Legal
Privacy Policy
Last updated: April 2026
1. Introduction
CareCoda ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the CareCoda mobile application and website (collectively, the "Service"). Please read this policy carefully. If you disagree with its terms, please discontinue use of the Service.
2. Information We Collect
Account Information
When you create an account, we collect your name, email address, and password (stored securely as a hash).
Baby & Care Profiles
You may provide your baby's name, date of birth, and care event data (feeds, sleep, diapers, milestones) you choose to log. This data is entirely user-generated and entered by adult caregivers.
Device Information
We collect device identifiers, operating system version, and app version for debugging and push notification delivery (via Expo / Apple Push Notification Service).
Usage Data
We may collect anonymised usage analytics to improve the Service. We do not sell this data to third parties.
3. How We Use Your Information
- To provide, operate, and maintain the Service
- To enable caregiver coordination and real-time sync within your household
- To deliver push notifications about care events and reminders
- To generate pattern-based predictions and insights
- To respond to your support requests
- To comply with legal obligations
4. Caregiver Data Sharing
Care event data is shared only within your designated household group — among caregivers you explicitly invite. We do not share your household's care data with any third parties for marketing, advertising, or commercial purposes.
5. Children's Privacy (COPPA)
CareCoda does not collect personal information directly from children. All data is entered by adult caregivers on behalf of the children in their care. We do not knowingly allow children under 13 to create accounts. Baby profiles contain data entered by adults and are associated with adult caregiver accounts. We believe this design falls outside the scope of COPPA's direct collection requirements, but we recommend consulting legal counsel to confirm for your specific use case.
6. Third-Party Services
We use the following third-party services to operate the Service:
- Backend provider — for database and authentication infrastructure
- Expo / Apple Push Notification Service — for push notifications
- Analytics provider (if applicable) — for anonymised usage metrics
Each provider has its own privacy policy. We select providers that offer appropriate data protection standards.
7. Data Retention & Deletion
We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time by contacting us at privacy@carecoda.app. We will process deletion requests within 30 days.
8. Security
We implement industry-standard security measures including encryption in transit (TLS) and at rest. No method of transmission over the Internet is 100% secure. We cannot guarantee absolute security but are committed to protecting your data.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or an in-app notice. Continued use of the Service after changes constitutes acceptance of the updated policy.
10. Contact Us
Questions about this policy? Contact us at privacy@carecoda.app.