# CarePilot software asset — due-diligence summary

## Transaction snapshot
- Product: CarePilot, a Family Care Coordination OS for adults caring for ageing parents.
- Product world: the Care House.
- AI guide: Nura, a bounded source-aware intelligence that may understand, organise, clarify and propose; humans, guardians and trusted controllers retain authority.
- Commercial status: pre-revenue software asset. No verified revenue, active-user, public-launch or contract evidence was found in the supplied archive.
- Asking price: **USD 2,400**. Serious, reasonable offers may be considered.
- Seller contact: `pssmaysara@gmail.com`.

## Product status
The archive contains a substantial Flutter application foundation, Firebase server/rules source, product documents, tests and rendered UI evidence. It should not be described as production ready, fully compliant, fully secure, medically approved or fully finished.

The in-app terms call the product an “Advanced Functional Alpha”; support copy also uses “Private beta”. For acquisition purposes, the conservative position is: **advanced pre-launch functional software asset requiring production due diligence**.

## Verified technical stack
- Flutter and Dart.
- Riverpod state management.
- go_router navigation.
- Firebase Core, Authentication, Firestore, Cloud Functions, Storage, App Check and Messaging.
- Node 22 Firebase Cloud Functions.
- File and image picking.
- ML Kit Latin-script text recognition.
- PDF rendering support.
- Speech-to-text, TTS, receive-sharing intent and device-calendar integration.
- Flutter secure storage.

No localisation framework or ARB resource bundle was verified.

## Implemented functionality found in code
- Firebase bootstrap, authentication and runtime recovery.
- Care House shell with Home, Care, Family and Records destinations plus Nura Desk.
- Tasks: list, add/edit, assignment and Firestore repository.
- Appointments: list, add/edit, preparation context and device-calendar adapter.
- Care notes and care-recipient flows.
- Family setup, invitations, join/approval, member management and roles.
- Documents: upload, detail, Storage integration, source cards and OCR provider.
- Care Inbox: deterministic/Firebase extraction providers, source spans and review states.
- Structured drafts and human review items with source references and commit metadata.
- Nura Desk: session UI, semantic providers, persona orchestration, source awareness, uncertainty and command handoff.
- Safety and permission guardians.
- Controlled memory ledger with confirmation, correction and forget flows.
- Reports, care rituals, longitudinal timeline and doctor-visit packet surfaces.
- Notification preferences/runtime and server triggers.
- External email/SMS intake handlers and platform sharing intake.
- Voice capture, family handoff and TTS adapters.
- Account-deletion functions and scheduled cleanup functions.

## Test and evidence foundation
- 111 Flutter test files.
- 13 Node test files.
- 71 original golden screenshots.
- CI configuration for formatting, analysis, golden tests, the full Flutter suite, Functions lint/tests, Firestore/Storage rules tests and Android debug build.

The archive was inspected, but the acquisition-site build environment did not contain Flutter/Dart, so the Flutter suite and Android build were not rerun during website creation. Existing golden outputs were inspected directly. Node Function tests are separately reported in the QA notes generated with the website package.

## Known limitations and open work
- Production Firebase deployment and environment settings are not proven by the archive alone.
- Live Nura/Care Inbox semantic processing requires a buyer-selected endpoint, secret configuration, provider contract and data-flow review.
- Voice/background/lock-screen/call-interruption states are documented as not fully implemented or device-tested.
- External intake retention/deletion has an open production requirement in project evidence.
- Some security evidence refers to rule compilation/dry-run rather than complete emulator behaviour.
- Localisation is not implemented as a verified framework.
- No verified billing, subscription, public store release or production support operation.
- No verified public users, revenue, partnerships, testimonials or market validation.
- No final legal opinion, compliance certification or regulatory approval.

## Security caveats
Positive implementation signals include authenticated family scope, role checks, private-memory ownership, server-owned collections, App Check options, rate limiting, bounded provider responses, secret parameters, upload limits and Firebase rules tests.

Buyer checks still required:
1. Recreate or take control of infrastructure under buyer-owned accounts.
2. Rotate every credential and secret.
3. Verify App Check enforcement and release environment separation.
4. Run Firestore/Storage emulator tests and end-to-end role/recipient tests.
5. Audit logs, observability, retention, backup and deletion.
6. Perform dependency, mobile, cloud and penetration testing.
7. Define incident response, access controls and support procedures.

No claim of complete security is made.

## Legal and regulatory caveats
- In-app privacy and terms copy are explicit drafts and require final legal review.
- CarePilot is not positioned as a medical device, healthcare provider, diagnosis service, treatment service or emergency monitor.
- The buyer must confirm intended use and evaluate medical-device, consumer-health, privacy, AI and platform laws for target markets.
- GDPR/UK GDPR roles, lawful bases, processor agreements, data regions, international transfers, rights handling and retention require buyer review.
- Third-party package licences, brand clearance, asset ownership and contributor rights must be verified.

## Transferable assets — intended, subject to agreement
- Flutter/Dart source.
- Firebase Functions, Firestore rules, Storage rules and indexes source.
- Project-owned CarePilot mark and project-generated UI assets.
- Product, architecture, Nura, design-system and evidence documentation.
- Flutter and Node tests plus golden screenshots.
- Draft legal/trust copy.
- The acquisition website and interactive local demo.
- Source inventory, due-diligence summary and deployment instructions.

## Non-transferable or excluded by default
- Personal Google/Firebase/email/payment accounts.
- Private API keys, service-account files, signing keys, passwords and tokens.
- Non-transferable third-party services and licences.
- Any asset whose ownership cannot be verified.
- Regulatory approvals, compliance certification, revenue, users, contracts or market validation.
- Ongoing support or development unless separately agreed.

## Buyer verification checklist
- [ ] Confirm seller identity and authority to sell.
- [ ] Review full source and Git history if available.
- [ ] Verify ownership of brand, illustrations, screenshots and documentation.
- [ ] Audit open-source licences and third-party service terms.
- [ ] Run Flutter analysis, tests and Android/iOS/web builds in a clean environment.
- [ ] Run Node lint/tests and Firebase emulator tests.
- [ ] Review Firestore/Storage rules against final data model.
- [ ] Verify Firebase project and domain transfer options.
- [ ] Replace and rotate all environment secrets.
- [ ] Select and contract the AI provider; document data flow and retention.
- [ ] Perform privacy, security, accessibility and device testing.
- [ ] Obtain legal review for privacy, terms, AI transparency and medical boundary.
- [ ] Complete brand clearance and rename migration if needed.
- [ ] Define production hosting, monitoring, incident response and support.
- [ ] Validate commercial model and market demand independently.
- [ ] Define IP assignment, warranties, delivery acceptance and transition support in writing.

## Website/demo disclosure
The acquisition site is the real commercial website. `/demo/index.html` is separately labelled as an **interactive product demonstration using sample data**. It uses local browser state, does not expose project credentials and does not claim production persistence.
