Last updated: 2026
CareHandoff is built to work entirely on your device. There is no user account, no sign-in, and no CareHandoff server that stores your care records. Nothing about the people you care for, what you log, or the handoffs you generate is uploaded automatically to us or to any third party.
In this version of the app, CareHandoff itself collects nothing that leaves your device, with one narrow exception: if you choose to purchase CareHandoff Plus, Google Play Billing processes that transaction and shares standard purchase/transaction data with us as the app's developer (the same as any paid app on Google Play). We do not receive your care profiles, log entries, medication labels, attachments, handoffs, or any other content you enter into the app as part of that or any other process.
CareHandoff does not include third-party analytics or crash-reporting SDKs in this version. Google Play Console separately provides the developer with aggregate install, crash, and purchase metrics common to all Play Store apps, governed by Google's own policies.
Sensitive content - care profile details, log entries, medication names, notes, attachments, and more - is encrypted at rest using AES-256-GCM, with encryption keys held in your device's Android Keystore and never exported off the device. Data lives in the app's private storage area and is excluded from Android's automatic cloud backup.
CareHandoff never backs your data up automatically. If you choose to create a backup, you explicitly export an encrypted archive file, protected by a passphrase you choose, using Android's Storage Access Framework to pick where it is saved (for example, your own cloud storage app, a USB drive, or local device storage). We never see this file or your passphrase. Restoring a backup requires the exact passphrase used to create it; a wrong passphrase or a corrupted/tampered file is safely rejected without changing your existing data.
You can delete an individual record, delete an entire care profile, or delete all app data at any time from Settings. Deleted log entries move to "Recently Deleted" for 30 days before permanent removal, and you can empty Recently Deleted immediately if you prefer. Exportable full-data export remains available regardless of purchase status.
When you generate and export a handoff (as a PDF, image, or through Android's share/print system), that exported file leaves CareHandoff's encrypted environment. Once shared, protecting that file is your responsibility, the same as any document you send by email, message, or printed page.
CareHandoff is an organization and communication tool. It is not an electronic health record, diagnostic tool, medication-administration system, or emergency alert system, and it is not a substitute for instructions from a licensed healthcare professional. Always follow the care recipient's professional care plan and any emergency instructions provided by a qualified professional. If you are experiencing an emergency, contact local emergency services immediately - CareHandoff does not detect emergencies or contact anyone on your behalf.
CareHandoff may be used by caregivers to record information about a child receiving care. All of the protections described above (local-first storage, encryption, no automatic upload) apply equally to any care profile, regardless of the care recipient's age.
If this policy changes, an updated version will be published at this same address and bundled in a future version of the app.
Questions about this policy or your data can be sent to arcanesystemsinc@gmail.com.