Privacy Policy
Privacy Policy
Effective date: September 2, 2026
This Privacy Policy explains how Amrezo Inc. ("Amrezo," "we," "us," or "our") handles information when you use Cara: Mental Health Companion ("Cara"). Cara is a general wellness companion, not a medical provider, therapist, emergency service, or substitute for professional care.
Information Cara stores
Cara does not require or create a Cara account. By default, the following information is stored in the app's protected local container on your device:
- Your optional display name, adult confirmation, crisis region, preferences, consent choices, and permission settings.
- Conversations and messages, conversation summaries, memories, goals, check-ins (including mood, energy, and notes), insights, open conversation threads, communication preferences, and your feedback about exercises or responses.
- Derived wellness information, such as tentative patterns, formulations, coping strategies, intervention outcomes, and weekly summaries.
- Minimal safety-flow records, such as the assessed risk level, action selected, and timestamp. Safety screening runs on the device. Cara cannot monitor your safety or contact emergency services for you.
- Downloaded model files and related installation metadata.
- A randomly generated identifier used as an OpenAI API safety identifier when Premium cloud processing is used. This identifier is stored locally and is not your name or Cara account ID.
Because Cara conversations and check-ins concern personal wellbeing, information you choose to enter may be sensitive. Please do not enter information you do not want Cara to process. Cara's local memory filters are designed to reject certain highly sensitive details such as passwords and financial credentials, but you remain responsible for what you submit.
HealthKit
If you grant HealthKit permission, Cara requests read access to sleep analysis, step count, resting heart rate, mindful sessions, and workouts. It reads sleep, step, resting-heart-rate, and mindful-session samples to create daily aggregates and non-diagnostic wellness trends on your device. Cara does not write data to HealthKit in this release.
HealthKit-derived daily aggregates and trends remain device-only and are excluded from iCloud sync. Raw HealthKit samples are not sent to Amrezo, AIProxy, or OpenAI. Health information is not used for advertising. You can change Health permissions in iOS Settings and turn off HealthKit trends in Cara.
Voice conversations
If you grant microphone and speech-recognition permission, Cara uses the microphone for voice conversations. Speech recognition is configured to require on-device recognition, and speech synthesis uses the downloaded Kokoro model on your device. Microphone audio is not sent to Amrezo, AIProxy, or OpenAI. The resulting transcript is treated like a text message and stored or processed according to the choices described in this Policy.
Cara does not request access to your location, camera, photo library, or contacts.
Optional iCloud sync
Sync is off by default. If you enable it, Apple CloudKit synchronizes eligible Cara records through your private iCloud database. Eligible records include your profile and consent state, conversations and messages, memories, check-ins, goals, insights, personal-context records, communication preferences, and minimal safety-event metadata. HealthKit-derived records and downloaded-model metadata and files remain device-only.
Amrezo does not create an account or operate a server that receives your synced Cara database. Apple processes iCloud data under its own terms and privacy policy. Turning sync off stops future synchronization after you restart Cara, but does not automatically erase records already stored in iCloud or copies on your other devices. You can manage iCloud data through your Apple account and device settings.
On-device AI and model downloads
Cara's standard conversation, embedding, memory, retrieval, safety-screening, and voice features run on your device. On-device conversation content is not sent to Amrezo, AIProxy, or OpenAI.
When you download local AI or voice models, Cara connects to Hugging Face and, for one Kokoro voice asset, GitHub. Those services receive the network information ordinarily associated with a download request, such as your IP address, request time, user agent or device/network details made available by the connection, and the requested file. The downloaded models then run locally.
Optional Premium cloud processing
Premium cloud processing is off by default. Buying a subscription does not enable it. It is used only when you have an active Premium subscription, select the Premium cloud model, and affirmatively allow cloud processing. You can withdraw that permission at any time under You > Cara intelligence > Response model.
When enabled, Cara sends the following through AIProxy to OpenAI:
- Your current text message or on-device voice transcript.
- A bounded, relevant selection of recent conversation context, confirmed memories, communication preferences, goals, and permitted aggregate wellness trends.
- A randomly generated safety identifier.
This information is used to generate the requested response and, during memory maintenance, to propose memory or unfinished-thread candidates. Cara validates candidates locally before saving them. Microphone audio, raw HealthKit samples, contacts, downloaded models, and unrelated conversation history are not sent.
AIProxy acts as the API relay and OpenAI acts as the AI processor. Cara sets OpenAI response storage to off. Amrezo's OpenAI API project is configured for Zero Data Retention and is covered by a Business Associate Agreement with OpenAI. Under OpenAI's documented Zero Data Retention controls, eligible customer content is excluded from abuse-monitoring logs and is not used to train OpenAI models unless the API customer opts in. AIProxy's published policy says it records limited request metadata and logs response bodies for HTTP errors; an error response could therefore contain submitted or generated text. See OpenAI API data controls and the AIProxy privacy policy. No internet transmission is completely secure.
Purchases
Cara Premium subscriptions are offered through Apple's StoreKit and the App Store. Apple processes purchase, payment, subscription, and transaction information. Cara receives product and verified entitlement information needed to provide Premium features; Cara does not receive your full payment-card details. Apple's privacy policy and App Store terms govern Apple's handling of purchase information.
Analytics, advertising, and tracking
Cara does not include third-party analytics or crash-reporting SDKs. It does not display advertising, track you across other companies' apps or websites, sell personal information, or share information with data brokers.
Notifications and device security
If you enable daily check-in reminders, Cara schedules a local notification on your device. You can disable reminders in Cara or iOS Settings. If you enable the app lock, Cara uses Apple's device-owner authentication, such as Face ID or your device passcode; Cara does not receive or store your biometric data.
Retention and your choices
Local information remains until you delete individual items, erase Cara's data, or remove the app, subject to device and iCloud backups controlled by you or Apple. Premium cloud requests are subject to the provider controls described above. Download services may retain network logs under their own policies.
In You > Privacy, you can:
- Export a readable JSON copy of conversations, memories, open threads, check-ins, insights, personal-model information, formulations, intervention outcomes, and weekly reviews.
- Inspect or delete memories and conversations.
- Select Erase all Cara data to delete Cara records from the current device.
- Turn iCloud sync off or withdraw Premium cloud-processing permission.
Cara has no Cara account to delete. Erasing device data does not automatically remove existing records from your private iCloud database or copies on other devices. Manage those copies through iCloud and your devices. To ask questions about your information or request assistance, email support@messagecara.com. We may need enough information to understand and respond to your request, but because Cara generally stores data on your device or in your private iCloud database, we may not possess the data you seek.
Legal rights
Depending on where you live, you may have rights concerning personal information we control, including rights to access, correct, delete, or obtain a copy and to withdraw consent. You may contact us to exercise applicable rights. You may also have the right to complain to a privacy regulator.
Children
Cara is only for people aged 18 or older. We do not knowingly offer Cara to children. If you believe a person under 18 has provided information to us, contact us.
International processing
If you enable Premium cloud processing or download models, information may be processed in countries outside your own, including where AIProxy, OpenAI, Hugging Face, GitHub, or their infrastructure providers operate. Privacy laws in those countries may differ from those where you live.
Changes to this Policy
We may update this Policy to reflect changes to Cara, the law, or our practices. We will post the updated Policy with a new effective date. If a change materially affects your choices, we will provide notice as appropriate.
Contact us
Amrezo Inc. 6561 Western Skies Way Mississauga, Ontario L5W 1G4 Canada
Email: support@messagecara.com Website: https://www.messagecara.com
