Privacy Policy
How CareVaultHub collects, uses, and protects the information your family chooses to record.
Last updated: June 26, 2026
CareVaultHub ("CareVaultHub", "we", "us") provides a secure portal that helps families of dependents with developmental disabilities organize care information and keep it ready for the people who may one day need to step in. This policy explains what we collect, why, how we protect it, and the choices you have. It applies to our website, API, and iOS app (together, the "Service").
Information we collect
- Account information. The email address you sign up with, your display name, and the two-factor authentication settings on your account (we store a secret to validate your authenticator codes, never your codes).
- Care records you create. The information you choose to enter about the person you care for. This can include sensitive details such as diagnoses, medications, allergies, behavioral and safety notes, daily routines, providers, education, living situation, benefits, insurance, and legal and financial information, along with any documents you upload.
- People you invite. The name, email, and relationship of collaborators and successors you add to a record, so we can send invitations and manage their access.
- Technical and operational data. When you use the app we process limited technical data such as your device's push-notification token (so we can send reminders), IP address, and security and diagnostic logs needed to operate the Service and detect abuse.
- Cookies. Our website uses only the cookies required to keep you signed in and to keep your session secure. We do not use advertising or cross-site tracking cookies.
How we use your information
- To provide the Service: store, organize, and display your care records.
- To generate the Emergency Care Sheet and Care Summary you ask us to build.
- To send reminders, invitations, and security notifications you've enabled.
- To authenticate you, enforce access permissions, and keep accounts secure.
- To operate, troubleshoot, and improve the reliability of the Service.
- To comply with our legal obligations.
What we never do
The care records you create are yours. We do not sell or rent your information, we do not share it for advertising, and we do not use your care records to train machine-learning or AI models.
How information is shared
- With people you authorize. A record is visible only to its owner and the collaborators or successors that owner invites, according to the role granted. A successor's "break-glass" emergency access is deliberate, scoped, and permanently audit-logged, and the owners are notified.
- With service providers. We host the Service on Microsoft Azure, which stores and processes data on our behalf under its contractual and security obligations. We share only what is necessary to run the Service.
- For legal and safety reasons. We may disclose information if required by law, or to protect the rights, safety, and security of our users or the public.
- Business transfers. If CareVaultHub is involved in a merger, acquisition, or sale of assets, your information may be transferred, and we will notify you before it becomes subject to a different privacy policy.
Records that describe a dependent
CareVaultHub records often describe a dependent person, including children and adults with disabilities. These records are created and managed by an authorized family member or guardian who is responsible for the information they enter and for who they invite. The Service is intended for use by adults acting on a dependent's behalf, not by children directly.
How we protect your information
Every connection is HTTPS-only (TLS 1.2+). Records and uploaded documents are stored with encryption at rest on Azure SQL and Azure Blob Storage. Sign-in requires a password plus two-factor authentication, the most sensitive fields are gated behind a device biometric check, reads of sensitive data are audit-logged, and uploaded files are malware-scanned. See our Security page for more.
How long we keep it
We keep your information for as long as your account is active or as needed to provide the Service. When you delete a record or your account, we delete the associated care data; limited records may be retained where required for legal, security, or backup purposes, and are removed on our routine retention schedule.
Your rights and choices
- Access and correct. You can view and edit your records at any time in the app.
- Manage access. You can invite or remove collaborators and successors on each record.
- Export. You can request a copy of your data by emailing us.
- Delete. You can delete individual records and items in the app, and delete your entire account from Settings › Account, or by emailing us.
Depending on where you live, you may have additional rights over your personal information. To exercise any of these, contact us at the address below.
Where your data is processed
The Service is operated in the United States and your information is stored and processed there. If you access the Service from outside the United States, you understand your information will be processed in the United States.
Changes to this policy
We may update this policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you in the app.
Contact us
Questions about this policy or your data? Email support@carevaulthub.com. For security concerns, email security@carevaulthub.com.