CAREBOARD
Privacy Policy
Last updated: 28 September 2026
CareBoard is a shared daily-care app for families and unpaid carers. This policy explains, in plain English, what information CareBoard holds, why it is used, who it may be shared with, how long it is kept, and what rights people have.
This policy is written to be read. If anything is unclear, email support@quietlyusefulapps.com and we will give you a straight answer.
1. Who we are
CareBoard is made by QuietlyUsefulApps, the trading name of Chris Boyle, based in Scotland, United Kingdom.
For personal information processed in connection with operating CareBoard, QuietlyUsefulApps is the data controller. This means we are responsible for handling that information properly and lawfully.
Chris Boyle, trading as QuietlyUsefulApps254 Old Glamis Road
Dundee
Scotland
DD3 0EU
United Kingdom
2. What CareBoard is
CareBoard gives family members and other unpaid carers one shared place for day-to-day care information about a person they support.
A care circle may use CareBoard to record and share:
- daily routines and tasks;
- notes and pinned notes;
- concerns and concern updates;
- reminders;
- appointments and outings;
- medication information recorded as a reference;
- contacts;
- a care profile;
- care-circle membership and permission levels;
- daily activity and logs; and
- handovers and summaries.
CareBoard may be available as a web app, an installable progressive web app, and through mobile app stores.
3. What CareBoard is not
- CareBoard is not routinely monitored. Nobody at CareBoard watches what a care circle writes.
- CareBoard is not an emergency service.
- CareBoard is not a medical service and does not provide medical advice.
- CareBoard is not a prescribing or medication-administration system.
- CareBoard is not a clinical records system or professional healthcare record.
Information in a CareBoard is entered by members of the relevant care circle. Important emergency and medical information is explained again in section 23.
4. Information we collect
Account information
This includes your email address, display name, authentication records, session information and account status.
Your display name may appear beside notes, updates, routine activity, concerns, reminders, handovers and other content you contribute.
Care information entered by a care circle
This may include:
- the cared-for person's name and care profile;
- health, disability and support information;
- communication preferences;
- routines and routine tasks;
- notes and pinned notes;
- concerns and concern updates;
- mentions and tags;
- reminders;
- appointments and outings;
- medication reference information;
- as-needed medication information;
- photos that members choose to add (see “Photos and images” below);
- daily activity and logs; and
- handover content.
Care information is entered by members of the care circle. CareBoard may organise or assemble that information into summaries and handovers, but it does not independently diagnose, verify or invent care information.
Photos and images
Adding a photo is always optional. Members can add a photo to a Circle Chat message or a note, add a profile photo for the cared-for person, and add a reference photo to a medication. A photo from Circle Chat can also be turned into a note.
CareBoard only uses the camera when you choose to take a photo. When you choose a photo from your library, your device's own photo picker gives CareBoard only the photo you select; CareBoard does not browse or upload the rest of your library.
Before a photo leaves your device, CareBoard resizes it and saves it again as two JPEG images: a smaller preview and a larger viewing copy. Saving it again in this way leaves out the information a camera or phone stores inside the original file, such as the location where it was taken. The original file is not uploaded.
Photos are kept in private storage with our database provider, Supabase. They are never given a public web address. When a member views a photo, CareBoard checks that they are allowed to see it and then gives the app a link to it that expires after a short time. Those links are not saved.
A photo can be seen only by people who can see the item it belongs to. A photo on an “Only me” note can be seen only by the note's author. When a member blocks someone in Circle Chat, that person's Chat photos are hidden from the member who blocked them, as their messages are. When a Chat message is deleted, its photo is no longer shown with it.
Photos are used only to show them to the people allowed to see them in CareBoard. They are not used for advertising, tracking, profiling, image analysis or AI training.
People and contact information
This may include:
- care-circle members and their permission levels;
- the email addresses of invited members;
- invitations that have not yet been accepted;
- care-context labels entered by users, such as next of kin, emergency contact or power of attorney; and
- names, phone numbers and relationships of contacts added by a care circle, such as a relative, school, pharmacy or GP surgery.
Care-context labels are entered by users. They are not legally verified by CareBoard and are not proof that a person holds legal authority.
Notification information
If notifications are enabled, CareBoard stores the device or browser subscription details needed to deliver them.
CareBoard records when a notification event is generated and which care-circle members it is intended for. These records do not confirm that a notification was successfully received or displayed by a device.
Export and deletion records
Where applicable, CareBoard may retain limited technical records showing that an export, account deletion or CareBoard deletion was requested or completed.
Technical information
Standard technical and security logs may include IP addresses, timestamps, device or browser information, request information, authentication events and error details.
Information we deliberately do not collect
CareBoard does not currently collect:
- precise location information;
- advertising identifiers;
- your device contact book;
- video, or any photo you have not chosen to add;
- microphone recordings;
- information for advertising profiling; or
- information for training artificial-intelligence models.
CareBoard does not currently include an advertising SDK, analytics SDK or third-party crash-reporting SDK.
5. Sensitive care information and lawful processing
Information entered into CareBoard may relate to health, disability, medication, behaviour, communication needs or daily support.
UK data protection law treats health information as special-category personal information requiring additional protection.
For account administration and delivery of the CareBoard service, we process ordinary personal information where this is necessary to provide the service requested by an account holder.
We also process limited personal information where necessary for our legitimate interests in:
- keeping CareBoard secure;
- preventing misuse;
- investigating faults;
- supporting users; and
- protecting the integrity of the service.
We only rely on legitimate interests where those interests are not overridden by the rights and interests of the people concerned.
We may also process information where necessary to comply with a legal obligation.
Sensitive care information should only be entered where the person creating or managing the CareBoard is reasonably authorised to record and share it. Depending on the circumstances, this may include:
- the explicit agreement of the cared-for person;
- agreement from a person with parental responsibility for a child;
- authority to act for a person who cannot manage the matter themselves; or
- another lawful basis appropriate to the circumstances.
Where processing relies on explicit consent, that consent may be withdrawn. Withdrawal does not make earlier lawful processing unlawful, but it may mean that the relevant information must be removed or that CareBoard can no longer be used in the same way.
Members must not use CareBoard to record sensitive information they are not reasonably authorised to collect or share.
6. Information about children, cared-for people and non-users
CareBoard accounts are intended for adults aged 18 or over.
The person a CareBoard is about may be a child, a disabled or autistic person, an older person, or anyone else receiving informal care.
The cared-for person may not have a CareBoard account. In those circumstances, their information is normally provided by members of their care circle.
Where a CareBoard is about a child, information should be entered and managed by an adult with parental responsibility or another person with appropriate lawful authority.
Where the cared-for person can understand and participate, care circles should involve them in decisions about what is recorded and shared.
Members should only add information they are reasonably authorised to share and should avoid adding information that is unnecessary, excessive or unrelated to care coordination.
Care circles may also add contact information for people or organisations that do not use CareBoard, such as relatives, schools, pharmacies or GP surgeries. Only information that is appropriate and necessary for the care circle should be added.
7. How CareBoards and care circles work
A user may create or join more than one CareBoard. Each CareBoard centres on one cared-for person and has its own care circle.
Everyone accepted into a CareBoard can see that CareBoard's shared care information. That shared visibility is a core part of the service.
CareBoard information is not public, searchable or visible to users outside the relevant care circle.
The exception is a note its author marks “Only me”. An “Only me” note, and any photo on it, can be seen only by its author. Other members, including Owners and Admins, cannot see it. “Only me” notes are left out of handovers and are never included in another member's export.
CareBoard stores the information, synchronises it between authorised members and uses it to provide the features requested by the circle.
8. Invitations, member visibility and permission levels
CareBoard members choose who to invite. You should only invite people you are comfortable allowing to read the CareBoard's shared information.
Invited people cannot access the CareBoard's content until they accept the invitation and join the care circle.
Removed members lose access to that CareBoard.
Permission levels such as Owner, Admin, Editor and Viewer control what a member may create, change or manage.
Permission levels are app permissions only. They do not grant or prove legal authority.
Members may see other members' display names. An email address may also be shown where necessary to identify the correct person, such as in invitation, member-management or mention features.
9. How we use information
We use information to:
- create and manage accounts;
- provide CareBoards and care-circle access;
- store and synchronise care information;
- provide routines, notes, concerns, reminders and handovers;
- send sign-in codes, invitations and essential service emails;
- deliver notifications requested by users;
- provide support;
- investigate faults and security incidents;
- prevent misuse; and
- comply with legal obligations.
We do not use care information for advertising, marketing profiling, data brokerage or AI training.
10. Medication reference information
Medication details in CareBoard are entered by users and are provided as a reference for carers.
An Owner or Admin can add a photo to a medication, for example of its packaging, so carers can recognise it. The photo is only a visual reference. CareBoard does not analyse, read or check medication photos.
CareBoard does not check doses, suitability, interactions, prescribing instructions or timing.
Always follow the medication label and instructions supplied by the prescriber or pharmacist.
Contact a GP, pharmacist or other appropriate professional with medical questions.
11. Reminders and notifications
If notifications are enabled, CareBoard stores the subscription or device details needed to reach the relevant device.
Notifications may be delivered through Apple, Google, browser or operating-system notification services, depending on the device.
Notification content may include care-context information, such as a reminder label, concern title, appointment update or task description.
Notifications never include photos. A notification about a Chat photo only says that a photo was sent.
CareBoard may record that a notification was generated and who it was intended for. It does not currently retain confirmation that a device received or displayed the notification.
Notifications can be delayed, blocked, missed or unavailable. They must not be relied upon for emergencies or time-critical care.
Notifications can be disabled through CareBoard, the browser or the device settings, depending on the platform.
12. Browser and device storage
CareBoard may use browser or device storage for functions necessary to provide the service, including:
- keeping a user signed in;
- remembering the CareBoard most recently opened;
- storing app preferences;
- remembering notification state;
- temporarily holding drafts being worked on; and
- keeping CareBoards you have already opened available offline.
So that a CareBoard can still be used without a connection, the app saves a copy of care information you have already loaded on your device, including notes, Circle Chat, reminders, appointments and outings, and the processed JPEG copies of photos you have viewed or added. Changes you make offline are held on your device and are sent when you reconnect, where the app supports that change. The saved copy is kept separately for each signed-in account and each CareBoard.
Saved copies of care information and photos are removed when you sign out, or when you lose access to a CareBoard. Changes that have not been sent yet, including photos waiting to upload, are kept on the device for your account so they are not lost, and are sent if you sign in again. Deleting your account or a CareBoard in the app also removes those unsent changes from the device you use to delete it. When a photo is removed or you are no longer allowed to see it, the app removes its saved copy once it learns this while online.
CareBoard does not use advertising or tracking cookies.
Because the storage described above is used only where necessary to provide the service, CareBoard does not currently display a consent banner for those essential technologies.
13. Service providers
CareBoard uses a limited number of specialist service providers that process information on our behalf.
- Supabase provides database, authentication, private photo storage and backend services. CareBoard's main database is hosted in Central EU, Frankfurt, Germany.
- Netlify hosts and delivers the CareBoard web application, landing page and public legal pages.
- Brevo delivers sign-in, invitation and essential service emails, and transactional invitation text messages.
- Zoho Mail provides the support mailbox used when someone contacts CareBoard.
- Stripe processes subscription payments bought through CareBoard on the web, where paid subscriptions are enabled.
- Apple processes and manages subscription payments bought through the App Store. Apple tells CareBoard whether a subscription is active; it does not give us your payment details.
- Apple, Google, browser and operating-system notification services may process notification information where notifications are enabled.
When you choose to send an invitation by text message, the recipient's mobile number is sent to Brevo solely to deliver that transactional invitation. CareBoard does not store the recipient's mobile number.
So that you can tell your pending text invitations apart, CareBoard keeps a short label with each one: the contact's name if you chose them from your contacts, or the last four digits of the number if you typed it. The full number is never kept. The label is removed when the invitation is accepted or cancelled, and when the CareBoard or your account is deleted. An invitation that expires without being used keeps its label until it is cancelled.
We never receive or store your full payment card details.
We may also disclose information where required by law, court order or a lawful request from an authorised public body.
14. Sharing and international transfers
Care information is shared with members of the relevant care circle and with the service providers needed to operate CareBoard.
Some providers may be headquartered or operate outside the United Kingdom or European Economic Area.
Where personal information is transferred internationally, we rely on safeguards recognised under UK data protection law, such as adequacy regulations, approved contractual clauses or the UK International Data Transfer Addendum.
15. Security
CareBoard information is protected using encryption in transit, encryption at rest provided by the hosting services, authentication controls and database access rules.
Database access controls are intended to restrict CareBoard information to authorised members of the relevant care circle, together with strictly limited operational access described in section 20 or access required by law.
No online service can guarantee complete security. We review security arrangements and take reasonable steps to prevent unauthorised access, loss, misuse or disclosure.
Where a personal-data breach creates a legal duty to notify affected people or the Information Commissioner's Office, we will do so.
16. Retention
While a CareBoard is active, its information is retained so the care circle can maintain its shared care history.
When information is deleted in the app, it is removed from the live service promptly.
CareBoard does not currently schedule or maintain routine database backup copies of user data.
If routine backup arrangements are introduced in future, this policy will be updated to explain how long those copies are kept.
When an account or whole CareBoard is deleted, deletion is completed within approximately 30 days, apart from limited records that must be retained for legal, security or dispute-resolution purposes. Photo files are handled as described below.
When a photo is removed, or the item it belongs to is deleted, or its CareBoard or the account that added it is deleted, CareBoard stops showing it and no longer gives anyone a link to it. The stored image files are then deleted by a separate clean-up process that removes only files no longer attached to anything in CareBoard. Until that happens, the files stay in private storage and cannot be viewed through CareBoard.
Where we do keep a payment record after an account is deleted, it is deliberately minimal: which plan was bought, the period it covered, the date it was last paid, and a reference to the payment itself. It holds no care information and no CareBoard content, and it is no longer linked to your CareBoard account — it cannot be used to rebuild your CareBoard or identify you from our records alone. The payment reference still points to the transaction held by our payment provider, which is what makes it usable as an accounting record. We keep these records only for accounting, fraud prevention and support — never for marketing or profiling.
When our payment provider tells us about a payment, we keep the full message it sends for up to 90 days so we can process it and investigate any problem. After that we remove the message itself and keep only a small record that it happened — what kind of event it was, when it arrived and whether it was processed successfully.
If a subscription ends, your CareBoard remains readable and exportable. You simply won't be able to add new information until the subscription is restarted. We will never delete your family's care history simply because a subscription ended, and we will never charge you to retrieve your own information.
Supabase API and database logs are currently retained for approximately one day under the present hosting plan.
This log-retention period may change if the hosting plan changes. If it does, this policy will be updated.
Support correspondence is kept only for as long as reasonably necessary to deal with the request, maintain security, meet legal obligations or resolve disputes.
17. Exporting CareBoard information
Where the app permits, an Owner or Admin can export CareBoard information from Settings without charge.
The export includes:
- care-circle membership and app permission levels;
- the current standing routine;
- logged routine activity and notes;
- appointments and outings;
- current and historical medication references; and
- concerns and their updates.
Information attributed to a user whose account has been deleted may remain in an export as “Deleted user” where it forms part of the CareBoard's shared history.
A person may also request a copy of their personal information by emailing support@quietlyusefulapps.com .
18. Deleting a CareBoard
A CareBoard Owner can delete the whole CareBoard.
This removes the CareBoard's shared information, including its photos, for every member and cannot be undone. Photo files are removed from storage as described in section 16.
Members should consider exporting information first where a copy is needed.
19. Deleting an account
Any user can delete their own account through CareBoard.
Your login and personal profile are permanently removed and cannot be recovered.
What happens to a paid subscription depends on where it was bought.
Subscriptions bought through CareBoard on the web. Deleting your account also cancels the subscription, so you will not continue to be charged. If we cannot cancel it, we will not delete your account — we will tell you, and nothing will have changed.
Subscriptions bought through the App Store. These are managed by Apple, not by us, and deleting your CareBoard account does not cancel them. Apple will continue billing you until you cancel the subscription with Apple. If you do not want it to renew, cancel it in your Apple subscription settings — on your Apple device, or at apps.apple.com/account/subscriptions. You can still delete your CareBoard account whether or not you cancel first, and CareBoard will remind you of this before you do.
We do not keep your Apple subscription or transaction identifiers after your account is deleted. That means we cannot cancel, refund or look up an App Store subscription for you afterwards — only Apple can.
Deleting an account is different from deleting a CareBoard.
Deleting your account also deletes what you have written and the photos you have added, in every CareBoard you belong to or have belonged to:
- your Circle Chat messages (other members see that a message was deleted);
- your notes, including pinned notes and “Only me” notes;
- your updates on concerns; and
- every photo you added, wherever it appears — in Chat, in notes (including a note another member made from your Chat photo), as the cared-for person's profile photo, or on a medication. Photo files are removed from storage as described in section 16.
Shared care records that other members rely on — appointments and outings, reminders, routine tasks and their completion, concerns, medication details and the care profile — stay with the CareBoard. CareBoard removes your account identifiers and author link from those records. They are no longer linked to your deleted CareBoard account, and the app may show a generic attribution such as “Deleted user”.
If you reported a Circle Chat message, or somebody reported one of yours, the report record described in section 21 is kept for safety and support, without any link to your account, until its CareBoard is deleted.
Deleting your account in the app also removes CareBoard information saved on the device you use to delete it, including changes that had not been sent yet.
A user may also contact support@quietlyusefulapps.com for help with deletion.
20. Support access
Nobody routinely reads a care circle's information as part of running CareBoard.
The person operating CareBoard may access care information only where it is genuinely necessary to:
- investigate a problem reported by a user;
- protect the security or integrity of the service; or
- comply with a legal requirement.
Where support access is necessary, it is limited to the information needed to investigate or resolve the issue and ends when the support task is complete.
CareBoard does not routinely access or review care-circle information.
21. Circle Chat and reporting
Circle Chat is a private conversation between the people who have been invited to a CareBoard. It is not public and it is not open to anyone outside that care circle.
CareBoard does not routinely read or monitor private conversations.
CareBoard checks each Chat message before it is posted and refuses a small number of unambiguous threats and abusive or sexual demands. The check runs on our server, CareBoard does not keep the refused text, and the check is deliberately narrow so that carers can still record what has happened, including things other people have said.
CareBoard does not mediate disagreements between members. Where someone's messages are unwelcome, or a conversation has broken down, the controls for that are in the app: block the member, leave the CareBoard, or ask an Owner or Admin to remove them.
If you report a message, CareBoard keeps a record of it. That record includes the text of the message as it stood at the moment you reported it, so the record can survive the message later being changed or deleted, together with the reason you gave. You are shown a reference for the record. The record keeps the message's text. If the message had a photo, the record notes which photo it was; it does not copy the photo.
Reporting a message does not automatically result in any action against the person who sent it, and that person is not told a report has been made.
CareBoard may review a report where it indicates serious misuse of the service, or where review or action is needed for legal, safety or app store compliance reasons.
A record of a report is held with the CareBoard it belongs to and is removed when that CareBoard is deleted.
22. No advertising, selling, profiling or AI training
CareBoard does not:
- show third-party advertising;
- sell personal information;
- use care information for advertising profiles;
- share care information with data brokers; or
- use care information to train AI models.
CareBoard does not currently include an advertising, analytics or third-party crash-reporting SDK.
Where paid subscriptions are enabled, payments are processed by Stripe for subscriptions bought on the web, and by Apple for subscriptions bought through the App Store. CareBoard never receives or stores your full payment card details, and payment information is never used for advertising, profiling or AI training.
23. Emergency and medical disclaimer
CareBoard is not monitored and is not an emergency service.
In an emergency, call 999 in the United Kingdom or the appropriate emergency number for your location.
CareBoard does not provide medical advice.
Information is entered by members of the care circle, medication information is a reference only, and notifications must not be relied upon for emergencies or time-critical care.
For medical questions, contact a GP, pharmacist or other appropriate healthcare professional.
24. Your rights
Depending on the circumstances, people whose personal information is processed through CareBoard may have rights to:
- ask for a copy of their personal information;
- ask for inaccurate information to be corrected;
- ask for information to be deleted;
- ask for processing to be restricted;
- object to certain processing;
- withdraw consent where processing relies on consent; and
- receive certain information in a portable format.
These rights may apply to account holders, invited carers, contacts and the cared-for person.
A person properly authorised to act for someone else may exercise rights on their behalf.
These rights are not always absolute. We may need to confirm identity or authority before responding.
To make a request, email support@quietlyusefulapps.com .
We will respond without undue delay and normally within one month.
Anyone unhappy with how their information has been handled may complain to the Information Commissioner's Office: ico.org.uk .
25. Contacting us
Chris Boyle, trading as QuietlyUsefulApps254 Old Glamis Road
Dundee
Scotland
DD3 0EU
United Kingdom
26. Changes to this policy
We may update this policy when CareBoard, its service providers or its legal obligations change.
Where a change materially affects how personal information is used, we will provide notice through CareBoard, by email, or both, before the change takes effect where appropriate.
The date at the top of this page will always show when the policy was last updated.