CareBoard Privacy Policy
Last updated September 25, 2026
CareBoard is an iPhone app that gives a family a private, shared board for looking after an older parent or other loved one: medications, visits, meals, shifts, and short updates. This page explains, in plain English, what the app stores, where it goes, and how to delete it.
The short version
- Your household’s board lives on your devices and in iCloud (Apple CloudKit). There is no CareBoard server. The developer cannot read your board.
- Everyone who joins your household can see and edit the shared board.
- For weather alerts, the home address (or a one-time location) is sent to weather and map services to look up conditions.
- No ads, no tracking, no third-party analytics, and we never sell data.
- CareBoard is not medical advice and not an emergency service. In an emergency, call 911.
Who we are
CareBoard (bundle ID com.careboard.app) is built by Stephen Rau, an independent developer. In this policy, “we” means the developer, and “you” means anyone using the app. Questions go to privacy@thistledew.app.
Where your data lives
On your iPhone
CareBoard keeps a working copy of your household board on the device so it opens quickly and works offline. Some settings stay only on that device: the app lock and PIN, notification choices, hot and cold day warning choices, recent weather (kept for about 30 minutes), and sync bookkeeping.
In iCloud (Apple CloudKit)
When you start a live household, CareBoard saves it in a private area (a CloudKit “zone”) in the iCloud account of the person who started it. That person is the household owner. When others join, Apple’s CloudKit sharing gives them access to that same household zone. It then appears in their iCloud under “shared with me”. Apple stores and protects this data under the Apple Privacy Policy and iCloud terms. It uses the iCloud storage of the household owner.
Invite codes (CloudKit public database)
To let family members join with a short code (like CARE-XXXX-XXXX), CareBoard saves a small invite record in CareBoard’s public CloudKit database. It holds the invite code, the household name, the household’s internal ID, and the iCloud sharing link that lets someone join. It holds no care information. Anyone with the code can look it up. When an admin replaces the code, the old invite record is deleted.
No developer server
CareBoard has no server of its own. We do not receive, store, or have access to your care logs, photos, schedule, or profile. We cannot see your household board and cannot recover it for you.
What’s shared with your household
Everyone who joins your household can see and add to the whole shared board, including everything listed below under “What CareBoard stores”. They also see each member’s display name, face picture, and role (admin or caregiver). Your Sign in with Apple user ID is stored on your member record so the board knows it’s you on every device.
Treat the invite code like a house key. Anyone who has the code or join link can join the household and read and edit the board. Only share it with people you trust. An admin can replace the code in Household settings and can remove people from the household.
What CareBoard stores
You and your family decide what to enter. Depending on what you use, the shared board can include:
- Care recipient profile: name, nickname, date of birth (optional), a short condition summary, and care stage.
- Medications: names, strengths, instructions, and schedules, plus a record of each dose: given or missed, by whom, and when. There are also optional backup-caregiver alerts for missed doses.
- Care logs: meals and how much was eaten, drinks, naps, bathroom visits, mood, and behavior incidents (for example sundowning or wandering), with who logged them, when, and any notes.
- Schedule: appointments and visits (time, place, notes, repeats, who is going) and the duty roster of who is on shift.
- Wall and notes: status posts, optional photos you attach, acknowledgements, handoff notes, and an activity feed of what changed.
- Lists: the house shopping list and to-dos.
- Emergency contacts: names, relationships, and phone numbers you add for the SOS screen, plus an optional household helpline number.
- Home address: the care recipient’s home address (or ZIP code), used for weather alerts and the Nearby help list.
- Household members: display names, a color or preset icon, or a small photo you choose (shrunk to about 240 pixels), role, join date, and Sign in with Apple user ID.
- Household settings: household name, invite code, time zone, and missed-dose settings.
Sign in with Apple
Live households use Sign in with Apple. CareBoard asks Apple for your name only, which becomes your display name on the board. It does not ask for your email address. Apple gives CareBoard an anonymous user ID, which is saved with your member record.
Scanning and importing medication lists
You can add medications by pointing the camera at a label, choosing a photo, importing a PDF or image (for example a Hero Medication Report or a pharmacy printout), or pasting text. The text is read on your iPhone with Apple’s built-in text recognition (Vision and VisionKit). This includes the best-effort reading of handwritten lists. Images and files are not uploaded anywhere by CareBoard and are not saved. Only the medication details you review and confirm are added to the board. When you open the paste option, CareBoard reads your clipboard to pre-fill the text box.
Weather alerts and location
CareBoard can warn the family about heat, ice, storms, and poor air where the care recipient lives. It does not use Apple WeatherKit. Here is what it sends and to whom:
- Address suggestions: while you type the home address in Household settings, the text you type is sent to Apple Maps (MapKit) to suggest matching addresses.
- Finding the address on a map: the saved home address is sent to Apple’s geocoding service to turn it into map coordinates. If Apple can’t find it, the address is sent to OpenStreetMap Nominatim and then the US Census Bureau geocoder. If only a ZIP code is saved, the ZIP is sent to Zippopotam.us.
- Weather: the resulting coordinates, which are precise enough to point at the home, are sent to Open-Meteo for the forecast and air quality, and to the US National Weather Service for official alerts.
- “Use this iPhone” (optional): if you tap it, CareBoard asks iOS for location permission while the app is in use. It then requests one approximate location fix (accurate to about a kilometer) and sends those coordinates to the weather services above. That location is not saved to iCloud or shared with your household. If you say no, CareBoard won’t ask again, and weather still works from the address.
These services receive the request from your device, including your IP address, just as any website would. They get no care information. The home address itself is part of the shared household board.
Face ID, Touch ID, and PIN lock
You can lock CareBoard on your iPhone. Face ID or Touch ID checks happen entirely inside iOS. CareBoard only learns “yes” or “no” and never receives your face data or fingerprint. If you use a CareBoard PIN, only a salted, one-way hash of it is stored in this iPhone’s Keychain. It is marked “this device only” and is not synced to iCloud or shared with anyone. The lock applies only to the iPhone where you set it.
Notifications
If you allow notifications, reminders for due doses, visits, severe weather, and family activity (such as someone joining or leaving) are scheduled by CareBoard on your iPhone. You can turn each type on or off in Household settings. CareBoard also uses Apple’s silent iCloud push so a change made on one phone (like a dose marked given) updates the others. We don’t send marketing notifications.
Calendar (optional)
If you allow Calendar access, CareBoard adds household visits to the Apple Calendar you pick. It checks your calendar on the device only to find events it added before, so it doesn’t add duplicates. It does not upload your other calendar events anywhere. If the calendar you pick syncs with a service such as iCloud, Google, or Exchange, that service will receive the visit details under its own policy.
Camera and photos
The camera and photo library are used only when you choose to: scanning a medication label or visit paper, taking or picking your face picture, or adding a photo to a Wall post. You pick which photo to use. Face pictures and Wall photos are compressed and saved to the shared household board, so your household can see them. Scanned images are not saved.
Links that open other apps
Some buttons open another app or website, and what you send is up to you. Examples: calling a number (including 911), sharing or copying the shopping list, Look up on a shopping item (opens a Walmart or Instacart search for that item), and Nearby help (opens an Apple Maps or Google search for the service type near the saved ZIP code). Those services handle that information under their own privacy policies.
Analytics, tracking, and ads
- No advertising, and no ad networks.
- No tracking across other companies’ apps or websites, and no advertising identifier.
- No third-party analytics or crash-reporting SDKs. CareBoard contains no third-party code libraries.
- We do not sell or rent any data.
If you have opted in to share analytics with developers in iOS Settings, Apple may give us anonymous crash reports and usage statistics under Apple’s terms.
Children
CareBoard is made for adult family caregivers. It is not directed to children under 13, and we do not knowingly collect information from children.
How long data is kept and how to delete it
Your household board stays on your devices and in iCloud until someone deletes it. We hold no copy, so we can’t delete it for you, but you can:
- Delete individual entries: meals, drinks, naps, bathroom, mood, and behavior logs, shopping items, emergency contacts, and appointments can be undone or removed in the app. Removing an entry removes it from the shared board. You can also remove your photo from your profile or a Wall post you’re writing.
- Remove a person: a household admin can remove any other member in Household settings. This deletes their member record and ends their access to the shared board.
- Leave a household: CareBoard doesn’t have a “Leave household” button yet. To leave, ask the household admin to remove you. Then sign out and delete the app. Anything you added to the shared board stays with the household unless it is deleted.
- Sign out: Household → Sign out disconnects this iPhone from the household. It does not erase the household from iCloud. The local copy stays on the iPhone until you delete the app.
- Delete data on your iPhone: deleting the CareBoard app removes the app’s data and settings from that iPhone, and the lock is turned off. (iOS may keep the hashed PIN in the device Keychain after the app is deleted. It never leaves the iPhone.)
- Delete the whole household (owner): the household is stored in the owner’s iCloud. The owner can remove it by going to iOS Settings → [your name] → iCloud → Manage Account Storage (called “Storage” on some versions), choosing CareBoard, and deleting its data. This permanently deletes the household board for every member, and it cannot be undone. There is no in-app button for this yet.
- Invite record: replacing the invite code deletes the old invite record. If you’d like us to delete a leftover invite record from CareBoard’s public database, email us with the invite code.
- Sign in with Apple: you can stop using Apple sign-in with CareBoard in iOS Settings → [your name] → Sign-In & Security → Sign in with Apple.
If you need help deleting your data, email privacy@thistledew.app and we’ll walk you through it.
Security
Data in transit and in iCloud is protected by Apple’s CloudKit security, and the app can be locked with Face ID, Touch ID, or a PIN. No system is perfectly secure, so please use a passcode on your iPhone and share invite codes carefully.
Not medical advice. Not an emergency service.
CareBoard is a family organizer. It is not a medical device, not a medical record, and not a substitute for advice from doctors, nurses, or pharmacists. Always follow the prescriber and the pharmacy label. Reminders can be late or missed, for example when a phone is off, offline, or has notifications turned off. Weather alerts are a heads-up, not a guarantee. CareBoard does not contact emergency services for you. In an emergency, call 911 (or your local emergency number).
Changes to this policy
If our data practices change, we’ll update this page and the “Last updated” date above. Significant changes will also be noted in the app’s release notes.
Contact
Questions or requests about privacy: privacy@thistledew.app
Need help using the app? See CareBoard Support.