Privacy Policy
Last updated September 6, 2026
CareCub is a baby-care companion for parents, legal guardians, and authorized caregivers. It is not intended for children to use themselves.
When you use chat, voice logging, or structured parsing, baby-care logs such as feedings, sleep, and diapers may be included as context and processed by Google Gemini. The app asks for your consent before first use, and nothing is sent to Gemini unless you use those features.
Data we collect
- Account details: email address and Sign in with Apple identity.
- Baby profiles you add: name, birthday, gender, birth weight, and notes.
- Care logs you choose to save: feedings, sleep, pumping, diapers, and related notes.
- Health records you explicitly choose to import from a connected healthcare provider, such as growth measurements, immunizations, medications, and visits. CareCub records your authorization attestation and the version of the import consent you accepted.
- If you select a provider export file, CareCub sends that file directly to its authenticated API to create an encrypted, short-lived review. The file is not sent to Browserbase or an AI model, and nothing is stored as a health record until you confirm the child and choose what to import.
- If you use the secure-browser fallback on a mobile device, text you submit through its masked keyboard or Paste action is transiently relayed by CareCub's authenticated API to the selected field in your private Browserbase session. CareCub does not store or log that input, include it in AI requests, or place it in Browserbase metadata or session recordings.
- Care-circle memberships and invitations (who can view or log for a baby).
- Apple processes subscription purchases. CareCub reads the resulting entitlement so it can unlock CareCub Plus; CareCub does not receive your payment-card details.
- Voice is transcribed on your iPhone when on-device speech is available. On some older iOS versions, Apple’s speech recognition may process the audio. The transcript may be sent to our API and to Gemini to turn it into a log or answer a question. We do not keep the audio file.
Where your data is stored
- On your iPhone: sign-in tokens in the Keychain, and local settings such as dashboard layout.
- On our servers (Railway) and in Supabase (authentication and Postgres): accounts, baby profiles, logs, care-circle data, short-lived encrypted provider-file previews, and provider records you choose to import. Imported clinical details and retained source documents are application-encrypted, and provider identifiers used for matching are hashed.
- With Browserbase, only when you choose the secure-browser fallback: an ephemeral browser session and an encrypted provider-login Context. Session recording and logging are disabled. CareCub deletes downloaded export copies from Browserbase after encrypted ingestion and deletes the Context when you disconnect or delete that provider's data.
- With Google Gemini: only the text of a parse or chat request you start, which may include baby-care logs as context. Imported provider health records are not sent to Gemini.
How long we keep it
We keep account, profile, log, and imported provider data until you use the applicable deletion control or delete your account. Provider sign-in state expires after 10 minutes and uncommitted import previews expire after 30 minutes. After you delete your account, we remove your sign-in identity and the baby profiles you solely own, including their logs and care-circle memberships. If you only had caregiver access, those babies’ logs stay with the owner.
Children and family data
- CareCub is for parents, legal guardians, and authorized caregivers.
- By adding a baby, you represent that you have authority to provide and manage that information.
- The app is not directed at children and is not in Apple’s Kids Category.
Your rights
- You can correct baby details, delete individual logs or imported provider records, export your imported provider records, disconnect a provider, delete all data imported from a provider, and delete a baby profile you own in the app.
- Disconnecting a provider removes CareCub's connection metadata and revokes the recorded import consent; records already imported remain until you delete them.
- You can delete your account in Settings → Privacy & Security.
- Deleting your CareCub account does not cancel an App Store subscription; manage or cancel it separately in your Apple Account.
- You can turn off microphone access in iOS Settings.
- We do not sell personal information and do not show ads.
Security
Data in transit uses HTTPS. Imported provider records are encrypted separately in storage and are available only to owners of the selected baby profile, not to caregiver or viewer roles. Provider-resource identifiers used for matching are hashed, provider access tokens are not retained for the current manual-import feature, and clinical access and deletion actions are audited. Gemini sees only the text of requests you choose to send and does not receive imported provider records.
Service protection
We apply account and network usage limits to AI requests and may block abusive access. These controls help prevent misuse and keep the service available; they are not used for advertising.
This is not medical advice
CareCub’s summaries and chat replies are general education based on what you logged. They are not a diagnosis, treatment, or substitute for your clinician.
Contact
For privacy, account, or support questions, email chuanxiulz02@gmail.com.