Privacy policy
How CareVoice handles your data, your residents' data, and the data your team puts into our service.
Last updated 23 July 2026
Introduction
This Privacy Policy describes how CareVoice ("we", "our", or "us") collects, uses, stores, and shares personal information when you use our service. It is written for UK care professionals and the organisations that employ them.
CareVoice is a voice-first care intelligence platform. We treat the data you put into the service as your data, not ours. We do not use it to train AI models. We do not sell it. We do not share it with advertisers.
We operate under the UK GDPR and the Data Protection Act 2018. Care Voice Group Ltd is registered with the ICO as a data controller (registration reference ZC206230) — see our Trust Centre for the current status of our certifications and registrations.
Who we are
CareVoice is a trading name of Care Voice Group Ltd, a company registered in England and Wales, Company No. 17356608, with its registered office at 66 Paul Street, London EC2A 4NA. You can contact us at info@carevoice.app.
For account, billing, website and enquiry data, Care Voice Group Ltd is the data controller. For personal data inside the care records your organisation processes through the service ("Customer Data"), your organisation is the data controller and Care Voice Group Ltd acts as its data processor, as set out in our Terms.
The Information Commissioner's Office (ICO) is our supervisory authority. If you believe we have mishandled your personal data, you have the right to complain to the ICO at ico.org.uk.
What information we collect
We collect the following categories of personal information:
- Account information: name, email address, role, professional credentials, organisation membership.
- Resident / service user data: care notes, assessment data, health and care needs information that you input on behalf of the people you support. This is often special category data under UK GDPR (health data).
- Voice recordings and transcripts: the text transcription of voice capture sessions, and the audio itself. To be precise about the audio:
- Assessment voice capture: a temporary backup of the recording is held so a dropped connection doesn't lose your work. It is deleted as soon as the transcript saves, and in any case within 24 hours.
- Family recordings and visit recordings: the audio is stored with the person's record. We keep a visit recording's audio for no more than 90 days, and a family recording's for no more than 180 days — see how long we keep your data below. The transcript, and the information confirmed into the person's record from it, are kept as part of that record; it is the audio that expires.
- Phone-agent calls: handled by Vapi, who record the call. Callers are told at the start of every call that it is being recorded.
- Generated assessments and care plans: the structured output produced by our AI from your voice and source documents.
- Files you upload: PDFs and supporting documents you attach to assessments.
- Audit logs: every edit, view and change to an assessment is timestamped and logged for CQC inspections and safeguarding reviews.
- Usage data: features accessed, time spent, technical telemetry (anonymised by default).
- Device information: IP address, browser type, operating system, used for security and abuse prevention.
How we use your information
We use the information we collect for the following purposes:
- To provide the service you signed up for (capture, transcribe, structure, store)
- To process your voice into structured assessments using our AI processing pipeline
- To detect safeguarding concerns and clinical risk indicators in recorded documentation
- To maintain the audit trail required for CQC compliance
- To send transactional emails (account verification, password reset, OTP codes)
- To send service updates and onboarding emails (you can opt out of marketing email at any time)
- To process payments and manage subscriptions
- To improve and secure the service
- To comply with legal obligations
We do not use your data to train AI models. Our AI sub-processors (OpenAI, Anthropic, Deepgram) operate under enterprise API terms that prohibit training on customer data.
Sub-processors
We use the following sub-processors to deliver the service. We are putting data processing agreements in place with each one to ensure your data is handled in line with this policy and the UK GDPR.
- Supabase — primary database, authentication, file storage. Our Supabase project is hosted in London (AWS eu-west-2).
- OpenAI — large language model API for assessment generation. Stateless API calls, no training on customer data, 30-day abuse-monitoring retention then deletion.
- Anthropic — large language model API (Claude) for assessment generation and clinical reasoning. Same terms as OpenAI: stateless, no training, 30-day retention.
- Deepgram — speech-to-text transcription (Nova-3 model), EU endpoint. Deepgram processes the audio to return a transcript; their retention is governed by our agreement with them. Transcripts return to CareVoice and are stored in our UK database.
- ElevenLabs — speech processing for some transcription paths. Receives audio; does not train on it under our agreement.
- Vapi — voice agent telephony platform for our optional phone-based assistant. Vapi handles the call infrastructure on its side; structured data from calls is sent to our UK database via webhook.
- Stripe — payment processing and subscription management. CareVoice never sees raw payment card data; Stripe handles it directly under PCI DSS Level 1.
- Brevo — transactional and marketing email (account verification, password reset, OTP codes, service updates). EU-hosted (France).
- Vercel — application hosting, CDN, edge functions. Customer database queries always route to Supabase (London); Vercel does not persist customer data.
- Vercel Analytics — first-party page view and Web Vitals analytics. Anonymised, no cookies, no personally identifiable information.
- Google Analytics 4 — web analytics for marketing pages, loaded only after you give explicit consent via the cookie banner.
A complete data processing inventory (vendor, data touched, processing location, retention) is maintained internally and available on request to organisational customers and procurement teams.
Where your data is stored
Everything CareVoice itself stores is held in the United Kingdom, on Supabase infrastructure in London (AWS eu-west-2). This includes the database, file uploads, transcripts, generated assessments, and backups.
One thing sits outside that store, and we would rather name it than let the sentence above quietly cover it: recordings of calls to and from the phone agent are held by our telephony provider, Vapi, on their own infrastructure in the United States, under their retention policy — not in our UK database. It is the one category of your data that is at rest outside the UK. Their terms are in the sub-processor list above.
When the Agent processes your voice or text, the transcript is transmitted via encrypted API calls to our model providers (OpenAI, Anthropic, Deepgram, ElevenLabs). They do not train on your data. They may hold it briefly for abuse monitoring — see the retention terms listed for each provider above.
Payment records are processed by Stripe, which operates internationally. Email send logs are processed by Brevo, hosted in the European Union (France).
How long we keep your data
We retain personal data only as long as we need it for the purposes set out above:
- Raw audio of visit recordings: kept for no more than 90 days from the recording. We need it to check the transcript is accurate, to let a staff member review what was said before it enters the person's record, and to monitor whether our transcription is doing its job. After that the audio has served its purpose.
- Raw audio of family recordings: kept for no more than 180 days from the recording — long enough for the contribution to be reviewed and included in an assessment, and for a family member to come back to us if they disagree with what was captured or withdraw their consent.
- What survives the audio: the transcript and the information confirmed into the person's record are part of the care record and are kept for as long as that record is kept. Deleting the audio does not remove anything the service knows about the person.
- When we keep audio longer: we do not delete audio while an incident involving that person is still open, while its transcription has failed, or while it is under a legal hold — for example because it is evidence in a safeguarding matter or an ongoing legal claim, or because someone has asked us for a copy of their data. A service can also choose to keep its own audio for longer than the periods above. Nobody can set a shorter period than the ones we publish here.
- How the deletion happens: a job runs every day and deletes raw audio that has passed its window. We would rather be exact than reassuring: that job only acts on categories whose retention window has been configured, and a category with no window set is never purged — it fails safe rather than deleting something it should have kept. Where a window is set, a recording is destroyed within a day of reaching it, and we keep a record of what was deleted and when — the proof, without keeping the audio.
- Active customer data: retained for the duration of the customer relationship.
- After cancellation: your data stays available for a 30-day grace period in case you change your mind. To have it deleted, email us at info@carevoice.app and we will delete it within 30 days of your request. We do not yet delete it automatically — we would rather say so than claim a process we have not built.
- Right to erasure: on request, we will delete your personal data ahead of the grace period — within 30 days, as UK GDPR allows, and usually much sooner. (This previously said “immediately”, which contradicted the 30-day figure stated a few lines above and in our Terms.)
- Audit logs and security events: retained for 1 year for security and compliance investigations.
- Payment records: retained for 7 years to satisfy UK tax and financial regulations (held by Stripe).
- Email send logs: retained by Brevo for 6 months.
- Server logs (Vercel): retained for 30 days.
How we secure your data
We implement appropriate technical and organisational measures to protect personal data against accidental or unlawful destruction, loss, alteration, unauthorised disclosure, or access.
- Encryption: data is encrypted in transit and at rest by our platform providers (Supabase, Vercel)
- Access controls: role-based access controls scope every data read and write to the user's organisation
- Audit trail: every edit, view and change to an assessment is timestamped and logged
- Sub-processor agreements: we are putting data processing agreements (DPAs) in place with our sub-processors
- Staff access: our engineering team can only access customer data with explicit permission, for support purposes
Your rights under UK GDPR
Under UK GDPR you have the following rights regarding your personal data. To exercise any of these, contact us at info@carevoice.app:
- Right of access — get a copy of the personal data we hold about you
- Right to rectification — correct inaccurate or incomplete data
- Right to erasure — delete your personal data (also known as "right to be forgotten")
- Right to restrict processing — limit how we use your data in specific situations
- Right to data portability — receive your data in a structured, machine-readable format
- Right to object — object to specific processing activities, including marketing
- Rights in relation to automated decision making — request human review of significant automated decisions
We respond to data subject requests within 30 days. If you are unhappy with our response, you have the right to complain to the Information Commissioner's Office (ICO) at ico.org.uk.
Changes to this policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by email and update the "Last updated" date at the top of this page. Continued use of the service after a change indicates acceptance of the updated policy.
How to contact us
For any privacy-related question, including data subject requests:
- Privacy, data subject requests and general enquiries: info@carevoice.app — one inbox, read by the founder. Mark data subject requests clearly in the subject line and we will treat them as such.
- Post: Care Voice Group Ltd, 66 Paul Street, London EC2A 4NA
We aim to respond to privacy enquiries within 5 working days, and to formal data subject requests within 30 days as required by UK GDPR.