Privacy and data

Privacy notice

This notice explains the supplied acquisition site and adapts the application’s existing privacy copy. Buyer legal review is required before public product launch.

Draft acquisition-stage notice. It is not legal advice and does not claim GDPR, UK GDPR, HIPAA or other compliance certification.

1. Scope

This notice covers the supplied static acquisition website and summarises the privacy foundation found in the CarePilot application archive. It is not a final jurisdiction-specific product privacy policy.

2. Marketing-site data

The delivered site is static and contains no database-backed contact form, account system, analytics SDK or advertising tracker. Clicking an acquisition link opens the visitor’s own email client. The hosting provider selected by the owner may still process standard request logs such as IP address, user agent, requested page and time.

3. Email enquiries

When a visitor emails the seller, the sender controls the information included. Enquiry data may be used to respond, assess a potential transaction and maintain reasonable transaction records. Visitors should not send passwords, private medical records or production credentials.

4. Product data foundation

The application code is designed to handle account information, family coordination records, documents, review items, source links and visible Nura memory. Access is represented through authenticated, family-scoped roles and rules. The app copy states that care data is not sold and that no digital system can be guaranteed completely secure.

5. Nura memory and session context

Persistent memory is designed to be visible in a Memory Ledger and active only after direct choice or confirmation. Session conversation context is described as separate from hidden profiling. Forget and expiry states are represented in domain logic and rules, but production deletion behaviour remains a due-diligence item.

6. Service providers

The code references managed Firebase and Google Cloud services for authentication, storage, functions, messaging and reliability, plus device capabilities such as OCR and speech recognition. A buyer must review the final data flows, processor terms, regions, retention settings and international-transfer obligations before launch.

7. Retention and deletion

The archive contains account-deletion functions and memory-forget logic. Documentation also identifies open retention work for some pending external intake. Final schedules, backup handling, legal holds, export and deletion procedures require production design and legal review.

8. Buyer responsibilities

A buyer should replace seller contact information where appropriate, complete a data inventory, define controller/processor roles, confirm hosting regions, add required rights mechanisms and obtain legal review for each target market.

Contact: Acquisition and marketing-site privacy enquiries may be sent to pssmaysara@gmail.com.