Privacy notice.
Kithra · Chronix Health Group Ltd
Effective 21 September 2026 · Version 1.10 — the section about messages between a family and a carer now says that a block is recorded, not only a report. Blocking and reporting the person you are messaging went live on those conversations, so the notice names both. A block applies across the whole service and the person blocked is not told. Nothing else changes, and nothing is collected that this notice did not already describe — the care-circle section has named blocks since v1.8 and it is the same record. Supersedes v1.9 (we started keeping a record of what people search for again, deleted after 90 days), v1.8 (the notice gained a Care World section describing nine live marketplace purposes), v1.7 (Chronicus can read what you type, say or photograph for it), v1.6 (the product renamed from Care Vault to Kithra), v1.5 (the paragraph about counting page views removed), v1.4 (Railway added to the supplier table), v1.3 (the Cloudflare R2 backup’s location corrected to the European Union), v1.2 (support-access sentence corrected), v1.1 (child date of birth corrected; Speechmatics and Cloudflare R2 added) and v1.0.
In short
We are Chronix Health Group Ltd. We hold the care records you keep in Kithra and we are responsible for them.
Only the people you choose can see them. We do not sell information and we do not use care records for advertising. Care records are stored in the United Kingdom.
You can see it, correct it, take a copy, or have it deleted. Ask us and we answer within a month.
Who we are
Chronix Health Group Ltd — the controller for information held in Kithra.
Registered in England & Wales, company no. 16663224
11-13 Upper High Street, Epsom, Surrey, KT17 4QY
support@careworld.app
What we hold, and where it comes from
About you — you give us this. Your name, email address and password. Your plan and payments. A record of when you signed in.
About the person you care for — a family member gives us this, usually you. Their name and date of birth, conditions and allergies, medicines, appointments, visit notes, documents you upload, photographs, an NHS number if you add one, and who you have allowed to see each of those. If you ask Chronicus to fill the record in for you, what you type, say or photograph for it is held for thirty days while you check what it read.
About a child — deliberately less. Initials or a first name, their date of birth, and the first part of a postcode. We do not hold a child’s full name, photograph or address.
If you are the person a record is about, that information came from the family member who created it. You can ask us who they are.
Why we are allowed to hold it
| The situation | Lawful basis | Condition for health data |
|---|---|---|
| The person can decide and has agreed | Contract | Their explicit consent |
| Someone holds a health-and-welfare LPA or deputyship | Contract | Their explicit consent, given on the person’s behalf |
| A child under 13 | Contract | Explicit consent from someone with parental responsibility |
| Aged 13 or over | Contract | Their own explicit consent |
| The person cannot decide and nobody holds authority | Legitimate interests | Vital interests, with a recorded family best-interests declaration under section 4 of the Mental Capacity Act 2005 |
| The emergency card | Vital interests | Vital interests |
Where we rely on legitimate interests, ours is to let families coordinate care for someone who cannot arrange it themselves. We have weighed that against the person’s own interests and you can ask to see the assessment.
The emergency card rests on vital interests alone. It can be read without signing in because a paramedic cannot be asked for a password, and it carries only what a responder needs.
Telling someone a record exists
A person has the right to know we hold information about them.
Where they use Kithra, they see it. Where they do not, we ask the account holder to tell them and we record that they did. Where a person cannot be told — because they would not understand — we record that, and why.
A young person is told by us, directly. Three months before their sixteenth birthday we email them. On that birthday the record becomes theirs, and they choose what happens to it. If they do not answer, it is paused until they do.
Who else sees it
Only the people you choose. You set what each person in your circle can see and changes take effect immediately.
You may share a time-limited view of one person with another family’s circle. Both sides must agree and either can stop it.
We share with nobody else, unless the law requires it or a child is at risk.
Care World — finding and being found
Care World is the part of our service where families find carers and carers are found. This section says what we hold for it. Everything else in this notice — who we are, why we are allowed to hold information, the suppliers, security, your rights and the children section — applies here too.
A carer’s profile
If you offer care, you make a profile. It holds your headline, how you describe yourself, the area you cover, how far you will travel, the languages you speak, your rates, the kind of work you want, and the handle you choose. You decide whether to publish it. A published profile is meant to be read by families looking for care, including people who have no account with us. You can unpublish it at any time, and you can change any part of it.
Checking who a carer is, and whether they may work
Before we introduce a carer to a family, we check who they are and that they may work in the UK. We record which check was made, who made it, when, and the outcome. Those checks are carried out by Chronix Health Group Ltd. If we ever use an outside provider, we will name it in this notice before we start using it. We keep the record that a check was made even after an account closes.
We do not offer a criminal-record (DBS) check today. We may offer one in future. If we do, we will say so here first, and we would only hold that information under the extra conditions the law sets for records of criminal convictions and offences — Article 10 of the UK GDPR and Schedule 1 of the Data Protection Act 2018.
References — and what we hold about the person giving one
A carer can ask people who know their work to give a reference. To do that, the carer gives us that person’s name, email address, organisation, their relationship to the carer, and how they know them.
If you have been asked for a reference: we got your details from the carer, not from you. We use them to ask you for the reference, and for nothing else. We send the request by email, and up to three reminders over about ten days. When you reply, we keep your answer and the internet address (IP address) your reply came from, so we can show the reference was given once and by whom.
You can tell us to stop, or ask us to delete what we hold about you, at any time — email support@careworld.app. You do not have to give a reference, and you do not need an account to ask us.
Messages in a care circle
People in a care circle can message each other about the person they look after, and attach a file to a message. We hold those messages, and anything attached to them, so the circle can read them. We also hold what keeps it safe: who has blocked or muted whom, and anything reported to us.
Messages between a family and a carer
A family and a carer can message each other through Care World before anything is agreed. We hold those messages so both people can read them, and so we can act if one of them reports the other. If either of them blocks the other, we keep a record of that too — a block applies across the whole service, and the person blocked is not told.
Searching, and carers you save
When a family saves a carer, we keep that list so it is there next time. We keep a record of what people search for — the filters used, and who was signed in when the search was made — to show results and to make matching work better.
A search can include the kind of support being looked for, so a search may say something about the person who needs care. That is why we paused this until this notice described it, and why we delete a search after 90 days rather than keeping it.
We do not use it to decide anything about you, and we do not sell it or share it for advertising.
A check result from another Chronix Health Group product
Some checks are made in another of our products. When that happens, that product tells Care World three things: a scrambled (hashed) form of the email address, whether the check passed, and the date. Nothing else crosses. No document, no detail of the result, and nothing about anyone’s health.
Confirming a mobile number
If you give us a mobile number we send a six-digit code to it and check the code you type back. We do this to confirm the number reaches you, and for nothing else.
The carer-network waiting list
You can ask to hear when the carer network opens without making an account. We hold the email address and name you give us, and whether you are joining as a family or as a carer. We use it only to tell you when it opens. To come off the list, email support@careworld.app and we will delete what we hold.
The organisations that run Kithra for us
| Who | What they do | Where |
|---|---|---|
| Supabase | Database and file storage — where care records live | United Kingdom |
| Vercel | Runs the website and app | United Kingdom |
| Cloudflare | Protects against attack, serves images | Global, UK-first |
| Stripe | Takes card payments. We never see your card number | Ireland, United States |
| Resend | Sends our emails | United States |
| Twilio | Sends text messages and voice reminders | United States |
| Google Cloud | Calendar connection, where you turn it on | United Kingdom, United States |
| Anthropic | Provides the model behind Chronicus. It receives what you type, say or photograph for Chronicus, and nothing else. What you type, say or photograph for Chronicus is not used to train it | United States |
| Speechmatics | Turns speech into text when you dictate. Processed as you speak and not kept | European Union |
| Railway | Checks every file you upload for viruses, and strips hidden location data from photographs | European Union |
| Cloudflare R2 | A second, separate copy of your uploaded files, so a restore returns them | European Union |
Care records are stored in the United Kingdom. The one exception is the backup: the second copy of your uploaded files is held in the European Union, so that a fire or a fault in one place cannot take both copies with it. Where a service above sits elsewhere, it handles only what it needs — an email address to send an email, a payment to take a payment — under the UK’s approved transfer terms, the International Data Transfer Agreement or the UK Addendum.
If we change this list we will tell you before it takes effect.
Security
Encrypted with AES-256 in transit and at rest. Access is closed by default — nobody sees a care record unless you have chosen it.
Every access to a care record is logged, including by us. Our support staff can open a record when helping you with it.
How long we keep it
| Your account and its records | While the account is open |
| After you close it | Hidden at once, deleted after 60 days |
| Who opened a care record, and when | 7 years, including after deletion |
| Payments | 6 years, as tax law requires |
| Reports about a child’s safety | As long as the concern requires |
| Support messages and complaints | 6 months |
| Emails and texts we sent | 90 days |
| Sign-in records | 12 months |
| Your Care World profile, your messages, and the carers you saved | While the account is open |
| What people search for | 90 days |
| The record that we checked a carer, and the references given about them | Kept after the account closes, as the record that a check was made |
| The carer-network waiting list | Until the network opens and we have told you, or until you ask us to remove you |
| What you type, say or photograph for Chronicus, and the drafts it makes from it | 30 days from the last time you touched them |
Your rights
You can see what we hold, correct it, take a copy in a portable form, have it deleted, restrict how we use it, object to us using it, and withdraw consent where we relied on it.
Ask from your account, or email support@careworld.app. We answer within one month.
A young person’s right to deletion is stronger where the information was collected while they were a child — including anything a parent entered about them.
If you are unhappy, tell us. You can also complain to the Information Commissioner’s Office — ico.org.uk, 0303 123 1113, or Wycliffe House, Water Lane, Wilmslow, Cheshire, SK9 5AF.
Chronicus
Chronicus is an AI assistant inside Kithra. It reads what you give it: what you type, say, or photograph for it. It does not read your care records.
It can fill in a care record for you to check. Describe the person, or photograph a prescription or a letter, and Chronicus copies out what it can read as drafts. The prescription or letter is the record; what Chronicus reads from it is a summary for you to check, not a replacement for it. You keep, change or drop every line, and only what you keep is saved. Nothing Chronicus reads is ever written to the record by itself.
It does not summarise care records, and does not give medical, medication, benefits or safeguarding advice.
It drafts and suggests. Nothing is sent, changed or deleted until you confirm it. We do not make decisions about you by machine alone.
Children
Kithra holds information about children and children may use it.
We hold less about a child than about an adult. A child’s record is seen by the family managers who look after it and by the carers a family manager chooses to share it with. Nobody else. We do not profile children, use their information to advertise, or track where they are.
If you are a young person reading this: the information about you belongs to you. You can ask to see it, ask for it to be changed, or ask for it to be deleted — even if a parent put it there. Email support@careworld.app and we will help.
Changes
If we change how we use your information we will tell you before it takes effect.


