Caregiver Dashboard
Local-first, encrypted by design

How your care data moves.

Caregiver Dashboard keeps the working record on the device first, encrypts changes before they leave it, and brings approved devices back into sync when connectivity returns.

The two-way sync cycle

The original sync-cycle graphic below shows how a care event moves from local capture to encrypted server persistence and back to approved devices.

Two-way sync cycle across mobile: local-first encrypted writes move to server persistence and realtime broadcast, then return to local devices for decryption and SQLite merging.
THE TWO-WAY SYNC CYCLEMobile-only local-first end-to-end encrypted sync hub
STAGE 1: WRITE EVENT (LOCAL TO SERVER)

Mobile device

  1. 1.A caregiver records a medication, note, task, or visit.
  2. 2.The change is written immediately to local SQLite.
  3. 3.A local key encrypts the sync payload before it leaves the device.
ENCRYPT FIRST

Server persistence and sync hub

The encrypted payload waits in the sync queue, then reaches server persistence with family scope, actor metadata, and timestamps.

CIPHERTEXT + RLS METADATA
STAGE 2: SERVER PERSISTENCE AND BROADCAST

Database operations

  1. 4.Store the encrypted row and its scope metadata.
  2. 5.Apply automated retention for old sync records.
SERVER-OWNED APPLY

Realtime coordination

A realtime event tells approved family devices that new encrypted data is available. The broadcast carries coordination metadata, not plaintext care notes.

NO PLAINTEXT PHI
STAGE 3: RECEIVE EVENT (SERVER TO LOCAL)

Local device receives the change

  1. 6.The device receives a sync event when it is online.
  2. 7.It fetches the encrypted row for its authorized family scope.
  3. 8.The local key decrypts the payload.
  4. 9.The local projection merges the row into SQLite for the next screen render.
DECRYPT LOCALLY

What the caregiver sees

The same care record appears across approved devices, with offline writes preserved and conflicts resolved by explicit version and timestamp rules.

CONVERGENT LOCAL UX

Three principles behind the cycle

The mechanics are intentionally straightforward: the device stays useful without a network, while the sync layer protects scope and keeps every approved device aligned.

01 / LOCAL FIRST

Work does not stop offline

Caregivers can capture what happened immediately. The local record is the source of truth for the active workflow.

02 / ENCRYPTED

Payloads leave the device protected

Sync transports encrypted blobs with the metadata needed for routing, authorization, and convergence.

03 / SCOPED

Only approved contexts converge

Family and patient scope stays explicit so the right people see the right record on the right device.

Clear handoffs start with a dependable record.

From a family caregiver’s phone to an independent caregiver’s caseload, the workflow keeps documentation close at hand and synchronization deliberate.

Get Started