CareRing — Family Caregiver Coordination App
Effective date: March 22, 2026
Last updated: July 8, 2026
CareRing ("the App") is published by Vasil Nonchev, an independent developer based in Bulgaria, EU. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CareRing Android application and related services at carering.app.
The data controller responsible for your personal data is:
Vasil Nonchev
Bulgaria, European Union
Email: privacy@carering.app
| Category | Specific Data | Purpose |
|---|---|---|
| Account information | Name, email address (via Google Sign-In) | Authentication, account identification |
| Health & medical data Sensitive | Medications (names, dosages, schedules, prescriber); medication administration logs; medication inventory (stock quantities, batches, expiry dates, storage locations, refills); medical conditions (name, diagnosis date) and allergies (allergen, severity); emergency contacts and emergency notes | Medication tracking, care coordination |
| Care recipient data Sensitive | Care recipient details (name, date of birth, photo, insurance provider & policy number, emergency notes) | Identifying and coordinating care for the person being cared for |
| Care circle data | Circle membership, roles, care recipient profiles, home / household organization, care circle invitations | Coordinating caregiving among family members |
| Check-in data | Mood ratings, pain scores, notes, timestamps | Daily wellness tracking |
| Activity data | Tasks, appointments (type, doctor, location, address, phone, preparation and follow-up notes, date/time), care notes, activity logs | Task assignment, appointment management, care history |
| Device & technical data | Device model, OS version, crash logs, push notification token (FCM), time zone and notification preferences | Bug fixing, app stability (via Crashlytics), scheduling reminders at the right local time |
| Subscription data | Subscription tier / status, purchase tokens | Subscription management (via RevenueCat / Google Play) |
| Problem reports & diagnostics | Your account identifier and care circle identifier in our server logs and crash reports; and, if you use Settings → Report a problem, the diagnostics block in the email you send us (report reference, app version and build, device model, OS version, app language, account and circle identifiers, last sync time) | Tracing a support request or a fault back to your own activity so we can fix it without asking you for more information |
Analytics (opt-in, off by default): The App includes Firebase Analytics for anonymous product and usage metrics. Analytics is disabled by default and runs only if you explicitly opt in; you can withdraw that consent at any time in the App settings. When enabled, analytics collects only anonymous usage events and an anonymous app-instance identifier. The device advertising identifier is not collected — advertising-ID collection is turned off in the app build, so no advertising ID is used even when analytics is enabled. No health or care data is ever sent to analytics.
Problem reports (Settings → Report a problem): The App prepares an email to support@carering.app and shows you its complete contents first. Nothing is transmitted until you send it yourself from your own email app, and you can edit or delete any part of it beforehand. The prepared email carries a short report reference, your app version and build, your device model and OS version, your app language, your account identifier, your care circle identifier, and the time of your last successful sync — and deliberately no medication names, no names of people, no notes and no tasks. We never capture a screenshot or a recording of your screen. The same account identifier is written to our server logs and crash reports so a report can be traced to your own activity; it is a random account reference, not your name or email address. Server logs are kept for 30 days and crash reports for 90 days.
We never use your data for advertising, profiling, automated decision-making, or any purpose beyond providing the CareRing service.
We share data only with the following service providers, each acting as a data processor under appropriate agreements. Because Google Firebase and RevenueCat are operated on their own global infrastructure, some of this data may be processed outside the EU/Switzerland, including in the United States, under appropriate safeguards (Standard Contractual Clauses and/or the EU-US Data Privacy Framework). Only our Cloud Run application servers (europe-west1, Belgium) and our Supabase database (eu-central-2, Zurich, Switzerland) are region-pinned; the Firebase services below run on Google infrastructure, which may include the US.
| Provider | Service | Data Shared | Privacy Policy |
|---|---|---|---|
| Google (Firebase Auth) | User authentication | Email, name, auth tokens | Firebase Privacy |
| Google (Firebase Cloud Messaging) | Push notifications | Device tokens, notification content | Firebase Privacy |
| Google (Firebase Crashlytics) | Crash reporting | Device info, crash stack traces (no health data) | Firebase Privacy |
| Google (Firebase Analytics) | Anonymous usage metrics — only if you opt in (Section 2) | Anonymous usage events (no health data, no advertising ID) | Firebase Privacy |
| Google (Gmail SMTP email) | Sending account, notification, and optional daily-digest emails | Your email address and email content; daily digests may include care-circle and care-recipient names, recent activity, and adherence summaries | Google Privacy |
| Google Cloud Platform | Server hosting (Cloud Run) | Data processed by our backend services | GCP Privacy |
| Supabase | Database hosting (PostgreSQL) | All care data (encrypted at rest) | Supabase Privacy |
| RevenueCat | Subscription management | Anonymous user ID, purchase tokens | RevenueCat Privacy |
We do not sell, rent, or share your personal data with any other third parties.
We retain your personal data for as long as your account is active. When you delete your account (from Settings within the App):
Deletion is permanent and cannot be undone. Some non-identifying entries in shared care circles may be retained — without your name — so that the other members' care history stays intact.
As an EU resident or user of an EU-based service, you have the following rights under the General Data Protection Regulation:
| Right | GDPR Article | Description |
|---|---|---|
| Access | Art. 15 | Request a copy of all personal data we hold about you. |
| Rectification | Art. 16 | Request correction of inaccurate personal data. |
| Erasure | Art. 17 | Request deletion of your personal data ("right to be forgotten"). |
| Restriction | Art. 18 | Request restriction of processing in certain circumstances. |
| Portability | Art. 20 | Receive your data in a structured, machine-readable format (JSON export). |
| Objection | Art. 21 | Object to processing based on legitimate interest. |
| Withdraw consent | Art. 7(3) | Withdraw consent at any time without affecting prior processing. |
To exercise any of these rights, contact us at privacy@carering.app. We will respond within 30 days as required by GDPR.
You also have the right to lodge a complaint with the supervisory authority in your EU member state of residence. As we are based in Bulgaria, the lead supervisory authority is:
Commission for Personal Data Protection (CPDP)
Address: 2 Prof. Tsvetan Lazarov Blvd., Sofia 1592, Bulgaria
Website: www.cpdp.bg
Email: kzld@cpdp.bg
Your core care records are processed by our application servers within the European Union (GCP europe-west1, Belgium) and stored in our database in Switzerland (Supabase eu-central-2, Zurich). Switzerland is not part of the EU/EEA, but the European Commission has granted it an adequacy decision, so storing your data there is a lawful transfer under GDPR Art. 45 and your data receives an adequate level of protection equivalent to EU standards.
Beyond this, some limited data — push notifications, emails (including daily digests that may name a care recipient), crash reports, opt-in analytics, and subscription status — is handled by Google (Firebase and Gmail SMTP) and RevenueCat. Firebase Authentication, Cloud Messaging, Crashlytics, and Analytics run on Google infrastructure that may include the United States. Accordingly, this limited data may be processed outside the EU/Switzerland, including in the US, under appropriate safeguards (Standard Contractual Clauses and/or the EU-US Data Privacy Framework as approved by the European Commission). Your core care records in the database remain in Switzerland.
You must be at least 18 years old to create a CareRing account. CareRing is not intended to be used directly by anyone under 18, and we do not knowingly allow a person under 18 to create their own account. If you believe someone under 18 has created an account, please contact us at privacy@carering.app and we will delete it.
Care recipients (the person receiving care) whose information is entered in the App may be of any age, including minors. Their information is entered and managed by a responsible adult caregiver, who must have the authority to provide it and manages it under their own responsibility and consent.
CareRing sends push notifications for medication reminders, task updates, and care circle activity via Firebase Cloud Messaging. You can disable notifications at any time through your Android device settings or within the App's notification preferences.
The CareRing Android app does not use cookies and does not use any advertising trackers. We use Firebase Crashlytics for crash reporting. We also use Firebase Analytics to understand invite-funnel and growth metrics (for example, how new members join a care circle). Firebase Analytics is opt-in and off by default — it collects nothing until you explicitly enable analytics in the App's privacy settings. The device advertising identifier is not collected — advertising-ID collection is turned off in the app build, so no advertising ID is used even when analytics is enabled. Analytics uses only an anonymous app-instance identifier. You can turn analytics off again at any time in the App's settings.
We may update this Privacy Policy from time to time. When we make material changes, we will:
If you have any questions about this Privacy Policy or your personal data, please contact:
Vasil Nonchev
Email: privacy@carering.app
Website: carering.app