Privacy policy
Last updated: July 22, 2026
Sion Studio ("we") operates the CareFlow app ("the App"). This policy describes how we handle your information. By using the App, you agree to this policy.
1. Information we collect
- Account data: email address and authentication identifiers when you sign up or sign in.
- Health and medication data: care-subject profiles, medicines, inventory, plans, reminders, and intake logs you enter.
- Media: avatars and medicine package photos you upload.
- App settings: language, time format, reminder preferences, and similar options.
- Subscriptions: purchases are processed by Apple or Google; we may receive subscription status to unlock features (e.g. via RevenueCat).
- Device and usage: basic device identifiers and app version for sync and troubleshooting. We do not sell your personal data.
- Crash and stability diagnostics: when crash reporting is enabled, the App may send crash reports and related technical diagnostics to Sentry (for example app version, device model, OS version, and stack traces) so we can diagnose failures and improve stability. This data does not include medicine names, doses, intake records, emails, or passwords you enter.
- Diagnostic logs (optional): the App may store a small technical event log on your device; we receive it only if you choose to attach it when sending feedback.
2. How we use information
- Provide reminders, cabinet management, records, and optional multi-device sync
- Authenticate you, restore access, and manage entitlements
- When you use medicine-name recognition, process photos on our servers (optional, rate-limited)
- Respond to support requests and improve the product
- When you opt in to attach diagnostic logs with feedback, analyze technical events to troubleshoot issues (logs exclude medicine names, emails, and passwords)
- Analyze crashes and stability issues via Sentry to fix defects and improve reliability
3. Storage and sync
CareFlow is local-first: without an account, data stays primarily on your device. When signed in, selected data is transmitted securely and stored with Supabase for sync across devices.
Recognition sends photos to our Edge Function and may use Google Gemini vision models. Photos are used only to return a name suggestion, not to train public models.
4. Third-party services
- Supabase — auth, database, file storage
- RevenueCat — in-app subscription management
- Apple / Google — app distribution and payments
- Google Gemini — optional package label recognition
- Sentry — crash reporting and stability diagnostics
5. Notifications
If you grant notification permission, reminders are scheduled locally on your device. Reminder content is not shared with advertising networks.
6. Diagnostic logs (optional)
For technical support, the App may store diagnostic logs locally on your device (for example app start, sign-in, sync, subscription, and notification scheduling events). Logs are not uploaded by default and are capped at about 10MB on device; older entries are removed automatically.
- Logs do not include medicine names, doses, intake records, emails, passwords, or access tokens.
- We receive a log file only when you opt in under Help & feedback and send it to us.
- You may send feedback without attaching logs; other features work the same.
7. Retention and deletion
Local data. Without an account, your data stays on your device until you uninstall the App or clear app data. Signing out clears local data for the signed-in user on that device.
In-app content. When you delete medicines, reminders, or other records in the App, deletions follow sync rules. If you are signed in, changes sync to the cloud; if not, they remain on the device only.
Delete account. If you are signed in, open Settings → Account & data → Delete account to permanently delete your cloud account and associated synced data (including your profile, care subjects, medicines, plans, intake records, and uploaded avatars or medicine photos). Email-and-password users must re-enter their password to confirm; Google or Apple sign-in users confirm in the dialog. This cannot be undone. After deletion, you are signed out and local user data on the device is cleared.
If you cannot use in-app deletion or have other privacy requests, contact careflow2024@gmail.com.
8. Children
Caregivers may record medication information for minors; the account holder must be an adult or otherwise authorized to manage the data.
9. Changes
We may update this policy and post the effective date on this page. Material changes may also be communicated in the App.
10. Contact
Privacy inquiries: careflow2024@gmail.com