Security & Data Processors

Last Reviewed: June 17, 2026

ResourceCareConnect is built to handle some of the most sensitive information a family can have — records about children in foster and kinship care. This page describes how we protect that information and which categories of third-party services we use to operate the platform.

Security Practices

Encryption in Transit — All communication between your device and our servers is encrypted using TLS 1.2 or higher (HTTPS). Data is never transmitted in plain text.

Encryption at Rest — Your data — including all records, observations, uploaded documents, and photos — is encrypted at rest in our database and file storage systems. Encryption keys are managed separately from the data they protect.

Access Controls — Your data is strictly scoped to your household. No other user or household can access your records. Our API enforces household-level isolation on every request, and all data access requires an authenticated session.

Secure File Storage — Uploaded files — including photos, placement documents, and certificates — are stored in an encrypted object storage service. Files are never publicly accessible. Access requires a time-limited signed URL that expires after a short period.

Session Security — User sessions are managed server-side using encrypted session tokens. Sessions expire after a period of inactivity and are invalidated immediately on sign-out.

Audit Logging — Significant actions within your account — including record creation, document uploads, report generation, and account changes — are logged with timestamps and user identifiers for transparency and accountability.

AI Feature Data Handling — AI-assisted features fall into two categories. For text and voice processing (tone coaching, quick capture, voice note structuring): children's registered names from your household are replaced with generic identifiers (e.g. "Child 1") server-side before any text is transmitted to an AI provider. Only names registered in your household child profiles are automatically replaced — other content in the note such as case numbers, provider names, or medical identifiers is transmitted as entered. For document scanning features (appointment cards, certification documents, training certificates, placement documents): the document image or extracted document text is sent to an AI provider for field extraction — these transmissions may include names, dates, and document identifiers visible in the uploaded document, as that information is required for the feature to function. AI providers are contractually prohibited from training their models on your data. AI features can be disabled entirely in Account Settings.

Third-Party Data Processors

Category Purpose Data Accessed
Payment Processing Securely handling subscription payments and billing Payment card data (not stored by us), billing email, subscription status
File & Document Storage Storing uploaded photos, documents, signatures, and generated PDFs Uploaded files, encrypted at rest
Transactional Email Sending account confirmations, password resets, and notifications Your email address and name
AI Text & Voice Processing Powering optional tone coaching, quick capture, and voice note structuring features Text with child names replaced — registered household child names are substituted with generic identifiers (e.g. "Child 1") server-side before transmission; other content in the note (such as case numbers or provider names) is transmitted as entered
AI Document Scanning Powering optional appointment card, certification, training certificate, and placement document scanning features Document images (for image files) or extracted document text (for PDFs/Word files) — may include names, dates, and document identifiers visible in the uploaded document

We do not use advertising networks, social media trackers, or data brokers. We do not share your data with DHS, courts, or government agencies unless required by law. This list is reviewed and updated regularly.

Breach Notification Commitment

In the event of a data breach affecting your personal information, we commit to: beginning internal assessment within 72 hours of discovery; notifying affected users by email within 30 days of confirmed breach; complying with Oregon's data breach notification requirements under ORS 646A.600–646A.628, including notifying the Oregon Attorney General when required.

Reporting a Security Issue

If you discover a security vulnerability in ResourceCareConnect, please report it responsibly by emailing support@resourcecareconnect.app. Please do not publicly disclose security issues before we have had a reasonable opportunity to address them. We take all reports seriously and respond promptly.