Information CareMin handles

CareMin stores account names, work email addresses, roles, sign-in security events and IP addresses. If selected, it also stores an encrypted remembered email preference and hashed trusted-device and recovery tokens.

Provider workspaces may contain resident, staffing, roster, worked-time, occupied-bed-day, compliance and retained source-file evidence supplied by the provider.

Why the information is used

The information is used to authenticate users, isolate organisations, calculate and report care minutes, retain audit evidence, investigate security events and provide authorised support.

Storage and service providers

Production database and object storage are configured for Australian data residency where supported. Hosting and storage providers encrypt information at rest, and deployed browser connections use HTTPS.

When CareMin encounters a new upload format, a limited preview may be sent to the configured AI mapping provider to learn the file structure. Known formats are mapped deterministically without another AI request.

Cookies and remembered email

CareMin uses an HttpOnly session cookie for account access. A user may opt into a separate 30-day trusted-device cookie and a 90-day remembered-email cookie. The remembered email is encrypted before it is stored in the browser and can be removed by signing in with the option unchecked.

Retention and access

Security and audit records are retained to support accountability. Care data and evidence remain controlled by the provider. CareMin does not yet apply an automated retention schedule, and authorized deletion actions are immediate rather than soft deletion.

To ask about information associated with your account, contact your organisation administrator or CareMin support. Requests must be verified before account or provider information is disclosed or changed.