Pendlark early family beta

Privacy Policy

This plain-language policy explains what Pendlark handles while families test the product and what happens when an account deletion is requested.

Information you choose to provide

Pendlark may receive voluntarily provided account information such as your name, email address, and authentication details. If you choose to use them, this also includes your Support Profile, family and child support-needs information, consent choices, Family Care Calendar entries, Care Queue and saved-provider information, supported uploads and their document metadata, and feedback or support reports.

Technical and diagnostic information may be generated when the service runs, including bounded provider-search diagnostics, error details, device or request context, and security records needed to operate the product. Please do not upload information that you do not want Pendlark to handle.

How Pendlark uses information

We use information to operate Pendlark, provide the family organization features you request, secure accounts, troubleshoot failures, support users, and improve the beta. Necessary infrastructure and service providers may process information for those functions under their service boundaries.

Pendlark does not sell sensitive family information to advertisers. Access to account and family information is controlled through authentication and authorization. Shared provider catalog data and unrelated family records are kept separate from your account.

Your choices and deletion requests

You may request deletion from Account Settings. Pendlark verifies the signed-in account and current password, requires an explicit confirmation, resolves any recurring billing question before destructive work, and removes family content in an ownership-scoped sequence. Critical failures stop the process and create a recoverable Admin state rather than claiming completion.

A small amount of information may remain for payment or accounting, security or fraud prevention, audit, disputes, or support history. Where practical, retained records are anonymized or detached from the active family profile. No fixed legal retention period is stated here; unverified durations remain owner-reviewable.

Beta boundaries

Pendlark is an early beta and may change as the product is tested. Pendlark does not claim HIPAA compliance, a certification, or another regulatory certification in this policy.

Retention matrix

The current beta treatment is summarized below. “No fixed period set; owner review required” is intentionally not a statutory duration.

Auth user, credential account, sessions

Deleted immediately
Delete after verified cleanup
Retained minimally
None in the active account
Reason
No active sign-in after completion; Better Auth owns final removal.
Anonymized/detached
Recovery evidence is detached after completion.

Support Profile, child/family support-needs, onboarding

Deleted immediately
Yes
Retained minimally
None
Reason
Active family profile content is removed.
Anonymized/detached
No user link retained.

Calendar events, exceptions, reminders

Deleted immediately
Yes
Retained minimally
None
Reason
Family-specific organization state is removed.
Anonymized/detached
Not retained.

Care Queue/saved-provider relationships

Deleted immediately
Yes
Retained minimally
Shared provider catalog remains.
Reason
The family relationship is removed without deleting shared providers.
Anonymized/detached
No user link retained.

Supported upload objects and document metadata/proposals

Deleted immediately
Yes, including R2 object keys
Retained minimally
None after successful object deletion
Reason
Family content and storage exposure are removed; cleanup stops safely on failure.
Anonymized/detached
No storage URL or key is returned to the user.

User-scoped provider diagnostics

Deleted immediately
Yes
Retained minimally
Only an explicitly approved detached aggregate, if later adopted
Reason
Family search criteria must not remain attached to the user.
Anonymized/detached
Current beta deletes the user-scoped rows.

Feedback/support content

Deleted immediately
Yes unless an owner-approved minimal support-history rule exists
Retained minimally
None under the current beta rule
Reason
Reports may contain sensitive family content.
Anonymized/detached
Current beta deletes the user-owned issue and its actions.

Subscription grants/local entitlement

Deleted immediately
Revoke/delete after billing resolution
Retained minimally
None in the active account
Reason
Access must not continue after deletion.
Anonymized/detached
Billing evidence is detached where practical.

Payment/accounting event evidence

Deleted immediately
No
Retained minimally
No fixed period set; owner review required
Reason
Only minimal detached evidence may remain for accounting/payment review when owner-approved.
Anonymized/detached
Customer email and direct customer linkage are removed where practical.

Security/fraud/audit/dispute/deletion recovery record

Deleted immediately
No
Retained minimally
No fixed period set; owner review required
Reason
Explain the outcome, resolve disputes, and recover critical failures.
Anonymized/detached
Detached after successful completion where practical.

Shared provider catalog and unrelated family rows

Deleted immediately
No
Retained minimally
Preserved
Reason
Product data and strict family isolation must remain intact.
Anonymized/detached
Never attached to the deleted family by cleanup.