BridgeLog App Privacy Policy

Effective Date: September 10, 2026

1. What This Policy Covers

This policy describes how Acorns to Oaks Behavioral Services LLC ("we," "us," or "our") collects, uses, and protects information in BridgeLog, our clinical application for families and staff. It covers the BridgeLog Android app and the BridgeLog web app (a2o-bridgelog.web.app), which share the same secure backend. Our public website is covered separately by our Website Privacy Policy.

BridgeLog is invite-only. There is no public sign-up, and downloading the app from Google Play does not create an account or give you access. Accounts are created by Acorns to Oaks for the parents, guardians, caregivers, and care-team members of the children and clients it will serve once services begin. The app is used by adults 18 and over.

Acorns to Oaks is accepting inquiries; services begin once our clinical team is in place. No family accounts exist yet — this policy describes how BridgeLog handles information once they do.

2. BridgeLog and Your Health Information

BridgeLog exists to support clinical care, so the information families and staff enter into it is Protected Health Information (PHI) — a child's or client's behavioral data, session and journal notes, schedules, and related clinical records. Our handling of PHI is governed by HIPAA and described in our Notice of Privacy Practices, which controls if it conflicts with this policy for PHI. This policy adds the app-specific details: exactly what the app collects, where it goes, and what your choices are.

3. Information the App Collects

  • Account information: your name and email address, used to sign you in and show who did what. Staff sign in with our Google Workspace; parents and caregivers sign in with an email address and password on an account we set up with them.
  • Clinical information (PHI): the behavioral-tracking data, session and journal notes, and related records that you and the care team enter. This is the purpose of the app. It includes the child's first name and date of birth, the address of the place a session is delivered, and a caregiver's drawn signature confirming they were present. A signature is stored as the path the finger drew, not as a photograph, and the app has no access to your camera, microphone, photos or files.
  • Messages: BridgeLog includes secure in-app messaging for the care team. Messages about a child's or client's care are kept as part of the clinical record; administrative messages that are not part of the clinical record are kept separately for a shorter operational period and then deleted. Messages are not shared with third parties, and a notification about a new message never includes the message content.
  • Internal identifiers: an account ID and family ID that link your account to the right records and keep each family's data separated from every other family's.
  • App activity: sync and audit records of actions taken in the app (for example, sign-ins, edits, exports, and views of clinical data through the staff data viewer). We keep these for security and for the record-keeping HIPAA requires. The app contains no advertising and no third-party analytics — no data about how you use BridgeLog is sent to any analytics or advertising company.
  • Push notification token: if you allow notifications on Android, the app registers a device token (Google Firebase Cloud Messaging) with our backend so we can deliver reminders and alerts. Notifications are built on our server from fixed templates that cannot carry clinical content — a notification never includes a child's name or any health details.
  • Software-update identifier: each time the Android app starts, it checks for application updates using Expo's update service (650 Industries, Inc.). That check sends a randomly generated installation ID and technical build details (app version, platform, update channel) and, if the app failed to start on its previous launch, a brief technical error message so a faulty update can be rolled back. None of this is designed to carry names, email addresses, or clinical records, and we use it only to deliver app updates.
  • App and device integrity check: when the app talks to our backend, it asks Google Play services to confirm that it is the genuine BridgeLog app on a genuine Android device (Firebase App Check with the Google Play Integrity API). That check sends Google the app's package name, version and signing certificate, a device attestation generated by Google Play services, and whether the Google account on the device is licensed for the app. It carries no names, email addresses, messages, or clinical records. We use the result only for security; it is set to monitoring only and does not block anyone.

4. How We Use This Information

  • To provide and coordinate clinical care — the app's sole purpose
  • To keep each family's information visible only to that family and its care team
  • To maintain the security logs and audit trails required of a healthcare provider
  • To deliver notifications you have enabled and software updates

We do not sell, rent, or trade information from BridgeLog. We do not use it for advertising. We do not share it with third parties for their own purposes.

5. Service Providers

BridgeLog runs on infrastructure operated by service providers that process this data to provide their service to us, and not for their own advertising or marketing purposes:

  • Google (Firebase / Google Cloud): hosting, sign-in, database, and notification delivery for the app's own backend, and Google Play services (Play Integrity) for the app-and-device integrity check described in Section 3.
  • Expo (650 Industries, Inc.): delivery of application updates for the Android app, as described in Section 3. Expo receives the installation ID and build details described there — not names, email addresses, or clinical records.

6. Security

All connections between the app and our backend are encrypted in transit (HTTPS/TLS). Clinical data is encrypted at rest, with an additional layer of field-level encryption applied per family. Access is role-based: a parent can see only their own family; a care-team member can see only the families assigned to them; and administrator access is limited to our own organization. Sign-ins, edits, exports, administrative actions, and views of clinical data through the staff data viewer are recorded in an append-only audit log. Data the app stores on your device for offline use is kept in a protected store and can be wiped from within the app. No security measure is perfect, but BridgeLog is designed so that the most sensitive data has the most protection.

7. Retention

Clinical records in BridgeLog are retained for as long as healthcare record-keeping laws and our professional obligations require. When Acorns to Oaks furnishes Applied Behavior Analysis services, Acorns to Oaks is the provider of record for those services, and BridgeLog holds the clinical records Acorns to Oaks maintains, including the session data our Registered Behavior Technicians (RBTs) record, as described in our Notice of Privacy Practices. Messages about a child's or client's care are retained as part of the clinical record; administrative messages that are not part of the clinical record are kept for a shorter operational period and then automatically deleted. Audit logs are retained for the periods HIPAA requires. Account information is kept while the account is active and handled as described below when it is closed.

8. Account Deactivation and Data Deletion

Because BridgeLog accounts are created by us rather than self-registered, deactivation and deletion are handled by our team on request:

  • To deactivate your account (ending all access from your login), contact us using the details below. We deactivate promptly at the request of the account holder, or of the clinician responsible for that family's care.
  • To request deletion of your account data — your name, email, sign-in record, and device tokens — contact us the same way. We honor these requests except where a record must be kept by law.
  • Clinical records are different: healthcare laws require us to retain clinical records for a legally defined period, so they generally cannot be deleted on request during that period. You have rights to access and amend those records, as described in our Notice of Privacy Practices.
  • On-device data: you can clear BridgeLog's locally stored data at any time from the app's settings, or by uninstalling the app.

Deletion requests: email support@acornstooaks.healthcare or call (386) 227-7342. We will verify your identity before acting on a request.

9. Children's Privacy

BridgeLog is used by adults 18 and over — parents, guardians, caregivers, and care-team members. It is not directed to children, and children are not account holders. Information about children in BridgeLog is clinical information entered by the adults on their care team, protected under HIPAA and our Notice of Privacy Practices.

10. Changes to This Policy

We may update this policy from time to time. The effective date above reflects the most recent revision. If a change materially affects how clinical information is handled, we will notify account holders in the app or by email.

11. Contact

Acorns to Oaks Behavioral Services LLC
147 Birchmont Dr, DeLand, FL 32724 — Serving West Volusia, FL
(386) 227-7342
support@acornstooaks.healthcare

← Website Privacy Policy Notice of Privacy Practices Return to Home