1. Important notice about health information
CareSync is a caregiver coordination tool, not a medical device, and it does not provide medical advice, diagnosis, or treatment. Clinical decisions belong with licensed clinicians.
CareSync lets you record and share health-related information about a person you care for (a "loved one" or "patient"), such as medications and adherence, appointments, and care notes. JDAC is not a HIPAA "covered entity," and using CareSync does not create a HIPAA covered-entity or business-associate relationship unless JDAC has agreed to that in a separate signed writing. We nonetheless apply healthcare-grade safeguards to this information, described in Section 8.
You are responsible for having the authority and any necessary consent to enter and share another person's health information in CareSync. Do not enter information about a person you are not authorized to coordinate care for.
2. Information we collect
Account information. Your name, email address, password or passkey credential, role, and account settings.
Care-recipient (patient) information you enter. Information you choose to record about a loved one, which may include their name, date of birth/age, medications (name, dosage, frequency, notes), dose logs (taken/snoozed/missed/skipped and times), appointments (title, date, time, location, notes), care tasks, adherence history, free-text notes, and photos of prescription labels you choose to scan.
Care-team information. The email addresses of people you invite, the role you assign them (Admin, Editor, Viewer), invitation status, and each member's per-patient notification preferences.
Authentication and security data. Sign-in events, and — if you enable biometric sign-in — a WebAuthn passkey. Biometric sign-in uses your device's Face ID / Touch ID; your biometric data stays on your device and is never sent to or stored by CareSync. We keep append-only audit logs of care activity and authentication events, which may include timestamps, the acting user, IP address, and device/browser information.
Billing information. Subscription status and plan. Payments are processed by Stripe; CareSync does not store your full card number. Stripe handles payment details under its own terms and privacy policy.
Notifications data. If you enable reminders/push notifications, a device push token and your notification preferences.
Usage and diagnostics. Product-analytics events and error/diagnostic data used to operate, secure, and improve the Service, which may include pages/screens used, general device information, and error details.
Support communications. Information you provide when you contact us.
3. How we use information
- Provide and operate the Service (medications, appointments, tasks, care team, briefings).
- Generate your AI daily briefing (see Section 4).
- Send the reminders and notifications you enable.
- Authenticate you and secure your account, including passkey sign-in and audit logging.
- Process subscriptions and billing through Stripe.
- Provide customer support and respond to requests.
- Monitor, troubleshoot, secure, and improve the Service.
- Comply with legal obligations and enforce our Terms.
We do not sell your personal information, and we do not use the health information you enter for advertising.
4. AI daily briefings
CareSync generates a plain-language daily summary ("briefing") from the information in your care record (doses due, appointments, open tasks, adherence trends, supply warnings). To do this, relevant care information is processed by a third-party AI provider acting as our service provider to produce the summary and return it to CareSync. Briefings are factual summaries only and never medical advice. We do not use your content to train third-party public AI models.
6. Who can see a care record
CareSync is patient-centric: access is scoped to the care teams you belong to. Within a care team, members see the shared record according to their assigned role. Row-level security restricts data access to the signed-in user's authorized care teams. The account holder who adds a patient is responsible for managing that patient's care-team membership and for having authority to share the information.
7. Data retention
We keep your account and care information for as long as your account is active or as needed to provide the Service. Audit logs are retained to support security and integrity. Backups are retained on a rolling basis (see Section 8). When you delete content or close your account, we delete or de-identify the associated information within a commercially reasonable period, except where we must retain it to meet legal, security, or recordkeeping obligations. Information held by a service provider (e.g., Stripe) is subject to that provider's retention.
8. Security
We use administrative and technical safeguards intended to protect your information, including:
- AES-256 encryption at rest and TLS 1.2+ in transit
- Row-level security on data tables; access scoped to the signed-in user's care teams
- Append-only audit logging of care activity and authentication events
- Daily encrypted backups
- Optional biometric sign-in via WebAuthn passkeys (biometrics never leave your device)
No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
9. Your choices and rights
- Access, correction, export, and deletion. You can view and edit information in the app. You may request a copy of, correction of, or deletion of information we hold about you by contacting us at jonathan@jdacllc.org (or by using the in-app controls where available). We may need to verify your identity before acting.
- Depending on your state (e.g., California and other U.S. state privacy laws), you may have rights to know, access, correct, delete, and to not be discriminated against for exercising them. We do not sell personal information or share it for cross-context behavioral advertising.
- Notifications. You can turn reminders/push notifications on or off in the app or your device settings.
- Cancellation. You can manage or cancel a subscription from the in-app billing portal (see the Terms).
To make a request, email jonathan@jdacllc.org with enough detail to locate the record (for example, the account email). Where information sits with a service provider, we will tell you plainly what we can and cannot reach.
10. Children's privacy
CareSync is intended for adults (18+) coordinating care and is not directed to children under 13, and we do not knowingly collect personal information from children under 13 as account holders. Care recipients are generally adults. If you enter information about a minor you are responsible for, you represent that you have the authority and consent to do so.
11. Where we operate
CareSync is operated from the United States and intended for users in the United States. If you access it from elsewhere, you do so on your own initiative and are responsible for local compliance.
12. Changes to this policy
We may update this policy as the Service, our providers, or the law change. The "Effective date" above identifies the current version; material changes will be reflected there and, where appropriate, communicated in the app.
13. Contact
Questions or privacy requests: jonathan@jdacllc.org — JDAC, LLC.