Privacy Policy
Last updated: July 22, 2026
CKAutoFlow ("CKAutoFlow", "we", "us", or "our") provides an AI-assisted care documentation and workflow platform for aged care facilities (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices available to you.
The Service is provided to aged care facilities and other care organizations ("Facilities") as our customers. Facility staff ("Caregivers"), administrators ("Administrators"), and the family members of residents in their care ("Family Contacts") may all interact with the Service depending on their role.
1. Information We Collect
1.1 Account and staff information
When a Facility onboards, its Administrators create accounts for Caregivers. We collect: name, phone number, and either a WeChat identifier (for the mobile app) or an email address and password (for the web console).
1.2 Resident and care information
To provide care documentation, Facilities and their Caregivers may enter or generate the following about residents in their care:
- Basic identifying information: name, date of birth, room number, gender, care level, admission date
- Contact details for the resident's family or emergency contacts
- Voice recordings made by Caregivers while documenting care visits, and the transcripts and structured care notes (meals, mood, vital signs such as temperature/blood pressure/pulse, activities, medication, and general notes) that our AI generates from those recordings
- Medical notes entered by Facility staff, where the Facility chooses to record them
This information can include health-related information about residents. The Service is a documentation and workflow tool — it is not a medical device, does not provide medical advice, and does not replace clinical judgment or a Facility's own emergency procedures.
1.3 Family communications
Where a Facility enables it, we send family members daily summaries of a resident's care by email or WeChat, using an email address or WeChat identifier that the family member has provided.
1.4 Email monitoring (optional, Facility-controlled)
Facilities may optionally connect an email inbox (via IMAP credentials or Google/Gmail OAuth) so the Service can automatically detect receipts and invoices sent to that inbox and extract fields such as institution name, amount, and date using AI image recognition. When a Facility connects a Gmail account:
- We only access the messages and attachments needed to detect and process receipt/invoice content, as configured by the Facility's Administrator
- We do not use Gmail data for advertising, and we do not sell Gmail data
- Access is limited to the automated processing described above; Gmail data is not read by humans except as necessary for security, legal compliance, or with the Facility's consent
- Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements
- A Facility Administrator can disconnect this feature at any time from the admin console, or revoke access directly from their Google Account security settings; doing so stops all further access
1.5 Information from visitors and prospective customers
If you submit our contact/demo request form, we collect the information you provide (organization name, contact details, and message) to respond to your inquiry.
1.6 Technical information
We use a session cookie/token to keep you signed in and a small cookie to remember your language preference. We do not use advertising or cross-site tracking cookies.
2. How We Use Information
We use the information described above to:
- Provide, operate, and maintain the Service, including generating care documentation from voice recordings
- Detect care-related alerts (e.g., abnormal vital signs or concerning keywords) so Facility staff can follow up
- Send family communications that a Facility has enabled
- Process receipts/invoices that a Facility has configured us to monitor
- Respond to inquiries and provide customer support
- Maintain the security and integrity of the Service
We do not sell personal information, and we do not use resident or family data to train general-purpose AI models.
3. How We Share Information
We share information with the following categories of service providers ("subprocessors") strictly to operate the Service on our behalf, under contractual confidentiality obligations:
- Supabase — database and file storage
- Groq — speech-to-text transcription and AI text processing
- OpenAI — AI image recognition (for receipts) and AI text processing
- Resend — transactional email delivery
- WeChat (Tencent) — login and push notifications, for Facilities and users in mainland China
- Google — sign-in and, where a Facility opts in, Gmail-based receipt monitoring
- Vercel — application hosting
We may also disclose information where required by law, to protect the rights and safety of our users, or in connection with a merger, acquisition, or sale of assets (with notice to affected Facilities where practicable).
4. Data Retention
We retain information for as long as a Facility's account is active, or as needed to provide the Service. A Facility Administrator can request deletion of a resident's or staff member's data by contacting us; we will act on such requests except where we are required to retain information for legal or legitimate business reasons.
5. International Data Transfers
Because our subprocessors operate infrastructure in multiple countries/regions, information may be processed on servers located outside the country where you or a resident are located. We take reasonable steps to ensure information continues to be protected wherever it is processed.
6. Security
We use industry-standard safeguards, including encrypted network transport, hashed passwords, and encryption of stored credentials (such as email account passwords and OAuth tokens) used to configure the Service. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. Your Choices and Rights
Depending on your role and location, you may have the right to access, correct, or request deletion of information about you. Because resident and staff data is entered and controlled by the Facility, requests relating to that data should generally be directed to the Facility first; we will assist Facilities in responding to such requests. You may also contact us directly using the details below.
8. Children's Privacy
The Service is a business tool provided to care facilities and is not directed at children. We do not knowingly collect personal information directly from children.
9. Changes to This Policy
We may update this Privacy Policy from time to time. We will update the "Last updated" date above, and where changes are material, we will provide additional notice to Facility Administrators.
10. Contact Us
If you have questions about this Privacy Policy or how your information is handled, contact us at privacy@ckautoflow.com.