Skip to content
How it works Family Features Sick days Privacy
Get the app
Menu
How it works Family Features Sick days Privacy

Privacy Policy

Last updated: September 4, 2026

Holakare is a family medication and care tracker. One household shares its patients, treatments, medicines, doctor visits, and medicine cabinet in a single private place. This policy explains what we collect, how we use it, and the choices you have.

1. Information we collect

We collect the information you provide directly to us. When you create an account, that includes your name and email address. As you use the app, it includes the household health information you enter — the people in your household and their treatments, medicines, doses, doctor visits, and medicine-cabinet items. It also includes anything you record about a health episode, such as temperatures, symptoms, medicines given, food and fluids, notes, follow-ups, and any photos you choose to add. Photos are optimized on your device and stripped of location and camera metadata before they are stored.

Separately, and only if you ask for it, we collect the email address you give to join the waitlist. The button on our home page opens a sign-up page hosted by Mailchimp, who run our mailing list — you type the address there, not on our site. That page also offers an optional first and last name and an optional beta box; whatever of those you fill in reaches us too. That is not an account, and it is kept apart from any account you may later create. No health information is ever attached to a waitlist address.

2. How we use your information

We use the information we collect to provide, maintain, and improve the app, to keep your household's data in sync across your devices, to process subscriptions, and to send you technical notices and support messages such as email-verification, sign-in, and password-reset links. Any summaries, trends, or insights the app shows for a care episode are generated on your device from the information you entered; we do not send your household's health information to any third-party or AI service to produce them.

What you give us for the waitlist is used only to tell you when Holakare is available — a launch note, and a TestFlight beta invitation if you asked for one. It is not a newsletter, we do not use it for advertising, and we do not sell or share it for anyone else’s marketing. Every message carries an unsubscribe link. Unsubscribing stops the messages: Mailchimp keeps the address on a suppression list so that it is not mailed again, which is not the same as erasing it. If you want it deleted outright, write to [email protected] and we will remove it.

3. How your information is shared

We do not sell your personal information. Your household's data is scoped to your family — it is never shown to another household. We share information only with the service providers that help us operate the app on our behalf (for example, our hosting and email providers, and Apple for subscription processing), and only as needed to provide the service.

Waitlist addresses are held by Mailchimp (Intuit Inc.), which sends the launch and beta notes on our behalf from its us2 region. You sign up on Mailchimp’s own page, so alongside what you enter there Mailchimp also receives the technical request data any web request carries — your IP address and browser user-agent. It receives no household data and no health information of any kind.

4. Data security

We implement appropriate technical and organizational measures to protect your personal information against unauthorized access, alteration, disclosure, or destruction.

5. Children's privacy

Holakare is intended for adults managing their family's care. An adult account holder enters and controls all information, including any details about children in their household. The app is not directed to children, and children do not create their own accounts.

6. Your rights and deleting your data

You can access and update your information in the app at any time. You can permanently delete your account and its data from within the app, under Settings → Delete Account. Your sign-in is removed immediately. When the last member of a household deletes their account, the shared household data is scheduled for permanent deletion and is purged after a short recovery window (currently 30 days). During that window the data is inaccessible but can be restored — contact [email protected] if a deletion was an accident. After the window it is permanently deleted from the systems that serve the app. That deletion does not reach into our backups, and we would rather say so than imply otherwise: backups exist so a failure or an attack cannot destroy a household's medical history, and to do that job they are deliberately immutable — nobody can edit or selectively remove anything from them, including us. They age out instead, on a fixed schedule: the daily database backups within seven days. We are not publishing a specific timetable for any other backup layer until it has been proven in a live restore drill.

When the last member of a household deletes their account, we keep that person's email address for that same recovery window, for one reason: so we can confirm in writing once the deletion has actually completed. The confirmation is sent after the household record has been permanently deleted, not when the request is made, which is why the address has to outlast the sign-in. It is destroyed the moment the deletion completes, before the confirmation is even sent — so if that message fails to reach you, your address is still gone. It is used for nothing else, and if the deletion is canceled or does not go ahead it is destroyed then instead.

Two details about that deletion we would rather state than gloss. First, most of what goes — patient profile photos included — is held inside the household record itself and is removed in the same operation, checked before the deletion is recorded as complete. Where photos are instead kept as separate files, those files are removed immediately afterwards; if that removal fails they are already unreachable — nothing in the app can find or serve a photo once its record is gone — but the underlying bytes can remain in our private storage until a later clean-up removes them. Second, we keep one thing permanently: a record that the deletion happened, which includes a one-way fingerprint of the email address that asked for it. It cannot be turned back into your address, it is never used to contact you or to recognize you if you sign up again, and it exists so that if you ever ask us to confirm the deletion we can show it took place.

We keep your information only as long as you use Holakare. Households with no active subscription whose members have all been inactive for an extended period (at least 12 months, plus a grace period) may also be permanently deleted.

7. Analytics and crash reporting

This website uses goodday, our own self-hosted, cookieless analytics. Because we run it ourselves, the statistics it gathers stay with us and are not shared with an outside analytics company. goodday itself sets no cookies, collects no personal information, and does not track individuals across sites or devices. (That describes our analytics, not the whole site: joining the waitlist sends you to Mailchimp’s sign-up page, where you type an email address.) The aggregate statistics it collects — page views, referring site, country, and device type — help us understand how visitors find and use the site. We also count two anonymous interactions on this site: that a "get the app" or "see how it works" button was pressed, and which of the three example screenshots was chosen. Each records only which button or screenshot, and nothing about you — we count them because neither one moves you to a new page, so they are otherwise invisible to us. Analytics are switched off entirely on pages reached through a one-time link (such as a sign-in link, password reset, or household invitation), so the single-use code in those web addresses is never sent anywhere.

Signed-in pages that run in a browser use goodday on the same terms. On those pages we also record a generic "item created" event carrying only the kind of item added (for example "medicine" or "visit"), so we can see which areas are used. It never includes names, notes, photos, identifiers, or any other health or personal detail.

The iPhone app records anonymous usage — which screens you open and a small number of coarse actions, such as that a dose was marked taken or skipped. It never records what you entered, and it carries no advertising. These reports go to goodday, the same self-hosted analytics described above, and they contain no account, household, patient, or device identifier of any kind, so they cannot be linked to you or to each other. Screen names are fixed labels such as "Today" or "PatientDetail" — never a specific patient, medicine, doctor, appointment, or anything you typed. The action reports record only that something happened, not what it involved: "a dose was taken" is recorded, while which medicine, for whom, and any injection site are not. You can switch this off in Settings. The Apple Watch app carries no usage analytics at all.

The iPhone app can also send GoodDay Diagnostics — coded reports of non-fatal app failures, such as that a sync or a save did not complete. Those reports carry only fixed labels (an error type, an operation name, and recent screen names as breadcrumbs). They never include stack traces, names, notes, doses, identifiers, or the text of an error. You can switch this off in Settings, separately from anonymous usage. The Apple Watch app does not send diagnostics. Fatal crashes are still covered by Apple's own crash reports.

Beta (test) builds of the apps send crash reports — and a small sample of performance measurements — to Sentry, an error-monitoring service, so we can find and fix what breaks before a release; the App Store version does not include this crash reporting. These reports are deliberately configured to leave your health information out. They carry the technical detail of the failure: the kind of error, where in our code it happened, the app version, and the device model and operating system. We have turned off the options that would otherwise attach your account identity, your IP address, a picture of the screen you were on, or the addresses of the records being loaded. Crash reports are not used to profile you or to advertise.

8. Security and abuse prevention

To protect the sign-in, sign-up, and password-reset pages from automated abuse — bots, credential-stuffing, and spam — we use Cloudflare Turnstile, a privacy-preserving alternative to traditional CAPTCHAs. When you use one of those forms, your browser loads a small challenge from Cloudflare that checks you are a real person. Turnstile does not use tracking cookies, does not profile you, and is not used for advertising or to track you across sites. Cloudflare also serves as the network provider in front of the website and app, so it already processes the technical request data (such as your IP address) needed to route and protect that traffic.

9. Contact us

Holakare is operated by Metric Ton LLC. If you have any questions about this Privacy Policy, contact us at [email protected]. The terms that govern your use of Holakare are in the Terms of Service.

The family medication and care tracker.

Product

  • Shared tracking
  • Sick days
  • Devices
  • Updates

Company

  • Brand
  • Contact
  • Status

Legal

  • Privacy
  • Consumer Health Data
  • Terms
  • DMCA
  • Accessibility
Get the app

Holakare is a tool to help you organize care. It is not a medical device and does not provide medical advice. Always rely on a qualified healthcare professional; in an emergency, call your local emergency number.

© 2026 Holakare. All rights reserved. Made by Metric Ton.

No cookies. Nothing to accept.

Nothing to consent to here: no cookies, nothing about you sold. We do count page views — anonymously, on our own server, never following you across other sites. Joining the waitlist takes you to Mailchimp’s sign-up page, and the address goes to them so we can tell you when Holakare is out. How that works.