1. Scope
This notice covers the supplied static acquisition website and summarises the privacy foundation found in the CarePilot application archive. It is not a final jurisdiction-specific product privacy policy.
2. Marketing-site data
The delivered site is static and contains no database-backed contact form, account system, analytics SDK or advertising tracker. Clicking an acquisition link opens the visitor’s own email client. The hosting provider selected by the owner may still process standard request logs such as IP address, user agent, requested page and time.
3. Email enquiries
When a visitor emails the seller, the sender controls the information included. Enquiry data may be used to respond, assess a potential transaction and maintain reasonable transaction records. Visitors should not send passwords, private medical records or production credentials.
4. Product data foundation
The application code is designed to handle account information, family coordination records, documents, review items, source links and visible Nura memory. Access is represented through authenticated, family-scoped roles and rules. The app copy states that care data is not sold and that no digital system can be guaranteed completely secure.
5. Nura memory and session context
Persistent memory is designed to be visible in a Memory Ledger and active only after direct choice or confirmation. Session conversation context is described as separate from hidden profiling. Forget and expiry states are represented in domain logic and rules, but production deletion behaviour remains a due-diligence item.
6. Service providers
The code references managed Firebase and Google Cloud services for authentication, storage, functions, messaging and reliability, plus device capabilities such as OCR and speech recognition. A buyer must review the final data flows, processor terms, regions, retention settings and international-transfer obligations before launch.
7. Retention and deletion
The archive contains account-deletion functions and memory-forget logic. Documentation also identifies open retention work for some pending external intake. Final schedules, backup handling, legal holds, export and deletion procedures require production design and legal review.
8. Buyer responsibilities
A buyer should replace seller contact information where appropriate, complete a data inventory, define controller/processor roles, confirm hosting regions, add required rights mechanisms and obtain legal review for each target market.