Last updated September 3, 2026
These are the third-party providers that may process your data on our behalf to run the Service. They may only use it to provide their service to us.
| Provider | Purpose | Data processed | Region |
|---|---|---|---|
| Supabase | Database, authentication, and file storage (recording audio) | All account and care data, recording audio | Project region (currently shared infrastructure, see below) |
| Paddle | Merchant of record: subscription payments, sales tax/VAT, invoices | Name, email, billing country, card details (entered on Paddle’s own checkout), plan and billing status | United Kingdom / United States (global) |
| Vercel | Application hosting and delivery | Request data in transit, server logs | Global edge / United States |
| Anthropic | AI summaries, medication information, quick-add parsing | Recording transcripts, medication names, and quick-add text you submit | United States |
| Groq | Speech-to-text transcription (AI) | Recording audio you submit | United States |
| Resend | Transactional email (notifications) | Recipient name and email address, and the task, comment, or person named in the notification | United States |
| OpenStreetMap Nominatim | Care-location address search | Search text you type | United Kingdom / European Union |
| Your calendar provider | Calendar import (only when you paste a calendar link) | Our server fetches the link you provide; no credentials are stored | Depends on your provider |
We update this list before adding a new provider that processes personal or health data.
All data is transmitted over encrypted connections (TLS/HTTPS) and encrypted at rest by our database and storage provider.
Access to a family’s data is enforced both by database row-level security and by server-side membership checks on every API request.
Production access is limited to the operator and is used only to run and support the Service. We do not hold a SOC 2 or ISO 27001 certification today; if you need one for procurement, ask us and we will tell you honestly where we are.
Passkeys (Face ID / Touch ID) are available for phishing-resistant sign-in. Biometrics never leave your device; we store only a public key.
The three companies that carry the bulk of your data publish their own certifications. These are theirs, not ours: they cover the platforms Great Care runs on, not Great Care itself.
Supabase (our database, authentication and file storage) states that it is SOC 2 Type 2 compliant and ISO 27001 certified — supabase.com/security and trust.supabase.io.
Vercel (application hosting) states that it has a SOC 2 Type 2 attestation for Security, Confidentiality and Availability, and is ISO 27001:2022 certified — vercel.com/docs/security/compliance and security.vercel.com.
Paddle (our merchant of record) states that it has completed a SOC 2 Type 2 audit and is PCI DSS SAQ A compliant, which it describes as not directly storing card information — trust.paddle.com.
Two things that follow from that, stated plainly rather than left for you to work out. Supabase and Vercel both offer HIPAA Business Associate Agreements on their higher tiers; Great Care is not on those tiers and holds no BAA with either, which is why we do not offer one to you. And a provider being certified says nothing about the application built on top of it: Great Care itself holds no SOC 2 report and no ISO 27001 certificate, and the security of what we have built is described on this page rather than attested by anyone.
Great Care currently runs in a Supabase project that also hosts other small applications operated by the same owner. Great Care’s tables are logically separated by row-level security and by name, and no other application reads them. We plan to move to a dedicated project as usage grows; the runbook for doing that without data loss is already written, and this page will be updated when it happens.
Every change to care data is captured in an append-only audit log, so an accidental deletion of care data can usually be recovered. Audit copies of deleted records are kept for up to 90 days.
The database is hosted on Supabase with managed backups, and we maintain a documented restore procedure and an export path that works even if the app itself is unavailable.
Appointment recording is optional and off until you tap Record. Audio and transcripts are sent to the providers listed above solely to produce your transcript and summary; they are not used to train AI models under our agreements with those providers.
Before every recording, the app asks you to confirm that everyone in the conversation knows it is being recorded and has agreed. Recording laws vary by location; see our Terms of Service.
A Care Link is a read-only page for one person showing only the sections the family chose. Links use a 36-character random token, can be given an expiry, and can be turned off at any time from Team & Sharing. Opens are counted and shown to the family. Files and photos are never exposed through a Care Link.
Only strictly necessary session cookies from our authentication provider. No analytics, no advertising trackers.
If you believe you have found a security vulnerability, email security@greatcare.app. We welcome responsible disclosure and will work with you to resolve issues quickly.
For details on how we handle your information, see our Privacy Policy.