Policy

Privacy Policy

What Care Tales collects from patients, account holders and clinic staff, who receives it and what we do not do yet.

Effective September 22, 2026, version 1

Privacy Policy

Effective date: September 22, 2026

Who we are

Care Tales, Inc. builds patient education for healthcare organizations. Clinics, hospitals and medical groups buy Care Tales and give it to their patients. Patients open a module with a QR code, a link or one of our mobile apps. Our website is caretales.com. You can reach us at support@caretales.com.

This policy covers caretales.com, the module player, the chatbot an organization runs on our site, the chat widget an organization can place on its own website and our iOS and Android apps. We call all of that the service.

The short version

  • You can use a module without an account. We still record how the module was used.
  • If you use a chatbot that belongs to a healthcare organization, your messages are stored word for word. Staff at that organization can read them. So can Care Tales admin and team staff.
  • Chat text is sent to Google Gemini models to produce an answer.
  • We do not sell personal information and we do not use it for advertising.
  • We do not delete patient records on a schedule today. See "How long we keep information".
  • Our content is education. It is not medical advice.

What we collect from patients with no account

When you open a module from a QR code, a link or an embedded widget we record:

  • the module, timestamps, your browser's full user-agent string, whether the request looks automated and which QR code or link brought you
  • your IP address shortened to its first three parts, which points at a network rather than at you (the website widget is an exception, described below)
  • a visitor id kept in your browser so repeat visits from the same device can be joined
  • how you moved through the module: pages completed, time on each page, reading level and any switch between levels, quiz results including which wrong option you chose, video and audio events, other interface events and where you stopped
  • anything you type: answers to the surveys before and after a module, your rating from 1 to 5 and any comment you leave with it
  • your phone number and a record of your consent, if you asked us to text you a module link

Chat with an organization's chatbot

Your message and the answer are stored word for word, together with the page you were on, its title and message counts. We keep counters per visitor and daily totals, including an estimate of what the model call cost. On this path your IP address is used to look up an approximate city and region and is not stored.

The chat widget an organization places on its own website stores more: your full IP address, the country, city, region and coordinates from that lookup, your browser, operating system, device type, language, time zone, screen size and the page that referred you. The widget also reads up to 3000 characters of text from the page you are on and sends it to the model for context. That page text is not stored.

Chat inside a module

We do not store these conversations. We count only how often the chat is opened and how many messages are sent.

What we collect from account holders

  • Account: email address, display name, photo, the sign-in provider you used, your role and timestamps.
  • Profile: first and last name, phone number, reading level and the organizations you belong to.
  • Onboarding: language, reading level, the health areas you pick and a health area you write in yourself.
  • Progress: bookmarks, started and completed modules, current page, reading level, ratings, written feedback and surveys.
  • Chat history, when you are signed in.
  • Older accounts may still hold fields from an earlier web sign-up flow: date of birth, conditions, medications, gender, education, barriers, motivations, learning styles and confidence. Our database rules protect these as health information.

Reminders in the mobile app are scheduled on your own device. We hold no push tokens. The mobile app contains no analytics or crash reporting software.

What we collect from clinic staff and providers

Staff and provider accounts hold everything above plus roles, portal permissions, whether two-factor authentication is set up and, if the person adds one, a US phone number used only to text a backup sign-in code. If a staff member connects Care Tales to an external assistant tool, we log every call that tool makes.

What we do with it

  • run the module and remember your place, your language and your reading level
  • answer chat questions
  • show an organization how its patients are using its modules
  • read free-text answers and ratings so we can improve modules
  • keep the service working and safe, including rate limits and abuse prevention
  • reply when you contact support
  • meet legal obligations

We do not sell personal information. We do not share it with advertisers. We do not use patient chat text to train AI models.

Artificial intelligence

Chat answers come from Google Gemini models, run on Google Cloud (Vertex AI) in the United States. We send the model your message, recent turns of the conversation, extracts from the knowledge base the organization approved, that organization's own instructions and a line naming your approximate city and region. For the website widget we also send the text of the page you are on. For chat inside a module we also send that page's content.

Care Tales adds safety instructions the organization cannot override. The model is told to point people to 911 for red-flag symptoms, that it is not a doctor and must not diagnose, to answer only from the sources it was given, to keep the cautions those sources contain and to reply in your language.

AI answers can still be wrong. Check anything that matters with your care team.

Who else receives information

  • Google Cloud and Firebase host everything: sign-in, the database, file storage, our server code and the website.
  • Google Gemini receives patient chat text and module content as described above.
  • Google Cloud Text-to-Speech and Google Cloud Translate produce spoken audio and translations.
  • ip-api.com, a company outside Google, receives a shortened IP address during chat to look up a city and region. It does not receive any message text.
  • Twilio sends module links by SMS. Gmail SMTP sends our email.
  • Apple, Google and Microsoft handle sign-in if you choose one of them.
  • Google Analytics 4 runs on our marketing pages only. It is not loaded on module pages or organization pages.

We may also share information with professional advisors, with a buyer if the company is sold and when the law requires it.

We do not use Sentry, Stripe, PostHog, Mixpanel, Segment, Datadog, Amplitude, Hotjar, Intercom, Crashlytics, OpenAI or Anthropic.

Cookies and browser storage

We set a small number of cookies for signing in and for language, plus Google Analytics cookies on marketing pages. Module pages keep ids and preferences in browser storage rather than in cookies. There is no cookie banner on our site today. Our cookie policy lists each item and how to clear it.

How long we keep information

There is no automatic deletion schedule for patient data today. Chat transcripts, module sessions, visits, survey answers and rating comments are kept until the account or the organization they belong to is deleted.

  • Deleting an account deletes the user record and everything stored under it, organization membership, uploaded files and the sign-in record.
  • Deleting an organization deletes its visits, module sessions and chat transcripts.
  • Sign-in sessions last 12 hours, or 14 days if you asked to stay signed in. Share links last 90 days. Our database backups are kept for 98 days, so deleted data can remain in a backup until it expires.

We are building a retention schedule and a way to request deletion without writing to us. Until that exists, email support@caretales.com and we will find and delete what we can.

Your choices and requests

Depending on where you live you may be able to ask for a copy of your information, a correction, deletion or a limit on how we use it. Email support@caretales.com. We may need to confirm who you are before we act.

If you used a module without an account we may not be able to find your records. Nothing ties them to your name and you are never shown an identifier. Tell us the organization, the module and roughly when you used it, and we will do what we can.

Health information and HIPAA

Care Tales is built for HIPAA compliance. We are not HIPAA certified, and no such certificate exists for any company. Whether we act as a business associate depends on the written agreement with each organization.

Please treat what a module records as health information. Which condition module you read, what you answered in a survey, the comment you left and the messages you sent to a chatbot can each say something about your health.

Children

Our terms ask users to be 13 or older. Nothing in the product checks age today, and the current flows do not ask for a date of birth. A parent or guardian can write to support@caretales.com to have a child's information removed.

Where information is processed

Care Tales is a United States company and our data sits in Google Cloud. All of our databases are Google Firestore databases in Google's nam5 multi-region, which is in the United States. Uploaded files are in Google Cloud Storage in us-central1 (Iowa). Our website, background jobs and functions also run in us-central1. Database backups are kept in Google's US multi-region. Nothing is stored outside the United States by us. The one exception we know of is ip-api.com, described above, which receives a shortened IP address and is not a Google service.

Security

  • sign-in handled by Firebase Auth, with server-issued session cookies that can be revoked
  • two-factor authentication required for every staff and provider account
  • roles checked on the server on every request and never taken from the browser
  • database and storage rules that deny by default and keep each organization's data separate
  • patient chat transcripts readable only by that organization's providers and by Care Tales admin and team staff
  • rate limits on chat, contact forms, speech and SMS
  • encryption in transit and at rest, using Google Cloud defaults

We do not hold a SOC 2 report or any external security certification, and we do not encrypt individual fields inside the database. No system is perfectly secure.

Changes to this document

We will post a new version here with a new effective date. When a change matters to you we will give notice on the site or by email before it takes effect.

Contact

Questions, requests and complaints: support@caretales.com

Questions about this document
Write to support@caretales.com and we will answer.
All legal documents