Firefly Privacy Policy

Last Revised: July 20, 2026

Thanacare LLC (“Company,” “Thanacare,” “Villages by Thanacare,” “we,” “us,” and “our”) respects your privacy and is committed to protecting it through this Privacy Policy (the “Policy”). This Policy should be read together with the Firefly End User License Agreement, into which it is incorporated by reference, and with the LANTERN Initiative Member Agreement you signed with the Pediatric Palliative Care Coalition (“PPCC”).

This Policy describes the information we collect when you use the Firefly platform at firefly.yourvillages.org and associated applications (“Firefly”), and how we collect, use, protect, and disclose it. This Policy also does not apply to PPCC’s collection, use, or sharing of your information. To learn about how PPCC handles information, review PPCC’s Privacy Policy.

Firefly is a family-controlled personal health record platform operated by Thanacare LLC and made available to you through PPCC as part of the LANTERN Initiative. You and your family own the health information you enter (“Family Health Information” or “FHI”) and decide what to record and what to share, and with whom. Thanacare operates Firefly as a personal health record (PHR) vendor under the Federal Trade Commission’s Health Breach Notification Rule (16 C.F.R. Part 318). PPCC is not a covered entity under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), and Thanacare is not acting as a HIPAA business associate. Thanacare protects your FHI under a Data Protection Addendum with PPCC and applies privacy and security safeguards consistent with the standards in 45 C.F.R. Parts 160 and 164 (the “HIPAA Standards”) as a voluntary best practice. The consent you give to share information through the LANTERN Initiative, and your right to withdraw it, are governed by your LANTERN Initiative Member Agreement.

This Policy does not apply to information collected offline or through any other website, product, or platform instance operated by Thanacare, PPCC, or a third party, which have their own privacy policies. By using Firefly, you acknowledge that your information will be collected, used, and shared as described in this Policy. It may change from time to time (see “Changes to this Policy”).

What We Collect and How We Collect It

Information You Provide to Us

Information you may provide includes: your name; email address; telephone number; mailing address; date of birth; relationship to a child (such as parent, guardian, or family member); health conditions, symptoms, observations, medications, treatments, providers, and care-plan information about your child or family; documents you upload (such as advance directives or care plans); text, voice, photo, and other content you submit to features such as quick care entry, caregiver community posts, replies, and messages; and comments in free-text fields.

Please enter only information relevant to your child’s care. Do not enter Social Security numbers, payment-card numbers, or other sensitive information that Firefly does not need.

Information We Receive from PPCC

We may receive limited identifying information from PPCC to set up and maintain your access, such as your name and email address, and where program operations require, limited identifiers like a child’s name and date of birth (collectively, “Customer-Supplied Identifiers”). PPCC provides these under the Data Protection Addendum solely to provision your access to Firefly.

Important Information About Your Family Health Information

Firefly is a family-controlled personal health record. You and your family own your FHI and determine what to enter and what to share. PPCC’s role is limited to (a) providing the Customer-Supplied Identifiers needed at signup, and (b) receiving, through invitations you initiate within Firefly, access to the FHI you choose to share with PPCC’s authorized LANTERN coordinators. Because PPCC is not a HIPAA covered entity, your FHI is not handled under a HIPAA Notice of Privacy Practices or a business associate agreement. We protect your information in accordance with our obligations under the Data Protection Addendum between Thanacare and PPCC, and as described in this Policy. Thanacare also has independent obligations as a PHR vendor under the FTC Health Breach Notification Rule. If you voluntarily provide health information about yourself or others (for example, in notes or community posts), you are responsible for the accuracy and appropriateness of what you share and for not sharing information you do not have authority to share.

Automated Information Collection

We collect some information automatically, such as your IP address, pages viewed, browser type, operating system, and actions taken. Tools include:

Your Choices

We do not use your information for marketing. Communications from Firefly are operational, transactional, or service-oriented (account notifications, care reminders, and messages from your care team or community).

Text Messaging.If you provide a mobile number and consent to texts, you may receive messages relating to authentication, care reminders, or your care team. Reply STOP to opt out or HELP for help at any time, or contact support@yourvillages.com. Message and data rates may apply. We obtain your express written consent before starting any text-messaging service, in accordance with the Telephone Consumer Protection Act (“TCPA”) and applicable state law.

Accuracy and Access to Your Information

Because you control your FHI directly in Firefly, you can view, add to, and update much of your information yourself. You may also request access to, correction of, or deletion of your information by contacting support@yourvillages.com or by submitting a request through the in-app feedback option; we verify your identity before acting and respond within a reasonable time, and within any period required by applicable law. Where PPCC holds FHI you shared with it, you may also contact PPCC directly. See “Your Privacy Rights” below.

Information of Minors

Firefly is not directed to children for independent use. Accounts are created and managed by a parent or legal guardian, who acts as the child’s personal representative under applicable law. Where information about a child is recorded in Firefly, it is handled under this Policy, the Data Protection Addendum, the LANTERN Initiative Member Agreement, and applicable state law regarding minors. We do not knowingly collect information directly from children for their own independent use, and we do not use a child’s information for any purpose other than supporting the family’s use of Firefly and the LANTERN Initiative.

How We Use Your Information

We use your information to provide Firefly and support your participation in the LANTERN Initiative, including to: provide the service’s features; support PPCC in coordinating LANTERN resources; authenticate your identity and secure your account; communicate with you about the service and your care; operate, secure, monitor, and improve the service; enforce the Firefly End User License Agreement; and comply with legal and contractual obligations, including the Data Protection Addendum. We do not use your information for advertising or marketing to third parties.

Aggregate, de-identified information. Thanacare may create aggregate, de-identified information from FHI and platform activity to give PPCC reporting on program activity and engagement. This information is de-identified consistent with HIPAA Standards (Safe Harbor or Expert Determination), does not identify you, and is no longer FHI. Thanacare may combine such de-identified information with de-identified information from other platform customers for analytics, provided all data is de-identified before any combination.

How We Use Artificial Intelligence

Firefly may use artificial intelligence to assist with features such as care entry, summarization, and information retrieval. AI processing of FHI is performed only by a processor contractually bound to protect it under a business associate agreement and a data protection addendum with Thanacare (currently Amazon Web Services, using Amazon Bedrock under AWS’s HIPAA-eligible services; FHI is processed transiently for the feature and is not retained by the AI service). We do not permit our AI processor to use your FHI to train its general-purpose models, and we do not share FHI with any AI provider that has not entered into those protections with Thanacare.

How We Share Your Information

We do not sell or lease your information. We may share it as follows:

If Thanacare is involved in a sale, merger, or reorganization, we will require any successor to honor this Policy and the Data Protection Addendum, or to notify you and PPCC and provide a meaningful choice if its practices differ materially.

Third-party Websites

This Policy does not apply to third-party websites Firefly may link to; we encourage you to read their policies.

Your Privacy Rights

Firefly is provided through the LANTERN Initiative to families in Pennsylvania. Regardless of where you live, we give you direct, family-controlled rights over your information: you can access your information, correct it, delete it (subject to the log retention described under “Data Retention” and to legal requirements), receive it in a portable format, and withdraw your consent to our collection or sharing of it. We do not sell your information, share it for cross-context behavioral advertising, or use it for targeted advertising, and we will not discriminate against you for exercising any right.

To exercise any right, contact support@yourvillages.com or submit a request through the in-app feedback option. We will verify your identity, allow an authorized agent to act on your behalf, and respond within a reasonable time and within any period required by applicable law (generally within 45 days). If we decline a request, we will explain why, and you may ask us to reconsider.

Residents of other states. Some U.S. states give their residents additional privacy rights. If you are a resident of such a state, contact support@yourvillages.com, and we will honor any rights available to you under applicable law and let you know if you may also contact your state Attorney General.

Do Not Track

Firefly does not respond to “Do Not Track” browser signals, but we honor Global Privacy Control signals as described under “Cookies.”

For Visitors Outside the United States

Firefly is designed for use in the United States, and we store and process information in the United States. We do not represent that Firefly complies with the laws of any other jurisdiction.

Data Retention

You may delete FHI you have entered. We retain your FHI for as long as needed to provide Firefly to you and to support your participation in the LANTERN Initiative. If you close your account or leave the LANTERN Initiative, we delete or de-identify your FHI within a reasonable period afterward (and instruct our sub-processors to do the same), except where we must retain it to comply with law or the Data Protection Addendum. De-identification uses methods consistent with the HIPAA Standards (Safe Harbor or Expert Determination). Access and disclosure logs are retained for at least six (6) years, as set in the Data Protection Addendum and as required by law; these logs are kept for compliance and may be retained even after the underlying FHI they reference is deleted.

Changes to this Policy

If we change this Policy, a revised version will be posted here with an updated “Last Revised” date. For material changes, we will use reasonable efforts to give additional notice, such as by email or an in-app notice.

Safeguarding the Information We Collect

We use reasonable administrative, physical, and technical safeguards designed to protect your information against accidental loss and unauthorized access, use, alteration, and disclosure (consistent with the standards of the HIPAA Security Rule, which we apply as a voluntary best practice, and with the Data Protection Addendum), including encryption in transit and at rest, access controls, and audit logging. No system can be guaranteed perfectly secure. You are responsible for safeguarding your login credentials, including if you share them with a co-parent, caregiver, surrogate, or other person acting on your family’s behalf; if you believe your credentials have been compromised, change your password and notify us promptly.

Breach Notification. If there is a breach affecting your FHI, Thanacare will notify PPCC promptly and within the timeframes set in the Data Protection Addendum, and, as a PHR vendor under the FTC Health Breach Notification Rule (16 C.F.R. Part 318), will notify affected families without unreasonable delay and no later than 60 calendar days after discovery, and will notify the Federal Trade Commission (and, for larger breaches, prominent media) as the Rule requires. PPCC and Thanacare will coordinate so families receive timely notice; Thanacare will provide the required notice directly if coordination cannot meet the legal deadline. For a breach involving only identifiers (such as a name or email address), we will notify affected individuals and regulators as required by law.

How to Contact Us

To contact us about this Policy or your information:

Thanacare LLC support@yourvillages.com

For matters relating to your participation in the LANTERN Initiative, you may also contact PPCC using the information in your LANTERN Initiative Member Agreement.