Privacy Policy

Last updated: March 4, 2026

CircleCare (“we,” “us,” or “our”) is operated by Maple Ridge LLC. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the CircleCare mobile application and related services (the “Service”).

CircleCare is a family care coordination app that helps families manage medications, appointments, and emergency information for aging parents and loved ones. Because of the nature of our Service, we collect and process health-related information, which we treat with the highest level of care.


1. Information We Collect

Information You Provide

Account Information

  • Email address
  • First and last name
  • Password (encrypted, managed by our authentication provider)
  • Phone number (optional)
  • Timezone and language preference

Care Circle Information

  • Circle name (e.g., “Mom — Smith Family”)
  • Care recipient's name and date of birth
  • Circle member roles (owner, caregiver, care recipient)

Health and Medical Information

  • Medication names, dosages, and schedules
  • Medication confirmation status (taken, skipped, or missed)
  • Medical conditions and allergies
  • Blood type
  • Insurance information (carrier, policy number, group number)
  • Doctor information (name, specialty, phone, address)
  • Advance directives and DNR status
  • Appointment and task details

Emergency Contact Information

  • Names, phone numbers, and relationships of emergency contacts

Photos and Images

  • Care recipient photos
  • Medication reference photos
  • Insurance card photos

Communication Data

  • Messages sent to the AI Care Assistant (text and voice transcripts)

Information Collected Automatically

Device Information

  • Device timezone and language settings
  • Push notification token (for delivering notifications)
  • Device platform (iOS or Android)

Usage Information

  • Feature usage patterns (e.g., which screens you visit, actions you take)
  • App events (e.g., medication confirmed, circle created)
  • Error reports

We do NOT collect:

  • Precise location data
  • Contact lists or address books
  • Browsing history
  • Advertising identifiers

2. How We Use Your Information

We use your information to:

  • Provide the Service — Create and manage care circles, track medications, schedule appointments, store emergency information
  • Send Notifications — Medication reminders, confirmation alerts to family members, appointment reminders, and circle activity updates
  • Process Subscriptions — Manage your subscription status and enforce plan limits
  • Send Emails — Account verification, circle invitations, password resets, and optional email digests summarizing circle activity
  • Power the AI Assistant — Provide context-aware caregiving guidance based on your circle's medications, appointments, and activity (premium feature)
  • Improve the Service — Understand how features are used, identify bugs, and improve the user experience
  • Ensure Security — Detect fraud, enforce rate limits, and protect accounts

We do not use your health information for advertising, profiling, or any purpose unrelated to providing the Service.


3. How We Share Your Information

We share your information only with the following service providers, and only as necessary to operate the Service:

ProviderWhat They ReceivePurpose
Supabase (database & authentication)All account and circle dataData storage, user authentication, file storage
RevenueCat (subscription management)User ID, subscription statusManaging subscriptions and entitlements
Resend (email delivery)Email address, name, email contentSending account verification, invitations, and digest emails
Expo (push notifications)Device token, notification contentDelivering push notifications to your device
OpenAI (AI assistant)Chat messages, circle context (medications, appointments, activity)Powering the AI Care Assistant feature
PostHog (analytics)User ID, anonymized usage eventsUnderstanding feature usage and improving the Service
Apple / Google (app stores)Purchase transactionsProcessing subscription payments

We do NOT:

  • Sell your personal information to anyone
  • Share your health data with advertisers
  • Use your data for targeted advertising
  • Provide your information to data brokers

Within Your Care Circle

When you join a care circle, other members of that circle can see:

  • Your name and role in the circle
  • Medication confirmations and activity (e.g., “Margaret took Atorvastatin at 8:03 AM”)
  • Tasks and appointments you create or complete
  • Activity feed entries related to your actions

This sharing is fundamental to how CircleCare works — it enables families to coordinate care together.


4. How We Protect Your Information

  • Encryption in Transit — All data transmitted between your device and our servers uses HTTPS/TLS encryption
  • Encryption at Rest — Data stored in our database is encrypted at rest
  • Row-Level Security — Database access policies ensure you can only access circles you belong to
  • Secure Credential Storage — If you enable biometric login (Face ID / Touch ID), your credentials are stored in your device's secure enclave (iOS Keychain / Android Keystore) and never transmitted to our servers
  • Hashed Secrets — Invitation codes and verification codes are hashed before storage using bcrypt
  • Rate Limiting — Authentication endpoints are rate-limited to prevent brute-force attacks
  • Biometric Data — We never collect, store, or transmit your biometric data (fingerprint, face scan). Biometric authentication is handled entirely by your device's operating system

5. Data Retention

  • Active Account — We retain your data for as long as your account is active
  • Subscription Expiration — If your subscription expires, your circles enter a 14-day grace period (read-only access), after which they are archived. Archived data is preserved but not accessible until you resubscribe
  • Account Deletion — You can delete your account at any time from the Profile screen in the app. Upon deletion, we remove your account and personal data from our systems. Some data may persist in backups for up to 30 days
  • Activity Logs — Circle activity feed entries are retained for the life of the circle, as they serve as a shared care record for all circle members

6. Your Rights

Depending on where you live, you may have the following rights regarding your personal information:

All Users

  • Access — Request a copy of the personal information we hold about you
  • Correction — Update or correct inaccurate information via the app or by contacting us
  • Deletion — Delete your account and personal data from the Profile screen, or by contacting us
  • Portability — Request your data in a portable format

European Economic Area, United Kingdom, and Switzerland (GDPR)

  • Legal Basis — We process your health data based on your explicit consent (GDPR Article 9(2)(a)). We process account data based on contractual necessity (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) for security and service improvement
  • Withdraw Consent — You may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal
  • Restriction — Request that we restrict processing of your data in certain circumstances
  • Objection — Object to processing based on legitimate interests
  • Complaint — Lodge a complaint with your local data protection authority
  • Data Transfers — Your data is stored in the United States. We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure adequate protection for international data transfers. Our database provider (Supabase) has executed a Data Processing Agreement that includes these safeguards

Canada (PIPEDA)

  • Consent — We collect and use your personal information with your knowledge and consent
  • Access and Correction — You may request access to and correction of your personal information
  • Withdrawal — You may withdraw consent at any time, subject to legal or contractual restrictions
  • Complaint — You may file a complaint with the Office of the Privacy Commissioner of Canada

Australia (Privacy Act)

  • Access and Correction — You may request access to and correction of your personal information under Australian Privacy Principles (APPs)
  • Health Information — We treat medication, medical, and emergency data as “health information” under the Privacy Act and apply enhanced protections
  • Complaint — You may file a complaint with the Office of the Australian Information Commissioner (OAIC)
  • Data Transfers — Your data is stored in the United States. By using the Service, you consent to this transfer. We take reasonable steps to ensure our overseas service providers comply with the APPs

Mexico (LFPDPPP)

  • ARCO Rights — You have the right to Access, Rectify, Cancel, and Oppose the processing of your personal data
  • Consent — We obtain your consent for the collection and processing of sensitive personal data (health information)
  • Complaint — You may file a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI)

7. Children's Privacy

CircleCare is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us and we will delete it.

Note: Care recipients (e.g., aging parents) whose information is entered by caregivers are not “users” of the Service. Their information is entered and managed by authorized circle members.


8. Biometric Authentication

If you choose to enable biometric login (Face ID, Touch ID, or fingerprint), your email and password are stored in your device's secure enclave — a hardware-protected area of your device that is separate from our servers. We never receive, transmit, or store your biometric data. The biometric check is performed entirely by your device's operating system. You can disable biometric login at any time in the app settings.


9. AI Care Assistant

The AI Care Assistant is an optional premium feature that provides caregiving guidance. When you use it:

  • Your messages and relevant circle context (medications, appointments, recent activity) are sent to OpenAI for processing
  • Voice input is transcribed on your device before being sent — we do not transmit raw audio
  • Conversations are not used to train AI models
  • The AI assistant does not provide medical advice and is not a substitute for professional healthcare guidance

10. Push Notifications

We use Expo's push notification service to deliver medication reminders, family activity alerts, and other notifications. Your device's push token is stored on our servers and shared with Expo solely for the purpose of delivering notifications. You can disable notifications at any time through your device settings or the app's notification preferences.


11. Subscription and Payments

Subscription payments are processed entirely by Apple (App Store) or Google (Google Play). We do not collect or store credit card numbers, billing addresses, or payment method details. We receive only your subscription status (active, expired, trial) through RevenueCat, which acts as an intermediary with the app stores.


12. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.


13. Contact Us

If you have questions about this Privacy Policy or want to exercise your rights, contact us at:

Maple Ridge LLC
5900 Balcones Drive, Suite 100
Austin, TX 78731
Email: privacy@circlecare.app

For GDPR inquiries, you may also contact your local supervisory authority.
For PIPEDA inquiries, contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
For Australian Privacy Act inquiries, contact the OAIC at www.oaic.gov.au.
For Mexican data protection inquiries, contact INAI at www.inai.org.mx.


14. Spanish Version / Versión en Español

A Spanish-language version of this Privacy Policy is available at circlecare.app/privacy/es.

Una versión en español de esta Política de Privacidad está disponible en circlecare.app/privacy/es.