Privacy Policy

Effective September 18, 2026

Draft pending legal review. This document describes how the service actually behaves today and has not been reviewed by a lawyer. It is not legal advice and should be reviewed by counsel before the service takes paying customers.

Parental Guardians helps families coordinate care for an aging parent and spot scams before money is lost. Doing that means handling information about people who are often not the person paying for the service. This page says what we collect, what we deliberately do not, and what you can do about it.

1. What we do not collect

Two limits are built into the product rather than promised in this document:

2. What we collect

Account information

An email address or phone number, used to sign you in with a one-time code. Optionally your name, and the name you use for the person you care for. We do not collect their date of birth.

Care coordination data

Care circle membership and roles, tasks, check-ins, notes you write, and the activity timeline assembled from them.

Health signals, only if you connect a device

If you connect a wearable, dispenser or sensor, we store the readings it sends — heart rate, weight, step counts, medication dispensed or missed, and similar. No device is connected by default, and nothing in this category exists for an account that has not connected one.

Fraud and alert data

Alerts raised, their severity, what you did about them, and numbers you have chosen to block.

Call records, not call content

Who called whom, when, how long, how it ended, and consent given. Not the conversation.

Billing

Your plan and subscription status. Card details are handled by Stripe and never reach our servers — checkout happens on Stripe's own hosted page.

Technical and usage data

IP address and browser user agent on security-relevant actions, kept in an audit log. Page views, with record identifiers stripped out: a visit to a specific alert is recorded as /dashboard/alerts/:id, never with the real id.

3. Consent from the person being cared for

The service is built around their consent, not around watching them without it. Every data source requires an explicit opt-in, they can see who is in their care circle, and they can withdraw. You are responsible for having their agreement before you connect a device or add them to a circle. If you are acting under a power of attorney or guardianship, keep your own records of it.

4. Who we share data with

We do not sell personal information and we do not share it for advertising. We use these providers to run the service:

We may also disclose information where the law requires it, or where it is necessary to investigate fraud or protect someone's safety.

5. Cookies

One cookie, named token, holds your sign-in session. It is HTTP-only and same-site, so it is not readable by scripts and is not sent to other sites. We do not use advertising or cross-site tracking cookies. Some preferences, such as your chosen language, are stored in your browser and never leave it.

6. How your data is protected

Traffic between your browser and our service is encrypted with TLS. Calls are end-to-end encrypted between devices. Recordings are encrypted on your device. Access to a family's data is scoped to that family, and security-relevant actions are written to an audit log.

Two things we want to be accurate about rather than reassuring: the database is not yet encrypted at rest, and we do not hold a SOC 2 report or a HIPAA Business Associate Agreement. Both are planned. Neither is true today, and you should not choose this service on the assumption that they are.

7. How long we keep things

Account and care data are kept while the account is open. Sign-in codes expire within minutes. Audit log entries are kept for security and dispute purposes. Device recordings are never held by us at all, so their lifetime is entirely yours.

8. Your choices

You can view and correct your profile in settings, change what notifications you receive, unsubscribe from digest emails from any digest, disconnect a device at any time, and remove someone from a care circle.

You can delete your account yourself, from the danger zone in settings. It removes your profile, your care circle, and the tasks, alerts, check-ins, health signals, device keys and notifications belonging to it. It takes effect immediately and cannot be undone.

Three things it deliberately does not do. It does not delete data that belongs to someone else — a task you were assigned in another family's circle stays with them and is simply unassigned, and a dependent's account is detached rather than removed. It does not delete the security audit entries described in section 7, though it removes your user ID, IP address and device details from them. And it will not run while a paid subscription is active, because deleting the account would leave that subscription billing your card with no account to attach it to; cancel on the billing page first.

9. Children

The service is for adults. It is not directed at children under 13, and we do not knowingly collect their information.

10. Changes

If this policy changes in a way that materially affects you, we will tell you before the change takes effect. The effective date at the top always reflects the current version.

11. Contact

Questions, corrections, or a deletion request: privacy@parentalguardians.com.


Privacy Policy · Terms of Service