CareForge Privacy Policy

Effective Date: November 6, 2025

1. Introduction

CareForge AI, LLC respects that our users value confidentiality and control over their data. This Privacy Policy explains how CareForge collects, uses, and protects information in connection with its mobile and web applications.

CareForge is not a medical service and is not governed by HIPAA. We voluntarily apply strong data protection standards to safeguard your privacy and comply with all applicable U.S. privacy laws, including the California Consumer Privacy Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), and Utah Consumer Privacy Act (UCPA).

By using CareForge, you acknowledge that you have read and understood this Privacy Policy. We may update this policy periodically and will notify you of any material changes in-app or by email.

2. Data We Collect

CareForge collects only the data necessary to provide, secure, and improve the service. We do not collect biometric, medical, or diagnostic data.

  • Personal Information: name, email, and state/city voluntarily provided during registration or profile setup.
  • Authentication Data: credentials or tokens used for account login (e.g., Google sign-in).
  • Chat Content: text entered during AI conversations, used to deliver personalized responses.
  • Technical Data: device type, operating system version, and general diagnostic metadata for app performance and security.

3. How We Use Your Data

Your data is used to:

  • Operate and improve the app's functionality.
  • Personalize AI interactions using pseudonymized contextual information.
  • Provide customer support and service troubleshooting.
  • Ensure system security, fraud prevention, and service reliability.

We do not use your information for advertising, profiling, or commercial resale. We do not use your information to make automated decisions that have legal or similarly significant effects.

4. Data Storage and Security

CareForge hosts its systems on trusted cloud providers that meet industry security standards. User data and chat logs are stored on Render and encrypted both in transit and at rest, with access limited to authorized personnel.

AI processing is handled by Microsoft Azure OpenAI, which receives only pseudonymized text to generate responses. Data sent to Azure is processed securely and not retained or used for model training.

CareForge also uses Amazon Web Services (AWS) to store limited pseudonymized context data that helps personalize user experiences. This data is kept separate from chat logs and cannot be linked to individual users without internal keys.

All providers operate under strict data protection agreements and comply with applicable privacy laws.

5. Your Rights and Data Retention

You may delete your CareForge account and all associated data at any time through in-app settings or by emailing privacy@careforge.ai from the address linked to your account with the subject line "Account and Data Deletion Request."

When your account is deleted:

  • Your account and data are permanently erased and cannot be recovered.
  • Personal information (name, email, and profile details) is removed.
  • Chat history, mood logs, and other user entries are permanently deleted.
  • System backups and logs may persist for 30–90 days for audit or legal compliance, then are securely purged.

CareForge retains data only as long as necessary to operate the service, meet legal obligations, or honor user requests. Account deletion is permanent and irreversible. Please confirm before proceeding.

6. Data Sharing and Disclosure

CareForge does not sell or share your data for advertising purposes or profit.

We only share data with trusted service providers necessary to operate the platform, including Render, Azure, AWS, and Firebase. All such providers are bound by confidentiality and data protection agreements.

We may also disclose information if required by law or to respond to valid legal processes such as subpoenas or court orders.

7. Data Breach Notification

If your data is compromised due to a security breach, we will notify you as required under applicable state and federal law.

8. Children's Privacy

CareForge is not intended for individuals under 18. We do not knowingly collect or maintain data from minors.

9. Policy Updates

We will notify users in advance of any material changes. Continued use of the service after updates constitutes acceptance.

10. Contact

For privacy-related questions or requests, contact: privacy@careforge.ai