Skip to the content.

Privacy Policy

Effective Date: July 8, 2026

1. Introduction

ElderMate helps families care for elderly loved ones through automated AI wellness calls. This policy explains what data we collect, why, and how we protect it.

ElderMate (“we,” “us,” or “our”) operates a mobile application and associated services that enable guardians to schedule automated AI-powered wellness check-in calls to their elderly loved ones (the “Service”). This Privacy Policy describes our practices regarding the collection, use, disclosure, and protection of personal information when you use the Service. To provide the Service, we share certain personal data — including your loved one’s name, phone number, health notes, and the call audio and transcript — with named third-party AI and telephony providers (see Section 4). We ask for your permission in the app, and you must agree, before any of this data is shared.

By creating an account or using the Service, you acknowledge that you have read and understood this Privacy Policy. If you are a guardian setting up the Service for a loved one, you represent and warrant that you have obtained the loved one’s informed consent to participate in automated wellness calls and to the collection and processing of their data as described herein.

This Privacy Policy applies to all users of the Service globally, including users in the European Economic Area (EEA), the United Kingdom, California, India, and other jurisdictions with data protection legislation.

2. Information We Collect

We collect your account info, your loved one’s details, and data generated during wellness calls including transcripts, mood analysis, and health signals.

We collect the following categories of personal information:

(a) Guardian Account Information: Your name, email address, phone number, profile avatar, authentication credentials (via third-party sign-in providers), and the account identifiers we assign to your account and to each loved-one profile. Your phone number is used to place preview calls to you and for account contact. We also collect device push notification tokens and your notification preferences to deliver alerts about your loved one’s wellbeing.

(b) Loved One Information: Name, phone number, relationship to the guardian, timezone, gender, the language spoken on calls, health notes (as provided by the guardian), and profile avatar. This information is used to personalize wellness calls and tailor conversations appropriately.

(c) Call Data: For each wellness call, the call audio is recorded (captured and briefly retained by our voice provider, as described in Section 4), and we collect and store the full conversation transcript, call duration and timing information, AI-generated mood assessments (positive, neutral, or needs attention), health and wellbeing signals (including indicators of distress, health concerns, and loneliness), AI-generated conversation summaries and action items, topics discussed, and medication adherence status where applicable.

(d) Schedule Information: Call recurrence settings, preferred times of day, selected days of the week, call type (a medication reminder or a general/custom check-in call), timezone preferences, and any custom notes provided by the guardian.

(e) Alert Data: Alert type, severity classification, AI-generated insights, and suggested actions derived from call analysis.

(f) Care Notes and Follow-Ups: Notes and follow-up tasks you create about your loved one within the app (for example, an observation you record after a call), including the text you enter and your name as their author.

(g) Subscription Information: Your subscription status and entitlement details (such as expiry date), managed through our subscription provider (RevenueCat) and the Apple App Store or Google Play.

(h) Product and Operational Data: We record product and operational events — such as whether a call completed, whether a summary was generated, and error diagnostics — linked to your account and, where relevant, your loved one, to monitor and improve the reliability of the Service. We may derive anonymized, aggregated metrics from these events. Device type, operating system, and app version are included only if you choose to send us a support email.

3. How We Use Your Information

We use your data to make and analyze wellness calls, generate health insights, send you alerts, and improve the Service. We do not sell your data.

We use the personal information we collect for the following purposes:

(a) Service Delivery: To initiate and conduct automated wellness check-in calls at scheduled times, using the loved one’s name, phone number, timezone, and health notes to personalize each conversation.

(b) AI Analysis: To process the call transcript shortly after each call ends and generate mood assessments, health signal detection, conversation summaries, action items, and medication adherence tracking. This analysis runs as a background task using the completed transcript.

(c) Alert Generation: To identify situations requiring guardian attention, including missed calls, missed medications, emotional distress, health concerns, and indicators of loneliness, and to classify these by severity (critical, warning, or informational).

(d) Notifications: To deliver push notifications to guardians when alerts are generated or when important events occur related to their loved one’s wellbeing.

(e) Service Improvement: To analyze anonymized and aggregated usage patterns to improve call quality, AI accuracy, and overall Service reliability.

(f) Account Management: To authenticate users, manage subscriptions, and provide customer support.

We do not sell, rent, or trade your personal information to third parties for their marketing purposes. We do not use your data to build advertising profiles.

4. Third-Party Service Providers and AI Services We Share Data With

To make and analyze wellness calls, we share personal data with named third-party AI and telephony providers. Each acts only as our data processor, is bound by a data processing agreement, must protect your data to a standard equal to or greater than this policy, and may not sell it or use it for its own purposes.

To deliver the Service — placing AI wellness calls and turning them into summaries — we share personal data with the third-party providers named below. We share only the data each provider needs for its specific function. Each provider acts solely as our data processor: it processes the data only on our documented instructions, only to provide its service to us, and is contractually required to keep the data confidential and to protect it to a standard at least equal to the protections described in this Privacy Policy. None of these providers is permitted to sell your data or to use it to build its own independent products or profiles.

(a) Telephony providers — Twilio Inc. (United States), and Vobiz for calls placed to Indian (+91) numbers. Receives: your loved one’s phone number and the live call audio, in order to connect and carry the outbound phone call. For preview calls, also receives your (the guardian’s) phone number so we can call you.

(b) Conversational voice AI — ElevenLabs Inc. (United States). Receives: your loved one’s first name, gender, spoken language, and the health and reminder notes you provide, together with the live call audio and the resulting transcript, in order to conduct the AI voice conversation and produce a transcript. For preview calls, ElevenLabs also receives your (the guardian’s) name so the preview sounds like a real call. Call audio and transcripts are retained by ElevenLabs for a limited period (currently up to 30 days) and then deleted.

(c) Conversational and analysis AI models — Google LLC (Gemini) (United States). Google receives the in-call conversation, to power the live conversation, and — after the call ends — the call transcript, to detect mood, distress, health concerns, loneliness, and medication signals for your summary. OpenAI (United States) is used only as an occasional automatic backup for conducting the live conversation when the primary model is briefly unavailable; when it is used, it receives the in-call conversation only, and it does not receive the post-call transcript for analysis.

(d) Cloud database, authentication, and storage — Supabase. Receives and stores: guardian account information, loved one details, call records and transcripts, schedules, and alerts, with row-level isolation between accounts.

(e) Authentication providers — Apple and Google sign-in. Receives: your email address, name, and basic profile information, solely to authenticate your sign-in.

(f) Push notification delivery — Expo, and the Apple Push Notification service and Firebase Cloud Messaging. Receives: your device push token and notification content, in order to deliver alerts to your device.

(g) Subscription management — RevenueCat, and the Apple App Store / Google Play. Receives: subscription and entitlement identifiers, in order to manage your paid access.

We obtain your explicit, in-app permission before any personal data is shared with the AI and telephony providers in (a)–(c). When you set up your first wellness call, the app shows a disclosure that names these providers and the exact data shared, and requires you to affirmatively agree — no call is placed and no data is sent to any of these providers until you do. You can review this disclosure and withdraw your consent at any time in the app under Profile → AI & data sharing; withdrawing consent stops all future calls and pauses further sharing.

4.1 International Data Transfers

ElderMate and most of the providers listed above are located in the United States. If you or your loved one are located outside the United States, your personal data will be transferred to, stored, and processed in the United States and other countries where we or our providers operate. Where required by applicable law, we rely on appropriate safeguards for these transfers — such as the EU/UK Standard Contractual Clauses and equivalent contractual data-protection commitments with our providers — including for users in the European Economic Area, the United Kingdom, and India.

ElderMate is a family caregiving tool, not a medical device. Health signals are informational observations, not medical diagnoses or advice.

ElderMate is designed as a family caregiving and communication tool. It is not a medical device, healthcare provider, or diagnostic service, and it is not subject to health data regulations such as HIPAA (United States) or equivalent frameworks in other jurisdictions.

The health-related observations generated by our Service, including mood assessments, distress indicators, health concern flags, and loneliness signals, are derived from AI analysis of conversational patterns. This analysis is performed by sending the call transcript to Google’s Gemini, as described in Section 4. (OpenAI is used only as an occasional backup for conducting the live phone conversation and does not receive the transcript.) These observations are informational in nature and are intended to help guardians stay connected with and attentive to their loved one’s general wellbeing.

These observations should not be used as a substitute for professional medical advice, diagnosis, or treatment. If you have concerns about your loved one’s health, you should consult a qualified healthcare professional. In case of a medical emergency, contact emergency services immediately.

Health notes provided by guardians (such as medication schedules or known health conditions) are used solely to personalize wellness call conversations and are stored with the same security protections as all other user data.

Notwithstanding the above, we treat all health-related information with heightened care and apply the same technical and organizational safeguards as we do to all personal data processed by the Service.

6. Data Security

We protect your data with encryption in transit and at rest, row-level database isolation, webhook signature verification, and server-side-only API key storage.

We implement comprehensive technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction:

(a) Encryption in Transit: All data transmitted between the mobile application, our servers, and third-party service providers is encrypted using HTTPS/TLS protocols.

(b) Encryption at Rest: All data stored in our database is encrypted at rest using industry-standard encryption algorithms.

(c) Row-Level Security: Our database enforces row-level security policies that isolate each user’s data at the database layer. This means that even in the event of an application-level vulnerability, one user’s data cannot be accessed through another user’s authenticated session.

(d) Webhook Verification: Incoming webhooks are authenticated before processing. Call webhooks from our voice provider are verified using HMAC-SHA256 signatures, and subscription webhooks are authenticated using a shared secret, to prevent tampering and ensure data authenticity.

(e) Server-Side Key Management: All API keys and service credentials are stored exclusively on the server side and are never exposed to client applications.

(f) Access Controls: We enforce the principle of least privilege across our infrastructure. Administrative access to production systems is restricted and audited.

While we implement commercially reasonable security measures, no method of transmission over the Internet or method of electronic storage is completely secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents in accordance with applicable law.

7. Data Retention and Deletion

We keep your data as long as your account is active. When you delete your account, all data is permanently removed in a full cascade deletion.

We retain your personal information for as long as your account remains active and as reasonably necessary to provide the Service to you.

(a) Active Accounts: All data associated with your account, including guardian information, loved one profiles, call records and transcripts, schedules, and alerts, is retained for the duration of your account’s existence.

(b) Account Deletion: Upon account deletion, all associated data is permanently and irrevocably removed through a full cascade deletion process. This includes the guardian profile, all loved one profiles linked to the account, all call records and transcripts, all schedules, all alerts, and all associated AI-generated content. This deletion is not reversible.

(c) Deletion Timing: When you confirm account deletion in the app, your account and all associated data are permanently and irreversibly deleted immediately, with no grace period. The action cannot be undone. Copies held by our third-party processors and in routine system backups are purged in accordance with their standard retention schedules (generally within 30 days).

(d) Exceptions: We may retain limited, anonymized, and aggregated data that cannot be used to identify any individual for the purpose of improving Service performance and reliability. We may also retain data where required by applicable law or to resolve disputes or enforce our agreements.

(e) Withdrawing AI Data-Sharing Consent: You can withdraw your consent to share data with our third-party AI and telephony providers at any time in the app under Profile → AI & data sharing. Withdrawing consent immediately stops all future calls and pauses further sharing with those providers. Your existing summaries and transcripts remain available to you in the app until you delete them or delete your account.

To request account deletion, you may use the account deletion option within the app settings or contact us at yravinderkumar33@gmail.com.

8. Your Rights

Depending on where you live, you have rights to access, correct, delete, and port your data. We honor these rights regardless of jurisdiction.

We respect your data protection rights under applicable law. Depending on your jurisdiction, you may have some or all of the following rights:

(a) Rights Under the EU/UK General Data Protection Regulation (GDPR)

Legal basis for processing: We process your data based on (i) contractual necessity to provide the Service, (ii) your consent where applicable, and (iii) our legitimate interests in improving and securing the Service.

(b) Rights Under the California Consumer Privacy Act (CCPA/CPRA)

(c) Rights Under the Indian Digital Personal Data Protection Act (DPDPA, 2023)

We are committed to honoring data subject rights regardless of your geographic location. To exercise any of these rights, please contact us at yravinderkumar33@gmail.com. We will respond to verified requests within the timeframes required by applicable law (generally thirty days, with extensions where permitted).

9. Children’s Privacy

ElderMate is designed for adult guardians and their elderly loved ones. We do not knowingly collect data from children under 16.

The Service is designed for use by adult guardians (aged 18 or older) to schedule wellness calls to elderly loved ones. We do not knowingly collect or solicit personal information from children under the age of sixteen (16).

If we become aware that we have collected personal information from a child under 16, we will take prompt steps to delete that information. If you believe that a child under 16 has provided personal information to us through the Service, please contact us immediately at yravinderkumar33@gmail.com so that we can take appropriate action.

10. Changes to This Policy

We will notify you of material changes via in-app notification or email before they take effect.

We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors.

For material changes that significantly affect how we collect, use, or share your personal information, we will provide notice through one or more of the following methods: (i) an in-app notification, (ii) an email to the address associated with your account, or (iii) a prominent notice on our website. Such notice will be provided at least thirty (30) days before the changes take effect.

For non-material changes (such as clarifications, formatting, or minor wording updates), we will update the “Effective Date” at the top of this Privacy Policy. We encourage you to review this Privacy Policy periodically to stay informed about how we protect your data.

Your continued use of the Service after the effective date of any updated Privacy Policy constitutes your acceptance of the updated terms. If you do not agree with the changes, you should discontinue use of the Service and request account deletion.

11. Contact Us

For any privacy questions, data requests, or concerns, contact us at yravinderkumar33@gmail.com.

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:

ElderMate Email: yravinderkumar33@gmail.com

For data subject access requests, deletion requests, or other rights-related inquiries, please include sufficient information to verify your identity and specify the rights you wish to exercise. We will acknowledge your request within five (5) business days and provide a substantive response within the timeframe required by applicable law.

If you are located in the European Economic Area or the United Kingdom and believe that our processing of your personal data infringes applicable data protection law, you have the right to lodge a complaint with your local supervisory authority.

If you are located in India and wish to raise a grievance, you may contact our designated grievance officer at the email address above. We will acknowledge your grievance and resolve it in accordance with applicable law.


Your privacy matters to us.