CarePilot

Privacy Policy

Last updated: 3 August 2026

This Privacy Policy explains how ValiantLabs (“we”, “us”) collects and processes personal data when you use CarePilot, a tool that helps independent social workers convert handwritten notes into professional reports.

Data-protection roles

ValiantLabs is the data controller for the personal data needed to run your account and the service: your email address, authentication, support requests, security logs and subscription information.

For any personal data contained in the professional case notes you upload, you (the customer) are normally the data controller and ValiantLabs acts as a processor, processing that case-note data only on your documented instructions to produce your report. ValiantLabs is not the sole controller of the case-note content you upload, and this policy does not make it so. Processing of case-note data is subject to data-processing terms agreed between you and ValiantLabs, described in the Terms of Service.

Contact

If you have any questions about this policy or your personal data, email us at hello@valiantlabs.co.uk.

What CarePilot does

You upload photographs or scans of handwritten clinical notes. CarePilot uses optical character recognition (OCR) to extract the text, then an AI language model drafts a professional report from your notes. You review and edit the draft before exporting it as a Word or PDF document. Nothing is exported automatically.

Data we process

  • Your email address, used to create your account and sign you in. Passwords are hashed by our authentication provider; we cannot see them.
  • Images of handwritten notes you upload. These may contain special-category personal data (for example, health information about the people you support).
  • Text derived from those notes: OCR-extracted text, your scratchpad edits and AI-drafted report text held within a session.
  • Subscription details held via Stripe (for example, plan and billing status). We do not store your full card number; Stripe handles card data.

How your data is processed

  • Images are uploaded to a private Microsoft Azure Blob Storage container and processed by Azure Document Intelligence for text extraction. CarePilot attempts to delete each source image from Azure Blob Storage as part of the OCR request. A page is only reported as successfully completed after the image is confirmed absent. If deletion cannot be confirmed, the page is marked as failed rather than completed and may be retried. In exceptional circumstances, a temporary blob may remain until it is removed through the applicable storage or deletion workflow. We do not guarantee the instantaneous state of underlying cloud storage. Only the extracted text is kept for your session.
  • The AI rewrite drafts a professional report from your edited text, following strict faithfulness rules so it does not invent or interpret clinical findings.
  • You review and edit the draft before exporting. Exports (Word and PDF) are produced in your browser; CarePilot does not store exported files.
  • Working data for each session — uploaded images, OCR text, scratchpad edits and report versions — is removed when you press Clear Session and that action succeeds. Abandoned sessions are subject to the configured automated purge.

Lawful basis

For the account and service data where ValiantLabs is controller, we rely on contract (to run the service and your subscription) and legitimate interests (to operate, secure and improve the service).

For the personal data in the case notes you upload, you are responsible for identifying and documenting the appropriate UK GDPR Article 6 lawful basis and Article 9 condition for your processing. CarePilot does not determine that basis for you, and your acceptance of these documents does not provide consent on behalf of the children, families or any other people described in your notes. Explicit consent is one possible Article 9 condition, but it is not the only valid one; the right condition depends on your role and circumstances.

Your responsibilities as controller of case-note data

Because you are the controller of the case-note data you upload, you are responsible for ensuring you have a lawful basis to process and share it, for meeting your professional and legal obligations, and for any consent or notice required from the people described in your notes. CarePilot is a documentation tool and does not assume responsibility for your basis to process that underlying data.

Data retention

  • CarePilot attempts to delete each source image from Azure Blob Storage as part of the OCR request. A page is only reported as successfully completed after the image is confirmed absent. If deletion cannot be confirmed, the page is marked as failed rather than completed and may be retried. In exceptional circumstances, a temporary blob may remain until it is removed through the applicable storage or deletion workflow. We do not guarantee the instantaneous state of underlying cloud storage.
  • Session working data (uploaded images, OCR text, scratchpad edits and report versions) is removed when you press Clear Session and that action succeeds. Completing a report alone does not by itself delete your working data.
  • Abandoned sessions are subject to the configured automated purge, which removes their working data without further action from you.
  • Your account is retained until you ask us to delete it.

Deletion happens through the service’s deletion workflow. We do not make absolute guarantees about the instantaneous state of underlying cloud storage beyond that workflow.

Third-party processors

We use the following processors to deliver the service:

  • Base44 — application hosting, database and authentication.
  • Microsoft Azure — Document Intelligence OCR and temporary Blob Storage for images.
  • Stripe — subscription payment processing.
  • Google Fonts — web typography, loaded from Google’s content delivery network.

Each processor handles data only to provide the service and under appropriate terms. Some processors may operate outside the UK/EEA; where this happens we rely on appropriate safeguards such as a UK International Data Transfer Agreement.

Where you use CarePilot to process case-note data, a UK GDPR Article 28 Data Processing Agreement applies between you and ValiantLabs. This Data Processing Agreement is contained in the “Data Processing Agreement — UK GDPR Article 28” section of the Terms of Service and takes effect when you accept the Terms and use CarePilot to process case-note data. See the Terms of Service for the full terms.

Cookies and local storage

CarePilot uses an authentication session (cookies and browser local storage) to keep you signed in. We do not use advertising or tracking cookies.

Special-category data in case notes

Case notes may contain health data or other special-category personal data. Because you are the controller of that data, you are responsible for satisfying the Article 9 condition that applies to your processing. ValiantLabs, as processor, does not rely on your CarePilot account acknowledgement as consent for the people described in your notes. We process case-note content only to produce your report and for no other purpose.

Your rights

Under the UK GDPR you have the right to access, rectify, erase, restrict, port or object to the processing of your data, and to withdraw consent. To exercise any of these rights, email hello@valiantlabs.co.uk. You also have the right to complain to the Information Commissioner’s Office (ico.org.uk).

Changes to this policy

We may update this Privacy Policy from time to time. The date above shows when it was last revised.

CarePilot by ValiantLabshello@valiantlabs.co.uk© 2026 ValiantLabs