Security & consent

Biometric consent for adult day care, in plain English

Face templates and member photos are protected health information. Here is exactly what we do with them, what a family can control, and what never changes — no matter what.

HIPAA Business AssociateGuardian can sign consentNon-biometric path always existsBiometrics are erasable

Four things that never change

  • We are a HIPAA Business Associate

    Face templates and member photos are protected health information. We sign a Business Associate Agreement (BAA) with every center before any biometric or member data is captured — this is a precondition, not an add-on.

  • A guardian or authorized representative can sign consent

    Many members are cognitively impaired and cannot sign for themselves. Consent for facial recognition is a standalone, unbundled record — never buried in an intake packet — that names the purpose, the retention period, and the destruction schedule. Every consent record captures who signed and their relationship to the member.

  • A non-biometric path always exists

    Refusing facial-recognition consent never blocks a member from receiving service — not once, not ever. Staff photo-confirm the member and capture a signature instead. Same locked record, same evidence packet, no face match required. This is a permanent second path, not a fallback we hope nobody needs.

    Always available
  • Biometric data is erasable. The attendance record is not.

    A face profile — the embedding used for matching — can be deleted on request or automatically at disenrollment. The attendance record it helped produce is different: it's append-only by design, because a record that can quietly be edited isn't evidence. Two different retention promises, on purpose — biometric data and attendance records retention are not the same clock.

On-device matching

Matching happens on the device, not on our servers

The comparison photo taken at check-in is matched against a member's enrolled face profile directly on the device at your front desk, using an established open-source, on-device computer-vision engine. We do not run biometric matching as a service in our own data centers.

What leaves the device and reaches our servers is the resulting numeric embedding — not the raw matching process itself — stored alongside the signed consent record.

On-deviceEmbedding stored, not raw processing

Data handling

What we store, and what you control

DataWhat we storeWhat you can control
Enrollment photomember_face_profiles.enrollment_photo_urlStored, tied to the member's consent record.Deletable on request, or automatically at disenrollment.
Face embeddingmember_face_profiles.embeddingStored; used only for on-device matching at future check-ins.Deletable on request, or automatically at disenrollment.
Consent recordconsent_obtained · consent_signed_by_name · consent_signer_relationshipWho signed, their relationship to the member, and when — stored alongside the face profile.Retained per the destruction schedule named at signing.
Check-in / check-out photoStored as part of that day's attendance event.Not editable or deletable — it's part of the locked record.
SignatureStored as part of that day's attendance event.Not editable or deletable — it's part of the locked record.
Attendance eventattendance_events (append-only)Timestamp, method, and outcome — appended, never overwritten.No update or delete path exists, for anyone, including us.

Statutes we design against

Facial recognition triggers biometric-privacy law in several states — worth knowing before an adult day care center enrolls a member. We don't tell you that using AdultDayGenie makes your center compliant with any of them — compliance depends on your own policies, your consent process, and your state. Here is what we build toward.

  • Illinois BIPA

    Requires written consent, a public retention and destruction policy, and creates a private right of action for individuals.

    In force
  • Texas CUBI + new TX biometric law

    Capture and Use of Biometric Identifier Act, plus a new Texas biometric statute taking effect January 2026.

    New law eff. Jan 2026
  • Washington My Health My Data

    Requires affirmative, purpose-specific consent for consumer health data, plus a right to deletion.

    In force
  • Colorado Privacy Act

    Updated biometric-data provisions under Colorado's privacy law.

    Amended Jul 2025
  • Maryland

    New biometric-data requirements taking effect in Maryland.

    Eff. Oct 2026

This page describes how our product is designed. It is not legal advice, and using AdultDayGenie does not, by itself, make your center compliant with any law listed here. Talk to your own counsel about what your center needs.

Questions

Consent & data — frequently asked

No single product can promise that. We design our consent and retention flow around what these laws generally require — written, purpose-specific consent; a named retention and destruction schedule; and the ability to delete biometric data on request. Whether your center is compliant depends on your own policies and how you use the tool. This isn't legal advice.

Nothing changes for the member. Staff check them in with a photo confirmation and a signature instead — the same locked, exportable record, just without a face match.

The member, if they're able. If not, a legal guardian or another authorized representative can sign on their behalf. We record who signed and their relationship to the member.

Yes — on request, or automatically when a member is disenrolled. Deleting the face profile does not delete the attendance record it helped create; that stays locked, the same as any other day's evidence.

A member's face profile is kept only while it's in active use for check-in matching, per the retention period named at signing. It's deleted on request or automatically at disenrollment — whichever comes first. That's a separate clock from attendance records retention: the attendance events a face match helped create stay locked and append-only, independent of whether the face profile behind them still exists.

Yes, with every center, before any member data is captured.

Consent-first, by design

See how the four steps work, from signed consent to locked record.