← Back to CareRing

Privacy Policy

Last updated: July 8, 2026

CareRing ("we", "us", "our") is a family caregiver coordination app operated by Vasil Nonchev, based in Sofia, Bulgaria. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CareRing mobile application and related services.

We take your privacy seriously, especially given the sensitive nature of health-related information. We comply with the European Union General Data Protection Regulation (GDPR) and applicable Bulgarian data protection laws.

1. Data Controller

Vasil Nonchev
Sofia, Bulgaria
Email: privacy@carering.app

2. Data We Collect

2.1 Account Data (collected at sign-in)

DataSourcePurpose
NameGoogle Sign-InDisplay in care circles
Email addressGoogle Sign-InAccount identification
Profile photo URLGoogle Sign-InDisplay in care circles

2.2 Health & Care Data (entered by you)

DataPurpose
Care recipient details (name, date of birth, photo, insurance provider & policy number, emergency notes)Identifying and coordinating care for the person being cared for
Medication names, dosages, schedules, prescriberMedication tracking and reminders
Medication administration logsAdherence tracking
Medication inventory (stock quantities, batches, expiry dates, storage locations, refills)Stock tracking and low-stock / expiry alerts
Daily check-ins (mood, pain, sleep, appetite, mobility)Wellness monitoring
Medical conditions (name, diagnosis date) and allergies (allergen, severity)Medical information hub
Emergency contacts and emergency notesQuick access to important contacts
Appointments (type, doctor, location, address, phone, preparation and follow-up notes, date/time)Care schedule coordination
Care notesShared care documentation
Task assignmentsCaregiver coordination
Home / household organization and care circle invitationsGrouping members and inviting caregivers

2.3 Technical Data (collected automatically)

DataPurpose
Device push notification token (FCM)Sending medication reminders and task notifications
Crash reportsApp stability monitoring (via Firebase Crashlytics)
App version, device model, OS versionDebugging and compatibility
Time zone and notification preferencesScheduling reminders at the right local time
Subscription status (via RevenueCat)Managing your plan and entitlements

2.4 Analytics Data (opt-in, off by default)

The app includes Firebase Analytics for anonymous product and usage metrics. Analytics is disabled by default and runs only if you explicitly opt in (consent under the GDPR and ePrivacy rules). You can withdraw that consent at any time in the app settings. The device advertising identifier is not collected — advertising-ID collection is turned off in the app, so no advertising ID is used even when analytics is enabled. No health or care data is ever sent to analytics.

DataPurpose
Anonymous usage events (screens viewed, features used)Understanding how the app is used, to improve it
Anonymous app-instance identifierDistinguishing analytics sessions; not linked to any advertising identifier

3. Legal Basis for Processing (GDPR Article 6)

Health data is processed under GDPR Article 9(2)(a) — explicit consent. You may withdraw consent at any time by deleting your account.

4. How We Use Your Data

We do NOT:

5. Data Sharing

5.1 With your care circle members

When you join a care circle, other members of that circle can see the care data within it (medications, tasks, check-ins, notes, medical info). You control which circles you join and can leave at any time.

5.2 Third-party service providers

The providers below act only as processors on our behalf. Because Google Firebase and RevenueCat are operated by Google and RevenueCat on their own global infrastructure, some of this data may be processed outside the EU/Switzerland, including in the United States, under appropriate safeguards.

ProviderPurposeData sharedLocation
Google Firebase (Authentication)User sign-inEmail, name, profile photoGoogle infrastructure, may include the US (SCCs / EU-US Data Privacy Framework)
Google Firebase (Cloud Messaging)Push notificationsDevice token, notification contentGoogle infrastructure, may include the US (SCCs / EU-US Data Privacy Framework)
Google Firebase (Crashlytics)Crash reportingDevice info, crash logs (no health data)Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework)
Google Firebase (Analytics)Anonymous usage metrics — only if you opt in (Section 2.4)Anonymous usage events (no health data, no advertising ID)Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework)
Google (Gmail SMTP email)Sending account, notification, and optional daily-digest emailsYour email address and email content; daily digests may include care-circle and care-recipient names, recent activity, and adherence summariesGoogle infrastructure, may include the US (SCCs / EU-US Data Privacy Framework)
SupabaseManaged database hostingAll app data (encrypted at rest)Switzerland (eu-central-2, Zurich) — EU adequacy decision
RevenueCatSubscription managementAnonymous user ID, purchase receipts, subscription statusUS (SCCs / EU-US Data Privacy Framework)

We do not share health or care data with any third party for its own use. Your core care records are stored only on our EU-hosted application servers, our Swiss-hosted database (see Section 6), and your device. Limited care-related content may additionally pass through the notification and email providers listed above — for example, a reminder or a daily digest that names a care recipient — solely to deliver the messages you have set up.

6. Data Storage & Security

7. Data Retention

8. Your Rights (GDPR Articles 15-22)

You have the right to:

To exercise any of these rights, use the in-app settings or contact us at privacy@carering.app. We will respond within 30 days.

9. Account Deletion

You can delete your account at any time from Settings within the app. This will:

Deletion is permanent and cannot be undone. Deletion of the records held by Firebase and RevenueCat is carried out on a best-effort basis immediately after your account data is removed. Some non-identifying entries in shared care circles may be retained — without your name — so that the other members' care history stays intact.

10. Children's Privacy

You must be at least 18 years old to create a CareRing account. Care recipients whose information is entered in the app may be of any age, including minors — their information is entered and managed by a responsible adult caregiver, who must have the authority to provide it. CareRing is not intended to be used directly by anyone under 18, and we do not knowingly allow a person under 18 to create their own account. If you believe someone under 18 has created an account, please contact us and we will delete it.

11. International Data Transfers

Our application servers run in the EU on Google Cloud Platform (europe-west1, Belgium). Our database is hosted by Supabase in Switzerland (eu-central-2, Zurich). Switzerland is not part of the EU/EEA, but the European Commission has granted it an adequacy decision, so storing your data there is a lawful transfer under GDPR Article 45 and your data receives protection equivalent to EU standards. Beyond this, some limited data — push notifications, emails (including daily digests that may name a care recipient), crash reports, opt-in analytics, and subscription status — is handled by Google (Firebase and Gmail SMTP) and RevenueCat and may be processed outside the EU/Switzerland, including in the United States, under appropriate safeguards (Standard Contractual Clauses and/or the EU-US Data Privacy Framework). Your core care records in the database remain in Switzerland.

12. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. The "Last updated" date at the top reflects the most recent revision.

13. Contact Us

For privacy-related questions or requests:

Email: privacy@carering.app
Vasil Nonchev
Sofia, Bulgaria