1. Introduction
This Privacy Policy sets out the rules for collecting, using, and sharing personal data in connection with the use of the Carely mobile application (the “App”). The controller of personal data is Albert Napiórkowski (the “Controller”, “we”, “us”, “our”).
Carely is a mobile application for managing medication reminders. The App supports two distinct user roles: the Patient, who uses medication reminders, and the Caregiver, who monitors the Patient’s adherence to their medication schedule. The Controller makes every effort to protect the privacy of Users and to ensure full transparency of the practices applied to the processing of personal data.
2. Information We Collect
2.1. Patient Account – Anonymous Data
The Patient account is anonymous by design – registration does not require providing an email address or any other personal identifier. Supabase generates an anonymous session for the Patient that does not allow the data to be linked to the Patient’s identity. As part of configuring the App, the Patient may provide:
- Name or nickname (optional) – used solely for a personalized greeting within the App.
- Accessibility preferences (optional): the selected font size and the enabling of the screen reader function (text-to-speech).
- Answers to onboarding questions (optional): concerning how often medications are forgotten, the preferred way of handling reminders, and the level of monitoring.
The following Patient data necessary to provide the service is stored on the Supabase server:
- Medication data: medication name, form, dosage, schedule (days of the week and times of intake).
- Dose history: dose statuses (taken, skipped, postponed, delayed) together with timestamps.
- Medication supply data (optional): total quantity in the package, low-stock threshold, expiry date.
- Medication notes (optional): text added by the Patient to a specific reminder.
- Anonymous session identifier: generated automatically by Supabase, with no ability to be linked to the Patient’s identity.
Note on account recovery: A Patient who is not connected to a Caregiver cannot recover their account after losing their device – this is a deliberate design decision aimed at eliminating the barrier to registration. A Patient connected to a Caregiver can re-link their account after reinstalling the App using an invitation code.
2.2. Caregiver Account – Registered User Data
The Caregiver creates a full account requiring identity verification. We collect the following Caregiver data:
- Login credentials: email address and password, or Google / Apple login data (depending on the chosen registration method).
- Answers to onboarding questions (optional): relationship with the Patient, preferred alert intensity, Caregiver availability.
- Premium subscription data: subscription status and purchase identifier, handled by RevenueCat.
2.3. Data Collected Automatically
- Device information: platform (iOS/Android), operating system version, App version.
- Usage analytics: how the App is interacted with, collected via the PostHog tool.
- Error and performance data: technical information regarding App crashes and errors, collected via the Sentry tool.
- Purchase data: subscription and transaction information processed via RevenueCat and the Apple/Google payment systems.
- Feedback and reports: the content of messages sent by the User via the UserJot tool (optional in-App reports).
3. Purposes of Data Processing
We use the collected data for the following purposes:
- Providing services: delivering medication reminders in accordance with the Patient’s schedule.
- Adherence monitoring: providing the Caregiver with real-time information on the Patient’s adherence to the medication schedule (solely with the Patient’s consent, expressed by connecting the accounts).
- Push notifications: sending reminders to the Patient and alerts about unconfirmed or missed doses to the Caregiver.
- Real-time synchronization: updating dose statuses in the Caregiver’s dashboard via a WebSocket connection (Supabase Realtime).
- Subscription management: handling and verifying the Caregiver’s Premium subscription.
- Improving the App: analyzing usage patterns in order to improve functionality and the user experience.
- Error monitoring: identifying and resolving technical issues.
- Customer support: responding to reports and feedback submitted by Users.
4. Legal Bases for Data Processing
Personal data is processed on the following legal bases in accordance with Art. 6(1) GDPR:
- Performance of a contract (Art. 6(1)(b) GDPR): processing of data necessary to provide the App’s services – the Patient’s medication data and dose history, as well as the Caregiver’s account and dashboard data.
- Consent (Art. 6(1)(a) GDPR): product analytics (PostHog), push notifications (with iOS/Android system consent), sharing the Patient’s data with the Caregiver (through the deliberate connection of accounts via an invitation code).
- Legitimate interest of the Controller (Art. 6(1)(f) GDPR): error monitoring (Sentry), ensuring the security of the App, collecting User feedback (UserJot).
5. Data Shared Between the Patient and the Caregiver
The connection between the Patient and the Caregiver is entirely voluntary. The Caregiver generates a unique invitation code and provides it to the Patient via an external channel (e.g. SMS, WhatsApp). The Patient’s entry and confirmation of the code constitutes voluntarily given consent to sharing the following data with the Caregiver:
- medication list: name, form, dosage, schedule, notes, supply status,
- dose history: statuses and timestamps of all events (dose taken, skipped, postponed, delayed),
- real-time reminder statuses (via a WebSocket connection).
The Caregiver has read-only access to the medication data – they cannot add, edit, or delete the Patient’s reminders. The Patient can disconnect the Caregiver’s account at any time from the App’s settings. After disconnection, the Caregiver loses access to the Patient’s data.
6. Third-Party Services
In connection with the operation of the App, we use the following third-party services:
Supabase
- Purpose: Backend database (PostgreSQL), authentication, real-time synchronization.
- Data shared: Caregiver account data, Patient medication and dose history data, anonymous Patient sessions.
RevenueCat
- Purpose: Subscription management and payment processing.
- Data shared: User identifier, subscription status, purchase information.
Sentry
- Purpose: Error tracking and performance monitoring.
- Data shared: Error logs, device information, IP address, technical context of the event.
PostHog
- Purpose: Product analytics.
- Data shared: Usage patterns, User interactions, device information.
UserJot
- Purpose: Collecting feedback and reports from Users directly within the App.
- Data shared: The content of the submitted feedback and optional contact details voluntarily provided by the User.
Expo Notifications
- Purpose: Delivering push notifications to the Patient and the Caregiver.
- Data shared: Device token (push token), anonymous session identifier.
Apple / Google
- Purpose: Processing subscription payments.
- Data shared: Payment data and purchase history (handled directly by Apple/Google).
7. Data Retention Period
- Caregiver account data: stored for the entire period of using the App. After the account is deleted, the data is erased without undue delay, subject to obligations arising from legal provisions.
- Patient data (medications, dose history): stored on the server for the entire period of the anonymous session’s activity. The User may request the deletion of their data at any time in accordance with point 9 of this Policy.
- Analytics data (PostHog) and error data (Sentry): retained in accordance with the providers’ policies (typically from 90 days to 2 years).
8. Data Security
We apply appropriate technical and organizational measures to protect Users’ personal data, including:
- encrypted connections (HTTPS/TLS) for all data transmission,
- secure data storage on Supabase servers,
- encryption of Caregiver passwords (handled by Supabase Auth),
- data isolation – the Caregiver sees only the data of the Patients with whom they are connected,
- regular reviews and updates of security safeguards.
No method of transmitting data over the Internet or of electronic data storage is 100% secure. Accordingly, we cannot guarantee absolute data security.
9. User Rights Under the GDPR
In accordance with the GDPR, the User has the following rights:
- Right of access (Art. 15 GDPR): to obtain confirmation of whether the User’s personal data is being processed and to access that data.
- Right to rectification (Art. 16 GDPR): to request the immediate rectification of inaccurate data or the completion of incomplete data.
- Right to erasure (Art. 17 GDPR): to request the deletion of personal data (the “right to be forgotten”).
- Right to restriction of processing (Art. 18 GDPR): to request the restriction of data processing in specific cases.
- Right to data portability (Art. 20 GDPR): to receive the data in a structured, commonly used, and machine-readable format.
- Right to object (Art. 21 GDPR): to object to data processing based on the Controller’s legitimate interest.
- Right to withdraw consent: to withdraw the consent granted at any time, without affecting the lawfulness of processing carried out before the withdrawal.
- Right to lodge a complaint: to lodge a complaint with the President of the Personal Data Protection Office (UODO) if the User considers that the processing infringes the provisions of the GDPR.
To exercise the above rights, please contact the Controller using the details indicated in point 14 of this Policy.
10. Supervisory Authority
The President of the Personal Data Protection Office (UODO)
- Website: uodo.gov.pl
- Address: ul. Stawki 2, 00-193 Warszawa
- Telephone: +48 22 531 03 00
11. Protection of Children’s Privacy
The App is not intended for persons under 16 years of age (in accordance with Art. 8 GDPR and Art. 7 of the Act of 10 May 2018 on the Protection of Personal Data). We do not knowingly collect personal data from minors. If you believe that we have collected data from a child, please contact the Controller without undue delay.
12. Push Notifications
The App uses push notifications delivered via Expo Notifications for two purposes:
- Patient: reminders about medications in accordance with the established dosing schedule.
- Caregiver: alerts about the Patient’s unconfirmed or missed doses.
These notifications:
- are sent based on the medication schedules set by the Patient,
- are entirely optional – the User can disable them in the App’s settings or in the operating system,
- are not used to send marketing content or advertisements.
13. Changes to the Privacy Policy
The Controller reserves the right to update this Privacy Policy. The User will be informed of any material changes through:
- publishing a new version of the Privacy Policy in the App,
- updating the date in the document’s header,
- sending a push notification or email message (if required by law).
Continued use of the App after the changes take effect constitutes acceptance of the amended Privacy Policy.
14. Controller’s Contact Details
- Data controller: Albert Napiórkowski
- App: Carely
- Email: support@usecarely.com
- Address: ul. Drewnowska 13 m. 12, 91-002 Łódź, Polska
For requests concerning the GDPR, please include the note “GDPR Request” in the subject of your message and indicate the right you intend to exercise. A response will be provided within one month of receiving the request, in accordance with the requirements of the GDPR.
15. Final Provisions
By using the Carely App, the User confirms that they have read this Privacy Policy. This Privacy Policy is governed by Polish and EU law. In matters not regulated by this Policy, the provisions of the GDPR and the Polish Act of 10 May 2018 on the Protection of Personal Data shall apply.