Privacy Policy

CareChorus Health Foundation
Effective Date: 2026-04-01
Last Updated: 2026-08-11

Who We Are

CareChorus is a healthcare navigation app built by CareChorus Health Foundation, a Canadian non-profit organization. We help patients and caregivers organize and understand their health information, prepare for appointments, and navigate their care journey.

We take your privacy seriously. This policy explains what information we collect, how we use it, and the choices you have.

The Short Version

  • Your health information is stored on your device by default. We do not store it on our servers.
  • If you choose to connect your Google Drive, your data is stored in your own Google Drive account. This is what lets you restore onto a new device, use more than one device, and share.
  • If you choose to share a profile with a caregiver, they read it directly from your Google Drive. The health information never passes through our servers.
  • When you use an AI-powered feature, the relevant content passes through our server on its way to a third-party AI service that completes the task. Our server relays it and keeps no copy — it is not written to any database, log, or file of ours.
  • We use Google Sign-In to identify you. We access only your name and email address.
  • We do not sell your data. We do not use your data for advertising.

What Information We Collect

Information You Provide

  • Account information: Your name and email address, obtained through Google Sign-In when you create an account.
  • Health and care information: You may enter or upload documents, notes, appointments, medications, conditions, symptoms, and other health-related content into the app. This information is stored only on your device (and optionally in your own Google Drive if you connect it, or on the device of a caregiver you have chosen to share a profile with). We do not have access to this information. When you use an AI-powered feature, the relevant content is transmitted through our proxy server to a third-party AI provider for processing, as described below.
  • Feedback: If you choose to send feedback through the app, your message, the screen you were on, your app version, and platform are sent to our server. You may optionally include a screenshot, recent app logs, or both — each is a separate choice, and neither is attached unless you ask for it. The logs are a record of the app’s own recent activity, which we use to diagnose what went wrong. They are written to exclude the content of your health records, but they may mention the names of files or screens you were working with, so review them if that matters to you before sending. Feedback is associated with your account so we can follow up if needed.
  • Location (only when you ask for it): The Situations feature keeps a locality — a country, region, and city — so that guidance can reflect where you are. You can type it in yourself, or, on a phone or tablet, tap “Use my location” to fill it in from your device. That shortcut asks your permission first, requests only coarse (city-level) location, and turns the coordinates into a place name using your device’s own operating system — a lookup performed by Apple or Google under their terms, not by us. We store only the resulting country, region, and city, alongside the rest of that situation on your device. The coordinates themselves are never sent to us and never stored. Because the locality is part of the situation, it is included in the content sent to the AI service when you use the Situations chat.

Information Collected Automatically

  • App usage data: Anonymized, aggregate information about how features are used (e.g., which screens are visited, how often the app is opened). This data cannot be linked back to you individually. During the beta period, usage analytics are enabled by default to help us improve the app. You can disable them at any time in the app’s Privacy settings.
  • Crash reports: If the app crashes, technical information about the crash is collected automatically via Firebase Crashlytics to help us fix problems. Crash reports include device type, operating system version, and stack traces. They do not include your health information.

Cookies and Tracking Technologies

  • The CareChorus mobile app does not use cookies.
  • The share viewer web page does not use cookies, local storage, or any tracking technologies.
  • Our marketing website (carechorus.ca) does not use cookies. It uses your browser’s local storage only to remember your light/dark theme preference, and it uses Cloudflare Web Analytics — a privacy-friendly, cookieless analytics service that measures aggregate page views and traffic sources without cookies or any personally identifying information.
  • We do not use any third-party tracking pixels or advertising scripts.

Information We Do Not Collect

  • We do not collect your precise location. The only place CareChorus uses location at all is the optional “Use my location” shortcut described above, which asks for coarse, city-level location and keeps only the resulting place name — never the coordinates. It runs only when you tap it, and you can skip it entirely by typing the locality in yourself.
  • We do not access your contacts, camera, or microphone without your explicit permission for a specific feature.
  • We do not track you across other apps or websites.
  • We have disabled advertising identifier (AAID/IDFV) collection.

How Your Information Is Stored

Your health data is stored on your device. Documents, notes, appointments, medications, and all other personal health information you enter into CareChorus are kept in a local database on your device. CareChorus does not send this information anywhere except in the specific circumstances described in this policy.

If you connect your Google Drive, that information is also stored in your own Google Drive account, as described under Your Google Drive below. It stays in an account you own and control, and we have no access to it.

Your device’s own backups. Separately from anything CareChorus does, your phone or computer may back up its app data to a service you have enabled with the device maker — such as iCloud Backup on iOS or Auto Backup on Android. Where that is switched on, it may include CareChorus’s local database along with your other app data. This is a function of your device’s operating system rather than something CareChorus performs, sees, or controls, and it is governed by Apple’s or Google’s own privacy terms. You can review or turn off these backups in your device’s settings.

Your account information (name and email) is stored securely on our servers solely to maintain your account.

When Your Information Leaves Your Device

Google Sign-In

Authentication is handled by Google. We receive only your name and email address. We do not receive access to your Gmail or any other Google services beyond the optional Drive and Sheets features described below.

AI-Powered Features

CareChorus uses artificial intelligence to help you understand and organize your health information. When you use an AI-powered feature — such as document processing, the care navigation assistant, or medical summarization — the relevant content is sent securely to a third-party AI service to complete that task.

How it works:

  • Content you submit for AI analysis is transmitted through our proxy server, hosted in Montreal, Canada (Google Cloud northamerica-northeast2 region), to OpenRouter, a service that routes requests to an AI model provider.
  • Depending on the task and your settings, your content may be processed by Anthropic, OpenAI, or Google. By default, the app uses Anthropic for most tasks (including data extraction and medical summaries) and OpenAI for lighter tasks (such as classification).
  • Documents and content are sent as-is and are not de-identified before processing. This means personal identifiers present in your documents (such as names or dates of birth) may be included in the content sent to the AI provider. Refer to each provider’s privacy policy for their data handling practices.
  • Our proxy server passes your content straight through to the AI service and the response straight back to your device. It does not write either one to a database, a log file, or disk, so once the request finishes we hold no copy of what you submitted or what came back. Our logs record only that a request was made and by which account — never its content. We do not use what you submit to train or improve any model. The result is stored on your device (and in your own Google Drive, if you have connected it), not with us.

What AI does and does not do:

  • AI is used to extract, organize, and summarize health information that you provide. For example, it can read a medical document and extract key details like medications, diagnoses, and appointments.
  • AI does not make medical decisions or recommendations. All AI-generated outputs are presented to you for review, and you can discard them or reprocess with additional instructions.
  • You have the right to not use AI-powered features. The app’s core functionality (storing and viewing your health records) works without AI.

Your Google Drive (Optional)

CareChorus can store your health information in your own Google Drive. This is a single choice you make, and you can change it at any time in the app’s Storage settings. While it is on, your Drive is where your CareChorus information lives beyond this device — and it is what makes restoring, using more than one device, and sharing possible.

What this covers:

  • It is entirely optional and must be explicitly enabled by you. If you leave it off, your information stays on this device.
  • It includes your health records, documents, attachments, conversations, and other app data.
  • It uses the restricted drive.file scope, meaning the app can only access files it created — it cannot read or modify your other Google Drive files.
  • Your information is stored in a dedicated “CareChorus Data” folder in a Google account you own and control.
  • We have no access to that folder. Your health information is not stored on, and does not pass through, CareChorus servers.
  • You can turn it off at any time in the app’s settings.

The rest of this section describes what connecting your Drive makes possible. Each of these requires it; none of them is available while your information stays only on this device.

Restoring onto another device

If you install CareChorus on a new device and sign in with the same Google account, your health information is restored from your own Drive. Nothing is restored from us, because we never held it.

Keeping your devices in sync

If you use CareChorus on more than one device with the same Google account, each device reads and writes the same files in your Drive, so your information stays consistent across them. Alongside your records, the app keeps a record of the changes each device makes, so edits made in more than one place can be combined without either being lost. All of this travels through your own Google Drive; none of it passes through CareChorus servers.

You can share health information with a care provider or family member by generating a link to a web viewer. The person you share with views the data through a web application hosted on our servers, but the health data itself is loaded directly from your Google Drive — it does not pass through or get stored on our servers.

Our server stores only a share record containing a reference to the file in your Google Drive, an expiration date (maximum 7 days), and basic usage information such as view count.

Anyone who has the link can open it — viewing does not require a CareChorus account or signing in. Treat the link like the information itself: forwarding it forwards the access. You choose who receives the link, and you can revoke it at any time in the app.

Sharing with a caregiver

You can also share a person’s profile directly with a caregiver — a family member, friend, or care partner who uses CareChorus. Unlike the link above, they see the information inside their own copy of the app, and it stays up to date as you make changes.

How it works:

  • When you share, your app creates a spreadsheet in your own Google Drive containing the health information for the profile you chose to share. Your app creates this file under the same drive.file scope described above.
  • Your app then grants the caregiver’s Google account access to that one file. Google Drive access is granted per file and per email address, so the caregiver can see nothing else in your Drive.
  • The caregiver’s app reads that spreadsheet directly from your Google Drive. The health information does not pass through, and is not stored on, CareChorus servers.
  • To do this, the caregiver’s app asks their permission for the https://www.googleapis.com/auth/spreadsheets.readonly Google scope. This scope is necessary because the more restricted drive.file scope only sees files that the app itself created, and this file was created by your app, in your Drive.
  • The caregiver’s app keeps a copy of the shared information on their device so they can view it. You decide what to share and with whom, and you can revoke a caregiver’s access at any time from the app.

If you give a caregiver permission to make changes:

  • When you share, you choose whether the caregiver may only view the profile or may also add and edit information. View-only is a separate choice, and it is the default.
  • If you allow changes, your app creates a second spreadsheet, again in your own Google Drive, and grants the caregiver permission to write to it.
  • When the caregiver adds or edits something, their app writes a record of that change to that second spreadsheet. This asks their permission for the https://www.googleapis.com/auth/spreadsheets Google scope, which their app uses for this purpose only.
  • Your device reads those entries, checks them, and applies them to your data. The caregiver never writes to your health records directly, and changes are attributed so you can see which came from whom.
  • As with reading, this content moves between your Google Drive and the caregiver’s device. It does not pass through CareChorus servers.

What our servers hold for this feature:

CareChorus runs a small coordination service so a caregiver can find out that a profile has been shared with them, and be told when it changes. It is deliberately built to hold no health information and no record of who shares with whom:

  • Invitations. When you share, we store a one-way cryptographic hash of the caregiver’s email address, paired with the identifier of the spreadsheet in your Drive. We do not store your identity, the caregiver’s email address in readable form, the name of the person whose profile you shared, or any health information. An invitation is deleted once the caregiver accepts it, and expires automatically after 30 days if they do not.
  • Change notifications. If the caregiver has notifications enabled, we store an anonymous device token so we can tell their device that something has changed. The notification carries no content — it says only that there is new activity in a shared profile. The details are loaded by their app from your Google Drive afterwards.

Because these records do not identify you as the person who shared, they cannot be used to reconstruct who shares with whom.

How We Use Google User Data

CareChorus’s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

We request the following Google scopes:

  • drive.file — granted by anyone who connects their Google Drive. Used to create and maintain your CareChorus files in your own Google Drive. It cannot see any other file in your Drive.
  • spreadsheets.readonly — granted by caregivers only. Used to read a spreadsheet that someone else created in their own Drive and shared with the caregiver. The more restricted drive.file scope cannot do this, because it only sees files the app itself created.
  • spreadsheets — granted only by caregivers who have been given permission to make changes. Used to record the caregiver’s changes to a spreadsheet that the person sharing created and gave them access to.

Data obtained through these scopes is used only to provide the features described in this policy. Specifically:

  • We do not use Google user data to develop, improve, or train generalized artificial intelligence or machine learning models.
  • We do not transfer Google user data to third parties for advertising, marketing, credit assessment, or any similar purpose, and we do not sell it.
  • We do not allow humans to read Google user data, except with your explicit consent for a specific purpose (such as investigating a support issue you have reported), where required by law, or where the data has been aggregated and anonymized.
  • Health information in your Drive is not accessible to us. It stays in your Google account and, where you have shared it, in the account of the person you shared it with.

When you personally use an AI-powered feature, the content you submit is sent to a third-party AI provider to complete that specific task, as described in the AI-Powered Features section above. That content is not retained by us and is not used to train AI models.

We Do Not Sell Your Data

We do not sell, rent, or share your personal information with any third parties for advertising or marketing purposes. The third-party services listed below are used solely to provide app functionality.

Third-Party Services

CareChorus relies on the following third-party services:

ServicePurposeData Shared
Google Sign-InAuthenticationName, email
Google DriveOptional cloud storage and sharingHealth data (when enabled by you)
Google SheetsSharing a profile with a caregiverHealth data for the profile you chose to share, stored in your own Drive and read by the caregiver you granted access to
Firebase Cloud MessagingNotifying a caregiver that a shared profile changedAnonymous device token; the notification itself carries no content
OpenRouterAI request routingContent submitted to AI features
OpenAI, Anthropic, or Google (AI)AI processingContent submitted to AI features
Firebase AnalyticsAnonymized usage analytics (enabled by default during beta; can be disabled in Privacy settings)Feature usage events
Firebase CrashlyticsCrash reportingDevice info, crash stack traces
Cloudflare Web AnalyticsMarketing website traffic analytics (cookieless)Aggregate page views and traffic sources; no cookies or personal data

How We Use Your Information

We use the information we collect to:

  • Provide and improve the CareChorus app
  • Authenticate your identity and maintain your account
  • Process your requests through AI-powered features
  • Understand how the app is used in aggregate, so we can make it better
  • Respond to your support requests

Your Rights and Choices

Access and correction: You can view and edit all information stored in the app at any time. AI-generated outputs are presented to you for review. For some outputs, you can edit them directly; for others (such as document extractions and summaries), you can reprocess the content with additional instructions to correct errors.

Data portability: Your health data is stored on your device and, if you have connected your Google Drive, in your Google Drive account as structured files that you own and control.

Deletion: You can delete your account and all associated data by contacting us at privacy@carechorus.ca. Because your health data is stored on your device, you can also delete it directly by uninstalling the app. If you have connected your Google Drive, you can delete the “CareChorus Data” folder from your Google Drive.

Analytics: During the beta period, usage analytics are enabled by default to help us improve the app. You can disable them at any time in the app’s Privacy settings.

Withdrawal of consent: You can stop using AI-powered features at any time by not submitting content to those features. You can disconnect your Google Drive at any time in the app’s Storage settings. You can revoke a caregiver’s access to a shared profile at any time in the app; this removes their access to the file in your Google Drive. You can also review and remove CareChorus’s access to your Google account at any time from your Google account permissions page.

Children’s Privacy

CareChorus is not intended for use by children under the age of 13. We do not knowingly collect personal information from children under 13. If you believe a child has provided us with personal information, please contact us and we will delete it.

Privacy Law and Cross-Border Data

CareChorus Health Foundation is a Canadian non-profit organization. We are committed to handling your personal information in accordance with applicable Canadian privacy legislation, including federal and provincial laws that may apply to our activities.

We adhere to the following principles:

  • We collect, use, and disclose personal information only for the purposes identified in this policy, with your knowledge and consent.
  • We collect only the minimum information necessary to provide the service.
  • We retain personal information only as long as needed for the purposes for which it was collected. The records we keep for sharing contain no health information and expire on their own: a share link record holds a reference to a file in your Drive, your account identifier, and a view count, and expires after a maximum of 7 days; a caregiver invitation holds a one-way hash of the recipient’s email address and the identifier of a spreadsheet in your Drive, and is deleted as soon as it is accepted, or after 30 days if it is not. Feedback and account data are retained for as long as your account is active, and deleted upon request.

Cross-border data transfers: Our proxy servers are hosted in Canada (Montreal region). However, when you use AI-powered features, your content is forwarded to third-party AI providers whose servers may be located outside Canada, including in the United States. By using these features, you acknowledge that your information may be processed in jurisdictions with different privacy laws than Canada. We require that our service providers maintain reasonable security measures to protect your information.

Security

We implement technical and organizational measures to protect your information, including:

  • Encrypted transmission (TLS) of all data sent to or from external services
  • On-device storage of health data by default, which limits exposure in the event of a server breach
  • Restricted access to account data within our organization
  • Use of the most restrictive OAuth scopes available for Google Drive and Google Sheets access
  • Per-file, per-email access grants for caregiver sharing, so a caregiver can reach only the profile you shared and nothing else in your Drive
  • A coordination service for caregiver sharing that is designed to hold no health information and no record of who shares with whom
  • Disabled advertising identifier collection on all platforms

No method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security, but we are committed to using reasonable measures to protect your information.

Breach Notification

In the event of a data breach that results in a real risk of significant harm to you, we will notify affected individuals and the relevant privacy regulators as required by applicable law. Notification will include the nature of the breach, the information involved, and the steps we are taking in response.

Changes to This Policy

We may update this policy from time to time. When we do, we will update the “Last Updated” date at the top of this page and notify you through the app. Your continued use of CareChorus after changes are posted constitutes your acceptance of the updated policy.

Contact Us

If you have questions about this privacy policy or how we handle your information, please contact us:

CareChorus Health Foundation Email: privacy@carechorus.ca

Person responsible for privacy: Our privacy practices are overseen by the Executive Director of CareChorus Health Foundation, who can be reached at the email above.

Complaints: If you believe your privacy has been violated, you may contact us first to resolve the issue. If you are not satisfied with our response, you have the right to file a complaint with:

  • The Office of the Privacy Commissioner of Canada at priv.gc.ca
  • Your provincial privacy commissioner, if applicable