Draft, not yet reviewed by legal counsel. This page describes our real,
current data practices and intent honestly and in plain language. It is not yet a
lawyer-reviewed legal instrument — treat it as our current, good-faith commitment, and
expect it to be formalized (and possibly revised) with real legal review before CarePyre
scales beyond its initial community deployment.
Overview
The short version
CarePyre provides community members and their case workers, clinicians, and other support
providers with durable email accounts and phone service that survive whatever crisis brought
someone to us. We built this policy around one real, honest tension: we don't look at
your email, but we are a real organization subject to real legal process — if we are
served with a valid subpoena or court order for a specific account's contents, and that
account isn't encrypted, we are legally required to comply. That's exactly why we forcefully
encourage everyone to turn on PGP encryption (see "Encryption" below) — once your mail is
encrypted with a key only you hold, we have nothing readable to hand over even if compelled.
What we collect
- Account information: the email address and display name on your
CarePyre-issued mailbox, and (if you use our SIP phone service) your assigned phone
extension.
- Mail contents and metadata: the emails sent and received through your
CarePyre mailbox, stored on our mail server (mail.carepyre.org) until you delete them or your
account is closed.
- Mailbox credentials: if a provider or administrator provisions your
mailbox on your behalf, we store your mailbox password in encrypted form (AES-256-GCM) so it
can be retrieved and given to you, or so your webmail session can connect automatically. This
is a deliberate design choice to make onboarding actually work for people who may not be in a
position to manage a generated password themselves — see "Access controls" below for who can
see it.
- Usage and security logs: login timestamps, IP-based access records, and
similar technical logs used to keep the service secure and investigate abuse.
We do not read the contents of your email. CarePyre staff do not open,
scan, or review your mail as a matter of course. Automated spam/abuse filtering may process
mail content the same way any mail provider's spam filter does.
Who can create or manage an account on your behalf
If you're a participant, a provider you're working with (a case worker, clinician, or other
support staff member CarePyre has vetted) may create and manage your CarePyre email account
for you. This is intentional — many people arrive at CarePyre without the time, stability, or
access needed to set up their own account, and we'd rather meet people where they are than
put that burden on them during a crisis.
Access controls (least necessary, not everyone sees everything)
- A provider can only see and manage the mailboxes they themselves created — never
every participant in the system. This follows the same "minimum necessary" principle used in
healthcare privacy law: access is scoped to what someone actually needs for their work, not
granted broadly by default.
- A small number of CarePyre administrators can see and manage every account, for the
operational and security tasks running the service actually requires (support requests,
abuse response, legal compliance).
- Every mailbox creation and password reveal is tied to the specific person who performed
it, not anonymous.
Encryption
Every connection to your mailbox (webmail, IMAP, the console) is encrypted in transit via
TLS. Whether your stored mail is also encrypted at rest is up to you:
- Add a real OpenPGP public key or S/MIME certificate to your account (from the Mail page
in the console), and your mail starts being encrypted at rest automatically — CarePyre never
sees or holds your private key, so we could not read your mail even if we wanted to.
- Until you do, your mail is stored unencrypted, and — like any mail provider — we would be
able to read it if we chose to, and would be required to produce it in readable form if
legally compelled to.
We forcefully encourage encryption. We do not require it (yet). Nothing
currently blocks you from using an unencrypted mailbox — we'd rather you have a working
account today than no account while you sort out a PGP key. But we will keep reminding you
(a persistent notice appears in the console until a key is on file) because the difference
is real: an encrypted mailbox is one we structurally cannot hand over readable, even under a
subpoena.
When we disclose data
We do not sell your data, and we do not share it with advertisers. We disclose account
data only:
- When you ask us to (e.g., handing your own mailbox password to you, or exporting your
own data on request).
- To a provider who created your account, scoped to the account(s) they created.
- When legally compelled — a valid subpoena, court order, or other binding
legal process directed at a specific account. If your mail is encrypted at rest with your own
key, we have nothing readable to produce even in this case.
Where legally able to, we will make a reasonable effort to notify the affected account holder
before complying with a legal demand for their data.
A note on health information and HIPAA
CarePyre is a technology and infrastructure provider, not a health care provider. If a
provider using CarePyre-issued accounts is a HIPAA covered entity (for example, a licensed
clinician or health care organization) and uses those accounts to communicate protected
health information, that provider's own HIPAA obligations apply to how they use the service
— and CarePyre may need to enter into a Business Associate Agreement with that provider,
consistent with HIPAA's own requirements for organizations handling protected health
information on a covered entity's behalf. We take this seriously and are building our
technical safeguards (encryption, least-necessary access, audit trails, and the data
export/deletion tools described below) with that real possibility in mind — but this
paragraph is a description of our approach, not a legal determination that CarePyre is or
isn't a HIPAA business associate in any given relationship. If you're a provider with
questions about whether a BAA applies to your use of CarePyre, please reach out (see
"Contact" below) before sending anything you consider protected health information through
an unencrypted account.
Your rights over your own data
- Access and export: you can request a copy of the data we hold about your
account.
- Deletion: you can request that your account and its data be deleted.
Because our systems are built to keep an auditable record of what happened (so we can
investigate abuse and demonstrate compliance), a deletion request removes and redacts your
personal information — email address, display name, password, message contents — rather than
erasing the fact that an account once existed; this is the same real distinction most
regulated systems draw between "erase my personal data" and "pretend this never happened."
- To exercise either right, contact us (see "Contact" below) or, if you're a provider's
participant, ask the provider who manages your account.
Data retention
We keep your account and mail for as long as your account is active. If your account is
closed or you request deletion, we follow the deletion process described above. Security and
access logs are retained for a limited period for abuse investigation and are not kept
indefinitely.
Changes to this policy
We'll update the date at the top of this page when we make changes, and we'll make a
reasonable effort to notify active account holders of any change that materially affects how
their data is handled.
Contact
Questions about this policy, or want to exercise your access/deletion rights? Reach us
through the contact form on carepyre.org.