Skip to content
chaleur

Privacy is the first decision, not a policy added at the end.

chaleur is being designed to handle the most sensitive information — who a person cares for, and why they are vulnerable — without that information ever leaving the device it was entered on. The architecture treats a bespoke privacy mistake as fatal to the project, so the boundaries are built in rather than promised.

Where data lives

Sensitive data stays on the device.

All sensitive health and contact information (who a person cares for, and why they are vulnerable) is designed to stay on the carer's own device under encryption, with nothing held on chaleur's servers. The working prototype is built toward that architecture, and holding it is a foundational decision rather than a feature to be added later.

What gets shared

Coordination shares almost nothing.

When co-carers coordinate, only a thin, encrypted coordination signal (the bare fact that one co-carer has already acted) is designed to pass between them, relayed through a server that cannot read it; never a person's identity or condition. Secure cross-device sync is designed and pending independent review; it is not yet built.

What we don't do

The file that never gets created.

Public programmes that protect vulnerable people usually do it by listing them. chaleur is designed to deliver a vulnerability register's protective effect without ever assembling the centralised file of health data such registers require. The policy history behind that choice is set out on the Evidence page.

How data is protected

Independent review before any real use.

Encryption, key management and data-protection design are slated for external expert review as release gates, not self-certified.

Independent review is part of the plan, not a promise.

That review is one of the first tasks a clinical or institutional partnership would take on.

Explore partnerships