Privacy
Privacy commitments
AgeCare handles health information about older adults, some of whom have reduced capacity to consent, and some of whom are being watched over by relatives acting with the best of intentions. That combination deserves care, and it deserves plain language.
This page states our commitments and how the product is designed. It is written to be read, not to be survived. If anything here is unclear, or you think we've fallen short of it, write to privacy@agecare.app.
Who owns the record
The person being cared for is the data subject, and the product treats them that way even when a relative is the one paying. They own their care record. Coordinator status is granted by them and is transferable. Where a person cannot consent for themselves, a documented proxy-consent path records who consented, on what basis and when, with periodic re-confirmation.
What we collect
| Category | Examples | Why |
|---|---|---|
| Account | Name, email, role, the care network you belong to | To sign you in and to know which record you may open |
| Care data | Medications and doses, vital readings, appointments, tasks, visit notes, messages, documents | This is the record itself, the thing the product exists to keep |
| Safety signals | Check-ins, coarse activity signals, a safe-zone label, device battery | Only when switched on, and visible to the person they describe |
| Location | Position fixes and the safe zones drawn around them, while location sharing is on | To answer "has she left a boundary she agreed to?" — held for seven days, then deleted |
| Technical | Device type, app version, crash diagnostics | To keep the app working. Never joined to health content |
We practice data minimisation deliberately: a derived signal ("quiet for 3 h 40 min") is preferred to a continuous raw feed, and most of the product needs only a coarse label and a safe-zone flag rather than a coordinate.
Location is the exception, and it is fenced off accordingly. A boundary test and a map of the zones cannot be computed without coordinates, so they are kept — in one place, reachable only through the location permission scope, and for seven days. Sharing runs on a ladder rather than a switch: continuous, a check every few minutes, alerts only — where the geofence still runs but no routine position is ever written and the family sees no map and no history — or off, where nothing is collected and no alert can fire. The person being located chooses which, and can change it at any time.
Who can see it
Access is deny by default. New data is invisible until someone is explicitly granted it, through ten permission scopes the record's owner or coordinator controls, each explained in plain language. Revoking a grant takes effect immediately, on the next screen the other person opens.
Scopes are deliberately narrow. A caregiver does not need financial data. A clinician does not need family conversations. Professional access is time-bounded and lapses with the assignment it came from. Enforcement belongs in the database, not only in the interface.
What we never do
- We do not sell health data, and we do not run advertising.
- We do not use your care record to train models for anyone else's benefit.
- We do not enable covert monitoring: if a signal is on, the person it describes can see that it is on.
- We do not diagnose, and we do not contact emergency services.
Audit
Certain events deserve an append-only log that the older adult and their coordinator can read, not only operators. That list is: every read of an emergency profile, every permission grant and revocation with actor and timestamp, every document view and share, every export, and every access to location or activity data.
Security
TLS in transit; encryption at rest for the database and for document storage; short-lived signed URLs for document access; secrets held in a managed store; and a documented key-rotation procedure. Where a protection is planned rather than in place, the app says so on the screen concerned rather than implying safety that does not yet exist.
How long we keep things
| Data | Retention |
|---|---|
| Location and device telemetry | 7 to 30 days |
| Activity and inactivity signals | 90 days |
| Vital readings, doses, appointments | While the record is active; belongs to the older adult |
| Messages | Retained; deletable by participants |
| Documents | Until deleted by the owner |
| Audit logs | Longer than the data they describe |
Your rights
You can request access to your data, correction of it, an export, or deletion, by writing to privacy@agecare.app. Closing an account produces a real export and a real deletion. Where the family's wish to keep history conflicts with the older adult's wish to remove it, we resolve it in favor of the older adult.
Depending on where you live, you may have additional statutory rights: under the GDPR in the EU and UK, under state privacy laws in the US, under PIPEDA in Canada, or under the Privacy Act in Australia. We honor those requests regardless of where you're writing from.
Children
AgeCare is not intended for people under 18 and we do not knowingly create records for them.
Changes
If these commitments change in a way that affects you, we'll say so in the app rather than quietly updating this page.
Questions: privacy@agecare.app. This page describes our privacy commitments and product design; it is not legal advice, and it does not replace the terms you agree to when you create an account.