Caregiver Dashboard ← Back to Home

Privacy Policy

Effective Date: August 12, 2026

Last Updated: August 12, 2026

This Privacy Policy describes how Care Compass ("Company," "we," "us," or "our") collects, uses, discloses, and safeguards your personal information when you access or use our family care management application, platform, and associated websites or services (collectively, the "Services").

Please read this Privacy Policy carefully. By accessing or using the Services, you acknowledge that you have read, understood, and agree to be bound by all the terms of this Privacy Policy. If you do not agree with these terms, please do not access or use the Services.

1. Scope & Core Disclaimer

A. Non-Covered Entity / HIPAA Disclaimer

Caregiver Dashboard operates as a direct-to-consumer and enterprise care coordination tool designed to assist family caregivers and care teams in organizing health logs, schedules, and daily tasks. Unless explicitly bound by a separate, signed Business Associate Agreement (BAA) with a Covered Entity, Caregiver Dashboard, nor the company Care Compass Software, LLC, is not a "Covered Entity" or "Business Associate" as defined under the Health Insurance Portability and Accountability Act (HIPAA).

Information you enter into the Services is voluntary personal health information (PHI) provided by you and is governed by this Privacy Policy and applicable state/federal consumer privacy laws, not HIPAA statutory protections.

B. No Medical Advice

The Services are provided for informational and care coordination purposes only. No content or functionality provided by the Services constitutes medical advice, diagnosis, or clinical decision-making.

This Privacy Policy explains how the mobile caregiver dashboard application and related services (collectively, the "Service") collect, use, disclose, and protect information.

3. Information We Collect

We collect several categories of information to provide, maintain, and optimize our Services:

A. Information You Directly Provide

Account & Profile Information: Name, email address, physical address, phone number, password, profile photo, and role within a family or organization unit.

Care Recipient & Family Health Logs: Names, dates of birth, health history notes, daily vitals, mood logs, medication schedules, care activities, dietary logs, and emergency contact details that you enter into the platform.

Payment Information: Credit card details, billing address, and payment transaction history (processed securely via third-party payment processors; we do not store raw payment card data on our servers).

Communications & Support: Messages, notes, feedback, and support tickets submitted directly to us.

B. Information We Collect Automatically

Device & Technical Data: IP address, device identifier (UUID, IDFA), operating system, browser type, device hardware parameters, mobile network operator, and system performance metrics.

Usage & Analytics: Interaction logs, feature usage, timestamps, clickstream data, error reports, and crash logs.

Cookies & Tracking Technologies: Standard session cookies, persistent web beacons, and local browser storage used to maintain secure sessions and remember application preferences.

4. How We Use Your Information

We process your information strictly for legitimate operational, security, and contractual purposes:

Service Delivery: To create and maintain user accounts, establish family care groups, sync care coordination tasks across team members, and manage caregiver schedules.

Algorithmic & AI Processing: To analyze logged entries and health trends strictly within your account context to surface proactive risk summaries, care gap notifications, and trend reports.

System Security & Integrity: To verify identity, protect against fraud or unauthorized access, audit system activity, and ensure data encryption and backup integrity.

Transactional Communications: To send account updates, system alerts, password reset requests, billing invoices, and security advisories.

Legal & Regulatory Compliance: To comply with applicable laws, court orders, subpoenas, and regulatory requests.

5. De-Identified Data & AI Model Training

A. Explicit Prohibition on Selling Personal Data

We do not sell, rent, trade, or monetize user Personal Information, Health Logs, or Household Profiles to third parties, data brokers, or advertisers.

B. De-Identified Data Aggregation

We may create de-identified, anonymized, or aggregated statistical data sets derived from user usage patterns and health metrics. Such data will have all personal identifiers (names, addresses, specific IDs) permanently removed in accordance with recognized industry de-identification standards.

We retain ownership of de-identified aggregate metrics to conduct technical bench-marking, system performance tuning, and internal product research.

C. Artificial Intelligence & Machine Learning Processing

No Public Model Training: Your identifiable care logs, private notes, and health records are never used to train, tune, or improve public or foundation artificial intelligence models owned by third parties.

Isolated Inference Processing: Any machine learning or agentic AI processing used to generate risk detection alerts operates within an isolated, secure environment solely to generate insights for your designated care unit.

6. Sync, Encryption, and Security

Where sync-enabled features are used, the Service applies encryption and integrity protections in transit and/or at rest according to the relevant feature design.

For care and health content protected by the Service's encrypted sync and user-controlled or zero-knowledge-style safeguards, the Company is designed to receive and store only protected payloads rather than plaintext content during ordinary operation. In that normal supported encrypted flow, the Company does not possess the plaintext content and cannot read, decipher, or decrypt that protected content as part of ordinary Service operation.

You are responsible for maintaining secure control of your devices, credentials, backup passphrases, recovery secrets, and other key material under your control.

If user-controlled backup passwords or key material are lost, certain encrypted data may become unrecoverable.

7. Sharing and Disclosure

The Company does not sell your personal information.

Information may be disclosed:

8. Data Retention

A. Local-First Data Handling

The Service is designed for local-first operation. Data you enter is stored locally on your device. Local data remains on your device until you delete it, uninstall the app, or otherwise remove local storage.

B. Backups and Recovery

The Company does not automatically mirror or back up your local-only records unless data is explicitly transmitted to a Company-controlled backend feature that supports sync or server processing.

If you use backend-connected features, server-side retention may vary by feature, account status, legal obligations, and operational needs.

9. Your Choices and Rights

Subject to applicable law and your account context, you may have rights to request access, correction, deletion, portability, or restriction of certain personal information.

You may also stop using the Service at any time and remove local data from your device.

10. Children's Privacy

The Services are directed to adult caregivers and are not intended for unassisted use by individuals under 18 years of age. We do not knowingly collect personal information directly from children under 13 (or under 16 where required by law). If a caregiver logs information regarding a minor child within their care group, that caregiver warrants that they are the legal parent or guardian or possess express legal authority to manage such data.

11. International and Regional Privacy Rights

Privacy rights and disclosures may vary by jurisdiction. Additional notices may apply where required by law.

12. Changes to This Privacy Policy

We reserve the right to modify or update this Privacy Policy at any time. If material changes are made, we will notify you by updating the "Last Updated" date at the top of this policy, issuing an in-app notice, or sending an email notification to your account's primary contact address. Continued use of the Services following notice of changes constitutes acceptance of the updated terms.

13. Contact

For questions about this Privacy Policy or privacy requests, contact the Company through the support channel provided in the application or project documentation.