This notice explains what OurCareBook collects, why, and what you can do about it. It is written to be read, not to be skimmed past. If anything here is unclear, email our contact form (choose “Privacy request”).
What we collect
- If you request a demo: your name, work email, organisation, role, team size and anything you choose to write to us.
- If you use the product: your email address to sign you in, and the care records you and your team enter — client details, medications, appointments, documents, notes and updates.
- Documents you upload, and the text our systems read out of them.
- A record of activity — who viewed, changed, confirmed or deleted what, and when — because a care record without one cannot be trusted.
Why we use it
- To reply to demo requests and arrange a call.
- To run the product: sign you in, show each person only what their role allows, and read uploaded documents so a person can confirm what was found.
- To keep the service secure and to investigate problems.
We do not sell personal information. We do not use care records to advertise, and we do not use them to train AI models.
Who else handles it
We use a small number of service providers — for the database and document storage, web hosting, our application server, and reading uploaded documents. They are listed with what they do on our security page.
Cookies and storage
We don't use advertising or tracking cookies, and we don't sell or share browsing data. When you sign in, your browser stores a sign-in token so you stay signed in, and the app remembers small conveniences such as which client you last opened and your calendar view. These are strictly necessary for the service, so we don't ask for cookie consent. On the public website we count page visits with Vercel Web Analytics, which sets no cookies and doesn't identify you; it never runs inside the app.
Health information
Care records can include health information about the people being cared for. Access to it is limited by role, enforced in the database. Until the agreements with every provider that would handle real client records are in place, the product is used with de-identified or synthetic information only, and it says so on every screen.
How long we keep it
Demo requests are kept for up to two years unless you ask us to remove them sooner. Care records are kept for as long as the account that owns them is open, and deleted on request or when the account closes, subject to any retention the account owner is legally required to keep.
Your choices
- Export everything you can see, from inside the product, at any time.
- Ask us to correct or delete information about you.
- Ask what we hold about you through our contact form (choose “Privacy request”).
If you are a family member in someone else's care circle, the account owner can also remove you.
If something goes wrong
If we learn that personal information has been exposed, we will tell the people affected without unreasonable delay and as the law requires.
Changes
If we change this notice in a way that matters, we will say so here and, for account holders, by email.