Trust & Security
We'd rather show you than tell you.
Your residents' data deserves transparency, not marketing badges. Here's exactly how we handle it.
Current status
What's true today
Privacy by design
Encryption in transit and at rest, an audit trail on every assessment, and consent captured for family recordings.
Data Storage
CareVoice’s own database, files, and backups are stored on Supabase infrastructure in London (eu-west-2) and never leave the UK. One exception, named: phone-agent call recordings are held by Vapi in the US.
Audit Trail
Edits to an assessment are timestamped and attributed, giving each assessment a record of its own history for CQC inspections and safeguarding reviews.
Care Act 2014
Assessment templates and prompts cover the Care Act wellbeing domains. Built by someone who actually does the work.
Safeguarding Detection
Safeguarding concerns are flagged on every voice capture, with a keyword and pattern fallback if the model is unavailable. Flags are for your team to review — never a verdict.
Encryption
Data encrypted in transit and at rest by our platform providers. Role-based access controls scope every read and write to your organisation.
Data flow
Where your data goes
Your database is in London. When the Agent processes your voice recording, the transcript passes through encrypted API calls to our model providers. They do not train on your data, and hold it only briefly for abuse monitoring.
Your voice
Browser microphone
Your device
Speech-to-text
Deepgram Nova-3
Encrypted API call
AI structuring
OpenAI / Anthropic
Encrypted API call
Structured assessment
Supabase (eu-west-2)
London, UK
Registrations & certifications
Where we're headed
Some of these are legal registrations we hold, some are formal certifications we're working toward. ICO registration is a legal requirement for any UK data controller — not a certification or an endorsement — so we list it as a fact, not an achievement.
ICO Registration
DoneRegistered with the Information Commissioner's Office — registration reference ZC206230
GDPR Audit
PlannedFormal review of data subject rights, consent management, and breach procedures
Cyber Essentials
PlannedUK government-backed certification for cyber security
NHS DSPT
PlannedNHS Data Security and Protection Toolkit
ISO 27001
FutureInternational information security management standard
Questions
Common questions about data handling
Where is my data stored?
+
Everything CareVoice itself stores is on Supabase infrastructure in London (AWS eu-west-2) — your assessments, transcripts, resident profiles, and uploaded documents. Database backups also remain in the UK. One exception we would rather name than bury: recordings of phone-agent calls are held by our telephony provider, Vapi, on their own infrastructure in the United States. It is the one category of your data at rest outside the UK. See the Privacy Policy for their terms.
Does any data leave the UK?
+
Your stored data stays in London. When the Agent processes your voice recording, the transcript passes through encrypted API calls to our model providers (OpenAI, Anthropic, Deepgram, ElevenLabs). They do not train on your data, and hold it only briefly for abuse monitoring — see the Privacy Policy for each provider’s terms.
Who can access my data?
+
Only authorised users within your organisation. CareVoice uses role-based access controls. Our engineering team can access data only for support purposes with your permission. We never share, sell, or use your data for training AI models.
What happens if I cancel?
+
You can export everything at any time — every person you support, their assessments, incidents, alerts and documents, plus your service’s own context and protocols — in one machine-readable file, from Settings. That works whether your account is active, paused or closed: leaving CareVoice never costs you your records. After cancellation your data stays for a 30-day grace period; to have it deleted, email info@carevoice.app and we will delete it within 30 days of your request. We do not delete it automatically yet, and we would rather tell you that than claim a process we have not built.
Are you NHS approved?
+
No — we are not yet NHS DSPT certified or formally GDPR-audited; those are on our roadmap. We are registered with the ICO as a data controller (registration reference ZC206230), which is a legal requirement for any UK data controller rather than an approval or endorsement. Our infrastructure uses UK-based hosting, encryption in transit and at rest, and an audit trail on every assessment: each edit, view and change is timestamped and logged.
Questions we haven't answered?
We're a founder-led startup. Ask us anything about how we handle your data.