Legal
Privacy Policy
Last updated: April 26, 2026
1. Overview
Advocate (“we,” “us,” or “our”) is a caregiver health-tracking application. We take the privacy of health-related information seriously. This Privacy Policy explains what data we collect, how we use it, and your rights regarding that data.
By using Advocate, you agree to the collection and use of information as described in this policy.
2. Information We Collect
Account information: When you register, we collect your name, email address, and hashed password.
Health and care data: Data you voluntarily enter about a patient, including:
- Daily symptoms, mood scores, and episode descriptions
- Medication names, dosages, and adherence logs
- Sleep, hydration, activity, and lifestyle entries
- Vital signs and custom health metrics
- Notes and free-text observations
Usage data: We may collect standard server logs including IP addresses, browser type, and page interactions to diagnose technical issues and improve the Service.
3. How We Use Your Information
We use the information you provide to:
- Deliver core app features (daily logging, history, summaries)
- Generate AI-assisted health summaries from your logged data
- Send account-related emails (password resets, notifications you opt into)
- Diagnose technical problems and improve service reliability
We do not sell your personal or health data to third parties. We do not use your health data for advertising.
4. AI Processing
Advocate uses the Anthropic Claude API to generate health summaries from the data you log. When you request a summary, relevant entries are transmitted to Anthropic’s API for processing. Anthropic’s data handling is governed by their Privacy Policy.
AI-generated summaries are stored on our servers and associated with your account. They are not used to train AI models.
5. Data Storage and Security
Your data is stored on servers hosted by Railway (infrastructure provider). We use:
- HTTPS encryption for all data in transit
- Hashed passwords using bcrypt (plain-text passwords are never stored)
- JWT-based authentication with short-lived access tokens
No security system is perfect. We recommend using a strong, unique password and not sharing your account credentials.
6. Third-Party Services
Advocate integrates with the following third-party services:
- Anthropic Claude API for AI summary generation
- Resend for transactional email (password resets)
- Railway for backend infrastructure and PostgreSQL database hosting
- Vercel for frontend hosting
Each provider has their own privacy policies. We share only the minimum data necessary to provide the feature in question.
7. Health Data and HIPAA
Advocate may process information that qualifies as Protected Health Information (PHI) under HIPAA. Advocate is not a HIPAA-covered entity and is designed for personal caregiver use, not for regulated clinical or enterprise healthcare settings.
If you are a healthcare organization subject to HIPAA requirements, you should evaluate whether Advocate is appropriate for your use case before storing regulated PHI.
8. Data Retention
We retain your data for as long as your account is active. If you delete your account, we will remove your personal data and health logs within 30 days, except where we are required by law to retain certain records.
9. Your Rights
You have the right to:
- Access the personal data we hold about you
- Correct inaccurate data in your account settings
- Delete your account and associated data by contacting us
- Export your data (contact us to request a copy)
To exercise any of these rights, email support@advocatetrack.com.
10. Children's Privacy
Advocate is not intended for users under the age of 18. We do not knowingly collect personal information from children under 18. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.
11. Changes to This Policy
We may update this Privacy Policy as the Service evolves. We will notify you of material changes by posting a notice in the app or by email. The “Last updated” date at the top of this page reflects the most recent revision.
12. Contact
Questions, concerns, or data requests? Contact us at support@advocatetrack.com.