Privacy Policy
Covers opencare.world and poorpeople.app · Effective September 15, 2026
OpenCare is an independent software project. This page says, in plain language, what information the app handles, why, who else processes it, and what controls you have. If anything here is unclear, email updates@opencare.world and a human will answer.
What we collect
Account basics. When you sign up, our sign-in provider (Clerk) collects your email address and name.
What you put in. Circles, tasks, visit notes, messages, resources, and any photos or documents you attach. You control all of it and can delete it.
What we don't collect. No advertising trackers, no third-party analytics, no selling or renting data — ever. Standard server logs (IP addresses, timestamps) exist for security and are not mined for anything else.
A caution about health information
OpenCare is a coordination tool families use for care, so you may choose to write health-related notes. Be thoughtful about what you enter. OpenCare is not a medical service and is not a HIPAA covered entity — it is not a substitute for medical records, medical advice, or emergency services.
Who can see your information
Your circle. People you invite to a circle see that circle's tasks, visits, and messages. That's the point of the app.
Helpers you share with. If you create a helper link, anyone with that link sees the tasks assigned to that helper. You can revoke any link at any time.
AI agents you connect. If you generate an API key and connect an AI agent (Grok, Claude, ChatGPT, etc.), that agent — and the company running it — can access your circles on your behalf. Keys are scoped to your account and revocable on your Profile page.
Nobody else. Every account's data is scoped to its own circles, enforced in code and verified by testing.
Services that process data for us (subprocessors)
Like nearly every modern app, OpenCare is built on established infrastructure services. Each one receives only what its job requires:
| Service | Why we use it | What it handles |
|---|---|---|
| Clerk | Sign-in and account security | Your email, name, and login activity |
| Supabase | Database | Your circles, tasks, visit notes, resources, uploads |
| Amazon Web Services (AWS) | Hosting — the app runs on our own AWS server | All app traffic (encrypted in transit) |
| Resend | Email delivery (welcome emails, task lists, digests) | Recipient email addresses and email contents |
| Anthropic | AI features — the care agent that answers questions about your visit log, and Recover E chat | The visit-log text or messages involved in a question, only when you use those features |
| Cartesia & Deepgram | Voice for Recover E (speech synthesis and transcription) | Voice audio during a voice session, only if you use voice mode |
| Persona | Optional identity verification (currently disabled) | Nothing today; ID documents if the feature is re-enabled and you choose to verify |
AI note: questions you ask the care agent are processed by Anthropic's API, which per its commercial terms does not train models on API data.
Your controls
- Delete your account and its data yourself, any time, from your Profile page.
- Revoke any helper share link — it stops working immediately.
- Revoke any API key you've created.
- Ask us anything or request help with data at updates@opencare.world.
Retention, children, and changes
Data lives as long as your account does; deleting your account removes your data from the live database. Backups age out on a rolling basis. OpenCare is not directed at children under 16. If this policy changes materially, we'll note it here with a new effective date.