Privacy Policy
Effective September 18, 2026
Parental Guardians helps families coordinate care for an aging parent and spot scams before money is lost. Doing that means handling information about people who are often not the person paying for the service. This page says what we collect, what we deliberately do not, and what you can do about it.
1. What we do not collect
Two limits are built into the product rather than promised in this document:
- We do not store the content of emails, messages or calls. Fraud detection works on metadata and patterns — that a number called repeatedly, that a message matched a known scam shape — not on reading what was said.
- We never receive call audio or video. Calls between guardians are peer-to-peer and end-to-end encrypted. Our servers relay only the signalling needed to connect the two devices. If you record a call, the recording is encrypted on your own device with a passphrase we do not hold and is never uploaded. We cannot recover it if you lose the passphrase.
2. What we collect
Account information
An email address or phone number, used to sign you in with a one-time code. Optionally your name, and the name you use for the person you care for. We do not collect their date of birth.
Care coordination data
Care circle membership and roles, tasks, check-ins, notes you write, and the activity timeline assembled from them.
Health signals, only if you connect a device
If you connect a wearable, dispenser or sensor, we store the readings it sends — heart rate, weight, step counts, medication dispensed or missed, and similar. No device is connected by default, and nothing in this category exists for an account that has not connected one.
Fraud and alert data
Alerts raised, their severity, what you did about them, and numbers you have chosen to block.
Call records, not call content
Who called whom, when, how long, how it ended, and consent given. Not the conversation.
Billing
Your plan and subscription status. Card details are handled by Stripe and never reach our servers — checkout happens on Stripe's own hosted page.
Technical and usage data
IP address and browser user agent on security-relevant actions, kept in an audit log. Page views, with record identifiers stripped out: a visit to a specific alert is recorded as /dashboard/alerts/:id, never with the real id.
3. Consent from the person being cared for
The service is built around their consent, not around watching them without it. Every data source requires an explicit opt-in, they can see who is in their care circle, and they can withdraw. You are responsible for having their agreement before you connect a device or add them to a circle. If you are acting under a power of attorney or guardianship, keep your own records of it.
4. Who we share data with
We do not sell personal information and we do not share it for advertising. We use these providers to run the service:
- Stripe — payments and subscription management.
- Resend — sending sign-in codes and email notifications.
- Twilio — sending SMS codes and alerts.
- Vercel — hosting the website, plus aggregate traffic and performance measurement.
- PostHog — product analytics, receiving the scrubbed paths described above.
We may also disclose information where the law requires it, or where it is necessary to investigate fraud or protect someone's safety.
5. Cookies
One cookie, named token, holds your sign-in session. It is HTTP-only and same-site, so it is not readable by scripts and is not sent to other sites. We do not use advertising or cross-site tracking cookies. Some preferences, such as your chosen language, are stored in your browser and never leave it.
6. How your data is protected
Traffic between your browser and our service is encrypted with TLS. Calls are end-to-end encrypted between devices. Recordings are encrypted on your device. Access to a family's data is scoped to that family, and security-relevant actions are written to an audit log.
Two things we want to be accurate about rather than reassuring: the database is not yet encrypted at rest, and we do not hold a SOC 2 report or a HIPAA Business Associate Agreement. Both are planned. Neither is true today, and you should not choose this service on the assumption that they are.
7. How long we keep things
Account and care data are kept while the account is open. Sign-in codes expire within minutes. Audit log entries are kept for security and dispute purposes. Device recordings are never held by us at all, so their lifetime is entirely yours.
8. Your choices
You can view and correct your profile in settings, change what notifications you receive, unsubscribe from digest emails from any digest, disconnect a device at any time, and remove someone from a care circle.
You can delete your account yourself, from the danger zone in settings. It removes your profile, your care circle, and the tasks, alerts, check-ins, health signals, device keys and notifications belonging to it. It takes effect immediately and cannot be undone.
Three things it deliberately does not do. It does not delete data that belongs to someone else — a task you were assigned in another family's circle stays with them and is simply unassigned, and a dependent's account is detached rather than removed. It does not delete the security audit entries described in section 7, though it removes your user ID, IP address and device details from them. And it will not run while a paid subscription is active, because deleting the account would leave that subscription billing your card with no account to attach it to; cancel on the billing page first.
9. Children
The service is for adults. It is not directed at children under 13, and we do not knowingly collect their information.
10. Changes
If this policy changes in a way that materially affects you, we will tell you before the change takes effect. The effective date at the top always reflects the current version.
11. Contact
Questions, corrections, or a deletion request: privacy@parentalguardians.com.