Privacy Policy
Last Updated: March 30, 2026
I. Introduction
CareTrigger Ltd. (“CareTrigger,” “we,” “our,” or “us”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, transfer, store, and protect personal information when you use our mobile application, website, and all related services (collectively, the “Service”).
By accessing or using the Service, you acknowledge that you have read and understood this Privacy Policy and consent to the collection, use, and disclosure of your personal information as described herein. If you do not agree with this Privacy Policy, please do not use the Service.
This Privacy Policy is incorporated into and forms part of our Terms of Service. Capitalized terms not defined herein have the meanings ascribed to them in the Terms of Service.
II. Information We Collect
A. Information You Provide Directly
- Account Information: When you create an account, we collect your name, email address, phone number, date of birth, password, and any profile photo you choose to provide.
- Pair and Group Information: When you create or join a Pair or Group, we collect the names, email addresses, and phone numbers of the members you invite or connect with.
- Consent Records: We record and store evidence of consents you provide or receive, including consent to be monitored, consent for location sharing, and consent for remote device access.
- In-App Communications: We process the contents of messages and media shared internally between members of your Pairs or Groups via the Service.
- Support Communications: If you contact our support team or provide feedback, we collect the content of those communications along with associated metadata.
- Payment Information: If you subscribe to a paid plan, we or our third-party payment processors collect billing information. We do not directly store full credit card numbers on our servers.
B. Information Collected Automatically from Your Device
- Activity Data: Device usage patterns, including step count, device interaction patterns, screen activity metrics, and other sensor telemetry. This data is used to establish your baseline behavioral patterns and to detect deviations.
- Precise Geolocation Data: If you enable location services, we collect precise GPS coordinates, as well as location data inferred from IP addresses, Wi-Fi network associations, Bluetooth proximity, and cellular tower signals. You may disable location data collection at any time.
- Kinematic and Movement Data: Subject to your device permissions, we may access your device’s accelerometer, gyroscope, and compass to collect telemetry regarding your speed, altitude, heading, and acceleration.
- Device Information: Device type, model, operating system and version, unique device identifiers, mobile network information, language settings, time zone, and battery charge status.
- Device Diagnostics: Device identifiers, operating system versions, battery status, and network connectivity strength for maintaining application performance.
- App Usage Data: Data about how you interact with the Service, including features used, settings selected, in-app actions, and session duration.
- Log Data: IP address, access times, pages viewed, app crashes, and other system activity.
C. Information from Third-Party Sources
When you download or purchase the Service through an App Store, we may receive certain information from the App Store. The Service may also use third-party platforms to deliver Alerts, and we may receive delivery status information and related metadata from these services.
D. Audio and Video Data (Remote Device Access Feature)
If a User has explicitly granted consent for the remote device access feature, audio or video may be temporarily transmitted to the monitoring User in real time. CareTrigger does not record or store audio or video data from the remote device access feature on its servers, unless explicitly stated otherwise.
III. Algorithmic Transparency: Behavioral Profiling and Anomaly Detection
Behavioral Baseline
The Service securely learns your typical active hours, transit modes, geographic routes, and device interaction patterns to construct an individualized baseline of your normal daily routines. This baseline is continuously refined as the Service collects more data.
Anomaly Identification
The Service continuously compares real-time telemetry against your baseline. The system calculates risk indicators based on spatial deviations, temporal irregularities, and kinematic anomalies.
Automated Decisions
When an anomaly score exceeds a defined threshold, the system autonomously triggers an Alert to your designated Pair or Group members. This automated profiling is used exclusively for personal safety notifications. It does not produce legal effects, nor is it used to determine eligibility for credit, employment, insurance, or any other purpose. You have the right to request human review or contest the accuracy of any automated Alert.
Limitations
Algorithmic detection is inherently probabilistic and imperfect. The Service will inevitably produce false positives and false negatives. For a detailed description of these limitations, please refer to Section XV of our Terms of Service.
IV. How We Use Your Information
- Service Delivery: To provide, operate, maintain, and improve the Service, including establishing behavioral baselines, detecting anomalies, generating and delivering Alerts, enabling location sharing, and facilitating remote device access.
- Personalization: To tailor the Service to your usage patterns and preferences, including calibrating detection algorithms to your individual behavioral baseline.
- Communications: To send you service-related communications, including account verification, Alerts, security notices, technical updates, and support messages.
- Safety and Security: To detect, investigate, and prevent fraud, unauthorized access, and other illegal activities.
- Analytics and Improvement: To analyze usage trends, monitor the effectiveness of the Service, and develop new features. We may use aggregated and anonymized data for research and statistical analysis.
- Legal Compliance: To comply with applicable laws, regulations, legal processes, or governmental requests.
- Billing and Payment Processing: To process transactions, manage subscriptions, and handle refund requests.
V. Legal Grounds for Data Processing
- Performance of a Contract: Processing necessary to provide the Service to you in accordance with our Terms of Service.
- Explicit Consent: We rely on your explicit, revocable consent for the collection of precise geolocation data, kinematic data, behavioral profiling, remote device access, and the sharing of anomaly Alerts. You may withdraw consent at any time.
- Legitimate Interests: We process diagnostic logs, device data, and aggregated analytics based on our legitimate interest in maintaining application security, preventing fraud, and improving our anomaly detection algorithms.
- Vital Interests: In severe emergencies, we may process and disclose your location to emergency responders or your designated Pair or Group members to protect your vital physical interests.
- Compliance with Legal Obligations: Processing necessary to comply with applicable laws, regulations, or lawful governmental requests.
VI. Disclosure of Your Information
A. With Your Pair and Group Members
The core function of the Service involves sharing certain information with other Users in your Pair or Group, as you have consented to. This may include activity status, location data, SOS Alerts, kinematic data, in-app communications, and real-time audio/video streams (if remote device access is enabled). You control the scope of this sharing through the Service’s settings.
B. With Service Providers
We engage third-party service providers to perform functions on our behalf, including cloud hosting, data storage, analytics, payment processing, customer support, and Alert delivery. These service providers are bound by strict data processing agreements.
C. For Legal Reasons
We may disclose your personal information if we believe in good faith that such disclosure is necessary to: comply with applicable law; enforce our Terms of Service; detect, prevent, or address fraud, security, or technical issues; or protect the rights, property, or safety of CareTrigger, our users, or the public.
D. In Connection with a Business Transfer
If CareTrigger is involved in a merger, acquisition, or similar transaction, your personal information may be transferred as part of that transaction.
E. Aggregated and Anonymized Data
We may irreversibly de-identify and aggregate information for research, analytics, platform optimization, or other purposes, ensuring it can no longer be linked to any individual.
VII. Data Retention
- Real-time location data is routinely overwritten and retained only for the limited historical period configured in your settings.
- Behavioral baselines are retained for the duration of your account. Upon account deletion, historical behavioral profiles are permanently purged or anonymized.
- Activity data and sensor telemetry are retained for the duration of your account and for a reasonable period thereafter.
- Account information is retained for the duration of your account. Upon deletion, we will delete or anonymize your personal information within a reasonable timeframe.
- Audio and video data from the remote device access feature is streamed in real time and is not stored on our servers.
VIII. Your Choices and Rights
A. Account Settings
You may update or correct your account information at any time through the Service’s settings. You may enable or disable location sharing, remote device access permissions, and other optional features at any time.
B. Data Access, Portability, and Deletion
Depending on your jurisdiction, you may have the right to: access your personal information; request a machine-readable export; request correction of inaccurate data; request deletion of your personal data; object to or restrict certain processing; and withdraw consent at any time. To exercise these rights, please contact us at the address provided below.
C. Opt-Out of Communications
You may opt out of promotional communications by following the unsubscribe instructions or by adjusting your settings. You may not opt out of service-related communications that are essential to the operation of your account.
D. Location Data and Sensor Controls
You may disable location data collection, background location tracking, or behavioral anomaly detection at any time through the Service’s settings or through your device’s operating system settings. Disabling these features may limit or entirely disable the core functionality of the Service.
E. Remote Device Access
You may revoke consent for remote device access at any time through the Service’s settings.
F. Right to Contest Automated Decisions
You have the right to request human review of any automated decision made by the Service, including any Alert triggered by the anomaly detection system, and to contest the accuracy of such decisions.
IX. Children's Privacy and Protections for Minors
The Service is not directed to children under the age of thirteen (13), and we do not knowingly collect personal information from children under 13. Children cannot autonomously create accounts. A minor may only be added to a Pair or Group through an account provisioned by a verified parent or legal guardian.
We require verifiable parental consent before activating sensors or collecting data from a child’s device. Parents and legal guardians maintain full authority to review, restrict, or demand the deletion of their child’s data at any time.
X. How We Protect Your Information
We implement advanced technical and organizational security measures to protect your personal information, including:
- Encryption of data in transit using TLS
- Encryption of data at rest using industry-standard encryption (e.g., AES-256)
- Access controls and authentication mechanisms
- Regular security assessments and vulnerability testing
- Secure development practices and code review processes
However, no method of electronic transmission or storage is 100% secure. While we strive to use commercially acceptable means to protect your personal information, we cannot guarantee its absolute security.
XI. International Data Transfers
Your information may be transferred to, processed, and stored in countries other than the country in which you reside. Where we transfer personal data from the European Economic Area (EEA), the United Kingdom, or Switzerland to countries that have not been deemed to provide an adequate level of protection, we rely on appropriate legally binding safeguards, primarily the European Commission’s Standard Contractual Clauses (SCCs) and the UK International Data Transfer Agreement.
XII. Additional Region-Specific Privacy Terms
A. European Economic Area (EEA), United Kingdom, and Switzerland (GDPR)
You have the right to access, rectify, erase, restrict processing, object to processing, and port your personal data. You also have the right to withdraw consent at any time and to lodge a complaint with your local data protection authority. Data Protection Officer: dpo@caretrigger.io
B. California (CCPA/CPRA)
California residents have additional rights including: the right to know what personal information we collect; the right to delete personal information; the right to opt out of the sale or sharing of personal information; the right to correct inaccurate information; and the right to non-discrimination for exercising privacy rights. CareTrigger does not sell your personal information in the traditional sense.
C. Brazil (LGPD)
If you are located in Brazil, you have rights under the Lei Geral de Proteção de Dados (LGPD), including the right to confirmation of processing, access, correction, anonymization, portability, deletion, information about sharing, and revocation of consent.
D. Australia
If you are located in Australia, we handle your personal information in accordance with the Australian Privacy Principles under the Privacy Act 1988 (Cth). You have the right to access and correct your personal information and to make a complaint to the Office of the Australian Information Commissioner.
XIII. Cookies and Similar Technologies
Our website and Service may use cookies, pixel tags, local storage, and similar technologies to collect information about your browsing and usage activity. We use these technologies for authentication, analytics, preferences, and security purposes. You can manage cookie preferences through your browser or device settings.
XIV. Third-Party Links and Services
The Service may contain links to third-party websites, services, or applications. This Privacy Policy does not apply to third-party services, and we are not responsible for the privacy practices of any third party.
XV. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you through the Service, by email, or by other appropriate means. Your continued use of the Service after the effective date of the revised Privacy Policy constitutes your acceptance of the changes.
XVI. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at:
CareTrigger Ltd.
Email: privacy@caretrigger.io
Data Protection Officer: dpo@caretrigger.io
Website: www.caretrigger.io
By using the CareTrigger Service, you acknowledge that you have read, understood, and agree to this Privacy Policy.