Last updated: July 8, 2026
CareRing ("we", "us", "our") is a family caregiver coordination app operated by Vasil Nonchev, based in Sofia, Bulgaria. This Privacy Policy explains how we collect, use, store, and protect your personal data when you use the CareRing mobile application and related services.
We take your privacy seriously, especially given the sensitive nature of health-related information. We comply with the European Union General Data Protection Regulation (GDPR) and applicable Bulgarian data protection laws.
Vasil Nonchev
Sofia, Bulgaria
Email: privacy@carering.app
| Data | Source | Purpose |
|---|---|---|
| Name | Google Sign-In | Display in care circles |
| Email address | Google Sign-In | Account identification |
| Profile photo URL | Google Sign-In | Display in care circles |
| Data | Purpose |
|---|---|
| Care recipient details (name, date of birth, photo, insurance provider & policy number, emergency notes) | Identifying and coordinating care for the person being cared for |
| Medication names, dosages, schedules, prescriber | Medication tracking and reminders |
| Medication administration logs | Adherence tracking |
| Medication inventory (stock quantities, batches, expiry dates, storage locations, refills) | Stock tracking and low-stock / expiry alerts |
| Daily check-ins (mood, pain, sleep, appetite, mobility) | Wellness monitoring |
| Medical conditions (name, diagnosis date) and allergies (allergen, severity) | Medical information hub |
| Emergency contacts and emergency notes | Quick access to important contacts |
| Appointments (type, doctor, location, address, phone, preparation and follow-up notes, date/time) | Care schedule coordination |
| Care notes | Shared care documentation |
| Task assignments | Caregiver coordination |
| Home / household organization and care circle invitations | Grouping members and inviting caregivers |
| Data | Purpose |
|---|---|
| Device push notification token (FCM) | Sending medication reminders and task notifications |
| Crash reports | App stability monitoring (via Firebase Crashlytics) |
| App version, device model, OS version | Debugging and compatibility |
| Time zone and notification preferences | Scheduling reminders at the right local time |
| Subscription status (via RevenueCat) | Managing your plan and entitlements |
The app includes Firebase Analytics for anonymous product and usage metrics. Analytics is disabled by default and runs only if you explicitly opt in (consent under the GDPR and ePrivacy rules). You can withdraw that consent at any time in the app settings. The device advertising identifier is not collected — advertising-ID collection is turned off in the app, so no advertising ID is used even when analytics is enabled. No health or care data is ever sent to analytics.
| Data | Purpose |
|---|---|
| Anonymous usage events (screens viewed, features used) | Understanding how the app is used, to improve it |
| Anonymous app-instance identifier | Distinguishing analytics sessions; not linked to any advertising identifier |
Health data is processed under GDPR Article 9(2)(a) — explicit consent. You may withdraw consent at any time by deleting your account.
We do NOT:
When you join a care circle, other members of that circle can see the care data within it (medications, tasks, check-ins, notes, medical info). You control which circles you join and can leave at any time.
The providers below act only as processors on our behalf. Because Google Firebase and RevenueCat are operated by Google and RevenueCat on their own global infrastructure, some of this data may be processed outside the EU/Switzerland, including in the United States, under appropriate safeguards.
| Provider | Purpose | Data shared | Location |
|---|---|---|---|
| Google Firebase (Authentication) | User sign-in | Email, name, profile photo | Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework) |
| Google Firebase (Cloud Messaging) | Push notifications | Device token, notification content | Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework) |
| Google Firebase (Crashlytics) | Crash reporting | Device info, crash logs (no health data) | Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework) |
| Google Firebase (Analytics) | Anonymous usage metrics — only if you opt in (Section 2.4) | Anonymous usage events (no health data, no advertising ID) | Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework) |
| Google (Gmail SMTP email) | Sending account, notification, and optional daily-digest emails | Your email address and email content; daily digests may include care-circle and care-recipient names, recent activity, and adherence summaries | Google infrastructure, may include the US (SCCs / EU-US Data Privacy Framework) |
| Supabase | Managed database hosting | All app data (encrypted at rest) | Switzerland (eu-central-2, Zurich) — EU adequacy decision |
| RevenueCat | Subscription management | Anonymous user ID, purchase receipts, subscription status | US (SCCs / EU-US Data Privacy Framework) |
We do not share health or care data with any third party for its own use. Your core care records are stored only on our EU-hosted application servers, our Swiss-hosted database (see Section 6), and your device. Limited care-related content may additionally pass through the notification and email providers listed above — for example, a reminder or a daily digest that names a care recipient — solely to deliver the messages you have set up.
europe-west1 (Belgium, EU). Data is encrypted in transit (TLS 1.2+). Sensitive personal fields are additionally encrypted at the application layer (AES-256-GCM) before storage, and data at rest is encrypted by our cloud database and storage providers.eu-central-2 (Zurich, Switzerland — covered by a European Commission adequacy decision; see Section 11). Data encrypted at rest by Supabase and in transit (TLS 1.2+).You have the right to:
To exercise any of these rights, use the in-app settings or contact us at privacy@carering.app. We will respond within 30 days.
You can delete your account at any time from Settings within the app. This will:
Deletion is permanent and cannot be undone. Deletion of the records held by Firebase and RevenueCat is carried out on a best-effort basis immediately after your account data is removed. Some non-identifying entries in shared care circles may be retained — without your name — so that the other members' care history stays intact.
You must be at least 18 years old to create a CareRing account. Care recipients whose information is entered in the app may be of any age, including minors — their information is entered and managed by a responsible adult caregiver, who must have the authority to provide it. CareRing is not intended to be used directly by anyone under 18, and we do not knowingly allow a person under 18 to create their own account. If you believe someone under 18 has created an account, please contact us and we will delete it.
Our application servers run in the EU on Google Cloud Platform (europe-west1, Belgium). Our database is hosted by Supabase in Switzerland (eu-central-2, Zurich). Switzerland is not part of the EU/EEA, but the European Commission has granted it an adequacy decision, so storing your data there is a lawful transfer under GDPR Article 45 and your data receives protection equivalent to EU standards. Beyond this, some limited data — push notifications, emails (including daily digests that may name a care recipient), crash reports, opt-in analytics, and subscription status — is handled by Google (Firebase and Gmail SMTP) and RevenueCat and may be processed outside the EU/Switzerland, including in the United States, under appropriate safeguards (Standard Contractual Clauses and/or the EU-US Data Privacy Framework). Your core care records in the database remain in Switzerland.
We may update this Privacy Policy from time to time. We will notify you of material changes through the app or by email. The "Last updated" date at the top reflects the most recent revision.
For privacy-related questions or requests:
Email: privacy@carering.app
Vasil Nonchev
Sofia, Bulgaria