Legal
Privacy Policy
MeetCaregivers — CareExpertAI
Last Updated: August 17, 2026
Last Updated: August 17, 2026
1. Introduction
MeetCaregivers, Inc. (“we,” “us,” or “our”) operates as the data controller for CareExpertAI (“the Service”), an AI-powered caregiving guidance platform. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service. Please read this policy carefully before using the Service.
By using the Service, you consent to the data practices described in this policy. If you do not agree with this policy, please do not use the Service. Questions about this policy may be directed to info@careexpertai.com.
2. Information We Collect
2.1 Personal Information
We collect information that you provide directly to us, including:
Account Information: Name, email address, password (hashed and never stored in plaintext)
Profile Information: Optional demographic information, preferences, and settings
Communication Data: Messages you send to us, feedback ratings (thumbs up/down), and support requests
2.2 Conversation Data
When you use the Service, we collect and store the following in our encrypted database:
Chat Messages: Your text questions and AI-generated responses, stored with AES-256-GCM field-level encryption
Voice Transcripts: When you use voice mode, the text transcript of your spoken question and the AI’s spoken response (see Section 2.3 for how voice audio is handled)
Session Information: Timestamps, session IDs, and conversation context needed to provide continuity
Saved Conversations: Conversations you choose to save, including any tags or notes you add
Feedback: Thumbs up/down ratings and any written comments on AI responses
2.3 Voice and Audio Data
How voice audio is handled. Voice audio is not stored by MeetCaregivers. When you use voice mode, your microphone audio streams via an encrypted real-time connection directly to our voice processing provider for real-time speech processing; this audio does not pass through our servers. When you use voice dictation (the microphone button within text chat), the audio clip passes through our servers only transiently for transcription and is deleted immediately afterward — it is never stored. In both cases, only the resulting text transcript is stored in our encrypted database. By using voice mode or dictation, you consent to this audio transmission subject to the applicable provider’s privacy policy.
Microphone Audio: Not stored by MeetCaregivers in either case. Voice mode audio streams directly to our voice processing provider and never touches our servers; dictation audio passes through our servers only transiently for transcription before being deleted
Voice Transcripts: The text representation of what was said is stored in our database (encrypted at rest)
Microphone Access: The Service requests microphone permission only when you initiate voice mode; you may revoke this permission in your browser settings at any time
2.4 Automatically Collected Information
We automatically collect certain information when you use the Service:
Device Information: IP address, browser type, operating system, device identifiers
Usage Data: Pages viewed, time spent, clicks, navigation paths
Log Data: Server logs, error reports, performance metrics retained for up to 90 days in operational log systems
Cookies and Tracking: Session cookies, authentication tokens, analytics data (see Section 9)
3. How We Use Your Information
We use the collected information for the following purposes:
Provide the Service: Process your requests, generate AI responses, maintain conversation history across sessions
AI Response Generation: Your text queries are sent to our AI response engine to generate caregiving guidance. Voice queries are processed by our voice AI provider. We do not use your conversations to train these AI models (see Section 4.1)
Knowledge Base Retrieval: Your query text is used to search our local clinical knowledge base to retrieve relevant evidence-based information. This search happens on our servers and the query text is not shared externally for this purpose
Personalization: Maintain conversation history, remember session context, and allow you to save and tag conversations
Security: Detect fraud, prevent abuse, protect against security threats, and support account authentication
Communication: Send service updates, respond to inquiries, and provide customer support
Compliance: Meet legal obligations, enforce our Terms of Service, and resolve disputes
Service Improvement: Analyze aggregated, de-identified usage patterns to improve response quality and platform reliability. We do not use individual identified conversations for this purpose
4. Data Sharing and Disclosure
4.1 Third-Party AI Processors
To deliver AI-powered responses, your data is processed by the following third-party AI providers acting as data processors on our behalf. We do not authorize these providers to use your data to train their own AI models beyond what is necessary to provide the service to you.
AI Response Engine. Your text questions are processed by our AI response engine to generate caregiving guidance and triage information. This provider processes data subject to their privacy policy and our data processing agreement with them. They do not use your queries to train their models without opt-in consent.
Voice AI Provider. When you use voice mode, your microphone audio is transmitted directly to our voice AI provider for real-time speech-to-speech processing and transcription. This provider processes data subject to their privacy policy. They do not train on API inputs by default.
Cloud Infrastructure Provider. Your account data and conversation history are stored on our enterprise cloud infrastructure provider’s platform in the United States. This provider manages user authentication and encrypted database storage, and supports multi-factor authentication as a platform capability.
4.2 Other Service Providers
We may share your information with additional trusted service providers who assist in operating the Service:
Content Delivery: Cloud-based content delivery networks for serving the application
Email Services: Email delivery providers for account notifications and support communications
Analytics: Aggregated, de-identified usage analytics providers
All service providers are contractually obligated to protect your information and may only use it for the purposes we specify.
4.3 Legal Requirements
We may disclose your information if required by law, court order, or government regulation, or if we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
4.4 Business Transfers
In the event of a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity. We will notify you via email and/or a prominent notice on our website prior to your information being transferred and becoming subject to a different privacy policy.
4.5 Aggregated Data
We may share aggregated, de-identified data that cannot reasonably be used to identify you for research, analytics, or service improvement purposes.
5. HIPAA and Protected Health Information
CareExpertAI is designed to support individual family caregivers and professional caregivers with general caregiving guidance, and in most cases is not used by, or on behalf of, a HIPAA “covered entity” or “business associate” as those terms are defined under the Health Insurance Portability and Accountability Act (“HIPAA”). Where that is the case, HIPAA does not, by itself, apply to your use of the Service, though we apply the safeguards described in Section 6 (Data Security) regardless.
If you are using the Service on behalf of an enterprise organization, health plan, provider group, or other entity that is a HIPAA covered entity or business associate and that intends to transmit Protected Health Information (“PHI”) through the Service, please contact info@careexpertai.com before doing so. Use of the Service to transmit PHI on behalf of such an organization requires a separate, signed Business Associate Agreement with MeetCaregivers.
We encourage all users describing a care recipient’s health circumstances to avoid including more identifying detail (such as full names, addresses, or medical record numbers) than is reasonably necessary to receive relevant guidance.
6. Data Security
Data Security Practices. We implement strong security measures to protect your data, including field-level encryption of health-related conversation data, access controls, and audit logging.
We use the following security measures to protect your information:
Field-Level Encryption: Conversation content (chat messages, voice transcripts, saved items) is encrypted at the database column level using AES-256-GCM before storage. Encryption keys are managed separately from the data.
Encryption in Transit: All data transmitted between your browser and our servers uses TLS 1.2 or higher (HTTPS). Voice audio uses an encrypted real-time connection.
Authentication Security: Passwords are never stored in plaintext. We use an enterprise identity management service for authentication; security measures may include multi-factor authentication (MFA) where enabled.
Access Controls: Role-based access controls and least-privilege principles govern who can access data within our systems.
Monitoring: Continuous security monitoring, audit logs for data access, and error tracking.
Incident Response: Documented procedures for detecting, containing, and recovering from security incidents. See Section 6.1 for breach notification.
No system is completely secure. We cannot guarantee absolute security of your information, but we are committed to promptly addressing any security incidents.
6.1 Security Incident Notification
In the event of a security incident that compromises your personal information, we will notify affected users by email within 72 hours of becoming aware of the incident where feasible, consistent with applicable law. Notification will describe the nature of the incident, the information involved, and steps we are taking to address it.
7. Data Retention
We retain your information for as long as necessary to provide the Service and fulfill the purposes described in this policy:
Account Data: Retained while your account is active and for up to 12 months following account deletion to comply with legal obligations and resolve disputes
Conversation History (Database): Stored indefinitely until you delete individual conversations or close your account. All conversation content is encrypted at rest.
Operational Logs: Server logs and operational logs are retained for up to 90 days for debugging and security purposes
Saved Conversations: Retained until you explicitly delete them or close your account
Voice Audio: Not retained by MeetCaregivers. Audio processed by our voice AI provider is subject to their retention policies.
Aggregated Analytics Data: De-identified aggregated usage data may be retained indefinitely
You may request deletion of your data at any time by contacting us at info@careexpertai.com.
8. Your Privacy Rights and Choices
Depending on your location, you may have the following rights regarding your personal information:
Access: Request a copy of the personal information we hold about you
Correction: Request correction of inaccurate or incomplete information
Deletion: Request deletion of your personal information (subject to legal retention obligations)
Portability: Request your conversation data in a portable format
Opt-Out of Marketing: Opt out of promotional communications at any time by clicking “unsubscribe” in any email or contacting us. You will still receive transactional emails related to your account.
Restriction: Request restriction of processing in certain circumstances
Object: Object to processing based on legitimate interests
Withdraw Consent: Where processing is based on consent, withdraw consent at any time without affecting prior processing
To exercise any of these rights, contact us at info@careexpertai.com. We will respond within 30 days (or as required by applicable law). See Section 12 for California-specific rights.
8.1 Other State Privacy Rights
Residents of states with comprehensive consumer privacy laws (which currently include, among others, Virginia, Colorado, Connecticut, Utah, Oregon, and Texas) have similar rights to know, access, correct, delete, and opt out of certain processing of their personal information, subject to the specific terms of the law applicable in their state. We will honor verifiable requests consistent with the law applicable to your state of residence. Depending on your state, you may also have the right to appeal a decision we make in response to your request; contact us using the information in Section 15 to do so.
Some of these states — including Colorado, Connecticut, and Virginia — require opt-in consent before processing sensitive personal information, which may include health information you or a care recipient’s health information shared through the Service. By choosing to submit health-related information to the Service, you consent to our processing of that information as described in this policy for residents of those states.
8.2 Washington Residents (My Health My Data Act)
Washington’s My Health My Data Act provides additional protections for “consumer health data,” which includes information related to caregiving needs, health conditions, or related services submitted through the Service. We do not share consumer health data with third parties for advertising purposes without the consent required under this law.
8.3 Browser Privacy Signals
Where you have a legally recognized browser-based opt-out preference signal enabled (such as Global Privacy Control), we honor that signal as an opt-out of sale/sharing in accordance with applicable law. We do not currently respond to the older, non-standardized “Do Not Track” browser setting, which is a different mechanism than Global Privacy Control.
9. Cookies and Tracking Technologies
We use cookies and similar tracking technologies to:
Maintain your session and keep you logged in securely
Store authentication tokens issued by our identity management service
Remember your preferences and settings
Analyze aggregated usage patterns to improve the Service
Provide security features and prevent fraud
We may also use advertising or retargeting technology, such as advertising pixels or ad-network conversion tracking, to support marketing efforts consistent with Section 14 (Advertising) of our Terms of Service. Where such technology shares your information with a third party for cross-context behavioral advertising, we provide the notice and consent or opt-out mechanism required by applicable law before that technology is activated. You can control cookies through your browser settings; disabling session cookies will prevent you from logging in.
10. Children’s Privacy
The Service is intended for users 18 years of age and older and is not directed at children under 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us at info@careexpertai.com and we will delete such information promptly.
11. Geographic Scope
CareExpertAI is intended for users located in the United States. Our servers are located in the United States and all data is processed here. We do not knowingly offer the Service to individuals located outside the United States. If you access the Service from outside the United States, you do so at your own risk and are responsible for compliance with your local laws.
The Service is hosted and operated in the United States for a US audience, and our compliance program is built around US law. We have not implemented the mechanisms that laws like the GDPR (EU) or the UK GDPR typically require for handling data lawfully across borders — for example, an EU-based representative or approved international transfer safeguards. Individuals located in the European Union, the United Kingdom, or a similar jurisdiction should not use the Service, since we cannot extend those protections at this time.
12. California Privacy Rights (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA):
Right to know what personal information we collect, use, and disclose
Right to request deletion of your personal information
Right to correct inaccurate personal information
Right to opt-out of the sale or sharing of personal information, including for cross-context behavioral advertising, subject to the notice and opt-out mechanisms described in this Policy
Right to limit use of sensitive personal information
Right to non-discrimination for exercising your privacy rights
Authorized agents and annual disclosure. You may designate an authorized agent to submit a request on your behalf. We may need to verify your identity before completing certain requests, consistent with what the request requires under law. California residents may also request, once per year, information about our disclosure of personal information to third parties for their own direct marketing purposes, consistent with California’s “Shine the Light” law.
12.1 Notice of Collection (CCPA)
In the preceding 12 months, we have collected the following categories of personal information:
Identifiers: Name, email address, IP address, device identifiers, account ID
Internet or Network Activity: Browsing history within the Service, interaction data, session logs
Audio/Electronic Data: Voice transcripts (text only; raw audio is not retained by us)
Health and Medical Information: Caregiving-related questions and responses that may describe health conditions of persons in your care (treated as sensitive personal information)
Inferences: Usage patterns derived from the above categories
Sale/sharing of personal information. MeetCaregivers may sell or share personal information, as those terms are defined under applicable law (including the California Consumer Privacy Act, as amended by the California Privacy Rights Act), subject to the notice and opt-out rights described in this Policy. We do not knowingly sell or share the personal information of minors under 16 years of age.
We collect the categories above for the business purposes described in Section 3. To exercise California rights, contact info@careexpertai.com.
13. Questions About This Policy
If you have questions about how your data is collected or used under this Privacy Policy, please contact us at info@careexpertai.com. We will respond within a reasonable time.
14. Changes to This Privacy Policy
We may update this Privacy Policy at any time to reflect changes in our practices, technology, or legal requirements. When we make material changes, we will notify you by email to the address associated with your account. The updated “Last Updated” date at the top of this policy reflects the most recent revision. Your continued use of the Service after an updated policy is posted constitutes acceptance of the changes. If you do not agree to the updated policy, please contact us to close your account.
15. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
MeetCaregivers, Inc. — Privacy Team
Email: info@careexpertai.com
Mail: 320 Nevada Street, Suite 301, Newton, MA 02460
By using CareExpertAI, you acknowledge that you have read and understood this Privacy Policy and agree to the collection, use, and disclosure of your information as described herein.