C.A.R.E.S.C.A.R.E.S.
Home
InformationPurposeConsentAccessSecurityStorageRetentionRightsBreaches
Privacy Policy

Privacy Policy

Last updated: 12 September 2026

Who we are

The C.A.R.E.S. service is operated by Cares Technologies Ltd, a company registered in England and Wales (company number 17439149), with its registered office at 71-75 Shelton Street, Covent Garden, London, WC2H 9JQ. Cares Technologies Ltd is the data controller for the personal data described in this policy: it decides why and how your data is processed. You can contact us about privacy at privacy@heycares.com.

What information C.A.R.E.S. may collect

C.A.R.E.S. may collect personal information such as name, phone number, email address, account type, emergency contacts, caregiver relationships and communication details.

The platform may also process health-related or sensitive information, including medication schedules, reminder history, daily check-ins, activity logs, emergency/SOS events, optional location sharing and routine-change alerts derived from recorded activity.

Why C.A.R.E.S. uses this information

C.A.R.E.S. uses information to provide reminders, daily check-ins, caregiver updates, emergency contact alerts, account access, secure communication, support features and service improvements. Information should only be used for the purpose of supporting the selected features.

Consent and optional features

Some features are optional and require user permission. These may include location sharing, medication photo support, the Companion, caregiver access and voice personalisation. Users can change optional permissions in their settings where available.

Who can see user information

Only authorised users should access shared information. This may include the older adult, approved family members, nominated caregivers, care-circle members or care provider staff with permission. C.A.R.E.S. should use role-based access controls so users only see information relevant to their role.

Payments

If you subscribe to a paid plan, payment is handled by Stripe, a regulated payment provider. Your card details go directly to Stripe and are never seen or stored by C.A.R.E.S. We receive only confirmation of your subscription status. Stripe’s own privacy policy applies to the payment process.

Service providers

C.A.R.E.S. uses a small number of trusted providers to run the service: Stripe for payments, an email delivery provider (currently Resend) to send verification, invitation and account emails, secure cloud hosting for the application and database (Render, in Frankfurt, Germany; see Where your data is stored), and Anthropic as the AI provider behind the optional Companion. These providers process data only on our instructions and for no other purpose.

Where your data is stored

C.A.R.E.S. runs on Render’s cloud platform, and your account data is stored on servers in Frankfurt, Germany, in the European Union. Data is encrypted in transit and at rest.

Because C.A.R.E.S. serves people in the United Kingdom, storing data in the EU is an international transfer under UK data protection law. This transfer is covered by the UK’s adequacy regulations, which recognise countries in the European Economic Area as providing adequate protection for personal data, so no further safeguard is required for it.

Three of our service providers process personal data outside the UK and the EEA, in the United States: Stripe (payments), Resend (verification and account emails) and Anthropic (the AI provider behind the optional Companion). Each of these transfers is made under that provider’s data processing agreement, which incorporates the UK International Data Transfer Addendum to the EU Standard Contractual Clauses, an appropriate safeguard recognised by UK data protection law for transfers to the United States.

The Companion and your data

The Companion is an optional feature. When you send the Companion a message, that message, the recent conversation, and a limited summary of information from your account (medication names and times, task and appointment titles, the wellbeing summary wording shown in the app, and the most recent shared check-in mood) are sent to our AI service provider, Anthropic, whose model generates the reply. This happens only when you choose to use the Companion.

C.A.R.E.S. does not store your Companion conversations on our servers. Our AI provider processes this information on our instructions to provide the reply. Do not include information in Companion messages that you would not want processed this way; the Companion works without you typing any personal or health details.

Medication photo check and your photos

The medication photo check works entirely on your device: photos are analysed in your browser and the reference photos and their visual summaries are stored on your device only. They are not uploaded to C.A.R.E.S. or to any third party.

The photo check is optional and can be switched on or off at any time in Settings. Each photo you check (and the suggestion) is kept as a small copy on the device where you checked it, so it can be looked at again for up to 24 hours. Checked photos are deleted automatically after 24 hours. They are not sent to C.A.R.E.S., to your Care Circle or to anyone else, and they cannot be seen from any other device. Reference photos used for enrolment always stay on your device.

Key safe and door codes

A care agency may record a key safe or door code for your home so the person visiting you can get in. The code is held encrypted, is never shown in full without a record being kept of who saw it and when, and appears only in your own data export and nowhere else. A code may be held on the carer’s phone for the visit day, and revocation cannot reach a phone with no signal. The phone removes it when it next syncs and when the carer signs out. On screen the code hides again after a short time; that is a courtesy for the screen, not a control.

Data security

C.A.R.E.S. will aim to protect user information using secure login, encryption, access controls, audit logs and secure cloud storage. Sensitive information should not be shared with unauthorised people.

Data retention and deletion

You can permanently delete your account at any time from Settings → Delete account. This erases your account and associated data from our systems, in line with your right to erasure under UK GDPR.

C.A.R.E.S. should only keep information for as long as needed to provide the service, meet legal requirements, resolve issues or protect users. Users should be able to request deletion of their account or certain personal information, subject to legal, safety or operational requirements.

If you answer the early-access questionnaire, your name, email address and answers are held on the basis of the consent you give on that form, until C.A.R.E.S. launches or until you ask to be removed, whichever is sooner. You can ask for a copy of your answers, or for their removal, at privacy@heycares.com.

User rights

Users may have rights to access, correct, delete, restrict or object to the use of their personal data. Users may also request a copy of their personal data where applicable. Requests can be made through the Data Rights page or by emailing privacy@heycares.com, the C.A.R.E.S. privacy contact. C.A.R.E.S. does not have a Data Protection Officer and is not required to appoint one; privacy matters are handled through this contact.

Data breaches

If a data breach occurs, C.A.R.E.S. will investigate the incident, take steps to reduce harm, and report the breach where required by law.