Security & Data Protection Notice

Last Updated: September 14, 2026

 

1. Our security commitment

CareTabs is designed to help people organize important information about themselves and people they care for. Users
may choose to store highly sensitive information, including medical and insurance information, Social Security
numbers, financial and legal records, estate documents, passwords, PINs, property information, and uploaded
documents.

Because of the sensitivity of this information, CareTabs uses administrative, technical, and organizational safeguards
designed to reduce the risk of unauthorized access, use, alteration, disclosure, or loss. Security is a shared
responsibility, and no internet-connected service can guarantee absolute security.

2. Data minimization and user choice

CareTabs does not require a user to store a Social Security number, password, PIN, bank credential, medical record,
or any other particular sensitive item. Users decide what information to enter and should store only information
reasonably necessary for their purposes.

Users are responsible for ensuring they have appropriate permission or legal authority to collect, store, manage, and
share information about another person through CareTabs.

3. Encryption and data protection

  • Encryption in transit. Data transmitted between a user’s device and CareTabs is protected using TLS.
  • Sensitive information at rest. Sensitive care-profile fields are encrypted at rest using profile-specific encryption controls.
  • Encryption key protection. Encryption keys are protected using Microsoft Azure Key Vault.
  • Uploaded documents. Uploaded files are encrypted at rest using Microsoft Azure storage encryption, including AES-256 where provided by the underlying storage service.
  • Profile separation. CareTabs uses profile-level access and data controls designed to prevent one profile from granting access to another.

4. Access controls and account security

Access to a care profile is limited to the account holder and people the account holder or an authorized profile Admin
chooses to invite. CareTabs currently supports role-based access such as Admin and Read access. Unless the
application expressly states otherwise, an invitee with access to a profile may be able to view highly sensitive
information stored in that profile.

  • Users should never share their CareTabs login credentials.
  • Users should invite other people through CareTabs’ sharing features rather than sharing a login.
  • Users should remove an invitee promptly when that person no longer needs access.
  • Users are responsible for securing their email account, devices, passwords, and other authentication methods used
    to access CareTabs.
  • CareTabs may require credential resets, session termination, or other protective actions when suspicious activity is identified.

5. Special protection for credentials and high-risk information

CareTabs may permit users to store passwords, PINs, Social Security numbers, financial information, and other
high-risk information. Users should store this information only when necessary and when they are legally authorized to
possess it.

Important: The presence of a password, PIN, account number, or other credential in CareTabs does not itself give an
account holder or invitee legal authority to access, control, transact on, or impersonate the owner of the underlying
account.

6. Application logging and product analytics

CareTabs uses operational logging and product analytics to maintain and improve the Service. CareTabs’ own product
analytics are designed to record product usage without recording the sensitive content being managed. Controls should
prevent care-profile contents, document names, search terms, free-text entries, Social Security numbers, health
information, financial information, and stored credentials from being intentionally included in product analytics events.

Application diagnostic logs may contain limited account information, such as an account email address, when
necessary to diagnose errors or security events.

7. Advertising and third-party tracking

CareTabs’ recommended security and privacy architecture separates public marketing activity from the authenticated
application. CareTabs will not intentionally run Meta Pixel, Google Ads remarketing/conversion tags, or comparable
behavioral advertising trackers on authenticated care-profile pages or other screens that display sensitive profile
content or expose profile-specific identifiers.

Any analytics or advertising technologies used on public marketing pages are subject to CareTabs’ Cookie Policy and
applicable consent, opt-out, and privacy requirements.

8. Service providers and subprocessors

CareTabs relies on selected third-party service providers to operate portions of the Service, including infrastructure,
storage, encryption-key management, authentication, payments, email delivery, application logging, analytics, address
autocomplete, and optional AI-powered features.

CareTabs maintains appropriate contractual and security requirements for service providers based on the
information they handle. These may include confidentiality, restricted use, reasonable security measures, incident
notification, deletion or return of information, and compliance with applicable privacy requirements. A current
subprocessor list should is maintained at https://www.caretabs.com/subprocessors/.

9. Data retention and secure deletion

CareTabs follows the retention practices described in its Privacy Policy.

  • Deleted profile and account records should be removed promptly from active systems.
  • Where profile-specific encryption keys are used, deletion may include destruction of the applicable encryption key so residual encrypted content is unreadable.
  • Associated uploaded files and profile photos should be erased from active file storage within the documented retention period, currently targeted at 7 days.
  • Profile export files should expire and be erased within the documented period, currently targeted at 7 days after creation.
  • Backup systems may retain encrypted residual copies for a limited rolling period before overwrite.
  • Certain billing, tax, fraud-prevention, security, legal-hold, and compliance records may be retained longer when reasonably necessary or legally required.

10. Profile exports

A profile export may contain highly sensitive information. When CareTabs generates an export, access should be
provided through a time-limited download mechanism. Users should protect export emails and downloaded files as
carefully as the information stored inside CareTabs. Anyone who obtains a valid export link or downloaded copy may
be able to access the information it contains.

11. Security monitoring and incident response

CareTabs maintains or will maintain an incident-response process designed to identify, investigate, contain, remediate,
and document suspected security incidents. Depending on the incident, CareTabs may preserve logs and evidence,
disable access, revoke sessions or credentials, isolate affected systems, engage security specialists, notify service
providers, and take other reasonable containment measures.

If CareTabs determines that an incident requires notification under applicable law, CareTabs will provide required
notices to affected individuals, regulators, law enforcement, business partners, or others within the time and manner
required by applicable law.

12. Health information and regulatory scope

CareTabs is generally designed as a consumer-directed information organizer. CareTabs does not represent that it is a
HIPAA covered entity or business associate merely because a consumer chooses to store health information in the
Service.

If CareTabs enters into a relationship in which it creates, receives, maintains, or transmits protected health information
on behalf of a HIPAA covered entity or business associate, CareTabs will evaluate the relationship and enter any
required Business Associate Agreement before handling information in that capacity.

Health and other sensitive information may be subject to federal or state privacy, security, consumer-health-data, and
breach-notification laws even when HIPAA does not apply. CareTabs will evaluate obligations based on its actual
services, data flows, business relationships, users, and jurisdictions.

13. Business continuity and availability

CareTabs uses commercially reasonable measures intended to maintain availability and protect stored information, but
it is not an emergency service or guaranteed system of record. Outages, software defects, cyber incidents, provider
failures, natural disasters, or other events may temporarily prevent access. Users should maintain independent copies
of information they cannot afford to lose or be unable to access.

14. User security responsibilities

  • Use a strong, unique password and protect the email account or authentication method associated with CareTabs.
  • Keep devices and browsers reasonably current and protected.
  • Do not share login credentials.
  • Invite only people who are authorized and trusted to view the entire information set made available to them.
  • Review and remove access when it is no longer needed.
  • Store only sensitive information that is reasonably necessary.
  • Protect downloaded exports and documents outside CareTabs.
  • Report suspected unauthorized access or security issues promptly.

15. Changes to this notice

CareTabs may update this Security & Data Protection Notice as its technology, security program, products, service
providers, or legal obligations change. The Last Updated date will identify the current version.

 

Email: Support@Caretabs.com

Security & Data Protection Notice

Copyright © 2026 CareTabs Inc. All rights reserved.

Scroll to Top
CT

CareTabs Assistant

Online — Ready to help

Powered by CareTabs AI