Legal
Privacy Policy
Last updated September 16, 2026
AbilityOS provides operational software to healthcare and human-services organizations. This policy explains how we handle website, account, support, and service information.
Information we process
We process account details, organization settings, support communications, security logs, and information entered by authorized customers. Customers control the records they enter into their workspace.
How information is used
Information is used to provide and secure the service, authenticate users, support customers, deliver transactional messages, maintain audit records, and improve reliability.
Protected and sensitive information
Access is role-based and tenant-scoped. Organizations remain responsible for configuring access appropriately and entering information only when authorized. AbilityOS does not sell personal or clinical information.
Website analytics
On abilityos.net and app.abilityos.net, we collect safe page labels, demo and sign-in link clicks, broad referral categories, device categories, browser and operating-system families, IP addresses, internet provider and network number, and approximate country, region, and city inferred locally from the IP address. Signed-in app routes are reduced to broad areas such as Clients or Reports; we do not collect record IDs, clinical content, form contents, URL query strings, or full browser user-agent strings. Only platform super administrators can view these reports. A random identifier in session storage groups activity within a browser visit; it resets after 30 minutes of inactivity or 24 hours. We respect Do Not Track and Global Privacy Control, and you can disable visitor analytics below.
This preference applies to visitor analytics in this browser. Do Not Track and Global Privacy Control are also respected.
Staff activity
Authorized platform super administrators can review recorded sign-ins and audit activity separately for each organization, including each login’s IP address, approximate location, internet provider, browser family, operating system, and outcome. The activity dashboard summarizes account actions without displaying clinical note text or client record details.
Service providers
We may use carefully selected infrastructure, storage, monitoring, and email-delivery providers to operate AbilityOS. They receive only the information necessary to provide their service.
Retention and security
Records are retained according to customer configuration, contractual requirements, and applicable law. We use encryption in transit, access controls, audit logging, backups, and operational monitoring.
Your choices
Contact your organization administrator for workspace-record requests. For AbilityOS privacy questions, contact hello@abilityos.net.