Privacy
Last updated August 20, 2026
Families trust KoraCommand with some of the most sensitive information they have — a parent's medications, appointments, and bills. This page is written to be read, not to protect us. If anything here is unclear, ask us before you upload a thing.
The short version
- We store the care information you and your circle put into KoraCommand, so we can show it back to your family.
- Only people your circle's Owner has invited can see your circle. We do not sell or rent your data, ever, and we do not run advertising.
- Documents you upload are read by AI providers we use as subprocessors, so their content can become plan items. That is the one place your information leaves our systems.
- You can export your circle's data or delete it, and deletion means deletion.
- Care plans are health-related information and we treat them that way. KoraCommand is still not a healthcare provider and not a HIPAA covered entity — it coordinates; it never advises.
What we collect
Account information. Your name, email address, and a password that we store only as a salted scrypt hash — we never see or store the password itself.
Care information you enter. Everything you or your circle add: the person being cared for, medications, appointments, bills, tasks, notes, contacts, and activity history.
Documents you upload. Medication lists, discharge papers, insurance statements, bills, and photos, along with what our AI stack extracted from them.
Patient-portal connections, if you choose to connect one. You can link a patient portal such as MyChart instead of uploading paperwork. You sign in on the portal's own page and pick what to share — medications, upcoming appointments, conditions and allergies, care team. We receive a read-only access token for exactly those sections and store it encrypted (AES-256-GCM) on our servers; it is never sent to the browser, to an AI provider, or to our backup provider. We never see your portal password, and we never write anything to your chart. Everything the portal returns becomes a suggestion card that a family member approves or sets aside — nothing lands on the plan by itself. You can disconnect in the app at any time, which deletes the token; the portal also lists KoraCommand under its linked apps, where you can revoke access on that side.
Circle and invite information. Members, their roles, invitations sent, and who accepted, declined, or was removed.
Waitlist email addresses, if you give us one before you have an account.
Basic operational logs our servers create — request times and error records — used to keep the service running and secure.
We do not use third-party analytics, advertising trackers, or session recording.
Who can see your circle
Access is controlled by four roles, and there is exactly one Owner per circle. Collaborators can edit the plan; Contributors can add notes, tasks, and documents and can suggest changes to medications, appointments, and bills; Viewers can only read. Nobody outside your circle can see it.
Our team does not read your care data as a matter of course. We access it only when you ask us to for support, or when we are legally required to. If we ever need to look at something to fix a problem you have reported, we will do the minimum required to solve it.
AI processing — read this one
When you upload a document or use the assistant, the relevant content is sent to one AI provider, who processes it on our behalf: Anthropic. That is the entire list. This is how a photo of a pill bottle becomes a medication in your plan. No other model provider can receive your family's content — the list is enforced in our code, not just in this policy, and if Anthropic is unavailable the app falls back to on-server extraction rather than reaching for a different vendor.
Kora, the care navigator on our public website, is a separate assistant that answers general caregiving, paperwork and product questions for visitors. It explains; it never diagnoses or advises on medication. It runs on an open-weight model hosted by Groq. It has no access to any care plan, account or document, and it never receives your family's content — what you type into it is a public-website conversation, so do not paste a relative's records there.
We send the minimum needed for the task. We do not use your family's data to train our own models, and we choose providers on the basis that they do not train on data submitted through their business APIs. Provider terms are outside our control and can change; we will update this page and tell existing families if the list or the terms change materially.
If you would rather your documents were never sent to an AI provider, use quick-scan mode, which extracts what it can locally and never leaves our servers. Data pulled from a connected patient portal is already structured, so it is never sent to an AI provider for extraction at all; the assistant sees the plan itself, the suggestion cards waiting for review, and the portal record's one-line summary — the same things a family member sees on screen.
Where your data lives
Your circle is stored on servers we operate. We keep an encrypted backup copy with our hosting and database providers so a hardware failure never costs a family their plan. Data is protected in transit with HTTPS. Sessions are signed tokens tied to your account, and they end when you sign out.
Our current infrastructure providers are our hosting platform and Supabase (backup storage). If we add a payment processor for subscriptions, it will receive your billing details directly and we will never store your card number.
How long we keep things
We keep your circle's information for as long as the circle exists. When the Owner closes a circle, its care data is deleted from our systems, and backups age out within 30 days. Closing your account deletes your account record; if you are the Owner of a circle, you will be asked to transfer ownership or close the circle first, so that your family is never locked out of a plan they depend on.
Waitlist emails are deleted on request, and in any case once early access is over.
Your choices
- See it. Everything we hold about your circle is visible in the app.
- Export it. Ask and we will send you your circle's data in a machine-readable file.
- Correct it. Edit anything in the plan directly, or ask us.
- Delete it. The Owner opens Care circle → "Close this circle" and the circle's care data is deleted; or email [email protected] and we will do it for you.
- Leave. Any member can leave a circle at any time; Owners transfer ownership first.
Depending on where you live — for example California, or the EU and UK — you may have additional rights to access, portability, correction, deletion, and to object to certain processing. We apply these rights to everyone rather than sorting families by geography. We will not discriminate against you for exercising them.
Children
KoraCommand is built for adults coordinating care and is not directed to children under 13. We do not knowingly collect information from children. A care plan may of course contain information about a family member of any age, entered by an adult member of the circle.
Security, honestly
We hash passwords with scrypt, sign sessions, rate-limit sign-in attempts, scope every action to your role on the server rather than trusting the browser, and serve the app under a strict content security policy. No system is perfectly secure. If we ever discover a breach affecting your information, we will tell affected families promptly and plainly, with what happened and what to do.
Changes and contact
If we change this policy in a way that matters, we will say so in the product rather than quietly editing this page.
Questions, requests, or concerns: [email protected]. We answer privacy requests within 30 days.
This policy describes real product behavior and is written in plain language on purpose. It has not yet been reviewed by counsel; a lawyer should review it before KoraCommand accepts paying customers.