Pendlark early family beta
Terms of Service
These terms describe the current scope and limits of the Pendlark family beta.
What Pendlark is
Pendlark is an administrative support and organization tool for families. It is not medical or legal advice, a diagnosis, a treatment recommendation, or a substitute for a qualified professional. Parents and guardians remain the final decision makers for their families.
Listings and program information
Provider listings are organizational leads only. A listing does not guarantee availability, new-patient status, insurance participation, suitability, accuracy, or quality. Program and waiver matches do not guarantee eligibility, acceptance, funding, or an outcome. Confirm details directly with the relevant provider or program before relying on them.
Autopilot, beta changes, and availability
Pendlark may present organizational suggestions and workflow support. Material Autopilot actions may require parent approval; no parent should assume that a message, match, or workflow step has been completed unless the product explicitly confirms it. Beta behavior, features, and availability may change, be interrupted, or be withdrawn as the service is tested.
Accounts and subscriptions
You are responsible for the accuracy of information you provide and for protecting your account credentials. In the current implementation, subscription and grant state is application-owned sandbox/test state and live billing is not enabled by default. Where the platform enables hosted recurring billing, checkout and subscription management use the hosted billing portal; Pendlark does not expose a direct cancellation or non-renewal API. An account deletion request is not reported complete while an active recurring subscription remains unresolved.
Deletion and retained records
Account deletion requires current-password verification and an exact confirmation phrase. Pendlark deletes or revokes family-scoped content in an ordered workflow, stops on critical failures, and may retain minimal detached records for payment or accounting, security or fraud, audit, disputes, support history, or recovery. The retention matrix below is the current owner-reviewable beta policy; it does not invent a fixed legal duration.
| Data class | Deleted immediately | Retained minimally | Reason | Anonymized/detached |
|---|---|---|---|---|
| Auth user, credential account, sessions | Delete after verified cleanup | None in the active account | No active sign-in after completion; Better Auth owns final removal. | Recovery evidence is detached after completion. |
| Support Profile, child/family support-needs, onboarding | Yes | None | Active family profile content is removed. | No user link retained. |
| Calendar events, exceptions, reminders | Yes | None | Family-specific organization state is removed. | Not retained. |
| Care Queue/saved-provider relationships | Yes | Shared provider catalog remains. | The family relationship is removed without deleting shared providers. | No user link retained. |
| Supported upload objects and document metadata/proposals | Yes, including R2 object keys | None after successful object deletion | Family content and storage exposure are removed; cleanup stops safely on failure. | No storage URL or key is returned to the user. |
| User-scoped provider diagnostics | Yes | Only an explicitly approved detached aggregate, if later adopted | Family search criteria must not remain attached to the user. | Current beta deletes the user-scoped rows. |
| Feedback/support content | Yes unless an owner-approved minimal support-history rule exists | None under the current beta rule | Reports may contain sensitive family content. | Current beta deletes the user-owned issue and its actions. |
| Subscription grants/local entitlement | Revoke/delete after billing resolution | None in the active account | Access must not continue after deletion. | Billing evidence is detached where practical. |
| Payment/accounting event evidence | No | No fixed period set; owner review required | Only minimal detached evidence may remain for accounting/payment review when owner-approved. | Customer email and direct customer linkage are removed where practical. |
| Security/fraud/audit/dispute/deletion recovery record | No | No fixed period set; owner review required | Explain the outcome, resolve disputes, and recover critical failures. | Detached after successful completion where practical. |
| Shared provider catalog and unrelated family rows | No | Preserved | Product data and strict family isolation must remain intact. | Never attached to the deleted family by cleanup. |
Auth user, credential account, sessions
- Deleted immediately
- Delete after verified cleanup
- Retained minimally
- None in the active account
- Reason
- No active sign-in after completion; Better Auth owns final removal.
- Anonymized/detached
- Recovery evidence is detached after completion.
Support Profile, child/family support-needs, onboarding
- Deleted immediately
- Yes
- Retained minimally
- None
- Reason
- Active family profile content is removed.
- Anonymized/detached
- No user link retained.
Calendar events, exceptions, reminders
- Deleted immediately
- Yes
- Retained minimally
- None
- Reason
- Family-specific organization state is removed.
- Anonymized/detached
- Not retained.
Care Queue/saved-provider relationships
- Deleted immediately
- Yes
- Retained minimally
- Shared provider catalog remains.
- Reason
- The family relationship is removed without deleting shared providers.
- Anonymized/detached
- No user link retained.
Supported upload objects and document metadata/proposals
- Deleted immediately
- Yes, including R2 object keys
- Retained minimally
- None after successful object deletion
- Reason
- Family content and storage exposure are removed; cleanup stops safely on failure.
- Anonymized/detached
- No storage URL or key is returned to the user.
User-scoped provider diagnostics
- Deleted immediately
- Yes
- Retained minimally
- Only an explicitly approved detached aggregate, if later adopted
- Reason
- Family search criteria must not remain attached to the user.
- Anonymized/detached
- Current beta deletes the user-scoped rows.
Feedback/support content
- Deleted immediately
- Yes unless an owner-approved minimal support-history rule exists
- Retained minimally
- None under the current beta rule
- Reason
- Reports may contain sensitive family content.
- Anonymized/detached
- Current beta deletes the user-owned issue and its actions.
Subscription grants/local entitlement
- Deleted immediately
- Revoke/delete after billing resolution
- Retained minimally
- None in the active account
- Reason
- Access must not continue after deletion.
- Anonymized/detached
- Billing evidence is detached where practical.
Payment/accounting event evidence
- Deleted immediately
- No
- Retained minimally
- No fixed period set; owner review required
- Reason
- Only minimal detached evidence may remain for accounting/payment review when owner-approved.
- Anonymized/detached
- Customer email and direct customer linkage are removed where practical.
Security/fraud/audit/dispute/deletion recovery record
- Deleted immediately
- No
- Retained minimally
- No fixed period set; owner review required
- Reason
- Explain the outcome, resolve disputes, and recover critical failures.
- Anonymized/detached
- Detached after successful completion where practical.
Shared provider catalog and unrelated family rows
- Deleted immediately
- No
- Retained minimally
- Preserved
- Reason
- Product data and strict family isolation must remain intact.
- Anonymized/detached
- Never attached to the deleted family by cleanup.
Beta status
Pendlark is provided as an early family beta. The service is offered for administrative organization and testing, not as a promise of professional, medical, legal, eligibility, provider, or program results.