Privacy & Confidentiality

Your clients' data is yours alone

Carearoo is built for Australian OTs who handle sensitive NDIS participant information every day. We take that responsibility seriously. Here's exactly how we protect it.

Australian Servers (Sydney)
AES-256 Encryption
Privacy Act Aligned
One-Click Delete of Uploads

Encrypted in Transit & at Rest

All data is protected with TLS 1.3 during transmission and AES-256 encryption at rest. Your client information is never readable by anyone without your credentials.

Australian Servers

All data is stored in Supabase's Sydney region (AWS ap-southeast-2). It never leaves Australian borders. No offshore data processing, no exceptions.

One-Click Delete of Uploads

You can permanently delete uploaded clinical documents (voice recordings, notes, attachments) from our servers at any time with one click. You control the data lifecycle. We recommend deleting your uploads once your finished report is downloaded.

Zero Third-Party Sharing

Your client data is never sold, shared, rented, or disclosed to any third party. The only external service that processes your content is Carearoo's AI engine for report generation, governed by strict enterprise data handling agreements.

You Own Your Data

You retain full ownership of everything you upload and every report you generate. Carearoo holds no licence over your clinical content. You can export or delete your data at any time.

Australian Privacy Act Aligned

Our practices are designed to align with the Australian Privacy Act 1988 (Cth) and the 13 Australian Privacy Principles (APPs), including purpose limitation, data minimisation, and security obligations.

In depth

The full detail behind each of our privacy commitments.

NDIS Practice Standards & Privacy

The NDIS Practice Standards require that participant information is collected, used, and stored in a way that respects their dignity and protects their privacy. Carearoo is designed with these obligations in mind.

We only collect the minimum information required to generate your report. Clinical notes and supporting documents you upload are used solely to produce that specific report. They are not analysed for any other purpose, fed into training datasets, or accessed by Carearoo staff.

NDIS participants' personal and sensitive information is handled as "sensitive information" under the Privacy Act, requiring a higher standard of protection. All data within Carearoo is treated to this higher standard by default.

Technical Security Measures

Carearoo is built on Supabase, which provides enterprise-grade security infrastructure:

• TLS 1.3 encryption for all data in transit • AES-256 encryption for all data at rest • Row-level security (RLS) policies ensure users can only access their own reports and files • JWT-based authentication with short-lived access tokens • Automatic session expiry and refresh token rotation • Secure file storage with access-controlled bucket policies

Our authentication is handled by Supabase Auth, and passwords are never stored in plaintext. All authentication flows use industry-standard bcrypt hashing.

AI Processing & Data Handling

When you generate a report, your clinical notes are sent to Carearoo's AI engine for processing. This is the only instance where your content leaves Supabase's Australian infrastructure.

Our AI processing agreement includes: • No use of inputs to train or improve AI models • No retention of prompts or outputs beyond the immediate request lifecycle • Compliance with applicable data protection laws

AI-generated content is returned directly to your session and stored in your Supabase-hosted report. It is not cached or logged externally.

Carearoo staff do not have access to the clinical content of your reports. Our administrators can only see account-level metadata (email, subscription status, report counts).

Data Retention & Deletion

Uploaded files (voice recordings, clinical notes, attachments) are stored in Supabase Storage under your user-specific path. Once you download your completed report:

• You can use the "Delete All My Documents" button to immediately remove all uploaded files from storage • Files are permanently deleted from Supabase Storage, not merely flagged but fully removed • Generated report drafts remain in your account so you can re-edit or re-download at any time

If you close your account, all associated data (reports, files, profile) is permanently deleted within 30 days. You may also request immediate deletion by contacting info@carearoo.com.

Your Rights Under the Privacy Act

Under the Australian Privacy Act 1988 and the APPs, you have the right to:

• Access the personal information we hold about you (APP 12) • Correct inaccurate or outdated information (APP 13) • Know why we collect your information and how it will be used (APP 5) • Request deletion of your personal information • Lodge a complaint with the Office of the Australian Information Commissioner (OAIC) if you believe we have breached the APPs

To exercise any of these rights, contact us at info@carearoo.com. We will respond within 30 days.

Important: clinical responsibility

Carearoo generates AI-assisted draft reports only. All content must be reviewed, verified, and approved by a registered Occupational Therapist before submission to the NDIS or any third party. Carearoo does not provide clinical, medical, or legal advice. The registered clinician remains solely responsible for the accuracy and clinical appropriateness of any submitted report.

Questions about your privacy?

We're happy to explain exactly how your data is handled. Reach out any time.