Back to Great Care

Privacy Policy

Version 2.1 · Effective September 4, 2026

Who we are

Great Care is operated by [Operator legal name], a sole proprietorship located at [Postal address, City, Country] ("Great Care", "we", "us"). Great Care helps families and caregivers keep medical and caregiving information for the people they care for in one private, access-controlled place.

For personal family accounts, we are the controller of the personal information you give us. We have not appointed a data protection officer or an EU/UK representative because our size does not currently require one; the operator personally handles privacy requests. Contact: privacy@greatcare.app.

This policy is written in plain language on purpose. If anything is unclear, ask us.

Health information, up front

Much of what you store in Great Care is health information about you or the people you care for: medications, conditions, allergies, healthcare contacts, health-card photos, appointment recordings. We treat all of it as sensitive data.

We process it only to provide the Service to you and the people you invite, on the basis of your explicit consent. You give that consent when you enter the information, when you invite someone into your group, and when you choose to record an appointment. You can withdraw consent at any time by deleting the information, leaving the group, or asking us to delete your account.

What we collect

Account details: your name, email address, phone and WhatsApp number if you add them, your role in each family group, and your sign-in credentials. Passwords are stored only as a hash by our authentication provider. If your group uses a shared family PIN, that 4-digit PIN is stored with the group and can be seen by group members. If you add a passkey (Face ID, Touch ID, fingerprint), we store only a public key and a device label; your biometrics never leave your device.

Care information you enter: profiles of the people you care for (including any photo of their health card and its number), medications and schedules, allergies, conditions, healthcare contacts, appointments (including calendar events you import from a link you provide), tasks, comments, documents and photos you upload, notes, and care locations or addresses.

Appointment recordings: if you use the recording feature, the audio you capture, the transcript, and the AI-generated summary.

AI assist inputs: the medication names you look up and the free text you type into quick-add, which are sent to our AI provider to produce the result.

Technical information: the server and platform logs kept by our hosting providers, your IP address (used to limit abuse), and an append-only audit record of changes to care data. We do not use analytics, advertising trackers, or third-party error reporting.

Billing information: when a group admin chooses a paid plan, Paddle (our merchant of record) collects and stores the card details and your billing country for tax; we never see the full card number. We receive and keep billing metadata only: the plan, its status, the renewal date and the Paddle customer and subscription identifiers. Paddle processes this under its own privacy policy. We also keep a usage meter per group (minutes transcribed, AI actions, storage used) to apply plan allowances and to understand our costs; it holds counts and timestamps, never the content.

How we use it, and our legal bases

To provide the Service: storing your care information and syncing it with the caregivers you invite. Basis: performance of our contract with you.

To process health information and recordings for features you choose to use, such as transcription, summaries, and medication look-ups. Basis: your explicit consent.

To keep the Service secure, prevent abuse, diagnose problems, and recover data after mistakes. Basis: our legitimate interest in running a safe, working service.

To meet legal, tax, and accounting obligations. Basis: legal obligation.

We do not sell your personal or health information, we do not share it for cross-context behavioural advertising, and we make no automated decisions about you that have legal or similarly significant effects. AI-generated content is a convenience for you to review, not a decision.

Who can see your information

Members of your family group can see the care information in that group. Group admins choose who is invited and who else is an admin. If your group uses a shared PIN, anyone who knows the PIN and a member email can sign in as that member, so treat the PIN like a house key.

Care Links: a member can create a read-only web link for one person that shows only the sections they choose (for example medications and allergies for a babysitter). Anyone with the link can view those sections until it expires or is turned off; the link is unguessable but not password-protected, so share it only with people you trust. We count how many times a link is opened and show that to the family. Documents and photos are never included in a Care Link.

Service providers (subprocessors) process information only to provide their service to us: hosting and database, file storage, transcription, AI summaries, transactional email, and address search. The current list, what each one receives, and where it operates is on our Trust page. We give 30 days’ notice on that page before adding a new subprocessor.

Calendar import: when you paste a calendar link (for example from Google or Outlook), our server fetches that link on your behalf. We do not store your calendar credentials.

Legal reasons: we may disclose information if required by law, or to protect the rights, safety, or property of our users, the public, or us.

Cookies and local storage

We use only strictly necessary cookies: the session cookies set by our authentication provider so you stay signed in. We store a few preferences in your browser (for example the last email you signed in with, your preferred sign-in method, and which banners you have dismissed). There are no analytics or advertising cookies, so no cookie banner is needed.

Where your data is processed

Your data is stored in the region of our database provider’s project. Some subprocessors, including our transcription, AI, and email providers, operate in the United States, so using those features transfers the relevant data there.

Where personal data leaves the EU, UK, Switzerland, or another jurisdiction with transfer rules, we rely on the provider’s data processing terms, which incorporate the EU Standard Contractual Clauses and the UK addendum, or on an adequacy decision where one applies.

How your data is protected

Data travels over encrypted connections (HTTPS) and is encrypted at rest by our database and storage provider.

Access to a family’s data is enforced both by database row-level security and by server-side membership checks on every request.

Every change to care data is written to an append-only audit log so accidental deletions can usually be recovered. The app signs you out after a period of inactivity. Passkeys are available so you can sign in without a password that could be phished.

No system is perfectly secure. Use a passkey or a strong password, and sign out on shared devices.

How long we keep it

While your account is active, we keep your information so the Service works.

When you delete a record in the app, it is removed from the live database immediately. A copy remains in the audit log for up to 90 days so an accidental deletion can be undone, then it is removed.

When you delete your account (or ask us to), the records, their audit-log copies, and any stored recording audio and documents are removed immediately for groups that had no other members; within 30 days at the latest in every other case. Our database provider’s backups roll off on the provider’s standard schedule after that.

We may keep limited records where the law requires it, for example billing records if paid plans exist.

Your rights and choices

In the app you can view, edit, and delete any care information you have entered, turn off any Care Link, remove members from a group you administer, and export a printable care summary for each person.

You can delete your account yourself from Settings → Danger zone → Delete my account. Groups where you are the only member are deleted with all their data, recordings and documents at the same time. For a full machine-readable copy of your family’s data first, email privacy@greatcare.app from the address on your account; we complete export requests within 30 days after confirming your identity.

Depending on where you live, you also have rights to access, correct, delete, restrict, or object to processing, to data portability, and to withdraw consent. We will respond within one month (GDPR/UK GDPR), 45 days (California), or the period your local law sets.

Complaints: in the EU you may contact your national data protection authority; in the UK, the Information Commissioner’s Office; in Canada, the Office of the Privacy Commissioner; in Australia, the Office of the Australian Information Commissioner. We would appreciate the chance to resolve your concern first.

California residents (CCPA/CPRA)

Notice at collection: in the past 12 months we have collected the categories listed under “What we collect”: identifiers, contact details, health information (sensitive personal information), user-generated content, and internet activity limited to server logs. Sources: you and the members of your group. Purposes: those listed under “How we use it”. Recipients: the subprocessors on our Trust page.

We do not sell personal information and we do not share it for cross-context behavioural advertising. We use sensitive personal information only to provide the Service you ask for, so no “Limit the Use of My Sensitive Personal Information” link is required.

You have the right to know, delete, and correct your personal information, and the right not to be discriminated against for exercising these rights. Email privacy@greatcare.app; an authorised agent may act for you with written permission. We verify requests by confirming the email on the account.

HIPAA

For families and individual caregivers, Great Care is not a HIPAA covered entity or business associate, and HIPAA does not apply to the information you choose to store. Your rights come from this policy and the privacy laws of where you live.

If you are a healthcare provider or agency that is a HIPAA covered entity, do not upload protected health information unless you have a signed Business Associate Agreement with us. We do not offer one today; contact us before using the Service in that setting.

Canada and Australia

Canada: we are accountable for personal information in our control and rely on meaningful consent as described above. Information may be processed in the United States by the providers on our Trust page and may be subject to the laws there.

Australia: this policy is our APP 1 privacy policy. Overseas recipients are located in the United States and the European Union. If a data breach is likely to cause serious harm, we will notify you and the OAIC as the Notifiable Data Breaches scheme requires.

Business customers

If a home-care agency or other organisation subscribes and enters information about its clients, the organisation is the controller and Great Care is its processor. A data processing agreement with the standard Article 28 terms is available on request, and the organisation is responsible for having a lawful basis and any consents it needs.

Today, the family group is the only boundary in the product: there is no separate organisation-level account. Organisations should keep that in mind when deciding what to enter.

Data breaches

If a breach affects your personal data, we will notify you without undue delay and notify the relevant regulator within 72 hours where GDPR or UK GDPR applies, or within the period your local law requires.

Children

Accounts are for adults (18 or older). The people you care for may be children; an adult with authority over their care enters that information. We do not knowingly let anyone under 18 create an account and we do not direct the Service at children. If you believe a child has created an account, email us and we will remove it.

Changes to this policy

We may update this policy as the product evolves. For material changes we will give at least 14 days’ notice in the app or by email before they take effect, and we keep the version number and effective date below current.

Contact us

Email privacy@greatcare.app, or write to [Operator legal name], [Postal address, City, Country].

See also our Terms of Service and Trust & Security page. This policy was drafted with AI assistance and independently checked against how the app actually works; it is not legal advice.