Your Privacy Matters
At Collective Care Compass, we understand that you are trusting us with deeply personal information about your health and wellbeing. This Privacy Policy explains how we collect, use, protect, and share your information. We are committed to transparency and giving you control over your data.
1. Information We Collect
1.1 Account Information
When you create an account, we collect:
- Email address (required)
- Password (hashed with bcrypt, never stored in plain text)
- Phone number (optional, for SMS notifications)
- Name (required for personalization)
- Role (caregiver or care recipient)
- Faith tradition preference (optional)
1.2 Personal Health Information
With your explicit consent, we collect personal health information you choose to enter:
- Medication names, dosages, and schedules
- Medical appointments and doctor notes
- Symptoms and mood tracking data
- Health conditions and diagnoses
- Care recipient information (if you are a caregiver)
- Insurance information and documents
- Medical test results and reports
Important: This app is a personal care coordination tool. It is not operated by or on behalf of a hospital, insurer, or healthcare provider. You enter your own information by choice, and you control it.
1.3 Journal and Emotional Wellbeing Data
We collect content you create:
- Journal entries and reflections
- AI chat conversations (with consent)
- Mood ratings and stress levels
- Body stress tracking data
- Gratitude logs and affirmations
1.4 Usage and Technical Data
To improve our Service, we collect:
- Device type and operating system
- Browser type and version
- IP address (anonymized after 30 days)
- Pages visited and features used
- Error logs and crash reports
- Performance metrics
1.5 Calendar Integration Data
If you connect external calendars (Google, Outlook, iCal):
- Calendar event titles and descriptions
- Event dates, times, and locations
- Attendee information
- Access tokens (encrypted and securely stored)
2. How We Use Your Information
2.1 Core Service Delivery
We use your information to:
- Create and maintain your account
- Provide medication reminders and appointment notifications
- Generate personalized insights and reflections
- Facilitate care team collaboration
- Sync with external calendars
- Create medical reports and summaries
2.2 AI Features (With Your Consent)
If you opt in to AI features, we use your data to:
- Provide AI-powered reflection and emotional support
- Translate complex medical language into plain terms
- Generate doctor visit summaries
- Detect patterns in mood and symptoms
- Provide faith-based affirmations and resources
Important: AI processing is done via OpenAI's API. Your data is sent to OpenAI servers for processing but is NOT used to train their models (we use their zero-retention API).
2.3 Communication
We use your contact information to:
- Send appointment and medication reminders
- Notify you of care team activity
- Send security alerts
- Respond to support requests
- Send service updates (with opt-out option)
2.4 Security and Accountability
We process your data to:
- Maintain security audit logs to detect and investigate unauthorized access
- Detect and prevent fraud or abuse
- Enforce our Terms of Service
- Comply with legal obligations
2.5 Analytics and Improvement
We use aggregated, anonymized data to:
- Understand which features are most helpful
- Improve user experience and design
- Fix bugs and optimize performance
- Develop new features
Note: We NEVER sell your data. We NEVER use health information for advertising. Aggregated analytics contain no personally identifiable information.
3. How We Share Your Information
3.1 With Your Care Team (With Your Permission)
You control who sees your health information:
- You explicitly invite each care team member
- You set granular permissions for each person
- You can revoke access at any time
- We log all access for your review
3.2 With Service Providers
We work with trusted service providers who help us operate:
- Database Hosting: Neon (PostgreSQL database)
- App Hosting: Replit (application infrastructure)
- AI Services: OpenAI (for AI features, zero-retention API)
- SMS Notifications: Twilio (only if you opt in to SMS)
- Email Services: Resend (for transactional emails)
- Medication Barcode Lookups: RxNav, the free drug directory run by the U.S. National Library of Medicine (only when you scan a barcode)
Each provider has their own security and privacy practices. We select providers with strong data protection track records and use them only for the specific purpose listed above.
More on medication barcode lookups
Most scans never leave our system. We already store the common medications, so we usually recognize the code ourselves.
When we do not recognize it, our server asks RxNav what drug the code belongs to. Three things are true about that:
- The request goes from our server, not from your phone or computer.
- We send the number printed on the barcode and nothing else. No name, no birthdate, no note about who takes the medication or why.
- We have no account with RxNav, so there is nothing there that ties one lookup to another, or to you.
RxNav is a public service of the U.S. government and is free to use. We chose it because a barcode is only useful if something can tell us what it means, and a public directory is the option that asks the least of you.
3.3 Legal Requirements
We may disclose information if legally required:
- To comply with court orders or subpoenas
- To protect our legal rights
- To prevent harm or illegal activity
- In response to lawful government requests
We will notify you of such requests unless prohibited by law.
3.4 Business Transfers
If we are acquired or merged with another company, your information may be transferred. We will notify you 30 days in advance and you can delete your account before the transfer.
3.5 We NEVER Share For:
- Advertising or marketing by third parties
- Selling to data brokers
- Training AI models (yours or anyone else's)
- Non-consensual research
4. How We Protect Your Information
4.1 Encryption
We encrypt sensitive authentication data:
- In Transit: TLS 1.3 (HTTPS) for all connections
- Passwords: Bcrypt hashing (never stored in plain text)
- 2FA Secrets: AES-256-GCM encryption
- Session Tokens: Secure, httpOnly cookies
- Calendar Access Tokens: Encrypted before storage
Honest note: Health content you enter (medications, journal entries, symptoms) is stored in a secured database but is not individually encrypted at the field level at this time. It is protected by access controls, consent gating, and secure infrastructure, and we are working toward field-level encryption in a future update.
4.2 Access Controls
We limit access to your data:
- Role-based access control (RBAC)
- Multi-factor authentication (2FA) support
- Session timeouts after inactivity
- Consent gating on all health-adjacent routes
- Audit logging of account and access events
4.3 Security Practices
We follow industry best practices:
- Regular security reviews
- Vulnerability scanning and patching
- Incident response plan
- Regular backups
4.4 Breach Notification
If a data breach occurs, we will:
- Notify affected users within 72 hours
- Report to regulatory authorities as required by applicable law
- Provide details about what was compromised
- Offer remediation steps (password reset, session invalidation)
5. Your Privacy Rights
5.1 Access and Export
You have the right to:
- View all data we have about you
- Export your data in machine-readable format (JSON)
- Receive a copy of your health records
Access these features in Settings > Privacy > Data Export
5.2 Correction and Update
You can update or correct your information at any time through the app or by contacting support.
5.3 Deletion
You can delete your account and all associated data:
- Go to Settings > Account > Delete Account
- Confirm deletion (irreversible action)
- Your data, including audit logs, is permanently deleted
- Deletion from backups completes within 90 days
5.4 Portability
You can export your data to use with other services. We provide data in standard formats.
5.5 Consent Management
You control your consent preferences:
- Opt in or out of AI features at any time
- Manage health information sharing with care team members
- Control marketing communications
- Adjust SMS notification preferences
Manage these in Settings > Privacy > Consent Preferences
6. Data Retention
We retain your data as follows:
- Active Accounts: Data retained while your account is active
- Deleted Accounts: All data including audit logs is permanently deleted when you delete your account
- Backups: Deleted from backups within 90 days
- Analytics: Aggregated, anonymized data retained indefinitely
7. Children's Privacy
Our Service is not intended for children under 18. If a child is a care recipient, their legal guardian must create and manage the account.
If we discover that we have collected information from a child under 18 without parental consent, we will delete it immediately.
8. International Data Transfers
Our servers are located in the United States. If you access our Service from outside the US:
- Your data will be transferred to and stored in the US
- We strive to honor the privacy rights of EU users consistent with GDPR principles
- We strive to honor the privacy rights of Canadian users consistent with PIPEDA principles
- Data transfers use Standard Contractual Clauses (SCCs) where applicable
9. Cookies and Tracking
9.1 Essential Cookies
We use essential cookies for:
- Session management (keeping you logged in)
- Security (CSRF protection)
- Remembering your preferences
9.2 Analytics
We use privacy-focused analytics (no third-party tracking):
- No cookies for analytics (server-side only)
- No third-party analytics services
- IP addresses anonymized after 30 days
9.3 No Advertising Cookies
We do NOT use advertising cookies or trackers. We do NOT sell your data to advertisers.
10. Third-Party Links
Our Service may contain links to third-party websites (support groups, resources). We are not responsible for their privacy practices. Please review their privacy policies.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do:
- We will update the "Last Updated" date
- We will notify you via email
- Material changes require 30 days notice
- You can review past versions upon request
12. Applicable Privacy Frameworks
Collective Care Compass is a personal care coordination tool, not a healthcare provider, health insurer, or their contractor. As a result, HIPAA's Privacy and Security Rules do not directly apply to this app. Instead, the following frameworks guide our obligations:
12.1 FTC Health Breach Notification Rule (United States)
As a personal health record application, we are subject to the FTC's Health Breach Notification Rule. If a breach of your identifiable health information occurs, we are required to notify:
- You, promptly and without unreasonable delay
- The FTC, if the breach affects 500 or more people
- Prominent media outlets in affected states where appropriate
12.2 California Confidentiality of Medical Information Act (CMIA)
For California residents, the CMIA provides additional protections for medical information. Under CMIA:
- We will not share your medical information without your authorization
- We will not sell your medical information
- You can request access to and correction of your information
- You have the right to know what information we hold about you
12.3 PIPEDA (Canada)
For Canadian users, we follow the principles of the Personal Information Protection and Electronic Documents Act:
- Consent for collection and use of personal information
- Access to and correction of personal information
- Safeguards for personal information
- Openness about privacy practices
12.4 GDPR (European Union)
For EU users, we provide:
- Right to access, rectify, and erase data
- Right to data portability
- Right to object to processing
- Data Protection Impact Assessments
13. Contact Us
If you have questions about your privacy or want to exercise your rights:
Privacy Team
Email: privacy@collectivecarecompass.com
Support: support@collectivecarecompass.com
Your privacy is our priority. We will never sell your data, and we give you full control over who can access your health information.