Privacy is the first decision, not a policy added at the end.
chaleur is being designed to handle the most sensitive information — who a person cares for, and why they are vulnerable — without that information ever leaving the device it was entered on. The architecture treats a bespoke privacy mistake as fatal to the project, so the boundaries are built in rather than promised.
Where data lives
Sensitive data stays on the device.
All sensitive health and contact information (who a person cares for, and why they are vulnerable) is designed to stay on the carer's own device under encryption, with nothing held on chaleur's servers. The working prototype is built toward that architecture, and holding it is a foundational decision rather than a feature to be added later.
What gets shared
Coordination shares almost nothing.
When co-carers coordinate, only a thin, encrypted coordination signal (the bare fact that one co-carer has already acted) is designed to pass between them, relayed through a server that cannot read it; never a person's identity or condition. Secure cross-device sync is designed and pending independent review; it is not yet built.
What we don't do
The file that never gets created.
Public programmes that protect vulnerable people usually do it by listing them. chaleur is designed to deliver a vulnerability register's protective effect without ever assembling the centralised file of health data such registers require. The policy history behind that choice is set out on the Evidence page.
How data is protected
Independent review before any real use.
Encryption, key management and data-protection design are slated for external expert review as release gates, not self-certified.
Consent and agency
Where the data lives is not the same question as whether the person agreed. Two paths lead into chaleur. A person can set it up for themselves, holding their own profile and consenting for themselves, which gives a vulnerable person agency rather than a label. More often a carer sets it up for someone they look after, and where that person can consent, the carer is asked to confirm the relationship and to record that the person has agreed to be added. The harder case is real and chaleur does not wave it away: where a person cannot consent, or does not know a profile exists, the design's answer is to hold that information only on the carer's own device, never in a central register, and to treat it as sensitive throughout. Holding the data carefully is not the same as resolving the question of consent and autonomy, and a formal pilot will need a consent and ethics framework that a clinical and ethics partner would help design.
Independent review is part of the plan, not a promise.
That review is one of the first tasks a clinical or institutional partnership would take on.