Caraid
Privacy policy
Effective August 26, 2026
The short version
- Caraid stores health data in Canada. Approved managed AI can process it outside Canada.
- We use personal information to store captures, transcribe and summarize recordings, organize care records, and support family sharing.
- We do not sell health data. We do not use it for advertising or cross-service tracking.
- Optional website analytics starts only after you allow it, and never includes your email address or health information.
- Filing a capture to a person's profile shares it with that person's care circle.
- Profile control, profile access, upload ownership, and filing are four separate rights.
Caraid Health Tech Ltd. operates Caraid. This policy explains how Caraid collects, uses, discloses, keeps, and protects personal information in the Caraid app and related services. Caraid is a consumer-directed care-record service. It is not a health-care provider and does not give medical advice.
Caraid's current service is intended for residents of Canada outside Québec. Québec is not currently a supported signup region.
1. Information we handle
Account and identity information
This can include your name, phone number, email address, and identifiers supplied by the sign-in method you choose. Identity records do not contain health information.
Captures and care-record information
This can include raw appointment audio, voice notes, documents and document images, transcripts, profile names, practical identifiers such as health card or insurance information, profile tags, summaries and other derived records, confirmed clinical values, corrections, and ledger items. A recording can include the voices or information of clinicians, family members, interpreters, and other people who are present.
Consent, sharing, and activity information
We keep consent records, authority type, invitations, care-circle access, corrections, and an audit history of important actions such as views, downloads, changes, and deletions. The audit uses opaque identifiers and closed event types. It does not contain transcript text, summary text, names, or contact values.
Technical and security information
We receive limited technical information needed to operate and protect the service, such as request time, route category, request outcome, and app or device information sent with a request. Caraid's application logs are designed to exclude health content, contact values, raw request bodies, and private invite links.
Optional website analytics
If you select Allow analytics on the public landing page, Caraid records a page view, closed identifiers for selected buttons, and a lead event after the early-access waitlist accepts a submission. The event can include an event identifier, an opaque browser identifier, a session time, the landing-page path, the origin of the referring site, and allowlisted campaign source, medium, and campaign values. Caraid does not send Google Analytics your email address, health information, full query string, referrer path, browser IP address, or browser user-agent string.
The browser sends these events only to Caraid. Caraid then sends the minimized event to Google Analytics from its server. Advertising user data and ad personalization are marked denied. Caraid does not use this data for advertising, audience targeting, or cross-service tracking.
Information held on your device
A recording or document can stay on your device while it waits to upload or if an upload is interrupted. Device-held copies are separate from Caraid's cloud systems. Anyone with access to the device may be able to access locally stored information, subject to the device and app safeguards in use.
2. Why we use information
We use personal information to:
- create and secure accounts, verify invited contacts, and prevent unauthorized access;
- upload and store recordings and documents;
- play, transcribe, and summarize recordings;
- suggest who a recording may concern, while requiring a person to confirm filing;
- use confirmed-filed documents and recording results to organize the affected profile's ledger;
- maintain a separate care record and ledger for each person;
- share a person's filed captures with that person's care circle;
- support consent, correction, export, access history, deletion, and privacy requests;
- operate, troubleshoot, secure, and improve the reliability of the service;
- measure whether the public landing page is useful, only when a visitor allows optional analytics; and
- meet legal obligations and respond to valid legal process.
For recordings, Caraid uses AI to make a record of what was said, produce a source-grounded summary, and suggest filing. For confirmed-filed recordings and documents, Caraid can use AI to organize the affected profile's ledger. AI output can be wrong. Caraid provides playback and correction tools and flags sensitive values such as medication doses for confirmation. The service does not make medical decisions or recommendations.
3. Consent, recording, and family sharing
An unfiled capture is processed for its uploader. It becomes part of a person's care record when a user confirms a profile tag. Caraid requires an active consent record before the first filing to that profile. A capable adult gives their own consent. A parent or guardian, or an authorized power of attorney or substitute decision maker, acts where their authority applies. Adult consent remains the capable adult's own express opt-in. It is not a caregiver's attestation.
If you record an appointment, you are responsible for participating lawfully and following any clinic rules. If the person holding the device is not attending, an attending participant must have agreed to the recording. Caraid encourages users to tell the people present and to pause or stop when appropriate.
Care-circle access is profile-wide and flat in the current service. A member who has access to a profile can view and help manage that person's filed care record. Adding a profile tag is the filing and sharing action. AI suggestions do not file information and do not grant access.
Four separate rights
| Right | What it controls |
|---|---|
| Profile control | Only an active profile controller can delete the whole care record. |
| Profile access | An active care-circle grant allows a member to view and help manage one person's care record. |
| Upload ownership | Only the original uploader can delete a recording or document everywhere. |
| Filing | A profile tag includes one capture in one person's care record. |
The creator of an unclaimed profile is a temporary steward. When a capable adult claims that profile, they become its controller. The creator keeps only their normal care-circle access unless that access is later removed.
A member can leave a care circle. Leaving ends that member's profile access. It does not delete the profile, change its tags, or delete captures. The member still owns captures they originally uploaded.
4. Who receives information
We disclose personal information only as needed for the purposes in this policy:
- Care-circle members. A filed capture and its profile-side record are available to members with current access to that profile.
- Service providers. Google Cloud hosts Caraid's application, database, object storage, identity service, and managed AI processing. Google Analytics receives minimized public-website events only after a visitor allows analytics; it does not receive an email address or health information from Caraid. Cloudflare provides DNS and can deliver invitation or verification email using a recipient address and delivery metadata, but no health content. App stores and the sign-in provider you choose handle information under their own terms.
- Legal and safety disclosures. We may disclose information when law requires it, or where law permits it to protect rights, safety, and the integrity of the service.
Every third party that receives personal data from Caraid is contractually required to provide protection for that data equal to the protection this policy describes.
We do not sell health data. We do not use health data for advertising, data brokerage, or cross-service tracking.
5. Where information is handled
Caraid stores stateful health information, including its application database, recordings, documents, logs, encryption keys, and backups, in Google Cloud's Montréal region. Data is encrypted in transit and stored with encryption controls.
Outside-Canada processing: Managed Vertex AI inference can process recordings, transcripts, summaries, documents, and ledger context at an approved United States multi-region endpoint. A global endpoint, which can process in the United States or European Union, is used only after explicit review. Account identity information in Google Identity Platform is not region-pinned and can be handled in the United States. Google Analytics can process optional public-website events outside Canada. Cloudflare can process an invitation or verification email address and delivery metadata in the United States and other countries where its network operates so it can route and deliver the message. Google Analytics and Cloudflare do not receive health content for these purposes. Information processed in another country can be subject to that country's laws and lawful access by its authorities. Email privacy@caraid.ca for questions about these service providers or their outside-Canada processing.
Caraid plans to move managed inference to Canada when the selected model supports suitable Canadian processing. Canadian storage is a location choice, not a promise that foreign law can never apply to a US-owned cloud provider.
6. Retention, withdrawal, and deletion
Caraid keeps active captures and care records so the people who use the service can maintain an ongoing history. We keep each data class only while it is needed for the purposes in this policy, to protect the service, or to meet legal obligations. Caraid has not set one fixed retention period for every data class. We will publish material changes when the class-specific schedule is finalized.
Deletion first ends every product read. Physical deletion from cloud storage then runs as durable background work. A receipt with no health details reports whether physical deletion is pending, failed, verified, retained as another subject's shared copy, or not required. Caraid calls deletion verified only after authoritative cloud-object deletion. A deleted capture is not available through the product while physical deletion is pending or if it needs retry.
- Delete a capture everywhere. Only its uploader can do this. All profile tags are removed and access ends everywhere.
- Remove from one care record. Untagging removes the capture from that profile. It preserves the uploader's copy and any other profile tags.
- Delete a whole care record. Only an active profile controller can do this. Caraid deletes that profile's identifiers and derived record, revokes its access, and removes its tags. Original uploads remain with their uploaders unless an uploader deletes them.
- Withdraw consent. The subject can withdraw. For a capture filed only to that subject, cloud deletion is queued. For a capture shared with another subject's profile, Caraid removes the withdrawing subject's tag but retains the copy needed for the other subject and marks it for review.
Audit events and deletion receipts with no health details can remain after health content is deleted so Caraid can prove what happened and protect the integrity of the service. A copy that remains on a user's device is outside the cloud deletion process.
The optional analytics browser identifier expires after 90 days and is not extended by each event. The analytics choice cookie expires after one year. Caraid configures Google Analytics user-level event retention to its shortest available period, currently two months. Aggregate reports can remain after the event-level retention period.
You can delete your account in the app under Settings → Delete account. Account deletion deletes your uploads everywhere, ends your access to other care records, and erases your name and contact details from the account. Your own care record is deleted when you control it; a care record managed by a guardian or legal representative stays with them, and your link to it ends. Deletion is immediate and permanent, with no recovery window. Physical deletion from cloud storage then runs in the background, and Caraid verifies it. If verification fails, the content stays blocked from all access, and a durable record of the failed work remains until Caraid's operators complete the deletion. Caraid keeps permanent PHI-free deletion records — tombstones and audit entries — as proof of deletion, and an opaque internal account reference with no name or contact details so the deleted account can never be signed into again. An invitation another care circle already sent to your contact stays with that circle while it is active, and requires fresh verification by whoever holds the contact. When that invitation ends, your contact details are removed from it. A person who cannot use the app can request account deletion on the account deletion page.
7. Your choices and privacy rights
Depending on your relationship to a profile and applicable law, you can:
- see and correct information in the app;
- request access to personal information Caraid holds about you;
- challenge information that is incomplete or inaccurate;
- export an available machine-readable copy;
- leave a care circle or revoke another member's profile access when authorized;
- remove a capture from one profile, delete your own upload everywhere, or delete a whole record when you are its controller;
- withdraw consent for your profile; and
- ask a question or make a complaint.
The current self-serve export contains accessible recording and document metadata, profile tags, summaries, confirmed clinical values, and ledger data. It does not contain media bytes, raw transcripts, or deletion receipts. You can download authorized media separately. Contact us for a broader access request. We normally respond to a written access request within 30 days, subject to identity verification and lawful exceptions.
8. Children, guardians, and legal representatives
Caraid keeps self, parent or guardian, power of attorney or substitute decision maker, and adult consent as distinct authority types. The person acting for someone else must have a valid basis to do so.
A minor can claim and access their existing profile in the current app while an active guardian keeps control. Caraid does not automatically transfer whole-record control based on age and does not yet offer the later “Manage my own care record” transition. Contact the Privacy Officer for a capacity, guardian-control, or disputed-authority request. We will verify the people and authority involved before changing access or control.
9. How we protect information
Caraid uses safeguards designed for sensitive health information. These include encryption in transit and at rest, managed encryption keys, separate staging and production data, least-privilege service identities, current-access checks before use, short-lived content access, append-only audit records with no health details, and application logging that excludes content and contact values.
No system can guarantee absolute security. If we identify a breach that creates a real risk of significant harm, we will notify affected people and regulators as required by applicable law.
10. Changes to this policy
We can update this policy as Caraid changes. We will post the new effective date here. We will give additional notice and seek new consent when required for a material new purpose.
Contact or complain
Caraid Health Tech Ltd.
Attn: Privacy Officer
121 Mill St
Stouffville, ON L4A 1J2
Canada
Email privacy@caraid.ca. Please do not include health details in your first email. We may need to verify your identity before we discuss an account or care record.
If we do not resolve your concern, you can contact the Office of the Privacy Commissioner of Canada. Residents of Alberta or British Columbia can also contact the Office of the Information and Privacy Commissioner of Alberta or the Office of the Information and Privacy Commissioner for British Columbia.
Policy ID: privacy-v2