Security & Privacy

How RecPlan protects your data and respects your residents\' privacy.

Authentication

All user accounts require email verification and password authentication. Passwords are never stored in plain text. Optional two-factor authentication is available for admin accounts.

Role-Based Permissions

Every user is assigned a role that determines what they can see, create, edit, and delete. Permissions are enforced at the data level — users only access information their role allows.

Organization Access

Each organization's data is isolated. Users can only access data within their own organization. Cross-organization access is never granted, even to platform administrators.

Privacy Controls

Resident and client profiles include granular consent management for photography, data sharing, and family portal access. Consent status is tracked and visible to authorized staff.

Consent Management

Consent is recorded per field with who gave consent, when, and any limitations. Staff can see consent status before sharing information or creating display materials.

Data Handling

All data is stored on secure, encrypted servers. Data is never sold, shared with third parties, or used for advertising. You own your data and can export it at any time.

AI Review and Approval

All AI-generated content is labeled "Generated by AI" and requires human review and approval before use. AI never makes permanent changes to resident records without explicit human approval.

User Responsibilities

Organizations are responsible for managing user access, removing access when staff leave, and ensuring consent is properly obtained before entering resident information.

For specific questions about security, privacy, or compliance, please contact our team. We're committed to transparency about how we protect your data.