Version 3.3 · Effective August 14, 2026
Privacy Policy
Care Chronicles is a care-record organization service available to customers in Canada and the United States through carechronicles.com. This policy describes how Care Chronicles handles personal information.
Privacy at a glance
- You choose what to save and who can see a shared care space.
- Care Chronicles does not sell personal information.
- Proactive AI processing starts only after Policy 3.3 acceptance while trial or paid service access is current.
- There is no separate per-care-space AI switch after acceptance.
- You can export or delete eligible information in the product.
Information we handle
We handle account details, authentication and security logs, subscription status, support requests, and the communications, contacts, documents, voice memos, reminders, and Care Circle information users choose to store. Stripe receives payment information directly; Care Chronicles does not store full payment-card numbers.
Purposes and authority
We use information to provide, secure, maintain, support, and bill for the service; deliver account notices; create user-requested exports; prevent abuse; and meet legal obligations. A user storing another person's information is responsible for having the authority or consent required to store and share it, including sending permitted excerpts and saved voice-memo audio to OpenAI as described below.
Essential cookies and local storage
The signed-in application uses an essential, secure session cookie to keep a user signed in. It also uses browser local storage to remember the selected care space and, when applicable, an invitation while the user signs in or creates an account. These technologies support the service and are not used for advertising. The current public site and application do not use advertising trackers or third-party analytics.
Sharing and service providers
Care-record information is shared with Care Circle members according to permissions assigned by a record Manager. Providers supporting VPS hosting, email delivery, malware scanning, and Stripe billing process information only as needed to provide those services. We may disclose information when required by law, to protect rights or safety, or during a business reorganization subject to appropriate safeguards. We do not sell personal information.
Included AI processing and OpenAI
AI processing is part of Care Chronicles for every care space whose Manager has accepted Policy 3.3 while that care space has current trial or paid service access. Policy 3.3 governs user-asked AI questions, automatic voice transcription, and the proactive suggestions described below. Existing users, including Managers who accepted Policy 3.2, must accept version 3.3 before any new OpenAI processing begins. A historical Policy 3.2 authorization records its earlier basis but does not authorize new processing. A Manager accepts the current policy during account setup or through the in-product policy update. After acceptance, there is no separate per-care-space AI switch, and the acceptance applies to care spaces that person manages and to information added to those care spaces later.
Care Chronicles may also prepare an isolated usability-study care space using only clearly fictional information. The study account can review a preloaded AI example and its citations, but it cannot send new questions, start proactive suggestions, send participant-added care-record changes, or send voice recordings to OpenAI. This does not activate AI for an ordinary customer care space.
When a user asks AI for help, Care Chronicles sends the user's question, a compact catalogue of records that user is permitted to access—which can include record types, titles, dates, and short descriptions or summaries—and selected relevant care excerpts to OpenAI's Responses API. After a user explicitly selects Finished reviewing for an upload or review and has not stated a concern, comment, or next move, Care Chronicles may send a current confirmed care-space goal, a bounded catalogue of permitted records, and selected relevant excerpts to the Responses API to propose one to three possible organizational next moves. Meaningful changes to saved records, goals, follow-ups, or completed work may cause those suggestions to be refreshed so they reflect the changed information. This proactive processing may occur without a typed AI question, but it begins only after the Manager accepts Policy 3.3.
Proactive suggestions are drafts. Care Chronicles requires a user to review and confirm a suggestion before it is saved as a care-record next step. It does not automatically send messages, book appointments, share records, or take another external action. It does not diagnose, recommend treatment, monitor for emergencies, or treat wording in a historical record as a current emergency signal. Contact qualified professionals or emergency services when appropriate.
After the Manager accepts Policy 3.3, while service access is current, a
saved voice memo that still needs a transcript is sent
automatically to OpenAI's /v1/audio/transcriptions service.
This may happen before any user asks an AI question. Permission to make a
recording and authority to have OpenAI process another person's
information are separate responsibilities; the Manager must have both
when required.
Care Chronicles sends Responses API requests with response storage
disabled (store:false). This disables Responses API response
storage, but it does not mean zero data retention or exclude every form
of temporary application state. Under OpenAI's default controls,
Responses abuse-monitoring logs may contain questions, excerpts, and
outputs and are retained for up to 30 days, or longer when required by
law or reasonably necessary to protect OpenAI's services or a third
party from harm. OpenAI also documents shorter-lived application state,
including prompt caching for supported models.
OpenAI says data sent to its API is not used to train or improve its
models unless the API customer explicitly opts in. Its current endpoint
table separately lists no abuse-monitoring retention and no
application-state retention for /v1/audio/transcriptions.
These are OpenAI's published provider controls, not a promise that no
data is retained anywhere. OpenAI describes the controls and exceptions
in its
API data-controls documentation.
Care Chronicles stores AI conversations and suggestion decisions in the care space until a user with permission deletes the applicable data. Care Chronicles also stores completed voice-memo transcripts in the care space. There is no per-care-space AI off switch after version 3.3 is accepted. Not asking new AI questions avoids question-initiated Responses requests, but a Finished reviewing handoff and later meaningful changes may start proactive Responses requests as described above. Not saving new voice memos avoids new automatic audio-transcription requests. When a trial expires, a paid period ends after cancellation, or service access is unavailable for nonpayment, no new Responses API or transcription requests begin. Retained care records, AI conversations, suggestion decisions, and completed transcripts remain subject to the normal retention and deletion rules below. Deleting an eligible care space or account stops future processing after any request already in progress, but does not remove provider logs still within OpenAI's published retention period. An existing Manager who accepted version 3.2 but does not accept version 3.3 will not have new AI questions, transcription, or proactive processing started and may contact the privacy address below for access, export, or deletion assistance.
Location, safeguards, and incidents
Information may be processed where Care Chronicles and its providers operate. We use encrypted connections, password hashing, optional two-factor authentication, access controls, malware scanning, activity records, and encrypted backups. No service can guarantee absolute security. Contact us promptly if you suspect unauthorized access.
Retention
Active user data is retained until the user deletes the relevant record or account, unless a longer period is required for legal, fraud-prevention, dispute, or security purposes. Encrypted disaster-recovery backups are retained for up to 14 days. Expired sessions and authentication tokens are removed automatically.
Access, correction, export, withdrawal, and deletion
Users can review and correct records, download PDF or ZIP exports, leave a Care Circle, remove members, change the Manager, delete care records, and delete an eligible account through the product. Privacy requests may also be sent to the address below. We may verify identity and authority before fulfilling a request.
Children and care recipients
Care Chronicles accounts are intended for adults capable of entering a contract. Information about a child or other care recipient may be stored and sent for the provider processing described above only by a person with appropriate authority or consent.
Changes and complaints
Material policy changes will be dated and communicated through the service or account email when appropriate. Questions, complaints, and access requests may be sent to privacy@carechronicles.com. Product support is available at support@carechronicles.com.