Privacy

How Sunday treats your family's information

This record is about someone you love. Here's exactly what Sunday collects, where it goes, and what happens when you ask for it back.

Last updated 27 September 2026.

Sunday is operated by Sunday Care, Inc., a California corporation. Where this policy says "we", "us" or "our", it means Sunday Care, Inc.

1. The short version

2. Whose information this is

Sunday is unusual: most of what it holds is about someone who isn't using it. You're the adult child, the sibling, the caregiver. The record is about your parent.

So this policy covers three groups. You, the person with the account. Your circle — the siblings and caregivers you invite, each of whom has their own account. And the person you're caring for, whose details make up most of the record and who typically has no account at all.

When you enter someone else's medical and insurance information, you're asserting that you have the authority or their permission to do so. Sunday can't verify that and doesn't try. If your parent asks what's held about them, or asks for it to be removed, write to help@sundaycare.app and we'll help. Some of it you can remove yourself from inside the app; section 10 is honest about which parts those are.

3. What Sunday collects

Your account

An email address and password, or Sign in with Apple. If you use Apple, Apple gives Sunday your name and an email address (which may be Apple's private relay address rather than your real one), and Sunday stores the name on your account. Sunday never sees your Apple password.

Sunday also records which circle you belong to, your role in it, and the name you go by in the circle.

The record you build

Everything below is entered by you or your circle — by typing it, by photographing a document, or by forwarding an email.

WhatSpecifically
The person First and last name, what you call them ("Mom"), date of birth, ZIP code and the state derived from it, living situation, who they live with, how you'd describe the care they need, the concerns you flagged at setup, and a photo if you add one. No street address is ever collected.
Insurance Plan type and name, plan or contract number, member ID, group number, the pharmacy block (RxBIN, RxPCN, RxGrp), customer service phone, and the photo of the card.
Care team Provider names, specialties, phone numbers, addresses and your notes.
Medications A list: name, strength, directions as printed, who prescribed it, whether it's active or stopped, and the photo of the label. No doses taken, no schedule, no adherence data — Sunday doesn't track any of that, by design.
Appointments Title, date and time, time zone, location, the provider, questions you want to ask, and your notes.
Documents The file you uploaded or forwarded, its type and title, and the full structured reading Sunday took off it.
Emergency card Allergies, advance-directive status, DNR/POLST status, and key contacts with their phone numbers.
Planning workspace Your answers to the needs assessment and the care level it estimated; communities you've added with their pricing; tour notes, photos and the questions you still have open; and how your circle voted on each place.
Activity A timeline of what happened in the circle — a document filed, a record updated — so the family can see what's moved.

Two things that stay yours alone

Your weekly check-in. When Sunday asks how you're doing and you answer, that answer is visible to you and to nobody else in your circle. That's enforced by the database, not by the app hiding a screen.

Your Ask Sunday conversations. Same rule. What you ask Sunday about your mother is between you and Sunday. Other circle members — including the organizer — cannot read your thread.

One honest caveat: "private from your circle" is not the same as "never leaves your phone." Your check-in answers are stored in Sunday's database, and your Ask Sunday questions go to Anthropic to be answered (section 6). Neither is visible to anyone in your family.

Payment

If you subscribe to Care+, Apple handles the payment and Sunday never sees your card. What Sunday stores is the subscription itself: which plan, Apple's identifier for it, whether it's active, when it renews or expires, whether it's a sandbox or production purchase, and the decoded transaction record Apple signed. That last one is kept for support and billing questions and is never shown in the app.

4. What Sunday doesn't collect

5. Where your information goes

Three companies process information for Sunday: Anthropic PBC, Supabase and Cloudflare. For each one, here is what it receives, how that information was collected in the first place, and every use that's made of it.

Anthropic PBC — the Claude API

What it receives. The contents of documents Sunday reads — the photo, upload or emailed file itself; for Ask Sunday, your question along with the assembled record summary described in section 6, which includes the parent's name and date of birth; and, for the medication checks and the medication grouping described there, the parent's medication list (names, strengths and directions), any allergies on file, and the parent's first name. Never your name, email address or account identifier, and never insurance member IDs or group numbers, which are stripped out before anything is sent.

How that information is collected. You or someone in your circle put it there: you photographed or uploaded the document, forwarded the email, or typed the question. The Ask Sunday summary is assembled by Sunday's own server from what your family entered. Nothing goes to Anthropic until you have said yes to AI features in the app — Sunday asks before the first use, and Settings turns it off or back on.

Every use. Four, each of them something you see in the app: reading a document you added; answering a question you asked Sunday; flagging medications worth discussing with the doctor — the "Worth a look" cards on Today; and grouping the medication list by what each one is for. Nothing else. Anthropic does not use this data to train its AI models, under its Commercial Terms of Service, and Sunday has no agreement permitting anyone else to. Retention at Anthropic is described honestly in section 6.

Supabase

What it receives. Everything in section 3 — the database, sign-in, private file storage and server functions all run on Supabase. This is where your family's record lives.

How that information is collected. Entered by you and your circle — typed in, photographed, or forwarded by email — plus your account details when you sign up and the subscription record Apple's signed transaction produces.

Every use. Storing the record, and serving it back to your circle under the access rules enforced in the database itself. Supabase processes it as Sunday's infrastructure and for nothing of its own.

Cloudflare

What it receives. Inbound email. Mail sent to your family's Sunday address — an address ending in in.sundaycare.app — arrives at Cloudflare first: the sender's address, the subject, the message body and any attachments, in transit.

How that information is collected. Someone sent it. You or your circle forwarded a bill, a letter or a discharge summary to the family's address, or someone outside the circle — a clinic, an insurer — wrote to that address directly.

Every use. One: carrying the mail to Sunday. Cloudflare checks the sender's SPF, DKIM and DMARC, rejects hard failures, and hands everything else straight to Sunday's own server for filing, where the handling in section 7 begins. Your family's record is never stored at Cloudflare.

The same protection, confirmed

We confirm that each of these three companies provides the same or equivalent protection for your information as this policy describes. Each processes it under written commercial terms with Sunday that bind it to confidentiality and security, each may use the data only to provide its service to Sunday, and none may sell it, share it for advertising, or use it for purposes of its own.

The platform, and the pipes

One more company touches your data without processing it on Sunday's behalf. Apple is the platform: Sign in with Apple and Care+ billing happen inside Apple's own systems, under Apple's own terms, and Sunday sends Apple no record data. This website is served as static files: it loads nothing from anyone and sets no cookies. The tooling that builds the app never touches your data at all.

Your data is stored on servers located in the United States. Anthropic, Supabase and Cloudflare are United States companies. If you need to know the specific region our database and file storage run in, write to help@sundaycare.app and we'll tell you.

Sunday does not sell your information, does not share it for advertising or cross-context behavioural advertising, and does not give it to anyone else — except where the law requires it, or to protect someone's safety.

6. When AI is involved

Sunday uses Anthropic's Claude models for four jobs: reading a document, answering an Ask Sunday question, flagging medications worth discussing with the doctor, and grouping the medication list by what each one is for. Every call is made by Sunday's own server, never by the app on your phone, so the key that authorizes them never sits on a device.

None of it happens until you say yes. The app asks before your first AI moment — stating in the app itself what's shared, who receives it and why — and records your answer. When that statement changes, the app asks again before any further use. Settings turns AI features off or back on at any time. With them off, documents still store and file for you to fill in by hand; nothing about the record changes except that Sunday stops reading, answering, flagging and grouping.

Reading a document

When you photograph a card, a label or a discharge summary — or when one arrives by email — the file itself is sent to Claude along with an instruction to extract what's legible. Claude sends back structured fields. Nothing about you or your family goes with it: not your name, not your email, not your account identifier, not the rest of the record. Just the document.

The reading comes back to you on a confirmation screen. Nothing is saved until you say it looks right, and you can correct any field before you do.

Ask Sunday

When you ask a question, Sunday assembles a plain-text summary of the record for the person you selected and sends it with your question. That summary contains:

What is deliberately held back

Insurance member IDs and group numbers are never sent to the model. They're stripped out of the insurance summary, and — since the change that let Ask Sunday read your documents — they're stripped out of document readings too, wherever those two fields appear. They stay in the app, on the Records screen, where you can look them up yourself.

Be aware of what that redaction is and isn't. It removes two named fields. Other details read off an insurance card — the plan or contract number, the member name printed on the card, the effective date, and the pharmacy routing block (RxBIN, RxPCN, RxGrp) — are part of the document's reading and are included. And because the redaction works on those two named fields, a member ID that a document happened to repeat inside a free-text summary or a general "key fact" would not be caught by it.

Original files are never re-sent. Ask Sunday works from the reading taken when the document was filed, not from the photo or the PDF. If the reading missed something, Sunday is instructed to say so and point you at the original rather than fill the gap with a guess.

Sunday reaches only your own family's record — enforced by the database, under your own credentials, on every single read. And within your family, a question about one parent never reaches the other parent's file.

Medication checks and grouping

Two quieter jobs run without a question being asked. When the medication list on a parent's record changes, Sunday sends that list — the names, strengths and directions on file — together with any allergies on the emergency card and the parent's first name, and asks Claude what on it is worth discussing with the doctor: two medications that may interact, a medication that conflicts with a listed allergy, the same medication listed twice. What comes back appears as a "Worth a look" card on Today. And when the Medications screen opens with medications not yet filed under a purpose, Sunday sends their names and asks what each one is generally for, so the list can be grouped that way.

Both are information to raise with the care team, never a diagnosis and never advice — every card says so — and both are covered by the same yes as everything else here. Nothing about you goes with either call, and nothing else from the record does.

Retention at Anthropic, stated honestly

Sunday calls the Anthropic API under its own commercial account. Sunday's code does not enable any zero-retention option, so Anthropic's standard handling for commercial API traffic applies, governed by Anthropic's Commercial Terms of Service and privacy policy. Under those Commercial Terms, Anthropic does not use Sunday's data to train its AI models. Sunday does not use your family's data to train any model either, and has no agreement permitting anyone else to. What Sunday cannot do is reach into Anthropic's systems and delete past requests on your behalf — so deleting your Sunday account (section 10) removes the record from Sunday, not the history of API calls that were made while you used it.

7. Email documents in

Every family gets its own Sunday email address, free on any plan. Anything sent to it is treated as material someone is trying to put in front of your family, and it's handled cautiously.

When an editor discards a queued email, the stored attachments and body file are deleted. The queue entry itself stays — sender, subject, arrival time, the preview and the manifest — as a record that the mail arrived and someone decided about it. There's no way to remove that entry from inside the app.

8. Analytics and crash reporting — not switched on

Two pieces of Sunday's code are built but not running. Anyone who inspects the app can see them, so here they are, stated plainly.

Product analytics. The app ships with an analytics library — PostHog's — included in its code. It is not activated: no analytics key is configured in the app as shipped, the library is never started, and no events are transmitted. PostHog has received no data from Sunday, about you or anyone.

Crash reporting. A crash-reporting module exists in Sunday's code as an inactive stub, and no crash-reporting library is installed behind it. Errors are written to the developer console during development and go nowhere else. No crash report has ever been sent anywhere.

If either is ever turned on, this policy changes first. The company involved would join section 5 by name — what it receives, how that information is collected, and every use made of it — before the first event or report is sent.

9. Who can see the record

Your circle, and nobody else. Access runs through membership: a person can reach a family's data only because there's a row saying they belong to that family, and what they can do with it depends on their role.

RoleCan
OrganizerEverything, including inviting people and deleting the shared record.
FamilySee everything and add to or edit the record.
CaregiverSee the record and add notes and observations from visits.
ViewerLook, not change.

This boundary lives in the database, so it holds even if a bug gets past the app. It's the thing we test hardest: every change to the rules runs against a proof that a member of one family cannot read or write a single row belonging to another.

Invitations are links carrying a one-time token that expires after seven days. The token alone grants nothing — it's redeemed on the server, which checks it before adding anyone.

Documents live in a private storage bucket. There are no public links, ever. When the app needs to show you a photo it mints a signed link that stops working after ten minutes.

10. How long it's kept, and what you can delete

Sunday keeps your family's record for as long as the account exists. There's no automatic expiry — a record about someone's care is meant to accumulate.

What you can delete from inside the app today

ThingWhat happens
A filed document The record and the stored file are both deleted. Anything the document created stays — if reading an insurance card added a policy to the record, deleting the card does not remove the policy.
An appointmentDeleted.
An open invitationRevoked and deleted.
A trusted email senderRemoved from the list.
A queued emailDiscarding deletes the stored attachments and body. The queue entry stays — see section 7.
Your accountSee below.

Some things have no delete button in the app yet: individual medications (you mark them stopped instead), providers, insurance policies, tour notes, the planning workspace, the activity timeline, your check-in history, your Ask Sunday conversations, and the parent's record on its own. If you want any of those removed, write to help@sundaycare.app and we'll do it.

Deleting your account

Settings → Delete account, from inside the app, with no email to anyone. What happens depends on whether you're alone in the circle.

If you're the only member: the whole family record is deleted — the parent's profile, every document, medications, insurance, providers, appointments, the planning workspace, the timeline, your conversations, your check-ins, the email queue, everything — and then your account itself. Nothing is kept for a grace period. There is no undo.

If other people are in the circle: the family's records stay with them. Your mother's record belongs to the circle, not to whichever sibling leaves first. What goes is your membership, your check-ins, and your account. Your name comes off what you contributed — documents you filed and notes you wrote stay in the record, anonymized. Your Ask Sunday conversations aren't deleted, but they become permanently invisible to everyone, including us in the app, because the only person who could ever read them no longer exists.

One thing we can't promise yet

When you delete a document, Sunday removes the stored file through our storage provider's own delete operation. That file is genuinely gone.

When you delete your account, the deletion runs inside the database and removes the entries that index your family's stored files. Every one of those files immediately becomes unreachable — through the app, through any link, through us. But because that step doesn't call the storage provider's delete operation, we can't yet promise the underlying copies have been erased. This is a known gap, it's flagged in our own code, and closing it is on the list. Until it's closed, we'd rather tell you exactly this than write a sentence we can't stand behind.

Backups. Our database provider keeps routine backups so a failure can't wipe out your family's record. Deleted data can persist in those backups for the provider's retention window after it's gone from the live database. Backups aren't used to restore individual records, and anything deleted stays deleted as they age out.

Deleting your account does not cancel a Care+ subscription. Apple bills it, so only Apple can stop it: on your iPhone, Settings → your name → Subscriptions → Sunday → Cancel. Do that first.

Deleting your account also doesn't reach into Anthropic's systems: requests already made while you used Sunday remain subject to Anthropic's own retention, as section 6 explains. Ask us and we'll do what we can.

11. How it's protected

No system is perfect, and we won't pretend otherwise. If you find something wrong, please tell us at help@sundaycare.app.

12. HIPAA, and why Sunday isn't covered by it

Sunday is not a covered entity or a business associate under HIPAA. HIPAA applies to health plans, healthcare clearinghouses, most healthcare providers, and the companies that handle protected health information on their behalf. Sunday is none of those. It's a consumer app that a family uses to keep its own copies of its own paperwork.

That means health information you put into Sunday isn't protected by HIPAA — it's protected by this policy, by the security described above, and by whatever consumer privacy law applies where you live. We say this plainly because "HIPAA compliant" is a phrase apps use loosely, and using it here would be misleading.

One practical consequence: when you hand a document to Sunday, you're taking a copy of it out from under your provider's HIPAA obligations and putting it under ours. We think ours are good. They're just different, and you should know which is which.

13. Sunday doesn't give medical advice

Sunday is an organizing tool, not a medical device and not a medical service. It doesn't diagnose, doesn't interpret symptoms or test results, doesn't recommend or change doses, and doesn't tell you what to do about anyone's health. When a question needs clinical judgment, Sunday says what the record shows and points you at the care team.

The care-level estimate in the planning workspace is a budgeting and planning aid. It is not a medical or clinical assessment, and no one should treat it as one.

AI can be wrong. A reading taken off a photograph can miss a digit or misread a word. Check anything that matters against the original document — Sunday keeps it for exactly that reason.

In an emergency, call 911 or your local emergency number. Sunday is not an emergency service, is not monitored, and cannot summon help.

14. Children

Sunday is for adults. You must be 18 or older to have an account, and the person whose care you're coordinating is expected to be an adult. Sunday isn't directed at children and doesn't knowingly collect information from anyone under 18. If we learn that we have, we'll delete it. Tell us at help@sundaycare.app.

15. Your choices

Depending on where you live, you may have rights to see the information held about you, correct it, take a copy of it, or have it deleted. We'll honour those requests from anyone who asks, wherever they live — we'd rather not run a privacy policy that depends on your postcode.

Requests about a parent's information can come from you or from them. We may ask for enough detail to be sure we're acting on the right record and that the person asking is entitled to ask.

16. Changes, and how to reach us

When this policy changes we'll update the date at the top, and if the change matters we'll tell you in the app before it takes effect. We won't quietly start doing something this page says we don't do.

Write to help@sundaycare.app. A person reads it.