This Privacy Policy describes how Utility Lab Studio («we») processes personal data within the mobile application CarePilot (the «App»). CarePilot is a family care coordination tool for caregivers. It is NOT a medical app and does NOT provide clinical advice.
This policy applies only to the App. The website utilitylabstudio.com has its own privacy policy.
1. Data controller
Two different kinds of processing live side by side in CarePilot, and it is worth telling them apart, because the same party is not responsible for both:
- Your account data (email, language, subscribed plan, technical data): the controller is Utility Lab Studio. We are the ones who decide how the app works, where data is stored and which providers are involved.
- The content of the care group (the information about the cared-for person, their medication, their appointments, their documents): the one who decides what gets recorded is the person who creates the group, and it is that person who is responsible for having a lawful basis to do so. We neither enter it nor can we read it: it travels encrypted from their device.
For any question, write to info@utilitylabstudio.com.
2. Data the App processes
2.1. Account data
- Email address (signup and login).
- Name or nickname (optional).
- Profile photo (optional).
- Auto-generated unique account identifier.
You can create your account with an email and password, with Google or with Apple. If you use Sign in with Apple and choose to hide your email, Apple gives us a private relay address (@privaterelay.appleid.com): your real email never reaches our servers.
2.2. Care group data
A care group contains information about the cared-for person («Care Recipient») and the people caring for them («members»). It includes:
- Name, age, optional photo of the cared-for person.
- Relevant medical data: allergies, conditions, blood type, insurance number (optional).
- Emergency and family contacts (name, phone).
- Patient address and contact details (optional, for SOS).
- List of group members, their roles and permissions.
2.3. Care activity data
- Medications, doses, frequencies, schedules and intake records.
- Medical appointments, specialists, reminders and notes.
- Daily care tasks and routines.
- Shared expenses, photographed receipts, custom categories.
- Optional documents: prescriptions, medical reports, related photos.
- Notes written by group members.
- Historical record of shift handovers.
- Audit log: who did what within the group, with timestamp.
2.4. Technical data
- Device identifier and push notification token (Firebase Cloud Messaging; on iPhone, delivered through the Apple Push Notification service, APNs).
- IP address, briefly logged for security and abuse prevention.
- Device language and timezone.
- App version, device model and OS (for technical diagnostics).
- Crash reports (Firebase Crashlytics) if the app stops responding. These contain technical stack traces, not personal data.
2.5. Data NOT collected
CarePilot does not collect: background location, your phone contacts, browsing history, social media data, biometric data (beyond the local fingerprint/face used by the OS to unlock the app, which NEVER leaves your device) or advertising behavioral data.
3. End-to-end encryption (E2E)
All sensitive group information is encrypted on your device before being sent to our servers. Only group members hold the keys to decrypt it. This includes:
- Name and personal data of the cared-for person.
- Medications, appointments, notes and documents (for expenses, the description and the category; see the exceptions below).
- Associated photos (prescriptions, receipts, reports).
- Audit log with action details.
- Display names of group members.
Utility Lab Studio has no technical access to encrypted content. Data flowing through our servers (Firebase, Cloud Storage) is encrypted such that only group members can read it.
A few exceptions remain unencrypted out of functional necessity, and we would rather list every one of them:
- Unique account identifiers (UID), the email used for login, the group ID and timestamps.
- The amount, the date and the currency of each expense. The server needs them to work out your weekly summaries and to warn you about spending that is out of the ordinary. The description, the category and who paid are encrypted: we can see that there was a €40 expense on a Tuesday, not what it was for.
- The group key, while an invitation code is active. So that it can be handed over to whoever joins, it stays stored on our servers protected by a secret of ours. The code is single-use: as soon as someone redeems it, both the code and that copy of the key are deleted.
4. AI processing
CarePilot offers a scanning feature: take a photo of a prescription, appointment or receipt and AI extracts the data automatically.
For this we use Google Cloud Vertex AI in the European region (europe-west1) with the Gemini 2.5 Flash model. We configured processing with Zero Data Retention:
- Scanned images are NOT retained on Google’s servers.
- Images are NOT used to train AI models.
- They are processed at submission time and discarded immediately after.
- Processing happens entirely within the European Union.
Official documentation: Vertex AI Data Governance.
5. Data shared with third parties
We do not sell or transfer data to third parties for commercial purposes.
Providers that process data on our behalf:
- Google LLC / Firebase — user authentication, encrypted database, encrypted photo storage, push notifications and crash reporting. Data stored in European regions whenever possible. (Firebase privacy)
- Google Cloud Vertex AI — image processing for prescription/appointment/receipt scanning, with Zero Data Retention.
- Google Play Billing — payment and subscription handling for the Plus and Pro plans on Android devices. Google Play receives only the minimum data necessary to process payments per its own policy. (Google privacy)
- Apple Inc. — on iPhone: payment and subscription handling through in-app purchases, push notification delivery (APNs) and Sign in with Apple, if you choose it. Apple processes that data under its own policy. (Apple privacy)
6. App permissions
CarePilot requests these permissions on your device only when necessary (exact names vary between Android and iPhone):
- Camera — scanning prescriptions, appointments, receipts and optional photos.
- Storage / Gallery — attach existing photos.
- Notifications — medication, appointment and shift reminders.
- Biometrics — optional fingerprint or face unlock (NEVER leaves the device).
- Precise location — only on demand, when tapping «Show my current location» in SOS. Never in background. Never stored.
- Internet — sync with encrypted servers.
- Vibration — notification feedback.
7. Purpose and legal basis
- To deliver the coordination service you requested (legal basis: contract performance, GDPR Art. 6.1.b).
- To comply with our legal obligations (GDPR Art. 6.1.c).
- To keep the app secure and prevent abuse (legitimate interest, GDPR Art. 6.1.f).
- To improve the service via anonymous technical reports (legitimate interest, GDPR Art. 6.1.f).
Health data about the cared-for person
The information recorded about the cared-for person —allergies, conditions, medication, medical documents— is a special category of data (GDPR Art. 9) and deserves a separate explanation.
That person usually does not use CarePilot and, in many cases, is not in a position to decide about their own data either: that is precisely why someone is caring for them. The person who creates the group is the one who decides what gets recorded and who is responsible for having a lawful basis to do so, normally as the relative in charge or as legal representative, relying on the protection of the vital interests of someone who cannot give their consent (GDPR Art. 9.2.c).
Utility Lab Studio does not add, complete or interpret any information about that person: we only store, encrypted, what group members write. We cannot read it.
If their legal representative wants to know what data exists, correct it or erase it, they can write to us at info@utilitylabstudio.com. Whoever organizes the group can also delete it at any time from the App, and deleting the group removes all of it.
8. Data retention
We keep your data while your account is active. When you delete your account from the App (Settings → Delete account), we erase:
- Your user account and all associated data.
- Groups where you are admin, with all sub-collections (medications, appointments, expenses, notes, documents, photos, audit logs).
- Your membership in groups where you are not admin (group data persists for other members).
- Your recovery key backup.
- Your authentication account.
Deletion is complete and irreversible. As per the right to be forgotten (GDPR Art. 17).
📄 Step-by-step guide: see Delete your CarePilot account for the detailed procedure inside the App, what data is wiped, what residual records may be retained for legal compliance, and how to export your information before deleting the account.
Inactive accounts
If you go 12 months without opening the app and you have no active subscription, we delete the account and its data. We email you 30 days beforehand and again 7 days beforehand, and simply opening the app resets the counter. If you organize a group with other people in it, we leave the group alone.
Visible history according to your plan
Depending on the group’s plan, a different window of expense, note and activity history is shown (14 days on the free plan, 6 months on Plus, no limit on Pro). Anything outside that window is hidden, not deleted: if the plan changes, it appears again.
Some technical records (anonymized error logs, security records) may be kept up to 90 days for operational reasons.
9. Data portability
From Settings → «Export my data» you can download a complete copy of your data in two formats:
- PDF — readable, formatted output.
- JSON — structured technical format, per GDPR Art. 20.
Both include all your information: profile, groups, routines, appointments, expenses, documents, notes and records.
10. Your rights
Under GDPR you have the right to:
- Access — via the export feature or by request to info@utilitylabstudio.com.
- Rectification — most data is editable directly in the App.
- Erasure — full deletion from Settings.
- Portability — PDF + JSON export.
- Restriction and objection — write to info@utilitylabstudio.com.
- Withdraw consent at any time.
- File a complaint with your local data protection authority.
11. Account recovery and key loss
To protect E2E encryption, your group’s encryption keys live on your device. CarePilot offers a key backup protected by a recovery code (PIN) that you choose.
If you lose your recovery code and log out from all your devices, the encrypted data will be unrecoverable — even by us. This is the direct consequence of real E2E encryption. Keep your recovery code in a safe place.
12. Minors
CarePilot is not directed at children under 16. We do not knowingly collect data from minors. If you believe a minor has created an account, contact us and we will delete it.
13. International transfers
Firebase and Vertex AI are configured to operate primarily from European regions (europe-west1). Some auxiliary Google services (push notifications, account management) may require transfers to the United States. In those cases, Google applies the European Commission’s Standard Contractual Clauses as a legal transfer mechanism.
14. Security
We apply appropriate technical and organizational measures to protect your data:
- In-transit encryption (TLS 1.3).
- End-to-end encryption of sensitive content.
- Encryption at rest on servers.
- Strict Firebase security rules limiting data access.
- Regular code and dependency audits.
- Optional fingerprint/face unlock at app level.
15. Changes to this policy
We may update this policy to reflect feature changes or legal requirements. We will notify you via the App or email when changes are material. The «last updated» date appears at the top.
16. Contact
For any privacy-related question, write to info@utilitylabstudio.com with «CarePilot Privacy» in the subject. We will reply within 30 days.