Security & consent
Biometric consent for adult day care, in plain English
Face templates and member photos are protected health information. Here is exactly what we do with them, what a family can control, and what never changes — no matter what.
Four things that never change
We are a HIPAA Business Associate
Face templates and member photos are protected health information. We sign a Business Associate Agreement (BAA) with every center before any biometric or member data is captured — this is a precondition, not an add-on.
A guardian or authorized representative can sign consent
Many members are cognitively impaired and cannot sign for themselves. Consent for facial recognition is a standalone, unbundled record — never buried in an intake packet — that names the purpose, the retention period, and the destruction schedule. Every consent record captures who signed and their relationship to the member.
- Always available
A non-biometric path always exists
Refusing facial-recognition consent never blocks a member from receiving service — not once, not ever. Staff photo-confirm the member and capture a signature instead. Same locked record, same evidence packet, no face match required. This is a permanent second path, not a fallback we hope nobody needs.
Biometric data is erasable. The attendance record is not.
A face profile — the embedding used for matching — can be deleted on request or automatically at disenrollment. The attendance record it helped produce is different: it's append-only by design, because a record that can quietly be edited isn't evidence. Two different retention promises, on purpose — biometric data and attendance records retention are not the same clock.
On-device matching
Matching happens on the device, not on our servers
The comparison photo taken at check-in is matched against a member's enrolled face profile directly on the device at your front desk, using an established open-source, on-device computer-vision engine. We do not run biometric matching as a service in our own data centers.
What leaves the device and reaches our servers is the resulting numeric embedding — not the raw matching process itself — stored alongside the signed consent record.
Data handling
What we store, and what you control
| Data | What we store | What you can control |
|---|---|---|
| Enrollment photomember_face_profiles.enrollment_photo_url | Stored, tied to the member's consent record. | Deletable on request, or automatically at disenrollment. |
| Face embeddingmember_face_profiles.embedding | Stored; used only for on-device matching at future check-ins. | Deletable on request, or automatically at disenrollment. |
| Consent recordconsent_obtained · consent_signed_by_name · consent_signer_relationship | Who signed, their relationship to the member, and when — stored alongside the face profile. | Retained per the destruction schedule named at signing. |
| Check-in / check-out photo | Stored as part of that day's attendance event. | Not editable or deletable — it's part of the locked record. |
| Signature | Stored as part of that day's attendance event. | Not editable or deletable — it's part of the locked record. |
| Attendance eventattendance_events (append-only) | Timestamp, method, and outcome — appended, never overwritten. | No update or delete path exists, for anyone, including us. |
Statutes we design against
Facial recognition triggers biometric-privacy law in several states — worth knowing before an adult day care center enrolls a member. We don't tell you that using AdultDayGenie makes your center compliant with any of them — compliance depends on your own policies, your consent process, and your state. Here is what we build toward.
- In force
Illinois BIPA
Requires written consent, a public retention and destruction policy, and creates a private right of action for individuals.
- New law eff. Jan 2026
Texas CUBI + new TX biometric law
Capture and Use of Biometric Identifier Act, plus a new Texas biometric statute taking effect January 2026.
- In force
Washington My Health My Data
Requires affirmative, purpose-specific consent for consumer health data, plus a right to deletion.
- Amended Jul 2025
Colorado Privacy Act
Updated biometric-data provisions under Colorado's privacy law.
- Eff. Oct 2026
Maryland
New biometric-data requirements taking effect in Maryland.
This page describes how our product is designed. It is not legal advice, and using AdultDayGenie does not, by itself, make your center compliant with any law listed here. Talk to your own counsel about what your center needs.
Consent & data — frequently asked
No single product can promise that. We design our consent and retention flow around what these laws generally require — written, purpose-specific consent; a named retention and destruction schedule; and the ability to delete biometric data on request. Whether your center is compliant depends on your own policies and how you use the tool. This isn't legal advice.
Nothing changes for the member. Staff check them in with a photo confirmation and a signature instead — the same locked, exportable record, just without a face match.
The member, if they're able. If not, a legal guardian or another authorized representative can sign on their behalf. We record who signed and their relationship to the member.
Yes — on request, or automatically when a member is disenrolled. Deleting the face profile does not delete the attendance record it helped create; that stays locked, the same as any other day's evidence.
A member's face profile is kept only while it's in active use for check-in matching, per the retention period named at signing. It's deleted on request or automatically at disenrollment — whichever comes first. That's a separate clock from attendance records retention: the attendance events a face match helped create stay locked and append-only, independent of whether the face profile behind them still exists.
Yes, with every center, before any member data is captured.
Consent-first, by design
See how the four steps work, from signed consent to locked record.