CareQuest Go Privacy Policy
Effective Date: June 25, 2026 | Last Updated: July 3, 2026
Chase Medical Services LLC ("Chase Medical," "we," "us," or "our") provides the CareQuest Go mobile application (the "App" or "Service"). This Privacy Policy explains how we collect, use, store, protect, and share information in connection with the App.
1. Introduction and Scope
CareQuest Go is a direct-to-consumer caregiving companion app. It helps family caregivers and their care recipients organize care information — including medications, conditions, routines, emergency details, care logs, and a shared "care party" of helpers — and uses light gamification (experience points, levels, and quests) to encourage consistent care coordination.
This Policy applies to information processed through the App. It does not apply to third-party services, websites, or apps that we do not control, even where the App links to or interoperates with them (for example, the Apple App Store).
CareQuest Go is intended for adults. See Section 11 (Children and Minors).
2. Who We Are and How to Contact Us
The business responsible for your information is:
Chase Medical Services LLC 1772 Catalpa Road, Cleveland, Ohio 44112 Contact: dev@chasemedicalcares.com
You can reach us at the address or email above with any question about this Policy or your information.
3. Information We Collect
We collect only the information needed to operate the caregiving features you use. We group it into account information, health-related information, and technical information.
3.1 Account and Identity Information
- Authentication credentials. You create an account using either an email address and password or a mobile phone number (verified by a one-time SMS code). Authentication is handled by Firebase Authentication. We do not store your password in plain text.
- Profile information. Basic profile details associated with your account, including gamification state (experience points, level, quests, badges, and streaks). Gamification data is engagement data and is not health information.
3.2 Health-Related Information You Provide
When you use caregiving features, you may enter information about yourself or a care recipient. This may include: - Care-recipient profiles — name, date of birth, phone number, and relationship. - Medications — medications you track and medication updates recorded in appointment summaries. - Chronic conditions — conditions captured during onboarding and elsewhere. - Emergency packs — personal information, allergies, medications, conditions, emergency contacts, insurance information, primary physician, medical history, and special instructions. - Emergency cards — emergency contact name and phone, allergies, and medications. - Care logs — log entries, free-text notes, and mood indicators. - Routines and reminders — routine steps, vitals to track, labels, notes, and care context. - Appointment packs — visit summaries, vitals, medication updates, notes, and related text. - Kudos and messages — appreciation messages you send within your care party.
We treat the categories above as sensitive health-related information and apply field-level encryption to them, as described in Section 6.
3.3 Family, Helpers, and Invitations
CareQuest Go lets you build a shared "care party." When you invite a helper, we process the recipient's email address or phone number, the invitee and inviter names, and any personal message you include, in order to deliver and manage the invitation. Invitation records are encrypted at rest.
3.4 Device and Technical Information
- Push notification tokens. If you enable notifications, we store a device messaging token so we can send reminders and alerts.
- Operational and security logs. To protect the Service and maintain an audit trail of access to sensitive information, we record technical metadata such as user identifiers, action type, resource accessed, timestamps, IP address, and user-agent. These records support security monitoring and our internal audit log (Section 6).
- Consent and authorization records. When you authorize sharing or exporting certain information, we record the authorization, including the name you signed under, a timestamp, and the IP address and user-agent present at the time of signing.
3.5 What We Do Not Collect
- We do not use third-party advertising or analytics SDKs in the App.
- We do not sell your personal information.
- We do not collect payment card details. Subscriptions are processed by Apple; we never receive your card or banking information (Section 7).
4. How We Use Information
We use the information we collect to: - provide and operate the caregiving features you choose to use; - authenticate you and keep your account secure; - coordinate care among the helpers you invite to your care party; - send reminders and notifications you enable; - maintain an audit trail of access to sensitive information for security and integrity; - detect, investigate, and respond to security incidents and abuse; - operate the gamification features (experience points, levels, quests); and - maintain, troubleshoot, and improve the reliability of the Service.
We process health-related information only to provide the features you use. We do not use it for advertising, and we do not sell it.
5. How We Share Information (Service Providers)
We share information with a limited set of service providers strictly to operate the Service. The table below reflects what each provider actually receives.
| Provider | Purpose | What it receives | Health information? |
|---|---|---|---|
| Google / Firebase & Google Cloud | Core infrastructure: authentication, database, file storage, encryption key management, serverless functions, push messaging | Account data and the encrypted health-related information you enter | Yes — handled under a Business Associate Agreement covering these Google Cloud services |
| Apple (App Store) | Processing and billing of in-app subscriptions | Purchase and subscription transaction data handled by Apple | No |
| RevenueCat | Subscription-state management for in-app purchases | Your app user identifier and subscription/product information | No health information |
| SendGrid | Sending transactional invitation emails | Recipient email address and generic (non-health) invitation content | No — health information is excluded by design |
| ClickSend | Sending transactional SMS notifications | Recipient phone number and generic (non-health) message content | No — health information is excluded by design |
Additional notes: - Google Cloud is the only service provider that handles health-related information, and it does so under a Business Associate Agreement. - RevenueCat receives only your app user identifier and subscription/product details — never health information. - SendGrid and ClickSend are used only for generic invitations and notifications. By design and by enforced engineering policy, no health information is included in messages sent through them. - We may disclose information if required by law, to comply with legal process, or to protect the rights, safety, and security of our users, the public, or Chase Medical. - We do not sell your personal information, and we do not share it with advertisers.
6. How We Protect Your Information
We apply technical and organizational safeguards designed to protect your information. In general terms:
- Field-level encryption. Sensitive health-related fields are individually encrypted using strong, industry-standard authenticated encryption (AES-256-GCM) with envelope encryption backed by a managed cloud key-management service, before the data is stored.
- Encryption in transit. Data exchanged between the App and our servers is protected using HTTPS/TLS.
- Access controls. You can read only your own data. Sensitive writes are processed through server-side functions that enforce authorization, rather than direct database access.
- Audit logging. Access to sensitive information is recorded in an internal audit trail that is designed to be tamper-evident and is verified on a recurring schedule.
- Encryption key rotation. Encryption keys for stored sensitive fields are rotated on a recurring scheduled basis.
- Breach monitoring. We run automated monitoring designed to detect suspicious patterns — such as repeated failed logins, unusual export activity, or unauthorized access attempts — and to alert our team.
- Session protection. The App automatically signs you out after a period of inactivity to reduce the risk of unauthorized access on a shared or unattended device.
- Data retention enforcement. Recurring automated processes enforce our retention schedule (Section 8).
Security incidents. If a breach of security affecting your personal information occurs, we will notify you and the appropriate authorities as required by applicable law.
Important: No method of electronic storage or transmission is completely secure. While we work to protect your information using the measures above, we cannot guarantee absolute security. You also play a role: keep your credentials confidential, and sign out on shared devices.
7. Subscriptions and Payment Information
CareQuest Go is offered as a premium subscription, which includes a limited free trial, purchased through Apple In-App Purchase and managed via RevenueCat. Apple processes all payments. We do not collect or store your payment card or banking details. RevenueCat receives only your app user identifier and subscription/product information to keep your premium status in sync. See the Terms of Service for subscription terms.
8. Data Retention
We retain information for as long as your account is active and as needed to provide the Service. Our retention schedule provides for a retention period of up to six (6) years for health-related records, audit logs, and consent records, consistent with common healthcare record-keeping practices, after which records are archived and/or securely disposed of through automated retention processes.
When information is securely disposed of, we use methods designed to render encrypted data unrecoverable.
9. Your Rights and Choices
The rights below reflect what is actually available in the App today.
- Access your data. You can view the information associated with your account directly within the App.
- Request a copy of your data (data export). You can request an export of your information by emailing us using the "Request data export" option in Profile → Privacy & Security, or by contacting us at the address in Section 2. This is currently a manual, email-based request handled by our team; it is not an automated one-tap download. (Separately, an in-app feature can generate a PDF summary of certain caregiver "appointment pack" information, subject to feature and authorization requirements; that feature is not a full export of your account data.)
- Request deletion of your data. You can request deletion of your account and associated data by emailing us using the "Request data deletion" option in Profile → Privacy & Security, or by contacting us at the address in Section 2. This is currently a manual, email-based request handled by our team. Individual items such as routines or an emergency pack can be deleted within the App.
- Manage notifications. You can control push notifications through your device settings.
- Manage your subscription. You manage or cancel your subscription through your Apple App Store account settings (Section 7 and the Terms of Service).
To exercise a request, contact us at the address in Section 2. We may need to verify your identity before acting on a request, and we will respond within the time required by applicable law.
10. California Residents
If you are a California resident, you have the right to request access to and deletion of the personal information we hold about you, and the right not to be discriminated against for exercising these rights. You can exercise these rights using the options in Section 9 or by contacting us at the address in Section 2.
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use third-party advertising or analytics SDKs in the App.
11. Children and Minors
CareQuest Go is intended for use by adults aged 18 and older. It is not directed to children, and we do not knowingly allow anyone under 18 to create an account or knowingly collect personal information directly from a child to create their own account. If we learn that we have collected account information directly from a person under 18, we will take steps to delete it.
A caregiver may, however, record health-related information about a care recipient who is a minor. If you enter information about a minor, you represent that you are authorized to do so.
12. Where We Operate
CareQuest Go is offered in the United States, and our infrastructure and processing are oriented to the United States. If you access the App from outside the United States, you understand that your information will be processed in the United States.
13. Changes to This Policy
We may update this Policy from time to time. When we make material changes, we will update the "Last Updated" date and, where appropriate, provide additional notice within the App or by other reasonable means. Your continued use of the App after an update takes effect constitutes acceptance of the revised Policy, to the extent permitted by law.
14. Contact Us
Questions about this Policy or your information can be directed to:
Chase Medical Services LLC 1772 Catalpa Road, Cleveland, Ohio 44112 dev@chasemedicalcares.com