Privacy Policy
Last updated: March 4, 2026
CircleCare (“we,” “us,” or “our”) is operated by Maple Ridge LLC. This Privacy Policy explains how we collect, use, share, and protect your personal information when you use the CircleCare mobile application and related services (the “Service”).
CircleCare is a family care coordination app that helps families manage medications, appointments, and emergency information for aging parents and loved ones. Because of the nature of our Service, we collect and process health-related information, which we treat with the highest level of care.
1. Information We Collect
Information You Provide
Account Information
- Email address
- First and last name
- Password (encrypted, managed by our authentication provider)
- Phone number (optional)
- Timezone and language preference
Care Circle Information
- Circle name (e.g., “Mom — Smith Family”)
- Care recipient's name and date of birth
- Circle member roles (owner, caregiver, care recipient)
Health and Medical Information
- Medication names, dosages, and schedules
- Medication confirmation status (taken, skipped, or missed)
- Medical conditions and allergies
- Blood type
- Insurance information (carrier, policy number, group number)
- Doctor information (name, specialty, phone, address)
- Advance directives and DNR status
- Appointment and task details
Emergency Contact Information
- Names, phone numbers, and relationships of emergency contacts
Photos and Images
- Care recipient photos
- Medication reference photos
- Insurance card photos
Communication Data
- Messages sent to the AI Care Assistant (text and voice transcripts)
Information Collected Automatically
Device Information
- Device timezone and language settings
- Push notification token (for delivering notifications)
- Device platform (iOS or Android)
Usage Information
- Feature usage patterns (e.g., which screens you visit, actions you take)
- App events (e.g., medication confirmed, circle created)
- Error reports
We do NOT collect:
- Precise location data
- Contact lists or address books
- Browsing history
- Advertising identifiers
2. How We Use Your Information
We use your information to:
- Provide the Service — Create and manage care circles, track medications, schedule appointments, store emergency information
- Send Notifications — Medication reminders, confirmation alerts to family members, appointment reminders, and circle activity updates
- Process Subscriptions — Manage your subscription status and enforce plan limits
- Send Emails — Account verification, circle invitations, password resets, and optional email digests summarizing circle activity
- Power the AI Assistant — Provide context-aware caregiving guidance based on your circle's medications, appointments, and activity (premium feature)
- Improve the Service — Understand how features are used, identify bugs, and improve the user experience
- Ensure Security — Detect fraud, enforce rate limits, and protect accounts
We do not use your health information for advertising, profiling, or any purpose unrelated to providing the Service.
3. How We Share Your Information
We share your information only with the following service providers, and only as necessary to operate the Service:
| Provider | What They Receive | Purpose |
|---|---|---|
| Supabase (database & authentication) | All account and circle data | Data storage, user authentication, file storage |
| RevenueCat (subscription management) | User ID, subscription status | Managing subscriptions and entitlements |
| Resend (email delivery) | Email address, name, email content | Sending account verification, invitations, and digest emails |
| Expo (push notifications) | Device token, notification content | Delivering push notifications to your device |
| OpenAI (AI assistant) | Chat messages, circle context (medications, appointments, activity) | Powering the AI Care Assistant feature |
| PostHog (analytics) | User ID, anonymized usage events | Understanding feature usage and improving the Service |
| Apple / Google (app stores) | Purchase transactions | Processing subscription payments |
We do NOT:
- Sell your personal information to anyone
- Share your health data with advertisers
- Use your data for targeted advertising
- Provide your information to data brokers
Within Your Care Circle
When you join a care circle, other members of that circle can see:
- Your name and role in the circle
- Medication confirmations and activity (e.g., “Margaret took Atorvastatin at 8:03 AM”)
- Tasks and appointments you create or complete
- Activity feed entries related to your actions
This sharing is fundamental to how CircleCare works — it enables families to coordinate care together.
4. How We Protect Your Information
- Encryption in Transit — All data transmitted between your device and our servers uses HTTPS/TLS encryption
- Encryption at Rest — Data stored in our database is encrypted at rest
- Row-Level Security — Database access policies ensure you can only access circles you belong to
- Secure Credential Storage — If you enable biometric login (Face ID / Touch ID), your credentials are stored in your device's secure enclave (iOS Keychain / Android Keystore) and never transmitted to our servers
- Hashed Secrets — Invitation codes and verification codes are hashed before storage using bcrypt
- Rate Limiting — Authentication endpoints are rate-limited to prevent brute-force attacks
- Biometric Data — We never collect, store, or transmit your biometric data (fingerprint, face scan). Biometric authentication is handled entirely by your device's operating system
5. Data Retention
- Active Account — We retain your data for as long as your account is active
- Subscription Expiration — If your subscription expires, your circles enter a 14-day grace period (read-only access), after which they are archived. Archived data is preserved but not accessible until you resubscribe
- Account Deletion — You can delete your account at any time from the Profile screen in the app. Upon deletion, we remove your account and personal data from our systems. Some data may persist in backups for up to 30 days
- Activity Logs — Circle activity feed entries are retained for the life of the circle, as they serve as a shared care record for all circle members
6. Your Rights
Depending on where you live, you may have the following rights regarding your personal information:
All Users
- Access — Request a copy of the personal information we hold about you
- Correction — Update or correct inaccurate information via the app or by contacting us
- Deletion — Delete your account and personal data from the Profile screen, or by contacting us
- Portability — Request your data in a portable format
European Economic Area, United Kingdom, and Switzerland (GDPR)
- Legal Basis — We process your health data based on your explicit consent (GDPR Article 9(2)(a)). We process account data based on contractual necessity (Article 6(1)(b)) and legitimate interests (Article 6(1)(f)) for security and service improvement
- Withdraw Consent — You may withdraw consent at any time by deleting your account. Withdrawal does not affect the lawfulness of processing before withdrawal
- Restriction — Request that we restrict processing of your data in certain circumstances
- Objection — Object to processing based on legitimate interests
- Complaint — Lodge a complaint with your local data protection authority
- Data Transfers — Your data is stored in the United States. We rely on Standard Contractual Clauses (SCCs) as approved by the European Commission to ensure adequate protection for international data transfers. Our database provider (Supabase) has executed a Data Processing Agreement that includes these safeguards
Canada (PIPEDA)
- Consent — We collect and use your personal information with your knowledge and consent
- Access and Correction — You may request access to and correction of your personal information
- Withdrawal — You may withdraw consent at any time, subject to legal or contractual restrictions
- Complaint — You may file a complaint with the Office of the Privacy Commissioner of Canada
Australia (Privacy Act)
- Access and Correction — You may request access to and correction of your personal information under Australian Privacy Principles (APPs)
- Health Information — We treat medication, medical, and emergency data as “health information” under the Privacy Act and apply enhanced protections
- Complaint — You may file a complaint with the Office of the Australian Information Commissioner (OAIC)
- Data Transfers — Your data is stored in the United States. By using the Service, you consent to this transfer. We take reasonable steps to ensure our overseas service providers comply with the APPs
Mexico (LFPDPPP)
- ARCO Rights — You have the right to Access, Rectify, Cancel, and Oppose the processing of your personal data
- Consent — We obtain your consent for the collection and processing of sensitive personal data (health information)
- Complaint — You may file a complaint with the Instituto Nacional de Transparencia, Acceso a la Información y Protección de Datos Personales (INAI)
7. Children's Privacy
CircleCare is not intended for children under 16. We do not knowingly collect personal information from children under 16. If you believe a child under 16 has provided us with personal information, please contact us and we will delete it.
Note: Care recipients (e.g., aging parents) whose information is entered by caregivers are not “users” of the Service. Their information is entered and managed by authorized circle members.
8. Biometric Authentication
If you choose to enable biometric login (Face ID, Touch ID, or fingerprint), your email and password are stored in your device's secure enclave — a hardware-protected area of your device that is separate from our servers. We never receive, transmit, or store your biometric data. The biometric check is performed entirely by your device's operating system. You can disable biometric login at any time in the app settings.
9. AI Care Assistant
The AI Care Assistant is an optional premium feature that provides caregiving guidance. When you use it:
- Your messages and relevant circle context (medications, appointments, recent activity) are sent to OpenAI for processing
- Voice input is transcribed on your device before being sent — we do not transmit raw audio
- Conversations are not used to train AI models
- The AI assistant does not provide medical advice and is not a substitute for professional healthcare guidance
10. Push Notifications
We use Expo's push notification service to deliver medication reminders, family activity alerts, and other notifications. Your device's push token is stored on our servers and shared with Expo solely for the purpose of delivering notifications. You can disable notifications at any time through your device settings or the app's notification preferences.
11. Subscription and Payments
Subscription payments are processed entirely by Apple (App Store) or Google (Google Play). We do not collect or store credit card numbers, billing addresses, or payment method details. We receive only your subscription status (active, expired, trial) through RevenueCat, which acts as an intermediary with the app stores.
12. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the app or by email before the changes take effect. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
13. Contact Us
If you have questions about this Privacy Policy or want to exercise your rights, contact us at:
Maple Ridge LLC
5900 Balcones Drive, Suite 100
Austin, TX 78731
Email: privacy@circlecare.app
For GDPR inquiries, you may also contact your local supervisory authority.
For PIPEDA inquiries, contact the Office of the Privacy Commissioner of Canada at www.priv.gc.ca.
For Australian Privacy Act inquiries, contact the OAIC at www.oaic.gov.au.
For Mexican data protection inquiries, contact INAI at www.inai.org.mx.
14. Spanish Version / Versión en Español
A Spanish-language version of this Privacy Policy is available at circlecare.app/privacy/es.
Una versión en español de esta Política de Privacidad está disponible en circlecare.app/privacy/es.