Privacy Policy

CareLedger · Last updated August 10, 2026

How CareLedger stores your journal

CareLedger keeps the parenting entries you create—such as dates, categories, original notes, and drafts you choose to save—in the app's local SwiftData store on your device. The app does not require an account to create or view these local records.

Optional AI Rewrite

AI Rewrite starts only when you choose it for an event. For that request, the app sends the event note, selected date, category, a rotating pseudonymous installation identifier, and a request identifier to the CareLedger product API over HTTPS. The service uses those approved fields to return a neutral drafting suggestion for your review.

Attachments, payment information, access tokens, and unrelated local journal entries are not part of an AI Rewrite request. You can skip the request, cancel it while it is in progress, save the original note, or edit any draft before saving it.

Service processing and retention

The product API uses configured service-side provider credentials and validates both incoming requests and outgoing structured drafts. Operational records are limited to redacted request metadata, such as a product request ID, status, model configuration, latency, token usage, and retry count. The service does not retain event-note text or provider completion text in operational logs. Rate-limit counters use the rotating pseudonymous identifier and expire automatically.

To protect AI Rewrite from unauthorized automated use, CareLedger uses Apple App Attest. The service temporarily stores a single-use challenge for up to five minutes and stores the related App Attest public key, rotating pseudonymous installation identifier, and assertion counter for up to 90 days. It does not store App Attest proof objects.

Subscriptions

CareLedger Pro subscriptions are processed by Apple through StoreKit. CareLedger receives entitlement information needed to unlock Pro features. Payment-card information is handled by Apple and is not available to the app.

Your controls

You can delete local journal entries from the app. Deleting the app can remove locally stored records from the device. For a question about AI processing or a request concerning product-service data, contact the support address below and include the product request ID if the app provided one.

Policy updates

If CareLedger changes the categories of data it sends or stores, the app and this policy will be updated before that change takes effect.