Legal
Privacy Policy
Last updated: August 2026
1. Information we collect
Depending on the features you use, Carebow may process:
- Account information such as name, email address, phone number, and country.
- Authentication records and security metadata needed to operate your account.
- Family-profile information, including demographics and health context you choose to provide.
- Symptoms, answers, conversation context, and other information submitted to Ask Carebow.
- Vitals, booking details, service addresses, and safety information submitted through supported server-backed features.
- Payment identifiers and transaction status associated with Razorpay payment orders. Card or bank credentials are handled by the payment provider rather than entered into Carebow application storage.
- Technical logs needed to operate, secure, and troubleshoot the service.
2. How we use information
We use information to operate the product and the workflows you request, including to:
- Authenticate users and maintain account sessions.
- Provide patient-specific health guidance and safety checks.
- Create and manage bookings and payment records.
- Dispatch configured safety notifications and missed-check-in work.
- Operate customer support, troubleshoot failures, and investigate abuse or security incidents.
- Improve reliability and product quality using data we are permitted to process for those purposes.
3. Security practices
Carebow applies application-level security controls, but we do not describe those controls as a formal certification unless one has been independently completed.
- Passwords are hashed rather than stored in plain text.
- Authenticated mobile API access uses short-lived access tokens and rotating, revocable refresh tokens.
- Production traffic is served over HTTPS.
- Application file storage is intended to remain private rather than publicly readable.
- Mobile monitoring is configured to minimize direct identifiers and strip request bodies, cookies, authorization headers, arbitrary extras, and breadcrumb data from Sentry events.
- Payment confirmation validates Razorpay signatures in the direct verification path.
4. AI processing
Ask Carebow may send the text and context needed to generate a response to AI model providers configured by Carebow. Do not submit information that is unnecessary for the health question you are asking. Carebow should minimize the context sent to external providers and should not make compliance promises that exceed the contracts and technical controls actually in place.
5. Third-party and infrastructure services
Carebow uses external and self-hosted services to operate parts of the product. Depending on configuration and the feature used, these can include:
- Razorpay for payment processing.
- Twilio for configured SMS delivery.
- AI model providers used by Ask Carebow.
- Sentry for application error monitoring with data-minimization controls.
- Self-hosted PostgreSQL and object storage used by the Carebow backend.
- Authentication providers when you choose a supported third-party sign-in method.
6. Data retention and deletion
We retain information as needed to operate the account, maintain transaction and safety records, meet legitimate operational or legal requirements, and resolve disputes. Retention periods can differ by data type. You can contact Carebow to request account or data deletion; some records may need to be retained where required for security, transactions, legal obligations, or dispute resolution.
7. Your choices
You can choose what optional profile and health context to provide. You can also contact Carebow to request access, correction, or deletion of personal information, subject to applicable requirements and records we must retain.
- Update supported profile information from the product where editing is available.
- Avoid adding optional health context that is not needed for the service you are using.
- Contact Carebow regarding access, correction, deletion, or privacy questions.
- Opt out of non-essential marketing communications where those communications are offered.
8. Children and family profiles
Carebow account access and family-profile data are different concepts. An adult account holder may add information about a family member when using supported care features. Users should only provide information they are authorized to provide and should use extra care when entering information about children or other dependents.
9. Changes to this policy
We may update this policy as the product, vendors, and data practices change. The date on this page should be updated when material changes are published.
10. Contact
For privacy questions or data requests, contact info@carebow.com.