Privacy and security
Privacy information
Last updated 10 August 2026
Your connection to this page is encrypted using HTTPS.
Information CareMin handles
CareMin stores account names, work email addresses, roles, sign-in security events and IP addresses. If selected, it also stores an encrypted remembered email preference and hashed trusted-device and recovery tokens.
Provider workspaces may contain resident, staffing, roster, worked-time, occupied-bed-day, compliance and retained source-file evidence supplied by the provider.
Why the information is used
The information is used to authenticate users, isolate organisations, calculate and report care minutes, retain audit evidence, investigate security events and provide authorised support.
Storage and service providers
Production database and object storage are configured for Australian data residency where supported. Hosting and storage providers encrypt information at rest, and deployed browser connections use HTTPS.
When CareMin encounters a new upload format, a limited preview may be sent to the configured AI mapping provider to learn the file structure. Known formats are mapped deterministically without another AI request.
Cookies and remembered email
CareMin uses an HttpOnly session cookie for account access. A user may opt into a separate 30-day trusted-device cookie and a 90-day remembered-email cookie. The remembered email is encrypted before it is stored in the browser and can be removed by signing in with the option unchecked.
Retention and access
Security and audit records are retained to support accountability. Care data and evidence remain controlled by the provider. CareMin does not yet apply an automated retention schedule, and authorized deletion actions are immediate rather than soft deletion.
To ask about information associated with your account, contact your organisation administrator or CareMin support. Requests must be verified before account or provider information is disclosed or changed.