Privacy
How Sunday treats your family's information
This record is about someone you love. Here's exactly what Sunday collects, where it goes, and what happens when you ask for it back.
Before public release
Sunday is in private testing. Four things on this page still need to be settled before it ships publicly: the legal entity that operates Sunday, the governing jurisdiction, the effective date, and the exact hosting region of our database and file storage. Until then, treat this as an accurate description of how the software behaves — which is what it is — rather than a finished legal instrument. Questions: help@sundaycare.app.
On this page
- The short version
- Whose information this is
- What Sunday collects
- What Sunday doesn't collect
- Where your information goes
- When AI is involved
- Email documents in
- What Sunday measures
- Who can see the record
- How long it's kept, and what you can delete
- How it's protected
- HIPAA, and why Sunday isn't covered by it
- Sunday doesn't give medical advice
- Children
- Your choices
- Changes, and how to reach us
1. The short version
- Sunday keeps only what you and your circle put in. It never pulls records from a doctor, a pharmacy or an insurer on its own.
- Your family's record is reachable by the people you invite, and by no other family. That boundary is enforced in the database itself, not just in the app.
- Your weekly check-in answers and your Ask Sunday conversations are private to you — other people in your circle can't see them.
- Documents and photos live in private storage and open through links that expire in ten minutes.
- When you photograph a document or ask Sunday a question, that content is sent to Anthropic's Claude through Sunday's own server so it can be read or answered. Insurance member IDs and group numbers are stripped out first.
- Sunday does not sell your information, does not share it for advertising, and does not use it to train AI models.
- You can delete your account from inside the app, with no email to anyone. What that does — and one thing it doesn't yet do — is spelled out in section 10.
2. Whose information this is
Sunday is unusual: most of what it holds is about someone who isn't using it. You're the adult child, the sibling, the caregiver. The record is about your parent.
So this policy covers three groups. You, the person with the account. Your circle — the siblings and caregivers you invite, each of whom has their own account. And the person you're caring for, whose details make up most of the record and who typically has no account at all.
When you enter someone else's medical and insurance information, you're asserting that you have the authority or their permission to do so. Sunday can't verify that and doesn't try. If your parent asks what's held about them, or asks for it to be removed, write to help@sundaycare.app and we'll help. Some of it you can remove yourself from inside the app; section 10 is honest about which parts those are.
3. What Sunday collects
Your account
An email address and password, or Sign in with Apple. If you use Apple, Apple gives Sunday your name and an email address (which may be Apple's private relay address rather than your real one), and Sunday stores the name on your account. Sunday never sees your Apple password.
Sunday also records which circle you belong to, your role in it, and the name you go by in the circle.
The record you build
Everything below is entered by you or your circle — by typing it, by photographing a document, or by forwarding an email.
| What | Specifically |
|---|---|
| The person | First and last name, what you call them ("Mom"), date of birth, ZIP code and the state derived from it, living situation, who they live with, how you'd describe the care they need, the concerns you flagged at setup, and a photo if you add one. No street address is ever collected. |
| Insurance | Plan type and name, plan or contract number, member ID, group number, the pharmacy block (RxBIN, RxPCN, RxGrp), customer service phone, and the photo of the card. |
| Care team | Provider names, specialties, phone numbers, addresses and your notes. |
| Medications | A list: name, strength, directions as printed, who prescribed it, whether it's active or stopped, and the photo of the label. No doses taken, no schedule, no adherence data — Sunday doesn't track any of that, by design. |
| Appointments | Title, date and time, time zone, location, the provider, questions you want to ask, and your notes. |
| Documents | The file you uploaded or forwarded, its type and title, and the full structured reading Sunday took off it. |
| Emergency card | Allergies, advance-directive status, DNR/POLST status, and key contacts with their phone numbers. |
| Planning workspace | Your answers to the needs assessment and the care level it estimated; communities you've added with their pricing; tour notes, photos and the questions you still have open; and how your circle voted on each place. |
| Activity | A timeline of what happened in the circle — a document filed, a record updated — so the family can see what's moved. |
Two things that stay yours alone
Your weekly check-in. When Sunday asks how you're doing and you answer, that answer is visible to you and to nobody else in your circle. That's enforced by the database, not by the app hiding a screen.
Your Ask Sunday conversations. Same rule. What you ask Sunday about your mother is between you and Sunday. Other circle members — including the organizer — cannot read your thread.
One honest caveat: "private from your circle" is not the same as "never leaves your phone." Your questions go to Anthropic to be answered (section 6), and the fact that you submitted a check-in, along with which of the three answers you picked, is included in product analytics (section 8). Neither is visible to anyone in your family.
Payment
If you subscribe to Care+, Apple handles the payment and Sunday never sees your card. What Sunday stores is the subscription itself: which plan, Apple's identifier for it, whether it's active, when it renews or expires, whether it's a sandbox or production purchase, and the decoded transaction record Apple signed. That last one is kept for support and billing questions and is never shown in the app.
4. What Sunday doesn't collect
- No street address. A ZIP code sets the family's clock and anchors the search for nearby communities. That's all that's needed, so that's all that's asked.
- No Social Security numbers, no financial account numbers. Sunday never asks, and nothing in the app has a place to put them.
- No location tracking. Sunday doesn't read your device's location, ever.
- No contacts, no calendar. Sunday doesn't read your address book or your calendar.
- No microphone. The camera permission is for photographing documents; the microphone is explicitly disabled.
- No advertising identifiers, no ad networks, no third-party trackers.
- No dose tracking. Sunday will never ask whether a pill was taken.
- No push notification tokens. Appointment reminders are scheduled on your phone by your phone. Nothing about them leaves the device.
5. Where your information goes
Sunday uses a small number of service providers. Each one gets only what it needs to do its job.
| Provider | What it does | What it receives |
|---|---|---|
| Supabase | Database, sign-in, file storage and the server functions that do Sunday's privileged work. | Everything in section 3. This is where your family's record lives. |
| Anthropic | Reads documents; answers Ask Sunday questions. | Document contents, and the assembled record described in section 6 — which includes the parent's name and date of birth. Never your name, email address or account identifier. |
| PostHog | Product analytics — which features get used. | Event names, your account identifier, and the small set of properties listed in section 8. No record contents. |
| Cloudflare | Receives mail sent to your family's Sunday address, and serves this website. | Inbound email in transit — sender, subject, body and attachments — passed straight through to Sunday's server. This website loads nothing from anyone and sets no cookies. |
| Apple | Sign in with Apple; App Store subscriptions; app delivery. | Whatever Apple's own systems handle — sign-in and payment. Sunday sends Apple no record data. |
| Expo (EAS) | Builds the app and delivers updates to it. | No record data. App code only. |
Anthropic, PostHog and Apple are United States companies, and PostHog is configured to its US region. If you need to know the specific region our database and file storage run in, write to help@sundaycare.app and we'll tell you.
Sunday does not sell your information, does not share it for advertising or cross-context behavioural advertising, and does not give it to anyone else — except where the law requires it, or to protect someone's safety.
Crash reporting
Sunday's code is wired for crash reporting and the setting for it exists, but the crash-reporting library is not installed in the app today and no crash reports are being sent anywhere. Errors are written to the developer console during development and nowhere else. When that changes, this page changes first.
6. When AI is involved
Sunday uses Anthropic's Claude models for two jobs. Both calls are made by Sunday's own server, never by the app on your phone, so the key that authorizes them never sits on a device.
Reading a document
When you photograph a card, a label or a discharge summary — or when one arrives by email — the file itself is sent to Claude along with an instruction to extract what's legible. Claude sends back structured fields. Nothing about you or your family goes with it: not your name, not your email, not your account identifier, not the rest of the record. Just the document.
The reading comes back to you on a confirmation screen. Nothing is saved until you say it looks right, and you can correct any field before you do.
Ask Sunday
When you ask a question, Sunday assembles a plain-text summary of the record for the person you selected and sends it with your question. That summary contains:
- the parent's name, date of birth, state and ZIP, living situation, care level and the concerns you flagged;
- the medication list;
- the care team, with phone numbers;
- appointments from the past week and the next thirty days;
- emergency information — allergies, directive status, key contacts;
- an insurance summary: the kind of plan, the plan name, and the customer service phone number;
- a list of every document on file for that person, and the full reading of the handful most relevant to what you asked;
- your last twenty messages in that conversation.
What is deliberately held back
Insurance member IDs and group numbers are never sent to the model. They're stripped out of the insurance summary, and — since the change that let Ask Sunday read your documents — they're stripped out of document readings too, wherever those two fields appear. They stay in the app, on the Records screen, where you can look them up yourself.
Be aware of what that redaction is and isn't. It removes two named fields. Other details read off an insurance card — the plan or contract number, the member name printed on the card, the effective date, and the pharmacy routing block (RxBIN, RxPCN, RxGrp) — are part of the document's reading and are included. And because the redaction works on those two named fields, a member ID that a document happened to repeat inside a free-text summary or a general "key fact" would not be caught by it.
Original files are never re-sent. Ask Sunday works from the reading taken when the document was filed, not from the photo or the PDF. If the reading missed something, Sunday is instructed to say so and point you at the original rather than fill the gap with a guess.
Sunday reaches only your own family's record — enforced by the database, under your own credentials, on every single read. And within your family, a question about one parent never reaches the other parent's file.
Retention at Anthropic, stated honestly
Sunday calls the Anthropic API under its own commercial account. Sunday's code does not enable any zero-retention option, so Anthropic's standard handling for commercial API traffic applies, governed by Anthropic's own terms and privacy policy. Sunday does not use your family's data to train any model and has no agreement permitting anyone else to. What Sunday cannot do is reach into Anthropic's systems and delete past requests on your behalf — so deleting your Sunday account (section 10) removes the record from Sunday, not the history of API calls that were made while you used it.
7. Email documents in
Care+ families get their own Sunday email address. Anything sent to it is treated as material someone is trying to put in front of your family, and it's handled cautiously.
- Cloudflare receives the mail, checks the sender's SPF, DKIM and DMARC, and rejects hard failures before Sunday sees them.
- Mail to an address that doesn't exist is accepted and silently dropped. Nothing is stored, and no bounce comes back — so nobody can probe for which addresses are real.
- Sunday records the sender's address, the subject, the message ID, when it arrived, a preview of the first 160 characters of the body, and a manifest of the attachments.
- Attachments are stored only if they're a type Sunday can actually read — JPEG, PNG, WebP or PDF — up to 8 MB each and ten per message. Everything else is recorded by filename and type only; its contents are never stored.
- If there's no readable attachment but the message body has real content in it, the body text is stored as a document and read.
- Mail files itself automatically only when the sender is someone in your circle or on a list your family approved, and the sender passed those authentication checks, and there's only one person on file to file it to. Everything else waits in a review queue until one of your editors approves or discards it.
- Sunday accepts at most 20 messages an hour for one family and 200 an hour overall. Over that, delivery is deferred, and the sending mail server retries.
When an editor discards a queued email, the stored attachments and body file are deleted. The queue entry itself stays — sender, subject, arrival time, the preview and the manifest — as a record that the mail arrived and someone decided about it. There's no way to remove that entry from inside the app.
8. What Sunday measures
Sunday sends product analytics to PostHog so we can see which features people actually use. Events carry an event name, your account identifier, and a small number of properties. No record contents are ever sent — no names, no medications, no document text, no notes.
Some of those properties do describe your family in general terms, so here they are plainly. Analytics see:
- which step of onboarding you finished, and — when you finish setup — your parent's living situation and the care level you described;
- the estimated care level (1, 2 or 3) when you complete the needs assessment;
- the type of a document when one is scanned, opened, updated or deleted — "insurance card", "medication" — never its contents;
- which kind of field was added — "insurance", "medications", "emergency info";
- which of the three answers you gave to the weekly check-in;
- the role on an invite you send or accept;
- which subscription plan you looked at, started, completed or failed to complete, and the reason a purchase failed;
- that a question was asked of Sunday — never the question, never the answer.
Signing out or deleting your account clears the identifier your phone uses for analytics. It does not delete events already sent. If you want those removed, ask us at help@sundaycare.app.
9. Who can see the record
Your circle, and nobody else. Access runs through membership: a person can reach a family's data only because there's a row saying they belong to that family, and what they can do with it depends on their role.
| Role | Can |
|---|---|
| Organizer | Everything, including inviting people and deleting the shared record. |
| Family | See everything and add to or edit the record. |
| Caregiver | See the record and add notes and observations from visits. |
| Viewer | Look, not change. |
This boundary lives in the database, so it holds even if a bug gets past the app. It's the thing we test hardest: every change to the rules runs against a proof that a member of one family cannot read or write a single row belonging to another.
Invitations are links carrying a one-time token that expires after seven days. The token alone grants nothing — it's redeemed on the server, which checks it before adding anyone.
Documents live in a private storage bucket. There are no public links, ever. When the app needs to show you a photo it mints a signed link that stops working after ten minutes.
10. How long it's kept, and what you can delete
Sunday keeps your family's record for as long as the account exists. There's no automatic expiry — a record about someone's care is meant to accumulate.
What you can delete from inside the app today
| Thing | What happens |
|---|---|
| A filed document | The record and the stored file are both deleted. Anything the document created stays — if reading an insurance card added a policy to the record, deleting the card does not remove the policy. |
| An appointment | Deleted. |
| An open invitation | Revoked and deleted. |
| A trusted email sender | Removed from the list. |
| A queued email | Discarding deletes the stored attachments and body. The queue entry stays — see section 7. |
| Your account | See below. |
Some things have no delete button in the app yet: individual medications (you mark them stopped instead), providers, insurance policies, tour notes, the planning workspace, the activity timeline, your check-in history, your Ask Sunday conversations, and the parent's record on its own. If you want any of those removed, write to help@sundaycare.app and we'll do it.
Deleting your account
Settings → Delete account, from inside the app, with no email to anyone. What happens depends on whether you're alone in the circle.
If you're the only member: the whole family record is deleted — the parent's profile, every document, medications, insurance, providers, appointments, the planning workspace, the timeline, your conversations, your check-ins, the email queue, everything — and then your account itself. Nothing is kept for a grace period. There is no undo.
If other people are in the circle: the family's records stay with them. Your mother's record belongs to the circle, not to whichever sibling leaves first. What goes is your membership, your check-ins, and your account. Your name comes off what you contributed — documents you filed and notes you wrote stay in the record, anonymized. Your Ask Sunday conversations aren't deleted, but they become permanently invisible to everyone, including us in the app, because the only person who could ever read them no longer exists.
One thing we can't promise yet
When you delete a document, Sunday removes the stored file through our storage provider's own delete operation. That file is genuinely gone.
When you delete your account, the deletion runs inside the database and removes the entries that index your family's stored files. Every one of those files immediately becomes unreachable — through the app, through any link, through us. But because that step doesn't call the storage provider's delete operation, we can't yet promise the underlying copies have been erased. This is a known gap, it's flagged in our own code, and closing it is on the list. Until it's closed, we'd rather tell you exactly this than write a sentence we can't stand behind.
Backups. Our database provider keeps routine backups so a failure can't wipe out your family's record. Deleted data can persist in those backups for the provider's retention window after it's gone from the live database. Backups aren't used to restore individual records, and anything deleted stays deleted as they age out.
Deleting your account does not cancel a Care+ subscription. Apple bills it, so only Apple can stop it: on your iPhone, Settings → your name → Subscriptions → Sunday → Cancel. Do that first.
Deleting your account also doesn't reach into our service providers. Analytics events already sent to PostHog remain until we remove them; requests already made to Anthropic remain subject to Anthropic's own retention. Ask us and we'll do what we can on both.
11. How it's protected
- Everything travels over encrypted connections, and is encrypted at rest by our database and storage providers.
- Access rules are enforced in the database on every read and write, not in app code that a bug could bypass.
- Documents sit in a private bucket. No public URLs exist. Links the app makes expire in ten minutes.
- The key that authorizes AI calls exists only in server configuration. It has never been in the app, in the source code, or in any file we publish.
- Subscriptions can only be written by the server after verifying Apple's cryptographic signature against a pinned Apple root certificate. The app cannot grant itself a paid plan.
- Inbound email is signed by our own relay and the signature is checked before a single byte of the message is parsed.
- Every change to the access rules runs against an automated proof that one family cannot reach another's data — on every table.
No system is perfect, and we won't pretend otherwise. If you find something wrong, please tell us at help@sundaycare.app.
12. HIPAA, and why Sunday isn't covered by it
Sunday is not a covered entity or a business associate under HIPAA. HIPAA applies to health plans, healthcare clearinghouses, most healthcare providers, and the companies that handle protected health information on their behalf. Sunday is none of those. It's a consumer app that a family uses to keep its own copies of its own paperwork.
That means health information you put into Sunday isn't protected by HIPAA — it's protected by this policy, by the security described above, and by whatever consumer privacy law applies where you live. We say this plainly because "HIPAA compliant" is a phrase apps use loosely, and using it here would be misleading.
One practical consequence: when you hand a document to Sunday, you're taking a copy of it out from under your provider's HIPAA obligations and putting it under ours. We think ours are good. They're just different, and you should know which is which.
13. Sunday doesn't give medical advice
Sunday is an organizing tool, not a medical device and not a medical service. It doesn't diagnose, doesn't interpret symptoms or test results, doesn't recommend or change doses, and doesn't tell you what to do about anyone's health. When a question needs clinical judgment, Sunday says what the record shows and points you at the care team.
The care-level estimate in the planning workspace is a budgeting and planning aid. It is not a medical or clinical assessment, and no one should treat it as one.
AI can be wrong. A reading taken off a photograph can miss a digit or misread a word. Check anything that matters against the original document — Sunday keeps it for exactly that reason.
In an emergency, call 911 or your local emergency number. Sunday is not an emergency service, is not monitored, and cannot summon help.
14. Children
Sunday is for adults. You must be 18 or older to have an account, and the person whose care you're coordinating is expected to be an adult. Sunday isn't directed at children and doesn't knowingly collect information from anyone under 18. If we learn that we have, we'll delete it. Tell us at help@sundaycare.app.
15. Your choices
Depending on where you live, you may have rights to see the information held about you, correct it, take a copy of it, or have it deleted. We'll honour those requests from anyone who asks, wherever they live — we'd rather not run a privacy policy that depends on your postcode.
- See it: most of it is already on your screen. For a full export, ask us.
- Correct it: almost everything is editable in the app.
- Delete it: see section 10 for what you can do yourself, and write to us for the rest.
- Object or complain: write to us. If you're in the UK or EU you may also complain to your local supervisory authority.
Requests about a parent's information can come from you or from them. We may ask for enough detail to be sure we're acting on the right record and that the person asking is entitled to ask.
16. Changes, and how to reach us
When this policy changes we'll update the date at the top, and if the change matters we'll tell you in the app before it takes effect. We won't quietly start doing something this page says we don't do.
Write to help@sundaycare.app. A person reads it.