Privacy

Privacy commitments

AgeCare handles health information about older adults, some of whom have reduced capacity to consent, and some of whom are being watched over by relatives acting with the best of intentions. That combination deserves care, and it deserves plain language.

This page states our commitments and how the product is designed. It is written to be read, not to be survived. If anything here is unclear, or you think we've fallen short of it, write to privacy@agecare.app.

Who owns the record

The person being cared for is the data subject, and the product treats them that way even when a relative is the one paying. They own their care record. Coordinator status is granted by them and is transferable. Where a person cannot consent for themselves, a documented proxy-consent path records who consented, on what basis and when, with periodic re-confirmation.

What we collect

CategoryExamplesWhy
AccountName, email, role, the care network you belong toTo sign you in and to know which record you may open
Care dataMedications and doses, vital readings, appointments, tasks, visit notes, messages, documentsThis is the record itself, the thing the product exists to keep
Safety signalsCheck-ins, coarse activity signals, a safe-zone label, device batteryOnly when switched on, and visible to the person they describe
LocationPosition fixes and the safe zones drawn around them, while location sharing is onTo answer "has she left a boundary she agreed to?" — held for seven days, then deleted
TechnicalDevice type, app version, crash diagnosticsTo keep the app working. Never joined to health content

We practice data minimisation deliberately: a derived signal ("quiet for 3 h 40 min") is preferred to a continuous raw feed, and most of the product needs only a coarse label and a safe-zone flag rather than a coordinate.

Location is the exception, and it is fenced off accordingly. A boundary test and a map of the zones cannot be computed without coordinates, so they are kept — in one place, reachable only through the location permission scope, and for seven days. Sharing runs on a ladder rather than a switch: continuous, a check every few minutes, alerts only — where the geofence still runs but no routine position is ever written and the family sees no map and no history — or off, where nothing is collected and no alert can fire. The person being located chooses which, and can change it at any time.

Who can see it

Access is deny by default. New data is invisible until someone is explicitly granted it, through ten permission scopes the record's owner or coordinator controls, each explained in plain language. Revoking a grant takes effect immediately, on the next screen the other person opens.

Scopes are deliberately narrow. A caregiver does not need financial data. A clinician does not need family conversations. Professional access is time-bounded and lapses with the assignment it came from. Enforcement belongs in the database, not only in the interface.

What we never do

  • We do not sell health data, and we do not run advertising.
  • We do not use your care record to train models for anyone else's benefit.
  • We do not enable covert monitoring: if a signal is on, the person it describes can see that it is on.
  • We do not diagnose, and we do not contact emergency services.

Audit

Certain events deserve an append-only log that the older adult and their coordinator can read, not only operators. That list is: every read of an emergency profile, every permission grant and revocation with actor and timestamp, every document view and share, every export, and every access to location or activity data.

Security

TLS in transit; encryption at rest for the database and for document storage; short-lived signed URLs for document access; secrets held in a managed store; and a documented key-rotation procedure. Where a protection is planned rather than in place, the app says so on the screen concerned rather than implying safety that does not yet exist.

How long we keep things

DataRetention
Location and device telemetry7 to 30 days
Activity and inactivity signals90 days
Vital readings, doses, appointmentsWhile the record is active; belongs to the older adult
MessagesRetained; deletable by participants
DocumentsUntil deleted by the owner
Audit logsLonger than the data they describe

Your rights

You can request access to your data, correction of it, an export, or deletion, by writing to privacy@agecare.app. Closing an account produces a real export and a real deletion. Where the family's wish to keep history conflicts with the older adult's wish to remove it, we resolve it in favor of the older adult.

Depending on where you live, you may have additional statutory rights: under the GDPR in the EU and UK, under state privacy laws in the US, under PIPEDA in Canada, or under the Privacy Act in Australia. We honor those requests regardless of where you're writing from.

Children

AgeCare is not intended for people under 18 and we do not knowingly create records for them.

Changes

If these commitments change in a way that affects you, we'll say so in the app rather than quietly updating this page.


Questions: privacy@agecare.app. This page describes our privacy commitments and product design; it is not legal advice, and it does not replace the terms you agree to when you create an account.