CareTime EVV — Privacy Policy
Effective date: 2026-05-22. Version 1.0. Last revised 2026-07-27 — wording only; no change to what the app does with your data.
This is the privacy policy in effect for CareTime EVV, written in plain language rather than legal boilerplate: it describes what the app actually does with data, in the terms a caregiver would use. The statements below are accurate to the shipping version, 1.0.
Who this app is for
CareTime EVV is built for paid family caregivers working under Medicaid Self-Directed Support waivers (IHSS, CDPAP, Money Follows the Person, Section 1915(c), state-direct programs). It is not certified for use by HIPAA Covered Entities — that is, home-care agencies, healthcare providers, health plans, or healthcare clearinghouses. If you are employed by such an entity, ask your compliance officer before installing.
The app is engineered with HIPAA Security Rule technical safeguards in mind (encryption at rest, access control with PBKDF2 + Keychain, tamper-evident audit chain, no third-party data egress) but you, the operator, are responsible for the Administrative and Physical safeguards: passcode-locking the phone, not photographing or forwarding generated PDFs, and disposing of data on the phone (Settings → Erase all local data) before the device changes hands.
Summary in one sentence
CareTime EVV stores everything you enter on your phone, and uploads nothing — not to us, not to your billing provider, not to any third party — unless you explicitly tap Generate & Share on a PDF.
What we collect
Nothing leaves your device. CareTime has no backend, no analytics, no crash reporters, and no third-party SDKs. The app developer (SpaceTrucker2196) has no servers, no database of users, and no way to see what's in your CareTime install.
The data CareTime captures and stores locally on your iPhone:
- Care recipient information you type in (name, role label, per-recipient timesheet code).
- Care activities you log: start time, end time, optional notes, the activity tapped, and which recipient the time is attributed to.
- Location at clock-in and clock-out, only if you grant Location permission. One fix per tap; no background tracking. Used for EVV (electronic visit verification) so visits can be verified later. If you don't grant Location, CareTime still works — the segments just don't get location data.
- Participant signatures you collect through the app, stored as an image alongside the segment.
- Optional PINs (4-digit participant PIN, 4–6-digit app-lock PIN). Both are hashed with PBKDF2-HMAC-SHA256 (210,000 iterations) before storage. The original numbers cannot be recovered.
- A SHA-256 audit log of every segment lifecycle event (start, stop, edit, etc.) so the record is tamper-evident.
- Settings you configure: employee + supervisor name and phone for the PDF header, pay period anchor, shift-block gap, billing provider name and submission contact line, default service code.
All of the above is stored inside the app's sandbox on this device.
What we don't collect
- No account. You don't sign up. There's no "sign in" button.
- No analytics. We don't know how often you open the app, what buttons you tap, or whether you finished onboarding.
- No crash reports. The app does not phone home when something goes wrong.
- No advertising identifiers. Apple's IDFA is never requested.
- No tracking across other apps or websites.
- No HealthKit, Motion, or photo-library access.
- No background location. Permission is "When-In-Use" only.
- No microphone access. (Dictation in notes happens via the iOS keyboard, which Apple handles on-device — CareTime never sees the raw audio.)
- No automatic uploads to any billing provider, Sandata, HHAeXchange, CareBridge, AuthentiCare, or any state EVV system. Submissions to those systems happen out-of-app via your existing flow with your billing provider.
When data leaves the device
The only paths data takes off your device are user-initiated:
- PDF Share. When you tap Generate & Share on a timesheet, EVV report, or plan-adherence report, iOS's standard share sheet decides where the PDF goes. CareTime doesn't pick a destination — you do. The PDF contains the data you'd expect (recipient name, care segments, times, signatures, etc.).
- iPhone iCloud Backup. If you have Settings → [your name] → iCloud → iCloud Backup enabled, your iPhone backs up the entire app sandbox to your private iCloud as part of the system backup. This is encrypted end-to-end if you have Advanced Data Protection on, and encrypted in transit + at rest in all configurations. It is the operating system doing this, not CareTime — CareTime itself never uploads anything to iCloud. The benefit: if you lose or replace your phone, your CareTime data restores with the rest of your apps.
Children
CareTime is not directed at children under 13. The expected user is an adult caregiver. The app does not request a date of birth or any information sufficient to identify a person as a child.
Health information
CareTime stores notes about care provided to your recipient(s). In the United States, this information may be considered Protected Health Information (PHI) under HIPAA, depending on your role and your billing provider's status as a covered entity. CareTime is designed to minimise the risk of inadvertent PHI exposure by:
- Storing all data locally on your device.
- Never transmitting any data to any third party.
- Hashing PINs before storage.
- Sandboxing the app per iOS standards.
- Optional app lock (PIN + biometrics + auto-lock).
We do not sign Business Associate Agreements; CareTime is sold as a personal-use caregiving tool to caregivers, not to billing providers or covered entities. If you are subject to HIPAA obligations through your employer / billing provider, consult your compliance officer before using CareTime for record-keeping.
Cookies, beacons, web tracking
The CareTime iOS app does not embed a web view that loads remote content. The only web request it can make is to open a support contact link in your default browser when you tap Settings → Help → Support / report a bug — that flow opens your browser, not an in-app webview, and CareTime sends no data with the URL.
Changes to this policy
If we change what CareTime does with data, we'll update this page and bump the version number above. App Store will require us to re-confirm the App Privacy disclosures for the next release.
Contact
This policy is hosted at spacetrucker2196.github.io/TimeForCare/privacy and mirrored at www.river.io/caretime/privacy.html.
To ask a question about this policy or about how CareTime EVV handles data, email support@river.io. We respond within a few business days.