Transparency
Privacy policy
Operator: . Privacy and support: contact.
1. Who operates the service
The planned service is operated under the 4LLs brand. For privacy matters, email support@caringback.com.
2. What the service does
CaringBack is a family care schedule. A family member can enter a routine based on instructions they received. The person receiving care accepts pairing, gets local alarms on their own device, and can report that they took it, snooze, or ask for help. Family members follow reports that reach the service and agree who will check in.
The app does not recommend or validate treatment. Telephone calls and recordings from earlier versions are not part of the v2 service being prepared for launch.
3. Data processed
- Account and family: family, person, member, device, and session identifiers; names people provide; pairings, invitations, roles, and consent choices.
- Routine: medication or item names, user-entered dose and unit, instructions supplied by the user, times, time zone, dates, schedule, and installation state. These may reveal health information.
- Reports and coordination: “Taken”, snoozes, corrections, sent and received times, help requests, acknowledgements by a family member, and check-ins when enabled.
- Optional location: coordinates and approximate accuracy for a one-time foreground location, only when the person grants this scope and chooses to share location for a specific help request. We do not continuously or in the background track location.
- Support and privacy contact: email address and message content sent to support or privacy, plus technical data and headers included by email services. The v2 version prepared for this launch does not offer photo or voice uploads.
- Device: technical identifiers, a notification token if registered, permission and alarm state, and sync time.
- Subscription: if and when a purchase is offered, Apple processes payment; RevenueCat and the server receive family/purchase identifiers and state needed to verify access and restore purchases. The app is being prepared and does not currently accept public purchases.
4. How we use data and service providers
We use these data to authenticate pairing, maintain schedules, sync reports, apply privacy choices, operate help requests, process deletion, and respond to support or privacy messages. Messages sent to support@caringback.com also pass through the sender’s and recipient’s email services. Cloudflare hosts the website and service; account and schedule data are stored in D1. iPhone local alarms use AlarmKit; notification services may receive tokens and technical notices when that feature is configured. Apple will process future App Store purchases, with RevenueCat helping verify subscription state.
The website does not install analytics, advertising cookies, or session replay. PostHog usage measurement is disabled in the launch configuration and receives no events. If this changes, we will update this policy and the in-app choice before enabling it. We do not sell personal data or use it for advertising or model training.
5. Consent and sharing
The person can separately allow sharing of the routine, check-ins, location, and help requests. The v2 version for this launch does not offer photo or voice uploads. Pausing sharing stops new family access on the server; help requests have separate consent and may remain available while other scopes are paused. Pausing or revoking sharing does not cancel alarms already scheduled on the person’s device.
Once a revocation reaches the server, new access to the covered data is blocked. An offline device may keep local copies until it reconnects and receives cleanup instructions. Screenshots, exports, and notes made by other people cannot be removed remotely. The app encrypts some operational data stored locally; this is not a device-security certification.
6. Retention and deletion
While an account is active, we keep the account and health data needed to provide the service; no automatic expiry period is configured for that category. A person can request deletion of their own account through the authenticated in-app flow. After confirmation, the server revokes the session and blocks new access immediately. A background process removes the person’s records; failures can be retried, and we do not promise a fixed completion time. A random request ID lets the person check only request status and timestamps, without exposing health data.
Records belonging to other family members may remain. Where needed to preserve those records, the deleted person’s identity is removed or replaced with a reference that cannot be linked back. Data on an offline device may remain until its next sync; exported copies cannot be recalled.
We have not confirmed a fixed deletion period for email correspondence voluntarily sent to support; it remains in the support mailbox and the email services involved. Cloudflare D1 recovery history may contain deleted records for up to 30 days, depending on the provider plan, which may use a shorter window. Restoring an older database could reintroduce deleted data; production operations do not authorize such a restore without reviewing completed deletions. Account deletion does not erase purchase history retained by Apple or RevenueCat under their rules. We do not claim provider copies are erased immediately.
7. Requests and contact
For information or privacy help, email support@caringback.com. Email is a contact channel, not an automatic deletion form. Do not include medication names, diagnoses, images, credentials, or medical documents in your first message. The authenticated self-service deletion flow will be available in the app before public launch.
For help with use, permissions, or connectivity, see Support. We will update this policy if the product, providers, or data practices change.