Elderly Safety Assistant
Elderly Safety Assistant ("the app") has two linked roles:
A client and caregiver are connected through a one-time pairing code or QR code. A caregiver may be linked to multiple clients, and a client may be linked to multiple caregivers; all linked caregivers can see the same client data unless a note is marked private.
If you are a caregiver setting up the app on behalf of someone who cannot give their own consent (for example, due to a cognitive condition), you confirm that you are authorized to do so and that you will explain the app's monitoring to them to the extent possible.
The app does not ask for an email address, phone number, or password. Each device signs in with an anonymous account, identified only by a randomly generated ID. Pairing links a client's anonymous account to a caregiver's anonymous account.
A display name and, optionally, a profile photo you choose from your photo library. These are shown to linked caregivers/clients so people can tell who is who.
With permission, the client's precise GPS location (including in the background, when the app is closed or the phone is locked) so caregivers can see the client's last known position. Location updates are paired with the device's battery level and charging state so caregivers know if a phone has died or lost connectivity.
When a client taps the SOS button, an alert is created and, where available, a snapshot of their location at that moment is attached.
Caregivers can draw a safe-zone circle around a location (e.g. home). When a client's device enters or exits a zone, an event is recorded and linked caregivers are notified.
Caregivers can add free-text notes (optionally marked private, visible only to the author), appointments (title, location, notes, date/time), and medication entries (name, dosage, schedule, notes) for a client. This data can include health-related information — only enter what is necessary for care coordination.
Used only to scan a pairing QR code during setup. No photo or video is captured or stored.
A device token used to deliver alerts (SOS, safe-zone events) when the app is not open.
Standard operational data such as timestamps of updates and, if you use a hosted backend, infrastructure logs (e.g. IP address, request metadata) generated by our hosting and push-notification providers as part of normal service operation.
We do not collect analytics, advertising identifiers, or run any ad or tracking SDKs.
During pairing, the client and caregiver devices exchange public keys and the client's device seals a symmetric key to each linked caregiver. Using that key, the following are encrypted on the device before they are ever sent to our servers, and can only be decrypted by paired caregiver devices — we cannot read them, even if our database were compromised:
Push notifications themselves are content-free: they carry only an alert type and internal record ID, never a coordinate or zone name. The receiving app fetches and decrypts the details locally.
Notes, appointments, and medications are currently stored unencrypted in our database, protected by access controls that restrict them to the client and their linked caregivers. If your device is compromised or you use a public/shared device, keep this in mind before entering sensitive details in these fields.
We do not sell personal data, and we do not use it for advertising.
We do not otherwise share personal data with third parties.
Location updates, SOS alerts, and safe-zone events are retained to support the care-monitoring history caregivers rely on. Notes, appointments, and medications persist until deleted by their author or the client's account is removed. When a client account is deleted or a pairing is removed, associated location, alert, and safe-zone data tied to that link is deleted or becomes inaccessible to the unlinked caregiver.
We use encryption in transit (TLS) for all network requests, and end-to-end encryption for the location, SOS-location, and safe-zone data described in Section 3. Database access is restricted by row-level security policies scoped to the authenticated device/account. No security measure is perfect, and we cannot guarantee absolute security.
The app is not directed at children and is not intended for use by children as a caregiver account holder. A client profile may belong to any age group requiring care and supervision; caregivers are responsible for appropriate use in that case.
We may update this policy as the app changes. We will update the "Last updated" date above and, for material changes, provide notice in the app.
If you have questions about this policy or want to exercise a privacy right, contact:
info@nextact.is