The short answer
Senecta pods have no ordinary camera: a low-resolution thermal sensor sees heat, and a microphone listens for the sounds of a fall. Both are analysed in real time and are not stored, recorded or transcribed, except the moments around an event classified as a possible fall, which are kept to confirm it and to share with the people responding. Your agency owns its clients' data. We never sell it, use it for advertising, or use it to train our models. It is encrypted in transit and at rest, access is role-based and logged, and we tell you within 24 hours of a security breach.
What a pod captures
- Heat, not pictures. The thermal sensor captures low-resolution heat images: a person is a warm shape, not a face. There is no ordinary camera in the pod.
- Sound, analysed as it happens. The microphone's audio is analysed in real time for the sounds that go with a fall, such as an impact or a call for help. It is not recorded or transcribed, and the system does not identify who is speaking.
- The check-in. After a possible fall, the pod speaks and listens for the client's answer, which is part of that event.
What we keep, and for how long
- Events. The thermal images and audio of an event the system classifies as a possible fall are kept, to confirm the event and to give to those responding: your agency, the emergency contacts and, if they are called, emergency services.
- Alerts and the home's history, kept while the home is active so that changes over time can be seen.
- The records you give us: the home's address, its emergency contacts, and your team's accounts.
- Deletion. You can export your clients' data at any time and for thirty days after the agreement ends. We delete or return it within thirty days of the end, unless the law requires us to keep it; backups roll off within 35 days. When you ask us to delete a client's data while the agreement runs, we do it within thirty days.
Who can see it
- Your team, with role-based access you control, and the people in a home's response plan when there is an event.
- Senecta staff only where they need it to run and support the service, under written confidentiality obligations and with training on handling health data.
- Service providers we use for cloud hosting, payments, messaging and error monitoring, bound to obligations at least as protective as ours. We give you thirty days' notice before adding one, and you can object.
How it is protected
- Encryption in transit and at rest, role-based access control and access logging.
- Notice to your agency within 24 hours of becoming aware of a security breach that affects your data, with what happened, what was affected and what we are doing about it.
- We do not hold a SOC 2 or ISO 27001 certification yet. We complete your security questionnaire on request, once a year, and will share a report if we obtain one.
What we will never do with it
- Sell or share it, or use it for advertising of any kind.
- Use it, even de-identified or aggregated, to train or improve our models or to build other products.
- Combine it with personal information from other sources, or use it for any purpose other than running your service.
- Identify people by their voice or face. The pods do not create voiceprints or face templates.
Consent and the laws that matter
Consent comes first. Before a pod is switched on, the agency obtains the client's consent, or their legal representative's, and gives the notices the law requires. About a dozen states require every party to a conversation to consent before it is recorded, among them California, Florida, Illinois, Maryland, Massachusetts, Pennsylvania and Washington (Reporters Committee summary), which is one reason the pods analyse sound in real time instead of recording it. A client's consent covers only conversations they take part in, so caregivers and regular visitors should also be told a monitoring system is in use. We provide a consent form template.
Health data laws. We treat what the pods produce as consumer health data under laws such as Washington's My Health My Data Act and Nevada's SB 370, and as sensitive personal information under the California Consumer Privacy Act.
HIPAA. Whether HIPAA applies depends on your agency. A provider is a covered entity only if it sends standard transactions, such as claims or eligibility checks, electronically, itself or through a billing service (HHS). A private-pay agency that never does is not covered; one that bills Medicaid waiver programs, the VA or long-term care insurers electronically usually is. If protected health information is involved, we put a business associate agreement in place with you; the service agreement commits both sides to negotiate one in good faith.
What you sign
Every agency signs the same three-page service agreement and a data processing addendum, sent with the order link. The addendum sets out everything on this page in contract terms: our role as your service provider and processor, the limits on use, security, subprocessors, deletion and breach notice. Our published policies are on the legal page.
Questions agency owners ask
Is a Senecta pod a camera?
No. It has no ordinary camera. Its thermal sensor captures low-resolution heat images in which a person is a warm shape, not a recognisable face.
Does it record conversations?
No. Audio is analysed in real time and is not recorded or transcribed. The only audio kept is the moments around an event classified as a possible fall.
Do you use our clients' data to train your AI?
No. Our data processing addendum rules it out, including in de-identified or aggregated form.
Do you have SOC 2?
Not yet. We complete your security questionnaire on request and will share a SOC 2 or ISO 27001 report if we obtain one.
Will you sign a BAA?
Where protected health information is involved, yes: the service agreement commits both sides to negotiate a business associate agreement in good faith.
Next step
Bring your privacy questions to the demo.
Thirty minutes: what the pods capture, what families are told, and how consent works in your state.
Book your agency demoThis page summarises Senecta's service agreement and data processing addendum (October 2026), which govern if anything here differs. It is not legal advice: check your own obligations, especially under HIPAA and your state's recording laws, with your counsel.