Privacy Policy
Effective Date: August 25, 2026
This policy describes exactly what My Care Sentinel does with your data — no more, no less. It is generated from and kept in sync with the app's actual behavior (see PrivacyInfo.xcprivacy, OnboardingConsentView.swift, and PrivacyInfoView in SettingsView.swift); an automated check (.github/workflows/ci.yml's release-readiness job) reviews this document against the app's actual code before each tagged release and fails the build if they've diverged.
Medical disclaimer
My Care Sentinel is a personal record-keeping tool. It is not a medical device and is not a substitute for professional medical advice, diagnosis, or treatment. Always consult a qualified healthcare provider with questions about a medical condition.
What we collect
My Care Sentinel does not require an account, an email address, or any sign-up. The only data the app touches is what you enter yourself: medications, doctors, conditions, side effects, appointments, lab results, and any visit recordings or notes you choose to create.
Where your data goes
- Your own iCloud account. Everything you enter is stored on your device and synced privately through your personal iCloud account to your other Apple devices, using Apple's CloudKit private database. My Care Sentinel has no server of its own that stores or has access to your medical records. Apple's own privacy practices govern data in your iCloud account.
- RevenueCat — contacted at every app launch, for every user, to check current subscription status (a RevenueCat-generated anonymous identifier and device/App Store data, not your medical records). If you subscribe to Premium, it additionally receives standard App Store purchase/ subscription validation data tied to that same identifier. No health data is ever sent to RevenueCat, subscriber or not.
- Apple Maps (MapKit) — contacted only when you tap "Use Current Location" while logging a hospitalization, to look up a nearby facility's name and address from your one-time location. Nothing else is sent with that request, and it is never sent for any other reason.
- Nothing else receives your data. My Care Sentinel does not sell your data, does not share it with advertisers or data brokers, and does not use it for tracking across other apps or websites. The one other network connection the app can make — downloading public reference data, never your data — is described under "App resource updates" below.
AI and voice features
Medication label scanning, voice entry, and visit-recording transcription all run on-device only. Speech recognition is explicitly configured to require on-device processing (requiresOnDeviceRecognition) rather than allowing Apple's optional server-side transcription, and AI text extraction uses Apple's on-device Foundation Models framework. No recording, transcript, or extracted health information is ever sent to a My Care Sentinel server or any third-party AI provider — there is no cloud AI service in this app's architecture, so there is nothing to send.
Apple Health
If you choose to connect Apple Health, My Care Sentinel only ever reads data (blood pressure, resting heart rate, weight, blood glucose) to show alongside your medication timeline — it never writes to Health, and nothing read from Health is stored on disk or synced anywhere. It exists only in memory while the relevant screen is open.
Location
My Care Sentinel never tracks your location continuously or in the background. Tapping "Use Current Location" on the New Hospitalization screen requests your location once, only for that action, and sends it to Apple's Maps service (MapKit) to look up the name and address of the nearest hospital — never to a My Care Sentinel server or any other third party. Your location itself is never stored; only the resulting facility name, address, and phone number (if found) become part of the hospitalization record you're creating, the same as anything you type in directly.
Calendar
If you grant calendar access, My Care Sentinel reads your events on-device only, to detect doctor appointments and prompt you about related medication updates. Your calendar itself is never uploaded or synced anywhere. If you confirm a detected appointment, the record you create from it becomes part of your own data (see "Where your data goes" above) — the same as anything you enter directly.
Crash and technical error reporting
My Care Sentinel uses no third-party crash-reporting or analytics service of any kind. If the app crashes, Apple's own built-in crash reporting handles it entirely outside the app — a symbolicated crash report reaches us only if you've separately opted into "Share With App Developers" in your device's own Settings → Privacy & Analytics, through Apple's system, not this app's. My Care Sentinel never sends a crash report itself.
The app also logs a small, fixed set of technical events locally (a required on-device speech feature being unavailable, a background ingredient-database lookup returning nothing) using Apple's standard system logging (OSLog). These entries never leave your device — they're visible only if you personally connect your device to a Mac and open Console.app or Xcode, the same as any other app's system log.
App resource updates
My Care Sentinel includes a capability to download updated reference data (such as the built-in drug/ingredient database) from assets.mycaresentinel.com/cdn.mycaresentinel.com — a one-way, public-data download with cryptographic integrity verification before install. As of this writing, that check is not yet active in a shipped release — the app currently relies solely on the reference data bundled at install time. This section will be updated when it goes live. Either way, this channel never sends any of your data; it only ever retrieves shared reference content the app ships with.
Your data, your control
You can export or permanently delete all of your data at any time from Settings → Privacy & Data. Deleting the app removes everything stored locally; removing it from iCloud removes the synced copy.
Children's privacy
My Care Sentinel is not directed at children under 13 and does not knowingly collect data from them.
Changes to this policy
If what the app actually does changes, this document changes with it — that's enforced by the CI check referenced above, not just a promise. Material changes will be reflected in the app's own onboarding consent screen.
Contact
Questions about this policy: privacy@mycaresentinel.com
Email: privacy@mycaresentinel.com
Support Portal: mycaresentinel.com/support