This Privacy Policy describes how Chemmo Holdings, LLC ("we," "us," or "Chemmo Holdings") collects, uses, and shares information when you use Bedside (the "App"). Bedside is an iPhone application that lets a person notify a chosen circle of contacts with an urgent alert when it is time to come to the bedside of a loved one in hospice or critical illness.
If you do not agree with this Policy, please do not use the App.
The App has two user types and this policy applies to both:
A single user can be both a Sender and a Receiver across different circles (for example, a Sender for their own parent's circle, and a Receiver in a sibling's circle).
This policy also addresses how we handle the contact information of Receivers, whose phone numbers, email addresses, and names are added to the App by Senders in order to send them notifications.
Bedside is deliberately scoped to circle membership and the alert event itself. We do not collect any of the following:
We use the information described above for the following purposes only:
We do not sell your information. We do not share your information with advertisers. We do not use your information for cross-app or cross-website behavioral tracking.
We do not embed any third-party analytics or crash-reporting SDK in Bedside. There is no Mixpanel, no Firebase Analytics, no Google Analytics, no Amplitude, no Segment, no Sentry, and no Crashlytics. Server-side error logs from our Cloud Functions are retained only as long as needed to diagnose technical issues and never linked to advertising or marketing systems.
The App relies on the following service providers, each of which receives the minimum information required to perform its function. Their handling of that information is governed by their own privacy policies, linked below.
| Provider | Purpose | Information shared | Privacy policy |
|---|---|---|---|
| Google Firebase (Authentication, Firestore, Cloud Functions) | Backend account management, data storage, server-side alert dispatch | Account information, circle data, alert event timestamps | firebase.google.com/support/privacy |
| Twilio | SMS notification delivery | Receiver phone numbers, the brief message text | twilio.com/legal/privacy |
| SendGrid (a Twilio company) | Email notification delivery | Receiver email addresses, the brief message text | twilio.com/legal/privacy |
| RevenueCat | In-app purchase entitlement management | Anonymous Apple-provided purchase identifier, your Firebase user ID | revenuecat.com/privacy |
| Apple (App Store, Push Notification Service) | App distribution, purchase processing, push delivery | Purchase records (processed by Apple, not us), push device tokens | apple.com/legal/privacy |
When you (a Sender) add someone as a Receiver, you are confirming that you have a legitimate basis to share their contact information with us for the purpose of contacting them on your behalf during a vigil. We store their name, phone number, and email only for as long as they remain in your circle. When you remove them, we delete their information.
Receivers who get notifications from us via Twilio (SMS) may reply STOP to opt out of future SMS messages from Bedside at any time, in accordance with U.S. carrier rules. Receivers who get email notifications via SendGrid will see an unsubscribe link in each transactional message; opting out applies to all future Bedside emails to that address.
For full details on how text-message consent works, including the in-app opt-in workflow, sample messages, and the STOP, START, and HELP keywords, see our SMS / Text Message Notifications page.
We keep your account information and associated data for as long as your account is active. When you delete your account (see Section 9), we delete your account record and associated profile, circle, vigil event timestamps, and push tokens from our systems within thirty (30) days, except where we are required to retain certain records for legal or accounting compliance.
SMS and email delivery logs maintained by Twilio and SendGrid are retained by those providers according to their own policies (typically 30 to 90 days).
Information transmitted between the App and our backend is encrypted in transit using HTTPS/TLS. Information at rest in Firebase is encrypted by Google's infrastructure. We follow industry-standard practices to protect against unauthorized access, but no system is perfectly secure; we cannot guarantee the security of information stored on or transmitted between our systems.
The App is not directed to children under 18 and we do not knowingly collect information from children under 18. If you believe a child has provided us with information, please contact us at the address below and we will delete it.
Bedside is a personal-notification tool used by individuals and their chosen contacts. It is not a medical device, electronic health record, or healthcare communication system. Chemmo Holdings, LLC is not a HIPAA Covered Entity and does not act as a Business Associate to any healthcare provider. We do not enter Business Associate Agreements.
We do not collect, process, or store Protected Health Information (PHI) as defined by HIPAA. The App's user interface deliberately avoids fields for diagnosis, prognosis, agency name, medications, or any clinical detail. If you choose to type clinical information into a freeform alert message, that information is transmitted to your Receivers as written, and we treat it as sensitive but it remains outside any HIPAA-regulated workflow.
You have the right to access, correct, export, or delete your personal information.
In-app deletion (fastest path): Open the App, go to Settings → Delete Account, and confirm. This invokes our account-deletion Cloud Function, which removes your user profile, circle, vigil event history, push tokens, and Firebase Authentication record. Deletion is irreversible.
Without the App: Follow the instructions at chemmoholdings.com/bedside/delete-account. For all other requests, contact us using the information in Section 13.
What survives deletion: Apple retains your purchase receipt regardless of whether you delete your Bedside account; that is how Restore Purchase works on a new account. Twilio retains message-delivery logs for its own carrier-compliance obligations. We have no control over those records.
Depending on where you live, you may have additional rights under laws such as the General Data Protection Regulation (GDPR), the California Consumer Privacy Act (CCPA), or similar laws. These rights typically include the right to know, the right to request correction or deletion, the right to object to or restrict certain processing, the right to data portability, and the right to lodge a complaint with your local data protection authority.
We will respond to verifiable requests within thirty (30) days, or such longer period as the relevant law permits if your request is complex.
Chemmo Holdings, LLC is based in Florida, USA. Our service providers (Google, Twilio, SendGrid, RevenueCat, Apple) operate globally. By using the App, you understand that your information may be processed in the United States and other countries, which may have data-protection rules that differ from your own.
We may update this Policy from time to time. If we make material changes, we will update the "Last updated" date at the top of this page and, where required by law, notify you through the App or by email. Continued use of the App after the effective date of an updated policy constitutes acceptance of the updated terms.
For privacy questions, requests under applicable privacy laws, or any other concern related to this Policy:
Chemmo Holdings, LLC
Attn: Privacy
Email: admin@chemmoholdings.com