
- Manual entry with classification selection
- Date range configuration
- Flexible dosing schedule setup

**Medication Privacy**: Only parents can add/edit medications. Caregivers with medical data permission can view but not modify.

## Settings Section

### Push Notification Settings

**Notification Types**:

- **Daily Reminders**: Evening prompts to record journal entries
- **Activity Notifications**: When village members add entries about your child

**Per-Child Configuration**:

- **Child Selection**: Use child picker to select which child's notifications to configure
- **Individual Settings**: Each child can have different notification preferences
- **Activity Notifications**: Choose between enriched, generic, or disabled

**Enriched Activity Notifications**:

- **Content**: Includes child's name and behavioral summary in push notification
- **HIPAA Consent Required**: Must acknowledge PHI will appear on lock screen
- **Multi-Device Sync**: May appear on other devices connected to your account

**Generic Activity Notifications**:

- **Content**: Simple "You have an update available" message
- **Privacy-Safe**: No PHI exposure in notification
- **Requires App Opening**: Must open app to see details

### Email Settings

**Email Types**:

- **Enriched Emails**: May include child's name and protected health information
- **Generic Emails**: No PHI, general app updates only
- **No Emails**: Opt out of all email communications

**Current Status**: Email functionality is being developed. Preferences are saved for future use.

**Global Setting**: Email preferences apply to all children in your account (unlike notifications which are per-child).

### Data Sharing Settings

#### Community Insights
**Purpose**: Anonymous contribution to help other families understand what works for children with similar profiles

**What's Shared** (All Anonymous):

- Age ranges and diagnostic conditions
- Behavior score trends and patterns
- Activity and intervention effectiveness
- Medication outcomes (no specific medication names)

**What's NEVER Shared**:

- Names or identifying information
- Specific journal entry content
- Contact information or location data
- Any identifiable personal details

**Consent**: "I agree to anonymously contribute to community insights that may help other families."

#### Quality Improvement Consent
**Purpose**: Allow VillageMetrics team to review your data to improve AI accuracy and app functionality

**What May Be Reviewed**:

- Journal entries (with AI redaction of identifying details)
- Ask Anything chat interactions
- Analysis accuracy and results
- Medication tracking effectiveness

**Privacy Protections**:

- HIPAA-compliant review process
- Anonymous ID system (no usernames visible)
- AI redaction removes identifying information
- Voluntary participation, revocable anytime

#### Data Export Access
- **Personal Export Consent**: Permission for you to export your own data via PDF/CSV
- **Consent Acknowledgment**: Understanding that exported data leaves HIPAA-protected environment
- **One-Time Setting**: Consent saved after first export, doesn't ask repeatedly

#### Clipboard Data Access
- **Personal Clipboard**: Your permission to copy VillageMetrics content to device clipboard
- **Risk Acknowledgment**: Clipboard may sync to other apps/services that aren't HIPAA compliant

#### Caregiver Clipboard Access
- **Village Permission**: Whether caregivers can copy content to their clipboards
- **Multi-Parent Requirement**: Both parents must consent if there are two parents
- **Use Case**: Allows therapists to copy notes to their own systems
- **Revocable**: Either parent can disable for all caregivers

### Delete My Data

**Self-Service Account Deletion**: You can completely remove your VillageMetrics account and all associated data on your own through the app.

**How to Delete Your Account**:

**If Your Subscription/Trial is Active**:

1. **Open Settings**: Tap the gear icon in the upper right corner of any screen in the app
2. **Navigate to Delete Option**: In the Settings screen, find and tap "Delete My Data"  
3. **Follow the Confirmation Process**: Read the warning and type the required confirmation phrase
4. **Complete Deletion**: Your account and data will be permanently removed

**If Your Subscription Has Expired**: You cannot access the Settings menu when your subscription expires, so the self-service deletion option is unavailable. To delete your account:

1. **Email Support**: Contact hello@villagemetrics.com using the same email address associated with your VillageMetrics account
2. **Request Account Deletion**: Specify that you want your account and all data permanently deleted
3. **Identity Verification**: Our team will verify your identity and only delete the account associated with the email address you're sending from
4. **Complete Removal**: All your data and account information will be permanently deleted

**What Gets Deleted**:

- Your user account and login credentials
- ALL children you created as a parent (if applicable)
- ALL data for those children from ALL village members (if applicable)

**What Does NOT Get Deleted**:

- Your caregiver contributions to other families remain preserved (those journal entries are owned by the parents of those children)

**Confirmation Requirements**:

- **Parents**: Must type "PERMANENTLY DELETE EVERYTHING" to confirm
- **Caregivers**: Must type "DELETE" to confirm  
- **Cannot Be Undone**: No recovery possible after deletion

### Subscription Management

- **Current Status**: Shows active subscription or free trial status
- **Renewal Date**: When next billing cycle begins
- **Restore Purchases**: Recover subscription after device change or app reinstall
- **Subscription History**: View past billing and renewal information

**Family Coverage**: One subscription covers unlimited children and unlimited caregivers

#### Subscription Cancellation & Data Retention

**How VillageMetrics Billing Works**:

- **Free Trial**: 4 weeks of full access to all features
- **Automatic Renewal**: After trial ends, automatically converts to annual subscription
- **Cancellation Policy**: Cancel anytime during your subscription period
- **No Refunds**: Cancelling doesn't provide refunds for time remaining in your billing period
- **Continued Access**: You can continue using all features until your current subscription period ends

**What Happens After Your Subscription Expires**:

**Your Data is Safe**: VillageMetrics does NOT delete your data when your subscription ends or expires. All of your journal entries, analysis insights, medication tracking, and child profiles remain securely stored in your account.

**Why We Preserve Your Data**:

- You can return anytime and have immediate access to all your historical data
- Your child's behavioral patterns and insights remain available if you resubscribe
- No loss of valuable tracking information due to billing changes
- Peace of mind that temporary subscription lapses won't erase your family's data

**If You Want Your Data Deleted**:

**Before Your Subscription Expires**: Use the self-service deletion option. Simply tap the gear icon in the upper right corner, then select "Delete My Data" in Settings. This completely removes your account and all data immediately.

**After Your Subscription Expires**: Once your subscription expires, you lose access to the app's Settings menu and cannot use the self-service deletion option. If you want your account and data completely removed after expiration:

1. **Contact Support**: Email hello@villagemetrics.com
2. **Request Deletion**: Ask for complete account deletion in your message
3. **Confirmation Process**: Our team will verify your identity and process the deletion
4. **Complete Removal**: All your data, child profiles, and account information will be permanently deleted

**Important Notes**:

- Data deletion is permanent and cannot be undone
- Consider exporting your data before requesting deletion if you want to keep records
- You can always resubscribe to regain access instead of deleting your account

## Support and Policy Section

### Help and Support
- **Contact Information**: hello@villagemetrics.com for technical issues or questions
- **Response Time**: Typically 24-48 hours for email support
- **What to Include**: Specific error messages, screenshots if helpful, description of issue

### Privacy Policy and Terms of Service
- **Easy Access**: View current privacy policy and terms of service within app
- **Legal Information**: Complete legal language governing app use and data protection
- **Updates**: Notified when policies change

### Log Out
- **Account Sign-Out**: Removes authentication token from device
- **Data Preserved**: All data remains in VillageMetrics (nothing deleted)
- **Re-Login**: Use same email address to sign back in

**Device Security**: Always log out when using shared devices

## Privacy Best Practices

### Understanding HIPAA Protection
- **Within VillageMetrics**: All data protected by HIPAA compliance measures
- **Outside VillageMetrics**: Protection cannot be guaranteed once data is exported/shared
- **Your Control**: You decide what data to export and share

### Consent Management
- **Informed Decisions**: Read all consent language carefully before agreeing
- **Regular Review**: Periodically review your data sharing settings
- **Revocable Permissions**: Most consents can be withdrawn in Settings
- **Multi-Parent Coordination**: Communicate with your partner about shared consent decisions

### Security Recommendations
- **Strong Email Security**: Use secure email account for VillageMetrics login
- **Device Security**: Use device lock screen protection
- **Shared Devices**: Always log out when using family or public devices
- **Caregiver Training**: Educate village members about privacy responsibilities

---

Settings and privacy controls in VillageMetrics are designed to give you maximum control over your family's data while enabling the collaborative features that make the app most effective for your child's care team.