Skip to main content

Privacy

Privacy and data use

A plain-language privacy summary for families, visitors, and caregivers using a shared care page. Last updated July 15, 2026.

Back home
Coordinated Care is not an emergency service, medical device, clinical record system, or HIPAA-compliant service in this v1 launch. Do not use it for urgent care, emergency decisions, diagnosis, treatment instructions, or regulated medical records.

What we collect

Care pages can contain names, notes, needs, check-ins, photos, visit signups, meal signups, care-log entries, preferences, and member invite emails.

Visitors can use a private share link without creating an account. We store a random visitor-identity secret so the same browser can edit or cancel its own contributions without exposing that secret in care-page records.

The iPhone app stores account or page-access credentials in Keychain, protected read-only care-page snapshots on the device, notification preferences, an installation identifier, and an APNs device token used to route optional notifications.

Who the service is for

Coordinated Care launches in the United States for adults. It is not directed to children under 13, and an adult should manage any care page that discusses a child or includes a child’s information.

If you believe a child submitted personal information without appropriate adult involvement, contact support@coordinatedcare.app so we can review and remove it where appropriate.

How access works

Visitor access is controlled by the private share link. Anyone with that link may be able to view and contribute to enabled visitor sections.

Members sign in using a short-lived email code or magic link. Admins can invite members, rotate the private share link, review reported content, and schedule page deletion.

In the iPhone app, a private link is exchanged once for a revocable credential scoped to that care page. The app discards the link token after exchange. Rotation, removal, blocking, page deletion, or credential expiry ends that access without erasing authorship history.

Cookies and sessions

The visitor-identity cookie remembers one browser across care pages, while access remains separately granted one care page at a time. The stored server credential is hashed and supports authorship continuity, check-ins, signups, and abuse prevention.

Authentication cookies are handled by Supabase for signed-in members. We do not use cookies for third-party advertising.

Notifications and device storage

Push notifications are optional. Apple receives generic alert text plus opaque notification and page keys; care-page names, health details, notes, photos, status text, and private share links are not included in the push payload.

If you enable care-page names on notifications, the iPhone changes the generic alert using a local App Group cache. The notification extension does not make a network request. Quiet hours and per-page notification choices can delay, mute, or group delivery while the in-app inbox remains available.

Previously loaded native data may remain in protected read-only snapshots so the app can explain that content is stale while offline. Sign-out, guest removal, blocking, rotation, deletion, and other confirmed access loss clear the applicable credentials, snapshots, and notification-name mapping.

Archive and memorial pages

An administrator can close a care page as a completed care period or an optional private memorial. Closing makes the page read-only, stops new invitations and guest access, pauses notifications, and keeps access limited to the existing care circle.

Archive and memorial status do not make a page public and do not replace deletion. An administrator may reopen a page, but participants must opt back into notifications.

Service providers

We use Supabase for authentication, database, private file storage, and member-only realtime refresh; Vercel to host the web application and mobile API; and Apple to deliver optional push notifications. These providers process data only to operate Coordinated Care under their applicable terms and privacy commitments.

When enabled, redacted operational monitoring may be processed by Sentry, and aggregate web performance information may be processed by Vercel. We do not use advertising networks, data brokers, cross-app tracking, Firebase, OneSignal, or StoreKit in native v1.

Deletion and retention

Admins can schedule a care page for deletion. Deleted pages are hidden immediately and retained briefly so admins can restore an accidental deletion.

Members can delete their account in the product. Before deletion, a sole administrator must promote an existing member or choose permanent deletion for each affected care page. Once accepted, the process immediately blocks product access and removes memberships, invitations, devices, notification subscriptions, attributable records, and queued uploaded files. Session revocation and Supabase login deletion continue through a recoverable process targeted to finish within 24 hours.

A guest with current access can erase their linked guest identity across care pages. We remove guest sessions, access, aliases, and attributable content; to prevent an erased browser cookie or installation secret from being reused, we retain only its revoked one-way hash, opaque identity link, credential kind, and minimal timestamps for at least 180 days. Native device IDs are cleared immediately, and the scheduled security cleanup removes the retained hashes after that denial window.

Admins can download a structured care-page export that includes page records, member and invite details, visitor session metadata, content reports, and audit logs. Exports exclude private share-link tokens and visitor session cookie tokens.

If blocking, revocation, or page deletion has left you without current guest access, contact support@coordinatedcare.app for privacy and deletion help. Do not email a private-link token, guest credential, or urgent medical information.