← Back to CareHub

CareHub Privacy Policy

Last updated: 2 September 2026

This version replaces the version published on 26 July 2026. What changed is the account of who receives your information. Section 6 now names every AI and translation service that receives content you create, and says what each one gets, including dictated audio, participant care records sent for translation, and profile photos. Section 7 now lists the email, push notification and translation providers we were already using but had not named. Sections 2, 7 and 11 now say plainly that in-app messages and in-app call records can be read by the directors and authorised administrators of your organisation, and how long they are kept. The organisation that operates CareHub, and its contact details in Section 17, have not changed.

Nardos Israel Zewde, an Australian sole trader, trading as Nardos' Studio (ABN 11 994 735 678) ("CareHub," "we," "us," or "our") is committed to protecting the privacy of everyone who uses the CareHub app and website (together, the "CareHub Platform"). This Privacy Policy explains what personal information we collect, how we use it, who we share it with, and the choices you have.

We handle personal information in accordance with the Privacy Act 1988 (Cth), the Australian Privacy Principles (APPs), and — for health information collected in NSW — the Health Records and Information Privacy Act 2002 (NSW) and its Health Privacy Principles (HPPs).

1. Who this policy applies to

This policy applies to all users of the CareHub Platform, including care providers, support workers, administrators, clients (also referred to as participants), and their authorised family members or representatives.

2. The information we collect

Depending on your role and how you use the CareHub Platform, we may collect the following categories of information.

Account information: name, email address, phone number, password (stored hashed), role (staff, admin, client, family), and organisation.

Profile information: profile photo, date of birth, address, emergency contacts, and other details you choose to add.

Client and care information: care plans, progress notes, schedules, shift records, incident reports, and other records created in the course of providing care. Some of this is sensitive information, including health information.

Documents you upload: documents you or your organisation upload to the platform, including service agreements, NDIS plans, identification documents (for compliance), clinical reports, and supporting evidence for incident reports.

Photos and media: photos taken in-app or uploaded from your device's photo library, used as profile photos, evidence attached to shift records or incident reports, or as supporting documentation. We access your device camera and photo library only with your permission.

Voice and audio: audio you record in the app. This includes short voice notes, voice messages sent in chat, and speech you dictate instead of typing. What happens to dictated speech depends on the language you choose, and Section 6 sets out each path in full. In Amharic, Tigrinya, Oromo, Somali, Nepali and Filipino, the audio recording itself is sent to Google to be transcribed and translated. In every other language your phone's own speech recognition converts the speech to text, and where that text is not already English the text is then sent to a translation service. Voice messages you send in chat are stored and delivered as audio and are not transcribed. We access your device microphone only with your permission, and recording only starts when you press the button to start it.

Calls made in the app: where your organisation uses in-app calling, we hold a record that a call took place, who took part, when it started, whether it was answered, and how long it lasted. That record is visible to both people on the call and to the directors and authorised administrators of your organisation, on the same footing as in-app messages. Call audio and video are not recorded or stored by us today. Where a direct connection between two devices cannot be made, call media is relayed in transit through the call relay provider named in Section 7. If we introduce call recording or call transcription, we will update this policy and tell affected users before it starts, as described in Section 6.

Contact information: emergency contacts you add to a profile and, where you have granted permission, entries selected from your device's contacts.

Location information: we collect your device's approximate and precise location in two distinct ways, described below.

Clock-in and clock-out location: when you start or finish a shift, we record a single location reading at that moment to confirm you are at the agreed place of work. This is a one-off reading taken while you are using the app, and it is stored against the shift record.

Background location while you are clocked in: if you are a support worker in an organisation that has on-shift travel recording switched on, and you have agreed to it in the app, the CareHub app also collects your device's location in the background, which means collection continues while the app is closed or not in use. Background collection starts when you clock in to a shift and stops when you clock out. It does not run before a shift, after a shift, or at any time when you are not clocked in. We collect it for two purposes only: to measure the distance you travel so that you are paid the correct per-kilometre travel allowance, and to record vehicle speed to support participant and worker safety. Individual location readings are processed on your device and are not uploaded to us. What we store is the total distance travelled during the shift, together with the maximum and average speed. While background collection is running, Android displays a persistent notification and iPhone displays the system location indicator, so you can always tell when it is active. You are asked to agree before any background collection begins, and you may decline or withdraw at any time, in the app or in your device settings. If you decline, every other part of the app continues to work, and travel distance is simply entered manually for reimbursement.

Who we share location and travel information with, and how long we keep it: your clock-in and clock-out locations and your shift travel records are visible to authorised managers and coordinators within your own care organisation, who use them to verify attendance, approve timesheets, and approve travel reimbursement. This information is held by the hosting and database providers listed in Section 7 and is not disclosed to anyone else. We do not sell location or travel information, we do not use it for advertising or marketing, and we do not disclose it to advertising networks, data brokers, or analytics providers. We retain clock-in and clock-out locations and shift travel records for seven (7) years from the date of the shift, which reflects the employee record-keeping obligations under the Fair Work Act 2009 (Cth) and the record-keeping requirements of the National Disability Insurance Scheme Act 2013 (Cth). After that period we securely delete or de-identify them.

SMS and communications: SMS messages we send to you (for shift reminders, verification codes, or operational notifications, delivered via Twilio), in-app messages you send to other users, support requests, and feedback. You can opt out of non-essential SMS at any time. In-app messages are work communications, not private correspondence: Section 7 explains who inside your organisation can read them and what is kept.

Usage information: how you use the app, including pages viewed, features used, device type, operating system, app version, and crash reports. This includes device identifiers we use solely within the app and our service providers — we do not track you across other apps or websites.

3. How we collect information

We collect information in the following ways.

- Directly from you when you register, set up your profile, or use the app.

- From your employer or care organisation if they invite you to join CareHub.

- Automatically through your use of the app, including usage analytics, crash reports, and device data.

- From third parties where you have authorised this — for example, payment processors or single sign-on providers.

4. How we use your information

We use your information to:

- Provide and operate the CareHub Platform.

- Create and manage user accounts.

- Enable care providers to schedule, deliver, and record care.

- Communicate with you about your account, updates, or support requests.

- Send operational SMS such as verification codes and shift reminders.

- Run automated extraction, transcription, translation and summarisation over documents, recordings, care records and communications to populate participant records, to turn speech into text, and to show a shift snapshot in a worker's own language (see Section 6).

- Improve the app through usage analytics and crash reporting.

- Comply with our legal obligations, including record-keeping requirements under the Privacy Act, the National Disability Insurance Scheme Act 2013 (Cth), the Fair Work Act 2009 (Cth), and other applicable laws.

- Detect and prevent fraud or misuse of the platform.

5. Sensitive and health information

Some information held in CareHub is health information or other sensitive information. We only collect this where it is reasonably necessary for providing care services and with appropriate consent. Access is restricted to authorised users within your care organisation based on their role.

We do not sell health information. We do not use health information for advertising, marketing personalisation, or any purpose unrelated to providing the platform and complying with our legal obligations. We do not share health information with advertising networks or data brokers.

6. Use of AI and automated processing

We use third-party services to process content you create in CareHub. What we send them is not limited to documents, and this section names every one of them and what each receives.

Google LLC (Gemini API), in the United States. Gemini processes documents uploaded to the platform — CVs, NDIS plans, service agreements, funding reports, and invoices — to extract structured fields such as dates, plan numbers, line items, and named entities. It also processes participant care records: progress notes, incident reports, shift notes, and the care information shown on a worker's shift snapshot. That content is sent so we can summarise it, draft handover and incident wording for a worker to check, answer questions asked in the in-app assistant, and translate a shift snapshot into a worker's own language. Those records are health information, and they are sent as part of ordinary use of those features, not only when someone asks for a summary. Gemini also receives audio: where you dictate a note in Amharic, Tigrinya, Oromo, Somali, Nepali, or Filipino, the recording of your speech is sent to Google to be transcribed and translated into English, and a note dictated that way can contain health information about a participant. In the recruitment features, applicant emails and their attachments are processed the same way.

Anthropic, PBC (Claude API), in the United States. Claude processes documents, emails, and shift notes to generate participant "knowledge facts" — atomic, attributed statements that populate the client summary view — and answers questions in the support-coordination assistant. That content includes health information. Claude also receives profile photos, for one narrow purpose: working out where the face sits in the picture so a circular avatar can be cropped without cutting off the head. Only the resulting pair of coordinates is kept.

Translated s.r.l. (MyMemory translation API), in the European Union. If you dictate a note in a language other than English, and it is not one of the six languages named above, your phone converts your speech to text and that text is then sent to MyMemory to be translated into English before it appears in the note box for you to check. Dictated care text sent this way can contain health information. We use the free public tier of that service, we do not hold a contract with it, and it is therefore not covered by the subprocessor commitments described in Section 7. If you would prefer that nothing left your device this way, dictate in English or type the note instead.

The speech-to-text step itself, in every language except those six, is performed by your own device or by the speech service your phone's maker operates, under that maker's privacy terms rather than ours.

Planned use: we are building call transcription for in-app voice calls. If we switch it on, call audio would be sent to an AI transcription provider in the same way dictation is today. It is not switched on at the date of this policy. We will update this policy and notify affected users before any call audio is transcribed.

For Google and Anthropic we have selected API tiers and configurations intended to exclude customer data from model training, and we review this annually. We have made no equivalent arrangement with MyMemory, which is why it is described separately above.

You may request that we attempt to exclude your records from AI-based processing where reasonably practicable. Contact privacy@carehq.au. Dictation and translation can also simply not be used: you can type instead, and everything else in the app continues to work.

AI-derived summaries, transcripts, and translations are intended as a starting point for human review. They are not clinical, medical, legal, or financial advice and should not be relied on without verification.

7. Who we share information with

We do not sell your personal information. We share information only in the following situations.

- Within your care organisation: information you enter is visible to authorised users in your organisation according to their role and permissions. This includes the messages you send through CareHub's in-app messaging. Messages sent in CareHub are work records: the directors and authorised administrators of your organisation can read them, and the record of who messaged whom and when is retained. The record of in-app calls — who called whom, when, whether the call was answered, and how long it ran — is visible to the same people, although the call itself is not recorded. Where a conversation has disappearing messages switched on, the message itself is deleted from CareHub about ten minutes after it is sent, but it can be read by anyone with access to the conversation during that time, the record that the conversation happened remains, and any copy taken in the meantime — including a screenshot — is outside our control. Disappearing messages are not a private channel and should not be used to record care information.

- Service providers (subprocessors): we use the following third-party providers to operate CareHub. Each accesses information only as needed to perform its service, and each is bound by data-handling obligations except where the entry below says otherwise.

- Supabase Inc. (database, authentication, file storage) — data stored in Singapore (AWS region ap-southeast-1).

- Vercel Inc. (web hosting and serverless compute) — primary execution in Sydney, Australia (region syd1); some static assets served from Vercel's global edge network.

- Twilio Inc. (SMS delivery) — United States.

- Google LLC (Gemini API for document extraction, for summarising and translating participant care records, and for transcribing dictated audio) — United States.

- Anthropic, PBC (Claude API for extraction from documents and care records, in-app chat, and locating the face in a profile photo) — United States.

- Metered (TURN relay for in-app voice and video calls) — used only when a direct connection between two devices cannot be established, in which case call audio and video pass through the relay while the call is in progress. Relay servers are operated in several countries, so a relayed call may pass through a server outside Australia. We do not record or store call audio or video.

- Resend, Inc. (transactional email delivery) — United States. Sends the email CareHub generates, including password resets, task and accountability reminders, and recruitment correspondence, so it receives the recipient's address and the content of those messages. Where that service is unavailable, the same message is sent instead through your organisation's own business mailbox.

- Google LLC (Firebase Cloud Messaging, push notifications) — United States. Receives your device's push token and the title and short text of each notification, which can include a participant's first name.

- Translated s.r.l. (MyMemory translation API) — European Union. Receives dictated note text for translation into English, as described in Section 6. This is that service's free public tier and, unlike the providers above, it is not covered by a data-handling contract with us.

- OpenStreetMap Foundation (Nominatim address lookup) — European Union. We do not send personal identifying information to Nominatim; only address query strings.

- Where required by law: we may disclose information when required by Australian law, court order, or a lawful request from a government agency, including notifications to the NDIS Quality and Safeguards Commission where applicable.

- With your consent: where you have specifically authorised us to share information.

8. Where your information is stored and overseas disclosure

The CareHub Platform is hosted in Australia (Vercel syd1, Sydney) and stores customer data in Singapore (Supabase, AWS ap-southeast-1). Some of our service providers — including Twilio, Google, Anthropic, and Resend — process limited data in the United States. That includes the voice recordings and participant care records described in Section 6, which are sent to Google and Anthropic in the United States, and the content of the email we send you, which passes through Resend. Push notifications are delivered through Google's Firebase Cloud Messaging in the United States. Where an in-app call has to be relayed rather than connected directly, the call passes through a relay server that may be outside Australia, as described in Section 7. In the European Union, OpenStreetMap Nominatim processes address queries and MyMemory processes the dictated text described in Section 6.

Where information is disclosed to overseas recipients, we take reasonable steps under Australian Privacy Principle 8 to ensure the recipient handles your information in accordance with the APPs, including by entering into contractual data-handling commitments.

9. How we protect your information

We take reasonable steps to protect your information from loss, misuse, unauthorised access, modification, or disclosure. These measures include:

- Encryption of data in transit (TLS); encryption at rest on supported infrastructure.

- Role-based access controls so users only see what they need to.

- Secure password requirements and the option to use SSO.

- Regular security reviews and monitoring.

- Confidentiality obligations on all staff and contractors.

No system is completely secure. If you believe your account or information has been compromised, please contact us immediately at support@carehq.au.

10. Data breaches

If a data breach occurs that is likely to result in serious harm, we will notify affected individuals and the Office of the Australian Information Commissioner (OAIC) in accordance with the Notifiable Data Breaches scheme under Part IIIC of the Privacy Act 1988 (Cth).

11. How long we keep information

We keep personal information only for as long as it is needed for the purposes set out in this policy, or as required by law.

For NDIS participants and the records of their care, our minimum retention period reflects the National Disability Insurance Scheme Act 2013 (Cth) and the NDIS Practice Standards: records are kept for at least seven (7) years from the date of last service. For participants who are minors, records are kept until the participant reaches the age of majority plus seven years.

Location and travel records, including shift clock-in and clock-out locations and measured trip distances and speeds, are kept for seven (7) years from the date of the shift, and are then securely deleted or de-identified.

In-app messages and the record of who messaged whom and when are kept for seven (7) years, on the same basis, except where a conversation has disappearing messages switched on, in which case the message content is deleted about ten minutes after it is sent and only the record that the conversation took place remains.

The record of in-app calls described in Section 2 is kept for seven (7) years on the same basis. There is no call audio to keep.

When information is no longer needed, we securely delete or de-identify it.

12. Your rights

You have the right to:

- Access the personal information we hold about you.

- Request that we correct information that is inaccurate or out of date.

- Withdraw consent for optional uses of your information, such as marketing communications. For sensitive or health information, we will not use your information for direct marketing without your separate, explicit consent (Australian Privacy Principle 7.4).

- Request that your account and associated data be deleted (see Section 13).

- Request that your records not be processed by our AI services (see Section 6).

- Make a complaint about how we handle your information.

NDIS participants have additional rights under the NDIS Practice Standards, including the right to choose who within your care organisation can access your information.

To make a request, email us at privacy@carehq.au. We may need to verify your identity before responding. We will acknowledge your request within 7 days and aim to substantively respond within 30 days.

If you are not satisfied with our response, you can contact the Office of the Australian Information Commissioner at www.oaic.gov.au.

13. Account and data deletion

You may request deletion of your account and associated personal information at any time by emailing privacy@carehq.au. We will:

- Acknowledge your request within 7 days.

- Complete deletion within 30 days, subject to any legal record-keeping obligations.

Records we are legally required to retain — for example, NDIS participant care records subject to Section 11's retention period, employee records, or financial records required by Australian tax law — will be retained for the minimum period required and then deleted. We will tell you which categories of information were retained and why.

An in-app account-deletion control is on our product roadmap. Until it is available, deletion is requested by email as described above.

14. Cookies

The CareHub website and app use minimal cookies necessary for authentication and platform functionality. We do not use third-party advertising cookies or cross-site tracking.

15. Children

CareHub is intended for use by care providers and the people they support. Where a client is a minor, their information is managed by their authorised representative or care organisation. The CareHub Platform is not directed at children under 13 as account holders, and we do not knowingly collect personal information directly from children under 13 without parental or guardian consent.

16. Changes to this policy

We may update this policy from time to time. If we make material changes, we will notify users through the app or by email before the changes take effect. The "Last updated" date at the top of this policy shows when it was last changed.

17. Contact us

If you have questions about this policy or how we handle your information, please contact:

Nardos Israel Zewde t/a Nardos' Studio

ABN 11 994 735 678

7 Dempster Cres, Regents Park NSW 2143

Privacy enquiries: privacy@carehq.au

Support: support@carehq.au