Privacy Policy

Last updated: 15 June 2026

1. Who we are

KareMate AI ("we", "our", "us") is the data controller for personal data processed through this service. We are subject to UK GDPR and the Data Protection Act 2018.

Data Protection Officer: dpo@caremate.ai

To exercise your rights or raise a concern, contact us at the address above. You may also lodge a complaint with the ICO (Information Commissioner's Office).

2. What data we collect

  • Account data: name, email address, password hash (via Firebase Authentication)
  • Patient / care recipient data: name, date of birth, medical conditions, allergies, medications, GP contact details, emergency contacts, care logs, appointment records, crisis plans, discharge summaries
  • Carer wellbeing data: mood scores, stress scores, sleep hours, break status, notes
  • Benefits data: benefit names and renewal dates
  • Usage data: AI chat messages, agent execution logs
  • Payment data: subscription tier (payment details handled by Stripe and never stored by us)

Health and care data is special category data under UK GDPR Article 9. We only process it with your explicit consent (Article 9(2)(a)), obtained at account registration.

3. Lawful basis for processing

PurposeLawful basis
Providing care coordination featuresContract (Art. 6(1)(b)) + Explicit consent for health data (Art. 9(2)(a))
AI-assisted summaries and plansExplicit consent (Art. 6(1)(a) + Art. 9(2)(a))
Subscription billing via StripeContract (Art. 6(1)(b))
Account security and authenticationLegitimate interests (Art. 6(1)(f))
Improving our serviceLegitimate interests (Art. 6(1)(f)) — anonymised data only

4. How we use AI (Google Gemini)

To generate care summaries, appointment preparation notes, crisis plans, and AI chat responses, we transmit patient data to Google Gemini (Vertex AI), operated by Google LLC. This involves a transfer of personal data to the United States. We rely on Google's Data Processing Agreement and Standard Contractual Clauses (UK Addendum) as the transfer safeguard under UK GDPR Article 46.

You consented to this transfer at account registration. You may withdraw consent at any time by contacting dpo@caremate.ai — note that withdrawing AI processing consent will disable AI features.

5. Third-party processors

  • Firebase / Google Cloud: Authentication and database hosting. DPA in place.
  • Google Vertex AI (Gemini): AI language model for care assistance. DPA + SCCs in place.
  • Stripe: Payment processing. DPA in place. Stripe does not receive health data.

6. Retention periods

  • Patient / care records: 3 years from last activity, then permanently deleted
  • Care logs and medications: 3 years from creation
  • Wellbeing logs: 1 year from creation
  • Benefits renewal records: 6 months after the renewal date
  • AI agent execution logs: 2 years (retained for audit and accountability)
  • Account data: until account deletion + 30-day grace period

7. Your rights

Under UK GDPR you have the right to:

  • Access — request a copy of all personal data we hold about you
  • Rectification — correct inaccurate data
  • Erasure — request deletion of your account and all associated data
  • Portability — receive your data in machine-readable JSON format
  • Restriction — request that processing is paused while a dispute is resolved
  • Objection — object to processing based on legitimate interests
  • Withdraw consent — including for AI processing of health data

Exercise any right via Settings → Account → Data & Privacy, or by emailing dpo@caremate.ai. We respond within 30 days.

8. Cookies

We use two strictly necessary session cookies (km-auth and km-admin) to keep you signed in. These are exempt from consent under PECR. We do not use advertising, analytics, or tracking cookies.

9. Data security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256 via Google Cloud default encryption). Access is controlled via Firebase Authentication tokens. We maintain an access audit log for all operations on patient data.

10. Children

Our service may be used to coordinate care for children. If a patient is under 16, the account holder (carer) confirms they have appropriate parental or guardian authority to input that data. We do not knowingly allow children under 16 to create their own accounts.

11. Changes to this policy

We will notify you by email of any material changes at least 14 days before they take effect. The current version is always available at this URL.