Back

Privacy Notice

Last updated: [DATE]

1. Who we are

Caregiver's Compass is operated by [LEGAL BUSINESS NAME] (trading as "Caregiver's Compass"), located at [BUSINESS ADDRESS]. We are the data controller of personal data processed through the Service. Contact: [CONTACT EMAIL].

2. What we collect and why

CategoryPurposeLegal basis
Email, name, password hashAccount creation, sign-in, supportContract
Care journal entries, calendar events, contacts, medications, voice notesProviding the Service to youContract
AI prompts and responsesGenerating AI guidance you requestedContract
Family-circle invites and member recordsLetting you share with family you chooseContract
Usage and device data (IP, browser, timestamps, error logs)Security, fraud prevention, debugging, improving the ServiceLegitimate interests
Marketing email (if you opt in)Product updates, tipsConsent

We do not collect or store your full card number — payments are handled by Paddle (see below).

3. Who we share data with

  • Paddle — our Merchant of Record for sales, subscription management, payments, tax compliance, invoicing, and refunds. Paddle independently controls the payment data it collects at checkout.
  • Supabase — managed database, authentication, and file storage (subprocessor).
  • Lovable / Cloudflare — application hosting and edge runtime.
  • Google (Gemini) and OpenAI (GPT) via Lovable's AI Gateway — to generate AI responses you request. Your prompts are sent to the selected model only when you trigger an AI feature.
  • Google — if you sign in with Google OAuth.
  • Professional advisers (legal, accounting) where strictly necessary.
  • Public authorities when required by law.

We never sell your personal data and we never share your journal or AI conversations for advertising.

4. International transfers

Our processors may store and process your data outside your country, including in the United States and the European Economic Area. Where transfers leave the UK / EEA we rely on Standard Contractual Clauses or adequacy decisions to protect your data.

5. How long we keep it

  • Account & profile: while your account is active, plus up to 30 days after deletion.
  • Care content (journal, calendar, meds, contacts, voice notes): deleted with your account.
  • Billing records: 7 years (tax requirements), stored by Paddle.
  • Security and audit logs: up to 12 months.

6. Your rights

Depending on where you live you may have the right to: access your data, correct it, delete it, restrict or object to processing, data portability, and withdraw consent at any time. You can exercise most rights from your Account page or by emailing [CONTACT EMAIL]. We will respond within 30 days. UK / EEA users have the right to lodge a complaint with their local supervisory authority.

7. Security

We use appropriate technical and organisational measures, including encryption in transit (TLS), encryption at rest for stored content, row-level security on user data, signed URLs for file downloads, and least-privilege access for staff.

8. Cookies

We use only essential cookies and local storage required to keep you signed in and remember your preferences. We do not use third-party advertising cookies.

9. Children

The Service is intended for adults (18+) and not directed to children under 13.

10. Changes

We'll post material changes in-app or by email at least 14 days before they take effect.

11. Contact

Privacy questions: [CONTACT EMAIL].