Privacy Policy
Last modified: August 3, 2026
1. Introduction
P2 Reserve LLC (“Compass Care,” “we,” “us,” or “our”) respects your privacy and is committed to protecting it through this privacy policy (“Privacy Policy”). Compass Care is a family preparedness and care coordination application that gives families one centralized place to organize documents, coordinate care, and manage health information so that everything is accessible during an emergency.
This Privacy Policy applies to personal information we collect when you:
- create an account and use the Compass Care mobile or web application;
- enter information about yourself and the people you care for, including health information, documents, and contacts;
- use features such as the Vault, AI Scan, Crisis SOS, tasks and reminders, and circle invitations; and
- visit our website and landing pages.
It does not apply to information collected by us offline, or by any third party whose application or content may link to or be accessible from our app and whose data practices we do not control.
Please read this Privacy Policy carefully. If you do not agree with our practices, please do not use Compass Care. If you have questions, contact us using the information at the end of this policy.
Controller. For users in the European Economic Area (“EEA”), the United Kingdom (“UK”), and Switzerland, P2 Reserve LLC is the “controller” of your personal information (called “personal data” under those laws). Our contact details, and the contact details of our EEA/UK representative where one is appointed, are in Section 14.
2. Children and Care Recipients Under 18
Compass Care is intended for use by adults to organize and coordinate care for themselves and the people they care for. You may use Compass Care to manage information about your dependents and care recipients of any age, including minor children, but only when you are their parent or legal guardian or are otherwise authorized to do so.
Compass Care is not directed to children, and we do not knowingly allow anyone under 18 to create their own account. We collect information about a minor only at the direction of an authorizing adult, and only as necessary to provide care coordination. By entering a minor’s information, you affirm that you are legally authorized to do so under the laws of your jurisdiction. If we learn that a person under 18 has created an account without authorization, we will delete that account. To review, update, or request deletion of a minor’s information, contact us.
We do not “sell” or “share” (as those terms are defined under California law) the personal information of any consumer, and we do not knowingly do so for consumers under 16.
3. Personal Information We Collect, Sources, Purposes, and Retention
The personal information we collect depends on how you use Compass Care. Almost all of it is information you choose to enter about yourself and the people you care for. The table below sets out, for each category we collect: what it includes, the source, the business or commercial purpose, and how long we keep it.
Sources. We collect personal information (a) directly from you when you register, enter information, upload documents, capture images, or use any feature; and (b) automatically from your device and our infrastructure (for example, IP address and request logs) when the app communicates with our servers.
| Category | What it includes | Source | Purpose | Retention |
|---|---|---|---|---|
| Identifiers | Name of you and each care recipient, email address, account UUID, OAuth profile (Google/Apple), session tokens, and similar identifiers. | You; OAuth provider | Account creation, authentication, app functionality | For the life of your account; deleted on account deletion (see Section 9) |
| Account credentials | One-time sign-in codes emailed to you when you sign in; we do not store a password for your account. | You | Authentication, account security | Each code expires after a short time and is not kept after use |
| Contact information | Emergency contact names and phone numbers, and provider or pharmacy phone numbers you save. | You | Care coordination, emergency response | For the life of your account, or until you delete the record |
| Demographic information | Date of birth of you and care recipients. | You | Health record accuracy, age-appropriate care | For the life of your account, or until you delete the record |
| Health information (sensitive) | Medications (drug, dosage, prescriber, pharmacy, refill dates, schedule), immunizations, appointments, blood type, allergies, and free-text medical notes for you and your care recipients. | You | Storing and organizing care information, reminders, Compass Score, AI crisis plan | For the life of your account, or until you delete the record |
| Documents and files | Files you upload to the Vault and their metadata (title, category, file name, type, issue and expiry dates, notes), including identity, medical, legal, financial, insurance, and education documents. | You | Document storage and retrieval, expiration reminders | For the life of your account, or until you delete the document |
| Photos and images | Profile photos of people in your circle and document images you capture for the AI Scan feature (for example, prescription bottles or insurance cards). | You | Personalization; AI Scan extraction | Profile photos: life of account. Scan images: passed through for extraction and not stored by us as separate records (see Section 8) |
| Precise geolocation (sensitive) | GPS latitude and longitude captured only when you trigger a Crisis SOS alert. | You/device | Capturing and displaying your emergency location so you can share it | Stored with the alert record; deleted when you delete the alert or your account |
| Approximate location / search text | Free-text place queries used for appointment and task location autocomplete, sent anonymously to a mapping service. | You | Location autocomplete | Not stored by us beyond the saved field you choose |
| User content | Tasks and reminders, family or circle membership and permissions, onboarding quiz answers, Compass Score snapshots, crisis progress and alerts, and notification preferences. | You | App functionality | For the life of your account, or until you delete the content |
| Push notification token | A device push token that lets us deliver notifications to your device. | Your device, only after you allow notifications | Delivering task updates from your care circle and emergency alerts | Removed when you sign out on that device, and in any case deleted with your account |
| Subscription information | Your plan status (free or Plus) and, if you subscribe to Compass Plus, your purchase history: Apple’s purchase and transaction information for your subscription, such as product, renewal, trial, and refund status. We never receive your payment card details; Apple processes payment. | You; Apple, through our subscription processor (RevenueCat), when you subscribe | Providing Compass Plus features and managing your subscription | For the life of your account |
| Internet and device activity | IP address and request logs automatically collected by our backend infrastructure. | Automatic | Security, fraud prevention, debugging | Limited log-retention period (typically up to 90 days) unless needed for security or legal reasons |
| Account login information (sensitive) | Email/OAuth identifier in combination with the one-time emailed sign-in codes and session tokens allowing access to your account. | You; OAuth provider | Authentication | For the life of your account |
| Biometric information | We do not collect biometric identifiers. If you turn on the optional app lock, Face ID or Touch ID matching happens entirely on your device, handled by its operating system; the app learns only whether the unlock succeeded, and no biometric data ever reaches us. Profile and document photos are stored as images and are not used to create faceprints or other biometric templates. | — | — | Not collected |
| Professional or employment information | Compass Care is a direct-to-consumer app and does not collect employment or professional records. | — | — | Not collected |
| Tracking / advertising identifiers | We use no advertising SDKs, no cross-app or cross-site tracking, and no data brokers. | — | — | Not collected |
How storage works. When the app runs in its local-only configuration, your information stays on your device and nothing leaves it except calls to the AI and mapping features described below. When the app is connected to our cloud backend, your information is stored and synchronized through that backend so it is available across your devices and to the people you invite to your circle.
Where AI data goes. When you use an AI feature, the relevant information (and, for AI Scan, the document image) is transmitted from the app through our backend to our AI provider (Anthropic) to perform the feature you requested, and is not retained by Anthropic as part of an ongoing record. See Section 8.
4. Sensitive Personal Information
Some of the information we collect is “sensitive personal information” under California law and “special category data” under European and UK law. This includes your health information, precise geolocation, and your account login credentials.
We use and disclose sensitive personal information only to provide Compass Care to you and the people in your circle, to secure your account, to prevent fraud, and as otherwise permitted by Cal. Civ. Code § 1798.121 and applicable law. We do not use it to infer characteristics about you, for advertising, or for any purpose other than providing and securing the service. Because we limit our use of sensitive personal information to these permitted purposes, we are not required to offer, and do not offer, a separate “Limit the Use of My Sensitive Personal Information” link — but you may still contact us to exercise your rights.
For users in the EEA, UK, and Switzerland, we process health and other special category data only with your explicit consent (Article 9(2)(a) GDPR), which you provide when you choose to enter health information or use a health-related feature. You may withdraw that consent at any time (see Section 6); withdrawing consent does not affect processing already carried out, and may mean we can no longer provide some features.
5. How We Use Your Personal Information and Legal Bases
We use your personal information to operate Compass Care and provide the features you ask for. Specifically, we use it:
- To create and support your account and authenticate you.
- To store, organize, and synchronize the documents, health information, contacts, tasks, and other content you enter.
- To generate your Compass Score and readiness snapshots from the completeness of your health and document information.
- To power AI features, including generating a crisis readiness plan and reading documents you scan.
- To deliver circle invitations and the notifications and reminders you turn on, such as refill, appointment, expiration, and task alerts.
- To capture and display your emergency location when you trigger a Crisis SOS alert, so you can share it with responders or the people in your circle.
- To maintain the security of the app, prevent fraud and abuse, and debug and improve functionality.
- To comply with our legal obligations.
We do not sell your personal information for money or other valuable consideration, we do not “share” it for cross-context behavioral advertising, and we do not use it for advertising, marketing profiling, or cross-app tracking.
Legal bases (EEA / UK / Switzerland). Where European or UK law applies, we rely on the following legal bases under Article 6(1) GDPR:
| Purpose | Legal basis |
|---|---|
| Creating and operating your account; storing and syncing your content; delivering invitations, reminders, and the features you request | Performance of a contract with you (Art. 6(1)(b)) |
| Processing health and other special category data; using precise location for Crisis SOS | Your explicit consent (Art. 6(1)(a) + Art. 9(2)(a)); you may withdraw it at any time |
| Securing the app, preventing fraud and abuse, debugging, and improving functionality | Our legitimate interests in running a safe, reliable service (Art. 6(1)(f)) |
| Retaining records and responding to lawful requests | Compliance with a legal obligation (Art. 6(1)(c)) |
Automated decision-making. We do not make decisions that produce legal or similarly significant effects about you based solely on automated processing. The Compass Score and AI-generated crisis plans are informational aids to help you; they do not make decisions about you, and you remain in control.
6. Your Rights and Choices
Depending on where you live — including U.S. states such as California, Colorado, Connecticut, Texas, Virginia, Oregon, Montana, and others, and the EEA, UK, and Switzerland — you may have some or all of the following rights regarding your personal information:
- Right to know / access what personal information we have collected about you, the sources, the purposes, and the categories of third parties to whom it is disclosed.
- Right to a portable copy of your information in a usable format.
- Right to correct inaccuracies in your information.
- Right to delete the personal information we have collected from you, subject to limited exceptions.
- Right to restrict or object to certain processing, and to limit the use and disclosure of sensitive information.
- Right to withdraw consent at any time where we rely on consent (such as for health data and precise location), without affecting prior processing.
- Right to opt out of the sale or sharing of personal information and of profiling for decisions with legal or significant effects — note that we do none of these, so there is nothing to opt out of.
- Right to non-discrimination for exercising any of these rights.
- Right to appeal a decision we make about your request (see below).
- Right to lodge a complaint with your local data protection authority (EEA/UK/Switzerland) or attorney general (U.S.).
How to exercise your rights. Because most of your information is stored in your account, you can review, edit, and delete much of it directly within Compass Care, including people, documents, health records, tasks, and circle members. In addition:
- Deleting your account. You can permanently delete your account and all data in the care groups you own directly in the app: go to Settings → Account → Delete account. We ask you to confirm your sign-in before the deletion runs.
- Requesting a portable copy. To receive a copy of your account and the care groups you own in a machine-readable format, contact us at info@usecompasscare.com and we will deliver it within the response times described under “Timing” below.
For any other request — including correction or an appeal — contact us at info@usecompasscare.com. We will verify your identity before fulfilling a request, by confirming control of the account email and, where necessary, additional information matching what we hold.
Authorized agents. You may use an authorized agent to submit a request on your behalf. We may require the agent to provide proof of your written authorization and may ask you to verify your own identity directly.
Timing. We respond within the timeframes required by applicable law — generally 45 days under U.S. state laws (extendable by another 45 days with notice) and one month under the GDPR/UK GDPR (extendable by two further months for complex requests). We may decline a request where the law allows, such as where we must retain information for security or legal reasons, and we will explain why.
Appeals. If we decline your request and you live in a state or country that provides an appeal right, you may appeal by replying to our decision or emailing info@usecompasscare.com with the subject “Appeal.” We will respond within the time required by law (for example, 45–60 days under applicable U.S. state laws). If we deny your appeal, you may contact your state attorney general or, in the EEA/UK/Switzerland, your supervisory authority.
California “Shine the Light.” California Civil Code § 1798.83 permits California residents to request information about disclosures of personal information to third parties for their direct marketing purposes. We do not disclose personal information to third parties for their direct marketing purposes.
7. Who We Share Your Information With
We do not sell your personal information and we do not share it for advertising. We disclose it only to the service providers and processors needed to run the app, and only to the extent each provider requires to perform its function. We treat these providers as our data processors. We enter into data processing agreements with them where available, and for transfers of personal information out of the European Economic Area or the United Kingdom we rely on appropriate safeguards such as the Standard Contractual Clauses. We are completing these agreements with each provider and will update this policy as they are finalized. The services that receive data are listed below.
| Service | What is sent | Purpose |
|---|---|---|
| Supabase (our backend service provider) | Substantially all data you enter, for authentication, sync, and storage. | App functionality, authentication, data synchronization, and storage. Acts as our processor, not an independent third party. |
| Anthropic (Claude API) | For Crisis plans: name, blood type, allergies, medications, insurance document titles, appointments, and emergency contact. For AI Scan: the document image you capture. Sent from the app through our backend to Anthropic. | To generate your crisis readiness plan and to read scanned documents. Under our terms with Anthropic, this data is not used to train AI models. See Section 8 for retention. |
| Resend (email delivery, via our backend) | The invitee email address, invite code, and care-focus label for circle invitations; and, when an emergency alert cannot reach a circle member’s device, that member’s email address and the alert message (first names only, never health information). | To send circle-invitation emails on your behalf, and to deliver an emergency alert by email when a circle member cannot be reached by push. |
| Expo (push notification delivery) | The device push token and the notification content, which is first names and IDs only, never health information. | To deliver task updates from your care circle and emergency alerts to your device. Acts as our processor, not for tracking. |
| RevenueCat (subscription management) | When you subscribe to Compass Plus, Apple sends purchase and transaction information for your subscription (product, renewal, trial, and refund status) to RevenueCat, along with the app user id, which is your account UUID, and the basic device and app information its software needs to work, such as platform and app version. RevenueCat never receives your payment card details or any health information. | To manage your Compass Plus subscription, keep your entitlement in sync across your devices, and notify our backend of subscription changes. Acts as our processor, not for tracking. |
| OpenStreetMap Nominatim | The free-text location query only, sent anonymously with no account information. | Location autocomplete for appointments and tasks. |
| Google Maps | A link containing GPS coordinates, opened only if you tap it within a crisis alert. | To display an emergency location in your map application. No data is sent through an API or key. |
| Datadog, Inc. (US1 region, USA) | De-identified operational telemetry only: which screens are opened (by their generic route name, never their content), error and crash reports, and network request timing. Sessions are anonymous and contain no names, no user identifiers, and no health information; interaction tracking is disabled. | Crash reporting and performance monitoring (de-identified), so we can find and fix problems and keep the app reliable. Acts as our processor, not an independent third party. |
We may also disclose personal information when required to comply with the law, to enforce our terms, or to protect the rights, property, or safety of Compass Care, our users, or others. Because some of this information includes health data and other sensitive data, we treat our AI, backend, and email providers as processors and pursue appropriate data protection terms with them.
8. How We Use Artificial Intelligence
Two features use AI, and both run only when you choose to use them. The Crisis plan feature sends relevant emergency information — such as your name, blood type, allergies, medications, insurance document titles, appointments, and emergency contact — to our AI provider to generate a readiness plan. The AI Scan feature sends an image of a document you capture so the AI can read it and help fill in your records.
This information is transmitted from the app through our backend to our AI provider (Anthropic) over an encrypted connection; the app does not send it to any AI provider directly, and we do not embed AI provider keys in the app. Under our terms with Anthropic, your inputs and outputs are not used to train AI models. Anthropic may retain inputs and outputs for a limited period for trust, safety, and abuse-monitoring purposes as described in its commercial terms, after which they are deleted, unless a zero-retention arrangement applies to our account. We do not permit our AI provider to use your information for any purpose other than processing your request, and we do not store the scanned image as a separate record once it has been read.
AI Scan and the AI Crisis plan are optional. You can always enter information manually instead, and when AI is unavailable the app falls back to manual entry or an on-device generator so nothing breaks.
9. How Long We Keep Your Information
We keep your personal information for as long as your account is active and as needed to provide Compass Care, and afterward only as required to meet legal, security, or recordkeeping obligations. Category-level retention is described in the table in Section 3. When you delete content in the app, or delete your account, we delete the associated information from our active systems, recognizing that removal from routine backups may take additional time. Your device push token is removed when you sign out on that device and is deleted with your account. Information sent to our AI provider is handled as described in Section 8.
You can delete individual records in the app at any time. To delete your entire account and associated data, use the Delete account option in the app under Settings → Account, or contact us at info@usecompasscare.com.
10. How We Protect Your Information
We have implemented reasonable measures designed to protect your personal information. These include encrypted transmission, row-level security and per-category permissions in our backend, access controls that limit what each member of your circle can see, processing of AI requests through our backend rather than directly from your device, and passwordless sign-in that uses one-time emailed codes, so we do not store a password for your account. Device push token records are readable only by the account they belong to and are written only through a validated server function. You control who joins your circle and what each member is permitted to view.
You can also turn on an optional app lock that asks for Face ID, Touch ID, or your device passcode before Compass opens. The biometric check happens entirely on your device, handled by its operating system. Compass never sees, collects, or stores your face or fingerprint data; it only learns whether the unlock succeeded. Your app-lock preference is saved on your device, not on our servers.
No system is perfectly secure, and we cannot guarantee absolute security. The safety of your information also depends on you: keep your email account secure, never share a sign-in code with anyone, and be thoughtful about whom you invite into your circle and the permissions you grant them.
Breach notification. If we become aware of a personal-data breach that affects you, we will notify you and the relevant authorities as required by applicable law (including, where applicable, within 72 hours of becoming aware, under the GDPR/UK GDPR).
11. Where Your Information Is Processed and International Transfers
Compass Care is operated from the United States, and your personal information is processed and stored in the United States. If you use the app from outside the United States, including from the EEA, UK, or Switzerland, your information will be transferred to and processed in the United States, where privacy laws may differ from those in your location.
Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, principally the European Commission’s Standard Contractual Clauses (and the UK International Data Transfer Addendum where applicable), together with supplementary measures such as encryption in transit. You may request a copy of the safeguards we use by contacting us.
12. Cookies and Tracking
The Compass Care application uses only the storage strictly necessary to run the app and keep you signed in (for example, session tokens stored on your device). To help us find and fix problems, the app also includes a crash reporting and performance monitoring service (Datadog). It receives only de-identified operational telemetry: which screens are opened (by their generic route name, such as “vault,” never their content), errors and crashes, and how long network requests take. Sessions are anonymous, interaction tracking is turned off, and this telemetry contains no names, no user identifiers, and no health information. We do not use advertising cookies or cross-site or cross-app tracking technologies, and we do not respond differently to “Do Not Track” signals because we do not track you across sites. Our public website may use only strictly necessary cookies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes to how we handle your personal information, we will notify you within the app or by email to the address associated with your account. The date at the top of this policy shows when it was last revised. Your continued use of Compass Care after a change takes effect means you accept the updated policy.
14. Contact Us
If you have questions or concerns about this Privacy Policy, or if you wish to exercise any of your privacy rights, please contact us at:
P2 Reserve LLC
Email: info@usecompasscare.com
Website: usecompasscare.com
EEA / UK residents. If you are in the EEA, UK, or Switzerland, you also have the right to lodge a complaint with your local data protection authority (in the UK, the Information Commissioner’s Office). Where we are required to appoint an Article 27 representative, we will publish their contact details on this page once the appointment is made.
