Privacy Policy
Effective Date: August 25, 2026
CarePerch ("we," "us," or "our") is a personal caregiver medication-record application. This Privacy Policy explains what information the CarePerch mobile application ("App") processes, why it is used, who receives it, and the choices available to you.
1. What Data We Collect
Account and profile information
- Name, email address, optional phone number, optional profile photo, and authentication-provider identifiers.
- Account status, onboarding state, subscription tier, and subscription expiration.
Care and medication records
- Names and profiles of loved ones, relationship, timezone, optional date of birth, allergies, notes, and emergency contacts.
- Medication names, dosage, form, route, instructions, schedules, refill details, administration outcomes, timestamps, reasons, notes, side effects, and reversal history.
- Caregiver invitations, assignments, roles, handoff notes, and the identity of the person who recorded an action.
Device, notification, and purchase information
- An Expo push token and device platform if you enable remote notifications.
- App account identifier, Apple product identifier, entitlement, purchase state, transaction identifier, and subscription dates needed to provide paid access.
- Label photos selected for medication scanning are processed on the device and are not uploaded by the scanner. A profile photo is uploaded only if you choose to save one.
Medication lookup information
- When you search for a medication, the medication text you type may be sent to the U.S. National Library of Medicine's RxTerms service to return matching names.
- When you check potential medication interactions, medication names or RxNorm identifiers may be sent to the U.S. National Library of Medicine's RxNorm service and the U.S. Food and Drug Administration's openFDA service to retrieve standardized names and drug-label information.
- CarePerch does not include your CarePerch account identifier, loved-one name, caregiver identity, dose history, or handoff-note content in those lookup requests. The service operators may receive ordinary network information such as your IP address under their own privacy policies.
This release does not include third-party advertising, analytics, or crash-reporting SDKs, and CarePerch does not track you across other companies' apps or websites.
2. How We Use Your Data
We process this information to:
- Create, synchronize, display, export, and protect the caregiver medication record.
- Schedule reminders and, if enabled, deliver account-bound notifications.
- Enforce caregiver, loved-one, device, and subscription access boundaries.
- Process purchases, restores, renewals, cancellations, refunds, and expiration.
- Authenticate accounts, prevent abuse, recover from failed operations, and respond to support or legal requests.
3. When Data Is Shared
We do not sell personal data. We share information only as needed to provide the App or comply with law:
- Caregivers you authorize: An invited caregiver can access only the loved ones and actions permitted by their assignment and role.
- Supabase: Provides authentication, database, file storage, and server functions for CarePerch account and care records.
- RevenueCat: Processes subscription status using an App account identifier and purchase information. CarePerch does not send medication, loved-one, caregiver-note, or dose-record content to RevenueCat.
- Apple: Processes App Store purchases and, if selected, Sign in with Apple. Apple controls its own processing under its privacy terms.
- Google: Receives authentication information only if you choose Google sign-in. Google controls its own processing under its privacy terms.
- Expo: Provides a device push token used to route remote notifications when you enable them. Notification content is limited to what the App needs to deliver the reminder.
- U.S. National Library of Medicine (NIH/NLM): RxTerms and RxNorm receive medication search text, names, or identifiers only when needed to provide medication-name suggestions or normalize a medication for an interaction check. CarePerch does not attach your CarePerch account identifier to these requests.
- U.S. Food and Drug Administration (FDA): openFDA receives medication names or identifiers only when needed to retrieve public drug-label information for an interaction check. CarePerch does not attach your CarePerch account identifier to these requests.
- Legal and safety requests: We may disclose information when required by applicable law or a valid legal process, or when necessary to protect rights and safety.
4. Data Security
CarePerch uses safeguards designed to reduce unauthorized access, including:
- Encrypted network connections to service providers.
- Supabase authentication, row-level database policies, storage policies, and server-only subscription/deletion operations.
- Person-scoped caregiver roles, immediate access revocation, and account-bound notification tokens.
- On-device protected storage for limited session and recovery state.
No security method is perfect. If you believe your account or data is at risk, contact us promptly.
5. Your Choices and Rights
Depending on your jurisdiction, you may have the following rights:
- Access and correction: Review or update profile and care information available in the App.
- Export: Export available medication administration records from the App.
- Notifications and photos: Decline or revoke device permissions in iOS Settings.
- Caregiver access: Change or revoke a caregiver's assigned access.
- Deletion: Start account deletion from Settings in the App.
You may also contact us to ask about access, correction, portability, or deletion rights available where you live.
6. Data Retention
Account and care records are retained while your account is active so they remain available across authorized devices. A subscription lapse or downgrade does not erase existing medication or audit records.
Account deletion first blocks new account activity, then removes CarePerch file storage, application records, the RevenueCat customer record, linked provider access when supported, and push-token ownership; the authentication identity is deleted last. If Apple or Google requires a manual disconnect, the App keeps a deletion receipt so you can finish or verify that step after sign-out. A minimal deletion tombstone and operational proof may be retained to prevent deleted-account recreation, recover a deletion request, meet security obligations, or comply with law. CarePerch does not retain medication or caregiver content in that tombstone.
7. Children's Privacy
CarePerch accounts are not intended for children under 13. An adult caregiver may enter information about a loved one, including a child, when they have authority to do so. If you believe a child created an account or information was provided without authority, contact us.
8. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated through the App or via email. Your continued use of the App after changes indicates acceptance of the updated policy.
Contact Us
If you have questions about this Privacy Policy, please contact us at:
Email: privacy@careperch.app