CareHub

Security & privacy

Built to protect the people you're caring for.

You're trusting CareHub with a parent's most sensitive records. Here's how we look after them — in plain language, without the scare tactics.

Encrypted in transit and at rest

Everything you send is protected on the way to us and stays encrypted while it's stored — with both Google-managed and customer-managed (CMEK) keys. The copy on your own device is encrypted too.

Built to HIPAA-grade standards

We hold ourselves to HIPAA-grade practices on BAA-covered infrastructure — even where the law wouldn't require it — because families keep health information here. It's a standard we work to, not a badge we claim.

Sensitive data kept separate

Health and other sensitive details are stored apart from everyday information, behind stricter, consent-gated access — so the most sensitive records are the hardest to reach, and never travel where they don't belong.

We never store passwords

The Accounts directory records where a parent's accounts are and who can reach them — never passwords, PINs, or security codes. A vault of secrets is exactly what's worth attacking, so we deliberately don't hold one.

Consent, not control

Your parent controls their own health and location sharing — no one can turn it on for them.

A caregiver or family owner can never enable sharing on someone else's behalf. While location is being shared, the person sharing it sees a clear, persistent indicator and can switch it off at any time. Where someone genuinely can't manage their own account, sharing has to rest on documented authority such as a power of attorney or guardianship — never a simple role toggle, and the subject's own choice always wins.

We don't sell data or run ads

  • We never sell or share your family's information.
  • There are no ads in CareHub, and there never will be — the subscription is how it's funded.
  • We don't put personal information into analytics or crash reports — only anonymous codes that help us fix problems.
  • Notifications stay vague on purpose: a lock-screen alert says you have a new message, never what it's about.
  • Guided remote view is end-to-end encrypted and never recorded.

Common questions

Is CareHub HIPAA compliant?

CareHub is built to HIPAA-grade standards on BAA-covered cloud infrastructure, even where the law wouldn't require it. HIPAA compliance is an ongoing practice rather than a one-time certificate, and we hold ourselves to that standard because families store health information with us.

Is my family's data encrypted?

Yes. Everything is encrypted in transit and at rest, using both Google-managed and customer-managed (CMEK) keys, with access controlled per family. The copy stored on your own device is encrypted as well, and guided remote view goes further with end-to-end encryption.

Do you store our passwords?

No. The Accounts directory records where a parent's accounts are and who can reach them — never passwords, PINs, security answers, or MFA seeds. There's no credential field to leak.

Do you sell our data or show ads?

No. We never sell or share your family's information, and there are no ads. We don't put personal information into analytics or crash reports.

Who decides what health or location information is shared?

The person it belongs to. Your parent controls their own health and location sharing — no one can turn it on for them.

Care that respects the person you're caring for.

Private by design, on their terms.

Get started