What Care Tales collects from patients, account holders and clinic staff, who receives it and what we do not do yet.
Effective date: September 22, 2026
Care Tales, Inc. builds patient education for healthcare organizations. Clinics, hospitals and medical groups buy Care Tales and give it to their patients. Patients open a module with a QR code, a link or one of our mobile apps. Our website is caretales.com. You can reach us at support@caretales.com.
This policy covers caretales.com, the module player, the chatbot an organization runs on our site, the chat widget an organization can place on its own website and our iOS and Android apps. We call all of that the service.
When you open a module from a QR code, a link or an embedded widget we record:
Your message and the answer are stored word for word, together with the page you were on, its title and message counts. We keep counters per visitor and daily totals, including an estimate of what the model call cost. On this path your IP address is used to look up an approximate city and region and is not stored.
The chat widget an organization places on its own website stores more: your full IP address, the country, city, region and coordinates from that lookup, your browser, operating system, device type, language, time zone, screen size and the page that referred you. The widget also reads up to 3000 characters of text from the page you are on and sends it to the model for context. That page text is not stored.
We do not store these conversations. We count only how often the chat is opened and how many messages are sent.
Reminders in the mobile app are scheduled on your own device. We hold no push tokens. The mobile app contains no analytics or crash reporting software.
Staff and provider accounts hold everything above plus roles, portal permissions, whether two-factor authentication is set up and, if the person adds one, a US phone number used only to text a backup sign-in code. If a staff member connects Care Tales to an external assistant tool, we log every call that tool makes.
We do not sell personal information. We do not share it with advertisers. We do not use patient chat text to train AI models.
Chat answers come from Google Gemini models, run on Google Cloud (Vertex AI) in the United States. We send the model your message, recent turns of the conversation, extracts from the knowledge base the organization approved, that organization's own instructions and a line naming your approximate city and region. For the website widget we also send the text of the page you are on. For chat inside a module we also send that page's content.
Care Tales adds safety instructions the organization cannot override. The model is told to point people to 911 for red-flag symptoms, that it is not a doctor and must not diagnose, to answer only from the sources it was given, to keep the cautions those sources contain and to reply in your language.
AI answers can still be wrong. Check anything that matters with your care team.
We may also share information with professional advisors, with a buyer if the company is sold and when the law requires it.
We do not use Sentry, Stripe, PostHog, Mixpanel, Segment, Datadog, Amplitude, Hotjar, Intercom, Crashlytics, OpenAI or Anthropic.
We set a small number of cookies for signing in and for language, plus Google Analytics cookies on marketing pages. Module pages keep ids and preferences in browser storage rather than in cookies. There is no cookie banner on our site today. Our cookie policy lists each item and how to clear it.
There is no automatic deletion schedule for patient data today. Chat transcripts, module sessions, visits, survey answers and rating comments are kept until the account or the organization they belong to is deleted.
We are building a retention schedule and a way to request deletion without writing to us. Until that exists, email support@caretales.com and we will find and delete what we can.
Depending on where you live you may be able to ask for a copy of your information, a correction, deletion or a limit on how we use it. Email support@caretales.com. We may need to confirm who you are before we act.
If you used a module without an account we may not be able to find your records. Nothing ties them to your name and you are never shown an identifier. Tell us the organization, the module and roughly when you used it, and we will do what we can.
Care Tales is built for HIPAA compliance. We are not HIPAA certified, and no such certificate exists for any company. Whether we act as a business associate depends on the written agreement with each organization.
Please treat what a module records as health information. Which condition module you read, what you answered in a survey, the comment you left and the messages you sent to a chatbot can each say something about your health.
Our terms ask users to be 13 or older. Nothing in the product checks age today, and the current flows do not ask for a date of birth. A parent or guardian can write to support@caretales.com to have a child's information removed.
Care Tales is a United States company and our data sits in Google Cloud. All of our databases are Google Firestore databases in Google's nam5 multi-region, which is in the United States. Uploaded files are in Google Cloud Storage in us-central1 (Iowa). Our website, background jobs and functions also run in us-central1. Database backups are kept in Google's US multi-region. Nothing is stored outside the United States by us. The one exception we know of is ip-api.com, described above, which receives a shortened IP address and is not a Google service.
We do not hold a SOC 2 report or any external security certification, and we do not encrypt individual fields inside the database. No system is perfectly secure.
We will post a new version here with a new effective date. When a change matters to you we will give notice on the site or by email before it takes effect.
Questions, requests and complaints: support@caretales.com