Elderhub Privacy Policy

Last updated: August 17, 2026

Overview

Elderhub is an iPhone app for keeping a care record for a parent, partner, or another person you help. It records medications and other health information, along with care tasks, notes, bills, contacts, and family sharing. Much of what is in it is information about someone other than the person typing it, so it is treated accordingly.

If you are in Washington State or Nevada, the Consumer Health Data Privacy Policy covers the same app in the specific terms those laws ask for, including how to withdraw consent and how to have data deleted.

What Elderhub Collects

Elderhub collects information you enter, information needed to operate a care circle, and information needed for notifications and purchases.

Elderhub does not collect location. The app never asks for it and contains no location code. It does not read Apple Health or connect to a monitor, wearable, or medical device; readings and events are typed in by a person. There is no advertising SDK or behavioral analytics. Nothing is sold and nothing is used for tracking.

Information About Other People

Most of what you enter is about someone else. When you add a person who will not use the app themselves, Elderhub asks you to confirm that they know you are keeping this record, or that you are the person who makes their health decisions. Please only enter someone else's health information if that is true.

Elderhub does not assess anyone's ability to make their own decisions. That is a clinical judgment and this app does not make it.

A person who joins the care circle with their own account is shown, before anything syncs, exactly who is in the circle and what each member can see about them. They can see that page again at any time, and they can leave whenever they want.

A record can remain local to one phone without an account or care circle. It is not uploaded merely because the app is installed. Sharing is an explicit choice that adopts the record into a care circle.

How Data Is Stored

Elderhub has a local store and, only when you choose to share a record, a shared store. The local store is a full working copy of the care record, including the records needed for offline use, so the app opens with no signal.

The local SwiftData store is protected by iOS with NSFileProtectionCompleteUntilFirstUserAuthentication. This protects the files before the first unlock after a reboot. After the first unlock, iOS may make them available while the phone is locked so offline reads, background sync, and local notifications can work. The care record is not end-to-end or client-side encrypted.

The shared copy is stored on Supabase in Postgres, encrypted in transit and at rest. Access is enforced per row by the database itself, not just by the app: a member of one family cannot read another family's record. Free-text notes and bill notes are ordinary plaintext fields protected by these access rules, not a password vault. Supabase processes the data to provide authentication, storage, and sync. See Supabase security.

To make offline sync and family history work, edited or deleted synced rows carry server timestamps and deletion markers. Deleted rows are hidden from the app but may remain as server tombstones while the care circle exists. For medications, doses, people, and membership changes, an audit log can retain old and new snapshots and the name recorded for the person who made the change.

Who Can See What

Device handover is a local phone setting, not a change to account permissions. In recipient mode, the selected person sees a read-only check-in screen, their medications, and the emergency card. The emergency card is never behind the caregiver code.

The Check-in Feature

If a daily check-in is turned on and the button is not pressed by the end of the agreed window, the app tells the caregivers in that group that no check-in happened. That is the whole feature. Elderhub does not detect falls or emergencies, does not decide that anything is wrong, and does not call anyone for help.

Notifications

Check-in, medication, and refill reminders are scheduled on the device itself. The message to caregivers about a missed check-in is a push notification sent from the server. You can turn notifications off in iOS Settings โ†’ Notifications โ†’ Elderhub.

Purchases & Subscriptions

The purchase is processed by Apple StoreKit. Elderhub never receives payment card details, billing address, or Apple ID credentials. RevenueCat receives the purchase receipt and the linked app account identifier to verify product, subscription, and entitlement status. It does not receive the care record or a payment profile. See RevenueCat Privacy. Subscription management and refunds are handled in your Apple ID account settings.

Third-Party Services

Retention & Deletion

Deleting your account (Settings โ†’ Delete my account, or by email) removes your account from the service and unlinks it from any care-recipient record. It deliberately does not delete the family's shared care record: that record belongs to everyone looking after that person, and one member leaving should not erase it for the others. Entries and audit records can keep the display name recorded for the person who made them so the history still reads sensibly. The app removes the shared copy from that phone.

Leaving a care circle stops that account's access and removes the shared copy from that phone. When the last member leaves, or the organizer deletes the circle, the active care-circle records and group audit history are deleted from the active database. Invitation, notification, service, and provider-backup records may follow their own retention periods.

Individual deletions are propagated as tombstones for sync and may remain in the server history described above while the care circle exists. Verified deletion requests sent by email are actioned within 30 days.

Your Rights

You can see and correct the records available to your role, export the emergency card as plain text, and delete entries from the app. Exporting sends a copy to the app or person you choose through the iOS share sheet; after that, the recipient's privacy policy controls that copy. Deleting an entry hides it in the app and follows the sync and audit retention rules above. For anything you cannot do in the app, email the address below.

Elderhub is not currently offered in the European Union or the United Kingdom.

Children's Privacy

Elderhub is not directed at children under 13 and does not knowingly collect their information.

Changes

Updates to this policy will be posted on this page with a revised date.

Contact

Privacy questions:
jackwallner+medlist@gmail.com

Support ยท Terms of Use