Access control
In My Care is invite-only. Every care circle is separate, and access is granted by invitation or by an approved request. What a member can see and do is determined by their role in that circle.
Access rules are enforced in the database itself, not only in the interface, so a member cannot reach another circle's records by changing what the app displays.
Sign-in
Sign-in is handled by the platform's managed authentication service. Passwords are never stored by the application. Google sign-in is available as an alternative.
Files and identity documents
Photographs, scans, voice notes and identity documents are stored in private storage that is not publicly reachable. Files are opened through short-lived links that are checked against the requester's role each time they are generated. There are no public thumbnails and no raw storage paths in the interface.
Audit history
Changes to care records are recorded in an audit history that ordinary members cannot alter or delete. Moderation actions are recorded in the same way.
Analytics and tracking
There are no advertising trackers or marketing pixels. Health content, message content, observation text, document numbers and file names are never sent to analytics.
What we do not claim
No system is completely secure. We do not claim certification, regulatory compliance, or that screenshots or device-level copying can be prevented. Members are responsible for keeping their own devices and passwords secure.
Reporting a security issue
If you believe you have found a vulnerability, or that an account has been accessed without permission, contact us using the address in the Privacy Policy. Please do not test against other people's care circles or access data that is not yours.
Signed-in members can also report unauthorised access from Settings, which links the report to the affected care circle.