OdeCare is a product of Aspeen Inc. (“Aspeen,” “we,” “us,” or “our”). This Privacy Policy explains how we collect, use, disclose, and protect your information when you use OdeCare hardware, the mobile application, the web dashboard, and our alert delivery services (together, the “Services”).
Unless Section 11 (deployments for care organizations) says otherwise, Aspeen Inc. is the data controller for the personal data described in this policy. By using our Services, you acknowledge that you have read and understood it.
1. Our Privacy-First Approach
OdeCare is built for privacy. There are no cameras and no microphones anywhere in the system:
- No cameras: OdeCare devices never capture images or video
- No microphones: We never record sounds or conversations. There are no recordings because nothing is recorded.
- Radar only: Room sensors detect presence and movement through reflected radio waves. They register that someone is present and moving — not who it is and not what they say or look like.
- Local processing on the hub: The home hub processes activity data locally, inside the home. Only derived events and alerts (for example, that the usual morning activity has not started) are transmitted to our servers — never video or audio, because none exists.
- No biometrics on our servers: Face ID and fingerprint login in the app happens entirely on your device via the OS secure enclave. This data never reaches our servers.
2. Information We Collect
2.1 Sensor and Hub Data
Radar room sensors, door sensors, and climate sensors send their readings to the home hub:
- Presence and movement patterns (whether someone is in a monitored room and how active they are)
- Door open/close events
- Climate readings (temperature, humidity)
- Device health data (signal strength, battery level of battery-powered sensors, firmware versions)
The hub processes this activity data locally. Only derived events and alerts are transmitted to our servers.
2.2 System Status Telemetry
The hub needs mains power and your home internet connection. It has no battery and no cellular fallback, so if power or internet goes down, the hub stops reporting and the app shows the home as offline. To make this work, the hub regularly reports its connection status, and we keep online/offline events with timestamps — to show system status in the app and to notify you about outages.
2.3 Account and Alert Plan Information
When you create an account and set up alerts, we collect:
- Name and email address
- Your phone number (used for alert delivery)
- Password (stored as a cryptographic hash; we never store plain-text passwords)
- Your alert plan: who receives alerts, in what order, through which channels (app notification, WhatsApp, Telegram, phone call), and your quiet hours
- Names and phone numbers of the people in your alert plan
If you add another person to your alert plan or invite them to the app, make sure they agree to receive alerts and to this processing.
2.4 Mobile Application and Usage Data
When you use our mobile application, we may collect:
- Features used and actions taken within the app
- Device type, operating system version, and app version
- IP address (used to derive approximate country/region; precise GPS location is never collected or requested)
- Push notification tokens (used solely to deliver alerts to your device)
- Crash reports and diagnostic data (collected anonymously to improve stability)
We do not collect precise GPS location. IP-based location is used only at the country/region level for compliance and service delivery purposes.
2.5 Third-Party SDKs and Services
Our mobile application integrates the following third-party SDKs that may collect limited technical data:
- Firebase Cloud Messaging (FCM) via
expo-notifications— used to deliver push notifications to your device. FCM collects push notification tokens and device platform/OS version to route messages. FCM does not receive any health, sensor, or personal data from OdeCare. Firebase Privacy Policy - Expo Update Service via
expo-updates— used for over-the-air app updates. It collects device platform, Expo SDK version, and update channel identifier. No personal data is transmitted. Expo Privacy Policy - expo-local-authentication — enables Face ID and fingerprint login in the app. All biometric matching occurs locally on your device using the OS secure enclave. No biometric data is ever transmitted to Aspeen or any third party.
- expo-secure-store — stores authentication tokens in your device's encrypted secure storage. This data never leaves your device.
We do not use advertising SDKs or behavioural tracking SDKs (such as Amplitude or Mixpanel), and we do not share data with ad networks or data brokers.
3. How We Use Your Information
We use the collected information to:
- Provide, operate, and maintain the Services
- Deliver alerts through the channels in your alert plan, respecting your quiet hours
- Show whether the home system is online and notify you about outages
- Authenticate your account and keep sessions secure
- Improve our products and develop new features
- Provide customer support and respond to inquiries
- Protect the security and integrity of our systems
- Comply with applicable legal obligations
- Run anonymized, aggregated analytics to understand how the Services are used
We do not sell your personal data — not to advertising companies, not to anyone else — and we do not use it for targeted advertising.
4. Alert Delivery: Push, WhatsApp, Telegram, and Phone Calls
When something needs attention, OdeCare escalates step by step, following your alert plan and quiet hours: an app notification first, then a message via WhatsApp or Telegram, then a phone call.
4.1 Push Notifications
Push notification tokens are stored on our servers solely to deliver alerts and are processed via Firebase Cloud Messaging (FCM). You can disable push notifications at any time in your device settings (iOS: Settings → Notifications → OdeCare; Android: Settings → Apps → OdeCare → Notifications). Disabling them does not affect your ability to view alerts within the app.
4.2 WhatsApp and Telegram Messages
To deliver a message, we pass to the selected messenger only two things: the recipient's phone number (or the messenger account linked to it) and the text of the alert. Alert texts contain short status information — for example, that there is still no usual morning activity at home. They never contain video, audio, or raw sensor data, because none exists.
WhatsApp (operated by Meta) and Telegram are independent services. Once a message is handed over for delivery, they process it under their own privacy policies, not ours: WhatsApp Privacy Policy · Telegram Privacy Policy.
4.3 Phone Calls
If messages go unanswered, OdeCare calls the first person in the alert plan, then moves to the next contact. We use telephony service providers to place these calls; they process the recipient's phone number and technical call data on our behalf under data processing agreements.
OdeCare is not a medical device and not an emergency response service. Alerts are delivered only to the contacts in your alert plan — never automatically to emergency services. In an emergency, call your local emergency services.
5. Family Sharing and Access Control
The account holder can invite relatives and carers to the family app:
- Invitations: To send an invitation, we process the invitee's contact details. If they accept, they create their own account, and Section 2.3 applies to them.
- What invited members see: Activity and system status for the home they were invited to, and alerts according to the alert plan.
- Access control and revocation: The account holder can see who has access and remove a member at any time. After removal, that person immediately loses access to new data. Messages already delivered to their phone remain on their devices and in their messengers.
6. Legal Basis for Processing (GDPR)
For users in the European Economic Area (EEA), United Kingdom, and Switzerland, we rely on the following legal bases under the General Data Protection Regulation (GDPR):
| Processing Activity | Legal Basis |
|---|---|
| Account creation and management | Performance of a contract (Art. 6(1)(b)) |
| Delivering alerts via push notifications, WhatsApp, Telegram, and phone calls | Performance of a contract (Art. 6(1)(b)) |
| System status monitoring (hub online/offline) | Performance of a contract (Art. 6(1)(b)) |
| Security and fraud prevention | Legitimate interests (Art. 6(1)(f)) |
| Product analytics and improvement | Legitimate interests (Art. 6(1)(f)) |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) |
| Marketing communications (if opted in) | Consent (Art. 6(1)(a)) — you may withdraw consent at any time |
7. Data Storage and Security
We use industry-standard security measures to protect your data:
- Encryption in transit: All data transmitted between your devices and our servers uses TLS encryption
- Encryption at rest: Stored data is encrypted using industry-standard algorithms
- Access controls: Access to production systems is restricted to authorised personnel using multi-factor authentication
- Regular security reviews: We conduct periodic security audits of our infrastructure and application code
No internet service can guarantee absolute security. That is why OdeCare is designed to collect as little as possible in the first place: there is no video or audio to protect, because none is ever captured.
For care organizations, we offer on-premise data storage options to meet specific compliance requirements.
8. Data Retention
We keep your data only as long as needed for the purposes described in this policy:
| Data Type | Retention Period |
|---|---|
| Account information | Until account deletion, plus 30 days for recovery |
| Activity events and system status (online/offline) | 90 days (configurable for care organizations) |
| Alert history, including delivery records | 1 year |
| Push notification tokens | Until notification opt-out or account deletion |
| Crash and diagnostic logs | 90 days |
| Anonymised, aggregated analytics | May be retained indefinitely |
Upon account deletion, we delete or anonymise your personal data within 30 days, except where retention is required by law.
9. Data Sharing and Disclosure
We do not sell your personal data — not to advertising companies, not to data brokers, not to anyone. We share information only in the following circumstances:
- Service providers: Trusted vendors (hosting, push notification delivery, telephony) process data on our behalf under strict data processing agreements. They are prohibited from using your data for their own purposes.
- Messengers you choose: WhatsApp (Meta) and Telegram receive the recipient's phone number and the alert text to deliver messages. They are independent services with their own privacy policies (see Section 4.2).
- People you invite: Family members and carers you add see the data described in Section 5.
- Care organizations: If OdeCare is provided to you by a care organization, that organization controls access to the data (see Section 11).
- Legal requirements: We may disclose data when required by applicable law, court order, or to protect the rights, property, or safety of Aspeen, our users, or the public.
- Business transfers: In the event of a merger, acquisition, or sale of assets, your data may be transferred. We will notify you by email or a prominent notice in the app before your data becomes subject to a different privacy policy.
- With your explicit consent: For any other purpose, only with your prior written consent.
10. International Data Transfers
Your data may be transferred to and processed in countries outside your country of residence, including the United States (where Firebase and Expo infrastructure operates). These countries may not provide the same level of data protection as your home jurisdiction. WhatsApp and Telegram operate their own global infrastructure; their handling of delivered messages is governed by their own policies.
For transfers of personal data from the EEA, UK, or Switzerland to countries not deemed adequate by the European Commission, we rely on:
- EU Standard Contractual Clauses (SCCs) as approved by the European Commission
- UK International Data Transfer Agreements (IDTAs) where applicable
You may request a copy of the applicable safeguards at hi@odecare.com.
11. Deployments for Care Organizations (B2B)
We run pilots and deployments with care organizations, which receive a dashboard for their staff. In these deployments:
- The organization is the data controller for its clients' data; Aspeen Inc. processes that data on the organization's behalf as a processor under a data processing agreement (DPA)
- The organization decides which of its staff can access which clients' data and manages that access
- We sign DPAs for corporate deployments before processing begins
If OdeCare monitoring is provided to you by a care organization, direct privacy questions and rights requests to that organization first. We support organizations in fulfilling those requests.
12. Cookies and Website Analytics
As of the “Last updated” date above:
- Our newer pages on odecare.com load no analytics scripts and set no analytics cookies
- Some pages built on our older site layout (for example, the blog and legal pages) load Google Tag Manager, which can set Google analytics and tag cookies
- The web dashboard at odecare.com/app uses only strictly necessary cookies and local storage to keep you signed in
Details are in our Cookie Policy.
13. Your Privacy Rights
13.1 Rights for All Users
Regardless of your location, you may:
- Access: Request a copy of the personal data we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your personal data (subject to legal retention obligations)
- Portability: Receive your data in a structured, machine-readable format
- Withdraw consent: Where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
13.2 Additional Rights for EEA/UK Users (GDPR)
If you are located in the EEA or UK, you also have the right to:
- Object to processing based on legitimate interests
- Restrict processing in certain circumstances
- Lodge a complaint with your local data protection authority (e.g., the ICO in the UK, or your national supervisory authority in the EU)
13.3 Additional Rights for California Residents (CCPA/CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA):
- Right to Know: Request disclosure of the categories and specific pieces of personal information we have collected about you, and the categories of third parties with whom we share it
- Right to Delete: Request deletion of your personal information, subject to certain exceptions
- Right to Correct: Request correction of inaccurate personal information
- Right to Opt Out of Sale or Sharing: We do not sell or share personal information for cross-context behavioural advertising. No opt-out is required, but you may contact us to confirm.
- Right to Limit Use of Sensitive Personal Information: We do not use sensitive personal information beyond the purposes permitted under CPRA
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your rights
To exercise any California rights, contact us at hi@odecare.com. We will respond within 45 days.
13.4 How to Exercise Your Rights
Contact us at hi@odecare.com with the subject line “Privacy Rights Request.” We will respond within 30 days (or within the timeframe required by applicable law). We may need to verify your identity before processing your request.
You may also delete your account directly from within our apps: Mobile app: Settings → Security → Delete Account · Web dashboard: Settings → Danger Zone → Delete Account. See the step-by-step account deletion guide. This initiates deletion of your personal data within 30 days.
14. Children's Privacy
Our Services are not intended for use by children under the age of 16 (or under 13 in jurisdictions where 13 is the minimum age). We do not knowingly collect personal information from children below this age. If we become aware that we have collected personal data from a child without verifiable parental consent, we will delete that information promptly.
If you believe we may have collected information from a child, please contact us at hi@odecare.com.
15. Account Deletion
You may delete your account at any time from within our apps: Mobile app: Settings → Security → Delete Account · Web dashboard: Settings → Danger Zone → Delete Account. You can also request deletion by contacting hi@odecare.com.
Upon deletion, your account is immediately deactivated and you are logged out from all devices. Your personal data will be permanently removed within 30 days, except where retention is required by applicable law (e.g., billing records).
16. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you by:
- Sending an email to the address associated with your account, and/or
- Displaying a prominent notice within the app
The updated policy takes effect on the “Last updated” date at the top of this page. Continued use of the Services after changes take effect constitutes acceptance of the revised policy.
17. Contact Us
OdeCare is a product of Aspeen Inc. If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Email: hi@odecare.com
Website: odecare.com
For EEA/UK users, Aspeen Inc. acts as the data controller for the personal data described in this policy, except in care-organization deployments (see Section 11). If you are not satisfied with our response, you have the right to lodge a complaint with your local data protection authority.