Privacy Policy

Effective June 29, 2026

This Privacy Policy explains how Cara ("Cara", "we", "us") collects, uses, and shares information when you visit our website, create an account, or use the Cara service (the "Service"). By using the Service you agree to this Policy.

1. Who is the controller

For data submitted by you about your business and your end customers ("Customer Data"), you are the controller and Cara is the processor acting on your instructions. For account, billing, and product-usage data about you and your team, Cara is the controller.

2. Information we collect

  • Account info: name, email, organization, role, password hash.
  • Billing info: processed by Stripe; we receive limited data such as subscription status and last-four card digits.
  • Customer Data: contacts, leads, opportunities, messages, calls, transcripts, calendar events, ad performance, and other content you or your integrations submit.
  • Communications content: emails, SMS, and voice recordings/transcripts handled through the Service via Resend, Twilio, and Retell AI.
  • Usage data: log data, device and browser info, IP address, referring pages, and interactions with the Service.
  • Ad measurement data: when you visit our marketing site we use the Meta Pixel to measure ad performance and improve campaigns. This sends a hashed identifier, page URL, and action signals to Meta. We do not fire the Pixel inside the authenticated Cara app or on pages that may contain health information.
  • Cookies & similar tech: for authentication, preferences, analytics, and ad measurement.

3. How we use information

  • Provide, secure, and improve the Service.
  • Generate AI Output (drafts, recommendations, classifications, forecasts).
  • Process payments and manage subscriptions.
  • Send service, security, and (with consent where required) marketing communications.
  • Detect, prevent, and respond to fraud, abuse, or violations of our Terms.
  • Comply with legal obligations.

4. Health information (HIPAA)

Where a home care agency uses Cara to handle Protected Health Information (PHI), that agency is the Covered Entity or Business Associate and Cara acts as its Business Associate under our Business Associate Agreement. We apply administrative, physical, and technical safeguards to PHI: per-agency data isolation enforced in the database, an append-only access log, automatic sign-out after inactivity, redaction of direct identifiers from application logs, and configurable retention with automatic destruction. Our security overview describes these in detail.

5. AI processing

We use AI model providers to generate AI Output. By default, records are de-identified before they leave Cara: the model receives initials, a coarse care category, and non-clinical logistics rather than names, contact details, dates of birth, or health free text. An agency administrator may opt into full-content AI processing for their own organization. We instruct providers not to train their models on Customer Data where their terms support that option. AI Output may be inaccurate; review it before relying on it.

6. How we share information

  • Service providers / subprocessors that help us run the Service, including hosting, database, email (Resend), voice AI and telephony (Retell AI, with Twilio or Telnyx as the underlying carrier), SMS (Twilio), AI models, payments (Stripe), and analytics. We have a signed Business Associate Agreement and Data Processing Agreement with Retell AI. Our current list, with the status of each vendor agreement, is published at /subprocessors.
  • Integrations you connect (e.g., Meta, Google Calendar, ShiftCare, AlayaCare, AxisCare). Data flows to those services under their own privacy policies and only at your direction.
  • Legal, safety, and compliance where required by law or to protect rights, safety, or property.
  • Business transfers in connection with a merger, acquisition, or sale of assets, subject to standard confidentiality.

We do not sell personal information, and we do not share it for cross-context behavioral advertising.

7. Communications you send through Cara

When you send emails, SMS, or place/receive calls through the Service, the content, metadata, and (for calls) recordings and transcripts may be stored to provide features such as inbox views, lead scoring, transcripts, and analytics. Email and SMS are not secure channels, so our own notification emails intentionally exclude names, contact details, and care information. You are responsible for obtaining required consents from recipients and for honoring opt-outs.

8. Data retention

We retain Customer Data for as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. Agencies can set a retention window in Compliance settings, after which inactive records are automatically and permanently destroyed. You may also delete individual records within the Service, permanently erase an individual's details, or request deletion of your account. See /data-deletion.

9. Security

We use technical and organizational measures including encryption in transit and at rest, per-agency isolation enforced by row-level security, least-privilege access controls, automatic sign-out after inactivity, an append-only access log for records containing health information, and redaction of direct identifiers from application logs. Details are at /security. No system is perfectly secure; we cannot guarantee absolute security.

10. International transfers

Cara and its subprocessors operate in the United States and other countries. By using the Service, you understand your information may be processed in jurisdictions whose data-protection laws may differ from your own.

11. Your rights

Depending on where you live (e.g., the EU/EEA, UK, California), you may have rights to access, correct, delete, port, or restrict processing of your personal information, and to object to certain processing. To exercise these rights, email privacy@trycara.io. For Customer Data, please contact the Cara customer (the controller) that uploaded the data; we will assist them in responding.

12. Children

The Service is not directed to children under 16, and we do not knowingly collect personal information from them.

13. Cookies

We use strictly necessary cookies for authentication and session management, optional analytics cookies to understand usage, and the Meta Pixel for ad measurement on our marketing site. Where local law requires prior consent for advertising cookies (such as the EU/EEA and UK), the Pixel is not loaded unless consent is given. You can control cookies through your browser settings; disabling some cookies may degrade the Service.

14. Changes

We may update this Policy from time to time. Material changes will be announced in-app or by email. Continued use after the effective date constitutes acceptance.

15. Contact

Questions or requests: privacy@trycara.io.