Last updated 29 July 2026 · applies to the CareMoss carer app for Android and iOS (com.caremoss.carer)
This notice covers the mobile app that care workers use to run their visits. The website privacy notice is separate and covers caremoss.com only.
The carer app is used by care providers — the companies that employ care workers and deliver care to the people they support. Under UK data protection law, your employer is the data controller: they decide what care records are kept, for how long, and who sees them.
CareMoss is the data processor. We run the software and store the records on the provider's behalf, under a written agreement with them. We do not use care data for our own purposes, we never sell it, and we never use it for advertising or to train AI models.
This means most requests about your own data — access, correction, deletion — go to your employer first. We help them answer, and you can always contact us directly at info@caremoss.com.
There is no self-registration. Accounts are created by a care provider for their own staff, and the app is unusable without one. If you have downloaded the app and do not work for a CareMoss customer, it collects nothing from you beyond a failed login attempt.
| Data | When and why |
|---|---|
| Email & password | To sign you in. Passwords are stored as salted hashes and are never readable by us. |
| Device details | Platform, app version, a random install identifier, and whether biometric unlock is enabled. Used to recognise your handset across sessions and to let your employer sign a lost device out. |
| Precise location | Only when you check in or out of a visit. See below. |
| Care records | Visit notes, tasks, observations and vital signs, body-map entries, medication administration (eMAR), and incident reports you file. This is health data about the people you support. |
| Photos | Only images you deliberately attach to a visit, taken with the camera or picked from your library. |
| Messages & alerts | Messages you send to and receive from your office, and which alerts you have read. |
| Work records | Timesheets you create and submit, including the travel time and mileage you declare on them, holiday requests, and your training and compliance record. |
| Your contact details | The phone number on your profile, which you can edit yourself. |
The app asks for precise location because attendance at a visit has to be verifiable. We have kept this as narrow as we know how:
If you decline the location permission the app keeps working, but every check-in will be recorded as manual and unverified — which your employer will see.
If you turn on Face ID, Touch ID or fingerprint unlock, the check happens entirely on your phone using the operating system's own security hardware. CareMoss never receives your fingerprint or face data — only a yes/no that the device accepted you, and a note on your account that biometric unlock is switched on.
Care happens in homes with poor signal, so the app records everything offline and syncs when the connection returns. While waiting to sync, that work — including care notes and medication records — is held in the app's storage on your device. Your session tokens are kept in the device's secure keystore. Signing out clears the cached records from the handset.
The app contains no advertising, no analytics SDK, no social media SDK and no third-party trackers. It talks to CareMoss servers and to nothing else. There is no advertising identifier, and we do not build a profile of you.
Data is sent over an encrypted HTTPS connection to CareMoss servers hosted in the European Union by our infrastructure provider, IONOS, acting as a sub-processor. The UK government's adequacy regulations recognise the EEA as providing an equivalent standard of protection, so no additional transfer safeguards are required.
Access is restricted to your own care provider's records — each provider's data is isolated from every other provider's. Access is role-based, and significant actions are written to an audit trail that your employer can review.
Care records are your employer's records, and their retention policy governs. Health and social care records are typically kept for a number of years after the last contact to meet statutory and regulatory duties, so a record generally cannot be erased simply on request while that duty applies. We delete data on the provider's instruction, and we delete or return their data at the end of our contract with them.
Requesting deletion. Because accounts are created and controlled by your employer, start there — ask your manager or their CareMoss administrator, who can deactivate your account directly in the CareMoss console.
You can also write to us at info@caremoss.com with the subject "App data deletion request". We will acknowledge within 5 working days, pass the request to the care provider responsible for the record, and confirm the outcome to you.
What happens when an account is deleted: your login, your device registration and your app session are removed, and you can no longer sign in. Care records you wrote about the people you support are not deleted with your account — they belong to the provider, form part of that person's care record, and are retained under the provider's legal duties. Uninstalling the app removes everything held on the handset.
Under UK GDPR you have rights of access, correction, erasure, restriction, portability and objection. Exercise them with your employer as the controller, or contact us and we will route it. If you are not satisfied, you can complain to the Information Commissioner's Office at ico.org.uk.
The app is a workplace tool for employed care workers and is not directed at or intended for anyone under 18.
If we change what the app collects we will update this page and change the date at the top. Material changes will also be notified to the care providers who use CareMoss.