CareTime EVV — Privacy Policy

Effective date: 2026-05-22. Version 1.0. Last revised 2026-07-27 — wording only; no change to what the app does with your data.

This is the privacy policy in effect for CareTime EVV, written in plain language rather than legal boilerplate: it describes what the app actually does with data, in the terms a caregiver would use. The statements below are accurate to the shipping version, 1.0.


Who this app is for

CareTime EVV is built for paid family caregivers working under Medicaid Self-Directed Support waivers (IHSS, CDPAP, Money Follows the Person, Section 1915(c), state-direct programs). It is not certified for use by HIPAA Covered Entities — that is, home-care agencies, healthcare providers, health plans, or healthcare clearinghouses. If you are employed by such an entity, ask your compliance officer before installing.

The app is engineered with HIPAA Security Rule technical safeguards in mind (encryption at rest, access control with PBKDF2 + Keychain, tamper-evident audit chain, no third-party data egress) but you, the operator, are responsible for the Administrative and Physical safeguards: passcode-locking the phone, not photographing or forwarding generated PDFs, and disposing of data on the phone (Settings → Erase all local data) before the device changes hands.


Summary in one sentence

CareTime EVV stores everything you enter on your phone, and uploads nothing — not to us, not to your billing provider, not to any third party — unless you explicitly tap Generate & Share on a PDF.


What we collect

Nothing leaves your device. CareTime has no backend, no analytics, no crash reporters, and no third-party SDKs. The app developer (SpaceTrucker2196) has no servers, no database of users, and no way to see what's in your CareTime install.

The data CareTime captures and stores locally on your iPhone:

All of the above is stored inside the app's sandbox on this device.

What we don't collect

When data leaves the device

The only paths data takes off your device are user-initiated:

  1. PDF Share. When you tap Generate & Share on a timesheet, EVV report, or plan-adherence report, iOS's standard share sheet decides where the PDF goes. CareTime doesn't pick a destination — you do. The PDF contains the data you'd expect (recipient name, care segments, times, signatures, etc.).
  2. iPhone iCloud Backup. If you have Settings → [your name] → iCloud → iCloud Backup enabled, your iPhone backs up the entire app sandbox to your private iCloud as part of the system backup. This is encrypted end-to-end if you have Advanced Data Protection on, and encrypted in transit + at rest in all configurations. It is the operating system doing this, not CareTime — CareTime itself never uploads anything to iCloud. The benefit: if you lose or replace your phone, your CareTime data restores with the rest of your apps.

Children

CareTime is not directed at children under 13. The expected user is an adult caregiver. The app does not request a date of birth or any information sufficient to identify a person as a child.

Health information

CareTime stores notes about care provided to your recipient(s). In the United States, this information may be considered Protected Health Information (PHI) under HIPAA, depending on your role and your billing provider's status as a covered entity. CareTime is designed to minimise the risk of inadvertent PHI exposure by:

We do not sign Business Associate Agreements; CareTime is sold as a personal-use caregiving tool to caregivers, not to billing providers or covered entities. If you are subject to HIPAA obligations through your employer / billing provider, consult your compliance officer before using CareTime for record-keeping.

Cookies, beacons, web tracking

The CareTime iOS app does not embed a web view that loads remote content. The only web request it can make is to open a support contact link in your default browser when you tap Settings → Help → Support / report a bug — that flow opens your browser, not an in-app webview, and CareTime sends no data with the URL.

Changes to this policy

If we change what CareTime does with data, we'll update this page and bump the version number above. App Store will require us to re-confirm the App Privacy disclosures for the next release.

Contact

This policy is hosted at spacetrucker2196.github.io/TimeForCare/privacy and mirrored at www.river.io/caretime/privacy.html.

To ask a question about this policy or about how CareTime EVV handles data, email support@river.io. We respond within a few business days.


← back to CareTime EVV