Privacy Policy
Last updated: February 22, 2026
1. Information We Collect
The information we collect depends on how you interact with us.
1.1 Website Visitors (No Account Required)
When you visit our website to read articles or learn about Alula, we collect:
Device and technical data such as IP address, browser type, device type, and operating system. Usage data such as pages visited, referring URLs, and time spent on pages. Cookies and similar technologies as described in our [Cookie Policy]. On the editorial website, analytics and marketing cookies are not active until you provide consent, because our editorial content covers health-related topics. On the Alula platform, analytics and marketing cookies are active by default but can be disabled through our cookie settings.
1.2 CareSpace Users (Account Holders)
When you create an account and use CareSpaces, we collect the information above plus:
Account Information. Name, email address, password (or Google OAuth credentials), and optionally your phone number, date of birth, gender, profile photo, biography, and timezone.
CareSpace Information. Your role, family relationship, availability, preferred contact method, home address, and any notes you provide.
Health and Medical Information. If you or other CareSpace members use our Captain Hub and Manifest features, the Service may store medical conditions, diagnoses, medications (including dosage, frequency, and prescriber), allergies, blood type, family health history, healthcare provider information, and health insurance details. This information is entered voluntarily by CareSpace members and is not verified by Alula. The Manifest feature allows care team members to share this health information with others outside the CareSpace in an emergency. By contributing health information to a CareSpace, you acknowledge that it may be shared externally via the Manifest in emergency situations.
Home Access and Emergency Information. Home addresses, access codes, pet information, medication storage locations, special instructions, and emergency contact details.
Payment Information. Payment details are collected and processed directly by Stripe. We do not store your full payment card information. We retain your Stripe customer ID, subscription plan, and billing history.
Communications. Content you create within CareSpaces (posts, comments, task notes) and communications with our support team.
Consent Records. Your acceptance of our Terms of Service, age verification, SMS consent, and cookie preferences.
1.3 Information Collected Automatically
For all users, we automatically collect:
- Usage data including pages and features accessed, actions taken, and session duration.
- Device and technical data including IP address, browser type, device type, and operating system.
- Analytics data to understand how the Service is used (you may opt out through cookie settings).
- Server logs for security and operational purposes.
1.4 Information from Third Parties
Google OAuth. If you sign in with Google, we receive your name, email address, and profile picture.
Google Calendar. If you enable calendar integration, we access your calendar events to provide scheduling features.
1.5 Information Provided by Others
Other CareSpace members may provide information about you, including health and medical information, emergency contact details, and care-related notes. If you are designated as a Captain (care receiver), other members of your CareSpace may enter and manage health information on your behalf.
2. How We Use Your Information
- Providing the Service: Operating CareSpaces and our informational website; managing accounts; processing subscriptions; and delivering notifications.
- Communication: Sending transactional emails, SMS notifications (with your consent), and in-app notifications.
- Improvement and Analytics: Understanding how the Service is used and improving features.
- Security: Detecting and preventing fraud, unauthorized access, and other harmful activity.
- Legal Compliance: Complying with applicable laws, regulations, and legal processes.
- Marketing Attribution: Tracking referral sources and campaign effectiveness.
3. How We Share Your Information
We do not sell your personal information. We share your information only in the following circumstances:
3.1 Within CareSpaces
Most content you contribute to a CareSpace — including posts, comments, tasks, events, health data, and emergency plans — is visible to all members of that CareSpace. Some content, such as documents, is shared at the individual level and is only visible to the specific members you choose to share it with.
3.2 Service Providers
We share information with third-party service providers who process data on our behalf, including cloud infrastructure, payment processing, analytics, email delivery, SMS delivery, and authentication services. Each provider is contractually obligated to use your information only as necessary to provide their services to us.
3.3 Legal Requirements
We may disclose your information if required by law or in response to valid legal process.
3.4 Business Transfers
If Alula is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change via email or prominent notice on the Service.
3.5 With Your Consent
We may share your information in other circumstances with your explicit consent.
4. Your Privacy Rights
4.1 All Users
You have the right to:
- Access and update your account information through your profile settings.
- Delete your account through Settings > Account or by contacting us at privacy@withalula.com.
- Request a copy of your data by contacting us at privacy@withalula.com.
- Manage cookie preferences at any time through the cookie settings link in the footer of the Service.
- Opt out of SMS notifications through your notification settings.
- Opt out of analytics and marketing cookies through the cookie settings link in the footer of the Service.
4.2 California Residents (CCPA/CPRA)
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to Know: You may request the categories and specific pieces of personal information we have collected.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing: We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: We only use sensitive personal information (health data, home access information) for the purposes of providing the Service as described in this Privacy Policy.
- Right to Non-Discrimination: We will not discriminate against you for exercising your privacy rights.
To exercise these rights, contact us at privacy@withalula.com. We will respond to verifiable requests within 45 days.
Categories of Personal Information Collected (CCPA Disclosure):
- Identifiers (name, email, phone, IP address)
- Customer records (billing information, subscription history)
- Protected classification characteristics (age, gender)
- Commercial information (subscription plans, transaction history)
- Internet or electronic network activity (usage data, analytics)
- Geolocation data (timezone, IP-derived approximate location)
- Sensitive personal information (health data, home access codes)
4.3 Other State Privacy Laws
Residents of Colorado, Connecticut, Virginia, and other states with comprehensive privacy laws may have similar rights. To exercise these rights, contact us at privacy@withalula.com.
5. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When data is no longer needed, we delete it or anonymize it in accordance with our retention practices:
- Active accounts: Data is retained for the duration of your use of the Service.
- After subscription cancellation: CareSpace data is retained for a limited grace period with read-only access, then permanently deleted.
- Cookie consent records: Retained to demonstrate compliance with applicable requirements.
- Payment records: Retained as required for tax, accounting, and legal compliance.
6. Data Security
We implement industry-standard technical and organizational measures to protect your personal information, including encryption of data at rest and in transit, network segmentation, hashed passwords, role-based access controls, and infrastructure monitoring.
While we strive to protect your information, no method of electronic transmission or storage is completely secure. We cannot guarantee absolute security.
7. Health Information Disclaimer
Alula is a care coordination tool designed to help families organize and share information about the care of loved ones. Alula is not a healthcare provider, medical device, or covered entity under HIPAA. The health and medical information stored on the platform is entered voluntarily by users and is not verified, reviewed, or endorsed by any medical professional.
Alula does not provide medical advice, diagnoses, or treatment recommendations. The Service is not a substitute for professional medical care. Always consult qualified healthcare providers for medical decisions. Alula disclaims any liability for actions taken based on health information stored on the platform.
Health information entered into a CareSpace is visible to all members of that CareSpace. Additionally, the Manifest feature allows care team members to share health information with individuals outside the CareSpace in emergency situations. You should only contribute health information you are comfortable being shared in this manner.
8. Children's Privacy
Alula is not directed at children under 13. We require all users to verify that they are 13 years of age or older when creating an account. We do not knowingly collect personal information from children under 13. If we learn that we have collected information from a child under 13, we will take steps to delete that information promptly.
If you believe a child under 13 has provided us with personal information, please contact us at privacy@withalula.com.
9. International Users
Alula is based in the United States. Our servers and service providers are located in the United States. The Service is intended for use within the United States, and we make no representations that the Service is appropriate or available for use in other locations.
If you access the Service from outside the United States, please be aware that your information will be transferred to, stored, and processed in the United States, where privacy laws may differ from those in your jurisdiction. By using the Service, you consent to the transfer of your information to the United States.
10. Third-Party Links and Services
The Service may contain links to third-party websites or integrate with third-party services. This Privacy Policy does not apply to those third parties. We encourage you to review the privacy policies of any third-party services you access through Alula, including Google (for authentication and calendar) and YouTube (for educational content).
11. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by posting the updated policy on the Service with a revised "Last Updated" date and, where appropriate, by email.
Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.
12. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about your data, please contact us:
Vestality LLC (d/b/a Alula) Email: privacy@withalula.com Website: https://withalula.com