CareHaven is a private app for caregivers. The summary below is the whole story; the rest of this page is the receipts.
The app does not collect:
Everything you log โ feedings, behaviors, sleep, vitals, doctor visits, milestones, goals, contacts, custom routines, photos attached to entries โ is encrypted on your device before it's stored, with a key only your circle holds. We have no way to retrieve it from our end.
If you delete the app, the data goes with it (unless you've made a backup or turned on sync).
You can opt in to auto-backup in Settings โ Privacy & Data. When enabled, the app writes a .chbak file to your Files app on a schedule you choose. The file is AES-256-GCM encrypted with a password only you know โ without that password, the file is unreadable, including by us.
You control where the file goes (iCloud Drive, Dropbox, your own NAS, anywhere). We never see it.
If you enable sync (Settings โ Sync), your care log stays in sync across your devices and everyone in your circle โ encrypted the whole way, so only your circle can read it. The contents are unreadable to us, and to anyone outside your circle.
Sync is off by default. Turning it off after using it may leave a copy in your synced storage, which you can delete from your device's Settings.
The app integrates with Apple Health for sleep, vitals, cycle, and body measurements. Reads happen only with your explicit permission via Apple's standard authorization flow. Writes happen when you log a vital, sleep entry, or cycle day in the app.
HealthKit data flows directly between Apple Health and the app's local store on your iPhone. It does not pass through any server we run, and no third-party SDK in the app reads HealthKit values.
The app includes optional AI features for medication info, pattern commentary on your own log, and visit-summary parsing. The data flow when you use these:
The provider receives only the stripped query, not your identity. We don't operate any server-side caching or logging of these queries. The AI tier is enrichment โ the deterministic chart underneath is always the source of truth, and AI never makes decisions for you.
These stripped queries go to a small set of vetted third-party AI services โ a primary service, plus a fallback used only if the primary is unreachable. We choose providers on capability and privacy posture, and we may change them as better options emerge; this policy will always describe the current data flow. If you'd like the names of the current providers, email us and we'll tell you.
Each provider's privacy policy governs how they handle the request on their side. Because we strip identifiers before any call, the data they receive isn't associated with you or your care recipient by CareHaven. We don't share customer data with any provider for training; we use them as inference endpoints only.
You can disable AI features entirely in Settings โ Privacy & Data. With AI disabled, no data leaves the device through these features.
This marketing site uses Plausible Analytics for cookieless, anonymous page-view counts. Plausible doesn't set cookies, doesn't use IPs, doesn't collect personal data, and has no fingerprinting. It tells us aggregate "this page got X views this week" โ nothing else. Plausible's data policy.
The signup form sends your email to Mailchimp via single opt-in so we can email you when CareHaven is ready for early-access testing. You can unsubscribe with one click. We use Mailchimp's standard opt-in confirmation and never share or resell the list.
CareHaven is designed for caregivers โ adults logging care on behalf of a person they're responsible for. The app does not target users under 13 directly. The data about a person (your child, your aging parent, your sibling) is yours as their caregiver; we have no access to it.
If you're a minor caregiver yourself (e.g., a teen sibling), the app still works the same way. We don't collect anything from you either.
Because we don't have your data, most data-rights requests don't apply โ there's nothing on our end for you to access, correct, or delete. The only thing we do hold is your email address if you signed up for the launch list. To remove that:
If you delete the app from your device, the local store goes with it. If you have sync enabled, you can delete synced data from your device's Settings (Manage Account Storage โ CareHaven).
If we ever change the privacy posture in a meaningful way (add telemetry, change what's collected, add ads, etc.), we'll:
We're not planning any of those changes. The privacy-first stance is the product, not a feature we'd compromise.
CareHaven is a tracking and coordination tool. It is not FDA-approved, not regulated as a medical device, and shouldn't be used to diagnose or make medical decisions. The app makes this disclosure inline (Settings โ About) and on the homepage. Always consult your healthcare provider.
Questions, complaints, or requests: reply to any CareHaven email, or use the contact form on the homepage. We read every message.