Data & security

How your data is held.

This page describes how My Care Hub protects the information in your profile — and where the honest limits are.

Last updated 15 July 2026

Encrypted in transit and at rest

Data moving between your device and our servers is encrypted with TLS. Data stored on our servers is encrypted at rest.

Access is limited and logged

Only staff who need access to run the service have it, under access controls, and administrative access is logged.

Share links are unguessable

Share links and QR codes use long random identifiers. They can't be discovered by guessing.

Sharing is scoped

A share carries only the fields you selected. Fields you didn't select are never sent to the person opening it.

You can revoke

Stop a share and the link stops working. Regenerate your QR code and the old one is dead.

Deletion means deletion

Delete your account and we remove your data within 30 days, apart from anything we're legally required to keep.

The honest limits

A share link is like a printed copy: anyone holding it can read the fields you selected until you revoke it. Give it to people you mean to give it to.

Once a provider has read your profile, they may record what's relevant in their own system. That copy is governed by their policies, not ours.

No system is perfectly secure. If a breach affects your data, we will tell you and the relevant regulator, as required by law.

Who processes data for us

Amazon Web Services hosts our infrastructure and database. Sentry handles error monitoring. Postmark delivers transactional email. When the AI assistant launches, its provider and data-handling terms will be listed here before the feature goes live.

Reporting a vulnerability

If you've found a security issue, email us. Tell us what you found and how to reproduce it. We won't pursue legal action against good-faith research that respects people's privacy and doesn't degrade the service.

info@mycarehubapp.com