Privacy Policy

Effective January 2026 • CareCircle Trust Framework

Privacy by Design

CareCircle is built on the principle of Data Minimization. We aim to collect only the data necessary to provide coordination features for your family. We do not sell your data, and we do not use it for advertising.

1. Information We Collect

  • Identity Data: Name, verified email address, and encrypted phone number.
  • Care Data: Tasks, appointments, and medication schedules (MTR) you explicitly log.
  • Vitals & Health: Health metrics shared within your Circle (protected with encryption and role-based access controls).
  • Safety Data: Temporary geofencing and SOS location data, stored only during active incidents.

2. Regulatory Compliance (2026 Standards)

HIPAA Privacy & Security

CareCircle is designed with administrative, technical, and physical safeguards to protect health information. Our platform includes encryption, role-based access controls, audit logging, secure infrastructure, and documented privacy and security practices that support the protection of health information. We continuously review and strengthen these safeguards as our platform evolves and as applicable privacy and security requirements change.

CCPA/CPRA Rights (California)

California residents have the right to Know, Access, Correct, and Delete their personal information. We support Global Privacy Control (GPC) signals.

GDPR (EU/UK)

We process data under the legal basis of Contractual Necessity and Explicit Consent. Where we transfer data internationally, we use appropriate safeguards such as Standard Contractual Clauses (SCCs).

3. Data Retention & Deletion

You own your data. Right to Deletion: you can request deletion of your account and associated data at any time — see Account Deletion for how to request it and what happens next.

When a verified request completes, we delete login access, authentication credentials, active sessions, device registrations, push subscriptions, active location and geofence access, and personal information not covered by a valid retention requirement.

Some information may be retained: qualifying shared care history for up to three years under CareCircle's own company retention policy, which is not a HIPAA requirement; provider-controlled records under an applicable agreement, business associate agreement or law; information under a research or legal hold until released; and required compliance documentation for six years where those obligations apply to us. Deleted information can also persist in routine system backups until those backups age out on our provider's normal cycle. Retained data is access-restricted, is never used for advertising or unrelated profiling, and is destroyed when its retention period expires unless a lawful hold applies.

Because CareCircle is built for shared family care, deleting one member's account does not automatically delete records legitimately shared with or controlled by other members of the same Circle.

4. Third-Party Processors

We use a limited number of "Sub-processors" to run CareCircle:

  • Vercel / AWSSecure Hosting & Edge
  • StripePCI-Compliant Billing

Contact Our Privacy Officer

For data export requests, deletion, or privacy inquiries: