Mallowa is built for individuals and families coordinating complex care. That work generates some of the most sensitive information anyone ever puts on a screen. We treat it that way. This policy describes the specifics; the short version is: we collect what we need to deliver coordination, we share with the people you choose, we never sell, and we never use your data to train AI models.
This Privacy Policy describes the data Mallowa collects, what we do with it, who we share it with (and don't), and the rights you have over the information about you and the person you support. It applies to mallowa.com and any related services operated by Trellis Care Coordination LLC (“Mallowa,” “we,” “us,” or “our”), an Oregon limited liability company with its principal place of business at 60982 Grand Targhee Drive, Bend, Oregon 97702.
Mallowa handles Protected Health Information (PHI) on behalf of individuals and families coordinating disability and developmental care. That responsibility shapes every choice in this document.
A few sections of this policy treat Family Users (parents, guardians, family members, and self-advocate individuals using Mallowa to coordinate their own care or care for someone they support) differently from Provider Users (clinicians, BCBAs, OTs, SLPs, RBTs, DSPs, agency staff, case managers, and educators using Mallowa in a professional capacity, generally as workforce members of a HIPAA-covered entity or business associate).
Where a section applies to one category and not the other, we say so explicitly. Where a section applies to both, you're both covered.
We collect three categories of information:
Mallowa does not collect: social security numbers, government IDs, biometric data, location data beyond audit-log IP addresses, advertising identifiers, or third-party analytics identifiers from care surfaces. We run no trackers of any kind on care data — no analytics, no pixels, no behavioral ad networks — anywhere inside the signed-in application.
On our public marketing pages only (the homepage, pricing, blog, and similar signed-out pages) we use two measurement tools, both named here so you can check them yourself: Plausible Analytics, which is cookieless and stores no personal data or cross-site identifier, and Google Analytics, used only to count visits and measure advertising, with Google Signals and ad personalization disabled and no user identifiers. Both report the page path only — query strings are never sent, so a referral or promo code in a link does not reach either company. Both are technically prevented from running on any signed-in page, so neither ever observes care activity. No session replay. No Facebook pixel, no behavioral ad networks, anywhere.
We use the information we collect to:
We do not use your information to train AI models, sell advertising, build user profiles for resale, or provide data to data brokers.
Mallowa uses AI to surface patterns in care data — sleep trends, medication-behavior correlations, environmental triggers, goal trajectories. This analysis is gated to the Growth tier and runs through a multi-layer de-identification pipeline before any data leaves Mallowa.
The pipeline:
The AI provider never sees a name, a date of birth, an address, or any other identifier listed in HIPAA §164.514(b) (Safe Harbor). The full 18-identifier handling is documented on the HIPAA / BAA page.
Care data is never used to train models — ours or anyone else's. AI features can be disabled by downgrading from the Growth tier.
Connecting a Google calendar to Mallowa is optional. The integration has strong privacy boundaries baked into the architecture:
You have rights over the information Mallowa holds about you and (where applicable) about the individual you support. Some are required by HIPAA, some by state privacy laws (including California's CMIA, Illinois's MHDDCA, Texas HB 300, and Oregon ORS 192.553), and some are commitments we make as a matter of principle.
To exercise any of these rights, email privacy@mallowa.com.
In the event of a breach of unsecured PHI as defined in HIPAA §164.402, Mallowa will notify affected individuals (or the covered entity, where Mallowa is acting as a Business Associate) without unreasonable delay and in any case within 60 days of discovery, in accordance with the HIPAA Breach Notification Rule (45 CFR §§ 164.400–414). Notice will include a description of what happened, the types of information involved, the steps individuals should take to protect themselves, what we're doing to investigate and mitigate harm, and contact information for questions.
Where required, we will also notify the Secretary of HHS and (for breaches affecting more than 500 residents of a state or jurisdiction) prominent media outlets serving that area. We notify state attorneys general where state law requires it.
Mallowa is designed to coordinate care for children and youth (often the individual at the center of a care team is a minor), but accounts on Mallowa must be created by adults (18+). Children do not directly create accounts.
Information about a child receiving care is treated as PHI and protected accordingly. The account owner (typically a parent or guardian) controls who is on the care team and what information they can see.
When the individual reaches the age of majority and takes over their own account, the existing account owner can transfer ownership through a future tooling pass (target: V1.5). Mallowa is not subject to COPPA because we do not knowingly collect personal information directly from children under 13; care information about minors is provided by the responsible adult.
Different categories of data have different retention windows:
We implement administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR §§ 164.302–318), including:
Security details and our responsible-disclosure program are on the Security page.
Mallowa is operated from the United States. Our infrastructure providers (Convex, Vercel, Cloudflare, Amazon Web Services, Anthropic, Paubox, Stripe, Sentry, Google, Microsoft) operate primarily from US data centers. If you access Mallowa from outside the United States, your information will be transferred to and processed in the United States.
Mallowa is built for the US healthcare context (HIPAA- aligned) and is not currently designed for use under the EU/UK GDPR, the Swiss FADP, or other non-US data-protection regimes. Users outside the US can use Mallowa but should understand that local protections may differ from US frameworks.
Pursuant to HIPAA §164.530(a), Trellis Care Coordination LLC designates the following individual as Privacy Officer and contact for receiving complaints and providing information about our privacy practices:
Skyler Kruger, Privacy Officer
Trellis Care Coordination LLC
60982 Grand Targhee Drive, Bend, Oregon 97702
privacy@mallowa.com
We'll update this policy when we change practices that are described here, when we add or remove a subprocessor, or when laws change in ways that require disclosure.
Material changes — anything that meaningfully affects the choices you have or what we do with your data — will be announced via in-app notification and email at least 30 days before the change takes effect, so you can review and decide whether to continue using Mallowa. New subprocessors that will handle PHI receive the same 30-day advance notice.
Non-material changes (clarifying language, fixing typos, adding new examples) take effect on the “Effective ” date at the top of this document.
Privacy questions, requests to exercise rights described above, or concerns about how Mallowa handled your data — email us:
By mail: Trellis Care Coordination LLC, Attn: Privacy Officer, 60982 Grand Targhee Drive, Bend, Oregon 97702.
For HIPAA-specific requests (Right of Access, accounting of disclosures, breach inquiries), see the dedicated HIPAA / BAA page for the formal process.