Privacy Policy

CX360 Intelligence — Mobile App Privacy Policy

Application
CX360 Intelligence (Android & iOS)
Package / bundle
cx360_enterprise
Provider
Core Solutions, Inc. (“Core”, “we”, “us”)
Effective date
August 5, 2026
Last updated
August 5, 2026

Data deletion

See Section 8 — How to request deletion of your data. You can submit a deletion request by emailing privacy@coresolutionsinc.com — no account or app access required.

Section 1Who this policy covers

CX360 Intelligence is a workforce application for behavioral-health and human-services organizations. It is not a consumer app and it is not available for public self-registration.

There are two distinct groups of people whose information is involved:

GroupWho they areCore’s role
App users Employees, contractors and Direct Support Professionals (DSPs) of a subscribing organization who sign in with a company code issued by their employer. Core is the controller of the account, device and sign-in data described in Section 3.
Clients / individuals served The people whose records your organization documents in the app (care records, facesheets, forms, visit verification). Core is a processor / business associate. The subscribing organization is the controller and owner of that data. Core handles it only under our services agreement and Business Associate Agreement (BAA) with that organization.

This policy describes the mobile app. Your organization’s own privacy notice, and Core’s master services agreement with them, also apply.

Section 2Summary in plain language

  • We collect only what the app needs to sign you in, keep your device authorized, let you document care, and record electronic visit verification (EVV).
  • We do not sell your data. We do not share it with advertisers or data brokers.
  • There are no advertising, analytics, marketing or tracking SDKs in this app. No advertising identifier is collected. No cross-app or cross-site tracking occurs.
  • Location is collected only at the moment you press Clock In or Clock Out, and only while the app is open. There is no background or continuous location tracking.
  • All app data on your phone can be removed at any time by signing out and uninstalling the app.
  • Server-side data can be deleted on request — see Section 8.

Section 3Information the app collects

Everything below is collected directly through the app. We collect nothing about you from third parties.

3.1  Account and sign-in information

DataWhyWhere it goes
Company code (tenant identifier)Routes your sign-in to your organization’s environmentSent to Core’s authentication API; stored on the device
Username / work emailAuthenticationSent to Core’s authentication API; stored on the device
PasswordAuthenticationSent over HTTPS to the authentication API. Stored on the device only if you enable “Remember me”, in the platform secure keystore (iOS/macOS Keychain, Android EncryptedSharedPreferences)
Session tokenKeeps you signed in between launchesDevice secure keystore
User profile returned at sign-inUser ID, user name, company ID, role, assigned client IDs, environment/schema identifiers, licensed modules, and the work contact phone number on your account record — determines what you can see and do in the appCached in the app’s encrypted-at-rest local database on the device

“Remember me” is optional and is presented on the sign-in screen. When it is off, your credentials are erased from the device at sign-out.

3.2  Precise location — Time Clock / EVV only

The app requests foreground (“while using the app”) location permission only.

  • A single GPS reading is taken at the instant you tap Clock In and again at the instant you tap Clock Out.
  • The coordinates are sent to Core’s EVV service as the visit’s start and end location, as required by electronic visit verification rules (21st Century Cures Act and equivalent state programs) that your employer must comply with.
  • The app never collects location in the background, never runs a location service while closed, and does not build a movement history or track routes.
  • Declining or revoking location permission does not lock you out of the app; your employer decides whether a clock event without location is acceptable.

Android permissions declared: ACCESS_FINE_LOCATION, ACCESS_COARSE_LOCATION, INTERNET.
iOS permission declared: NSLocationWhenInUseUsageDescription (no “Always” permission is requested).

3.3  Device information — device authorization (MDM)

Your organization can restrict the app to approved devices. To support this, the app registers the device with Core’s device-approval service and sends:

  • a device identifier generated by the app — a random UUID (on iOS, seeded from Apple’s per-vendor identifier). This is not an advertising ID and is not shared with anyone outside Core;
  • device name, model, manufacturer, platform, OS version and OS build;
  • whether the device is physical or an emulator;
  • the app version and build number;
  • periodic check-ins (only while the app is in the foreground and online) that report last-seen time and retrieve any administrator command such as lock, wipe, or force-update.

Network connectivity status (online/offline) is read on the device to pause these checks while offline; it is not transmitted as a separate data point.

3.4  Work content you enter or view

Depending on your role and what your organization has licensed, the app displays and submits:

  • the client directory and service locations for your organization;
  • client facesheets and form records;
  • forms and assessments you complete, including their answers and scores;
  • clock-in / clock-out events, including their timestamps, selected client, service location, and the EVV coordinates described above.

3.5  What the app does not collect

  • No advertising or marketing identifiers, and no advertising SDKs.
  • No third-party analytics, crash-reporting or attribution SDKs.
  • No contacts, calendar, photos, microphone, camera, SMS or call logs.
  • No background location, no geofencing, no continuous tracking.
  • No browsing history, no keystroke logging.
  • No purchase or payment information (the app contains no in-app purchases).

Section 4How we use the information

We use it only to:

  1. authenticate you and maintain your signed-in session;
  2. enforce your organization’s device-approval and access rules;
  3. show you the clients, locations, forms and modules your role permits;
  4. record and submit clock-in/clock-out events with the location evidence EVV programs require;
  5. save and sync the care documentation you enter;
  6. keep the app working offline by caching the above on the device;
  7. secure the service — detect unauthorized devices, unauthorized access and abuse;
  8. meet our legal, regulatory and contractual obligations, including HIPAA.

We do not use your data for advertising, profiling, automated decision-making, model training, or any purpose unrelated to delivering the service to your employer.

Section 5How we share information

We share information only in these circumstances:

  • With your employing organization. Your sign-in activity, device-approval state, clock events and documentation are visible to authorized administrators and supervisors at your organization. This is the core purpose of the app.
  • With infrastructure providers that host and operate the CX360 platform, acting solely on our instructions under written contracts (and BAAs where PHI is involved).
  • When legally required — in response to a valid subpoena, court order, or other lawful demand, or to protect the rights, safety or property of Core, our customers, or the public.
  • In a corporate transaction — as part of a merger, acquisition or asset sale, subject to this policy and to notice where required by law.

Section 6Where data is stored and how it is protected

On your device

  • Secrets — session token, device-approval token, and (only with “Remember me”) your credentials — are stored in the iOS Keychain or Android EncryptedSharedPreferences.
  • Working data — your profile, the client and location directories, cached form layouts, clock history and the open clock-in — is stored in a local on-device database that is protected by the operating system’s app sandbox and by full-device encryption.
  • Diagnostic logs are written only in development builds; passwords are fully masked and tokens are truncated before anything is logged. Release builds do not emit these logs.

In transit

Every request uses HTTPS/TLS.

On our servers

Data is held in Core’s access-controlled CX360 environment for your organization, segregated by tenant, with role-based access control, audit logging and encryption at rest, under our HIPAA Security Rule safeguards.

No system is perfectly secure, but we maintain administrative, physical and technical safeguards appropriate to the sensitivity of the data.

Section 7How long we keep data

DataRetention
Session tokenUntil you sign out, the token is rejected by the server, or the app is uninstalled
Remembered credentialsUntil you sign out with “Remember me” off, submit a deletion request, or uninstall the app
On-device cached profile, directories, forms and clock historyUntil sign-out (session data), an administrator wipe, a tenant switch, a deletion request, or uninstall
Device-approval record (device identifier, model, OS, check-in times)For as long as the device is enrolled with your organization, then per Section 8
Clock-in/clock-out and EVV recordsRetained by your organization for the period its EVV program, payer and state law require
Client records, forms and documentation (PHI)Retained by your organization under its own record-retention schedule and applicable law (medical-record retention periods are commonly 6–10 years, and longer for minors)

When a retention period ends, or a deletion request is fulfilled, data is deleted or irreversibly de-identified. Encrypted backups are purged on their normal rotation cycle, which may take up to 90 days after deletion from live systems.

Section 8How to request deletion of your data

You can request deletion of your data at any time. You do not need to be able to sign in to the app to make a request.

8.1  Delete data stored on your device (immediate, self-service)

  1. Sign out — open the navigation drawer and tap Logout. This clears the session token, your cached profile, your selected view, and any open clock-in from the device. If “Remember me” is off, your saved company code, username and password are erased as well.
  2. Turn off “Remember me” on the sign-in screen before signing out if you want stored credentials removed.
  3. Uninstall the app — removing CX360 Intelligence from your phone deletes the entire app sandbox, including the local database, all cached records, and every secret in Android EncryptedSharedPreferences.

Note for iOS: the device identifier and any remembered credentials live in the iOS Keychain, which iOS may preserve across a reinstall. To remove those, submit an account-deletion request as described below.

8.2  Request deletion of data on our servers (account and account-related data)

Email privacy@coresolutionsinc.com with the subject line “App Data Deletion Request” and include:

  • your full name;
  • the company code you use to sign in;
  • the username / work email on the account;
  • what you want deleted — the whole account, or specific items (for example, the device-approval enrolment for a phone you no longer use).

If you prefer, you may write to: Privacy Officer, Core Solutions, Inc., 555 East North Lane, Suite 5000, Conshohocken, PA 19428, USA.

What happens next

StepTiming
We acknowledge your requestWithin 5 business days
We verify your identity (we may ask you to reply from the email address on the account, or confirm details only you would know)
We complete the request, or explain in writing why part of it must be refusedWithin 30 days of verification; extendable once by 30 days for complex requests, with notice to you
Deleted data is purged from encrypted backupsWithin 90 days

What “delete my account” removes

Your user account and its ability to sign in, your cached profile held for the account, your device-approval enrolments and device identifiers, any remembered credentials held for you, and your session tokens.

What we cannot delete on your request alone, and why

  • Client records, care documentation and forms you created belong to your employing organization, not to you. They are that organization’s records — often legally mandated medical records — and Core, as its business associate, is not permitted to delete them without the organization’s instruction. Send those requests to your organization’s Privacy Officer or administrator; if you send them to us, we will forward your request to that organization and tell you we have done so.
  • Clock-in/clock-out and EVV records are payroll, billing and visit-verification records your employer and its payers must retain by law.
  • Security, audit and access logs required for HIPAA compliance and fraud prevention are retained for the period the law requires.
  • Anything we must keep to comply with a legal obligation, resolve a dispute, or enforce our agreements.

Where we cannot delete data, we will tell you specifically what is being kept, on what legal basis, and for how long.

8.3  If you are a client / individual served (not an app user)

If your care records are documented in CX360 by a provider organization, that organization is the controller of your records. Contact that provider directly to exercise your HIPAA rights of access, amendment, restriction or deletion. If you contact us, we will refer you to them and notify them of your request.

Section 9Your rights

Depending on where you live, you may have the right to:

  • access the personal information we hold about you and receive a copy;
  • correct inaccurate information;
  • delete information (subject to Section 8);
  • restrict or object to certain processing;
  • data portability — receive your data in a portable format;
  • withdraw consent at any time, including revoking location permission in your device settings;
  • not be discriminated against for exercising these rights.

Under HIPAA you may also have rights of access, amendment, accounting of disclosures and restriction with respect to PHI — exercised through the provider organization that holds your records.

To exercise any right, contact privacy@coresolutionsinc.com. We do not charge a fee for reasonable requests and we will not treat you differently for making one.

California residents

We do not sell or share personal information as those terms are defined by the CCPA/CPRA, and we have not done so in the preceding 12 months. We do not knowingly collect the personal information of anyone under 16.

EEA/UK residents

Our lawful bases are performance of a contract (delivering the service to your employer), legitimate interests (securing the service and preventing unauthorized access), consent (device location), and legal obligation. You may lodge a complaint with your supervisory authority.

Section 10Children’s privacy

CX360 Intelligence is a workplace tool intended solely for adults employed or contracted by our customer organizations. It is not directed to children, and we do not knowingly permit anyone under 18 to create or use an app account. If we learn an app account was created by a minor, we will delete it promptly.

Client records documented within the app may relate to minors receiving services. That information is provided and controlled by the treating organization under HIPAA and applicable state law — it is never collected from the child through this app, and it is never used for advertising, profiling, or any secondary purpose.

Section 11Permissions the app requests

PermissionWhen it is usedCan you decline?
Internet / network accessEvery sign-in and data requestNo — the app cannot function offline-only
Location — while using the app (fine/coarse)Only at the moment of Clock In and Clock OutYes; the rest of the app continues to work
Network stateTo pause device check-ins while offlineNot user-facing

You can revoke location permission at any time in Settings → Apps → CX360 Intelligence → Permissions (Android) or Settings → CX360 Intelligence → Location (iOS).

Section 12Google Play Data Safety summary

For transparency, this is what the app’s Play Data Safety declaration reflects:

Data type Collected Shared with third parties Purpose Optional
Name, email address, phone number (account profile)YesNoApp functionality, account managementNo
Password / credentialsYesNoAuthenticationNo
Precise locationYesNoApp functionality (EVV visit verification)Yes — permission can be declined
Health information (client records entered by the user)YesNoApp functionalityNo
Device or other IDs (app-generated device UUID)YesNoApp functionality, fraud prevention & securityNo
App info & performance / diagnosticsNoNo
Advertising ID, usage analytics, marketing dataNot collected

All data is encrypted in transit. Users can request data deletion as described in Section 8.

Section 13International transfers

Core operates in the United States, and data collected through the app is processed and stored in the United States. If you use the app from outside the U.S., you understand that your information will be transferred to and processed in the U.S., where data-protection law may differ from your own. Where required, we rely on appropriate safeguards such as the EU Standard Contractual Clauses.

Section 14Changes to this policy

We may update this policy as the app changes or the law requires. When we do, we will change the “Last updated” date above and post the revised policy at the URL published on the app’s Google Play and App Store listings. Material changes affecting how we use your data will additionally be communicated to your organization. Continued use of the app after an update means you accept the revised policy.

Section 15Contact us

Core Solutions, Inc. — Privacy Officer

Email: privacy@coresolutionsinc.com

General inquiries: info@coresolutionsinc.com

Address: 555 East North Lane, Suite 5000, Conshohocken, PA 19428, USA

If you are dissatisfied with our response, you may escalate to your organization’s Privacy Officer or to your local data-protection authority.

↑ Back to top