Back to CareMeds

Legal

Privacy Policy

This policy explains what CareMeds collects, how the medication app uses it, which providers process it, and what choices users have.

Effective date: June 10, 2026Last updated: June 10, 2026

1. What CareMeds Is

CareMeds is a consumer medication-management application for patients and caregivers. It helps users create medication profiles, build schedules, receive reminders, log adherence, review safety information, and coordinate care with invited caregivers.

CareMeds is not a medical provider, pharmacy, insurer, emergency service, or HIPAA-covered healthcare provider. We protect health information using technical and organizational safeguards, but use of CareMeds does not create a patient-provider relationship.

2. Information You Provide

  • Account information, including email address, display name, authentication provider, login method, account settings, onboarding status, and consent records.
  • Health and medication information, including medication names, ingredients, strengths, dosage, form, route, frequency, schedules, refill details, instructions, warnings, allergies, conditions, supplements, pharmacy details, prescriber details, notes, and medication issue history.
  • Patient and caregiver profile information, including profile names, birth year or date of birth if entered, timezone, daily routine times, relationship type, caregiver involvement, caregiver permissions, invite codes, and linked-patient relationships.
  • Adherence and safety information, including scheduled doses, taken, skipped, missed, snoozed, or uncertain dose logs, PRN dose context, safety warning acknowledgements, suppressed-warning reasons, missed-dose resolution details, and safety-check outputs.
  • Prescription label information if you use camera or scan flows, including images or image-derived text used to confirm medication details. The current app design processes these for medication recognition and confirmation rather than exposing user-controlled permanent photo storage.
  • Subscription and purchase state, including RevenueCat entitlement, product, renewal, expiration, management URL, and related billing-status metadata.
  • Support or legal correspondence you send to us, including the contents of your message and contact details needed to respond.

3. Information Collected Automatically

  • Device, app, and technical information such as device type, operating system, app version, Firebase authentication identifiers, Firebase user ID, anonymous or upgraded account state, timestamps, and app configuration needed to operate the service.
  • Push-notification and Live Activity data needed to schedule and display reminders, including local notification identifiers, dose identifiers, medication display text, dosage display text, scheduled time, reminder window, action buttons, and whether notification privacy mode is enabled.
  • Diagnostics and safety logs used to debug safety-critical features, including RxNorm lookup logs, AI prompt and response traces, deterministic safety logs, pipeline traces, errors, model name, timestamps, user ID, and patient ID where needed for authorization and auditability.
  • Website analytics for caremeds.app through Vercel Analytics and Vercel Speed Insights. These site tools help us understand page performance and traffic patterns for the landing page and legal pages.

4. How We Use Information

  • Create and manage CareMeds accounts, anonymous sessions, sign-in, password reset, account upgrades, and account deletion.
  • Store and sync medication profiles, patient profiles, caregiver links, reminders, schedules, adherence logs, inventory, safety warnings, and app settings across devices.
  • Generate medication schedules, reminder windows, PRN rules, missed-dose guidance, and medication safety summaries.
  • Send local reminders, time-sensitive reminders, Live Activities, caregiver alerts, and notification actions when enabled by the user and the operating system.
  • Operate AI-assisted medication label reading, medication identity matching, safety checks, schedule suggestions, missed-dose guidance, and caregiver assistant features.
  • Maintain subscriptions, entitlements, purchase restoration, customer-center access, and billing-status backup through RevenueCat and Firebase.
  • Secure the app, enforce Firestore access rules, troubleshoot crashes or errors, rate-limit AI requests, prevent unauthorized access, and respond to support, legal, or safety issues.

5. AI Processing and Drug Information Sources

CareMeds uses Firebase callable functions backed by Google Cloud Vertex AI/Gemini for AI-assisted features. Depending on the feature, medication names, dosage details, schedules, allergies, conditions, label-derived text, adherence context, and related profile information may be sent for analysis.

CareMeds also queries medication information sources such as RxNorm, openFDA, and DailyMed to identify medications, retrieve label information, and support safety checks. These lookup requests are designed around medication identifiers, names, and label evidence rather than advertising profiles.

AI output and drug-database information may be incomplete, outdated, or incorrect. CareMeds uses these features as organizational and informational support, not as medical advice.

6. Third-Party Services

  • Google Firebase Authentication for account creation, sign-in, anonymous sessions, password reset, and user identifiers.
  • Google Cloud Firestore for cloud sync of account, medication, patient, caregiver, adherence, safety, invitation, and billing-summary records.
  • Google Cloud Functions and Vertex AI/Gemini for server-side AI processing and safety-related generation.
  • Apple Push Notification Service, iOS notification features, Android notification features, and iOS Live Activities for reminders and medication actions.
  • RevenueCat for subscription purchase handling, entitlement status, purchase restoration, customer center, and related subscription metadata.
  • RxNorm, openFDA, and DailyMed for medication identity, label, class, and safety-information lookup.
  • Vercel Analytics and Vercel Speed Insights for the CareMeds marketing and legal website.

7. What We Do Not Do

  • We do not sell health data.
  • We do not use medication, adherence, allergy, condition, prescription, caregiver, or patient-profile data for third-party advertising.
  • We do not allow public read or write access to Firebase Storage. The current storage rules deny user access to all storage paths.
  • We do not intentionally collect precise location, contacts, or advertising tracking data as part of the CareMeds medication-management app.

8. Caregiver Sharing

If you invite or connect with a caregiver, that caregiver may be able to see and manage information for the linked patient according to the permissions in the app. This can include medication names, dosages, schedules, adherence logs, patient profile details, alerts, warning decisions, caregiver notification preferences, and other information needed to coordinate medication management.

Caregiver access is controlled through invite codes, linked patient records, caregiver-patient links, and Firestore authorization rules. You should only invite caregivers you trust.

9. Security and Retention

CareMeds uses Firebase Authentication, Firestore security rules, authenticated callable functions, transport encryption, cloud-provider encryption at rest, local app storage, optional biometric or device authentication features, and notification privacy settings to protect user information.

We keep information for as long as needed to operate the app, provide sync and caregiver features, maintain safety logs, comply with legal obligations, resolve disputes, and enforce our terms. Account deletion removes the Firebase user record and associated CareMeds user, patient, medication, schedule, adherence, invitation, safety-log, and RevenueCat customer mirror records that the deletion function controls, subject to legal, security, backup, and provider-retention limits.

10. Your Choices

  • You can edit medication, patient, routine, notification, caregiver, and profile information in the app.
  • You can enable or disable notifications, Live Activities, quiet hours, reminder behavior, and notification privacy mode where supported.
  • You can remove caregiver access through app settings where the app provides that control.
  • You can clear local cached CareMeds data during sign-out.
  • You can delete your account in the app. The app calls the CareMeds account-deletion function and then clears local app data.
  • You can contact legal@caremeds.app for privacy questions or data requests.

11. Children

CareMeds is intended for adults. Caregivers managing medication information for a minor must be adults and must have the authority to manage that information. We do not knowingly collect personal information directly from children under 13.

12. International Users

CareMeds is operated from the United States and uses service providers that may process information in the United States and other locations. If you use CareMeds from outside the United States, you understand that your information may be transferred to and processed in those locations.

13. Changes

We may update this Privacy Policy as the app changes. If we make material changes, we will provide notice through the app, website, or another appropriate method.