Care MCP
Who it's forMCPAPIPricing

Explore

Who it's forMCPAPIPricing

Service

PersonalProfessionalsOrganisations

Support

FAQContactLearn

Sign in

PersonalProfessionalsOrganisations

Privacy policy

In force since 2026-09-28.

The controller of your personal data is Portfoliobox Stockholm AB, org. no. 556894-4382, VAT no. SE556894438201, Rånövägen 30, 168 39 Bromma, Sweden, caremcp@portfoliobox.net. Write to caremcp@portfoliobox.net about anything in this policy.

When an organisation orders for its own clients through our API, the organisation is the controller of those clients' data and we process it on its behalf under a data processing agreement. If you are such a client, the organisation's own privacy policy applies, and your requests go to it first.

What we hold, and why

Your account. A stable identity from Apple or Google, or an email and a hashed password, your birth date, country, region where it matters, language and currency, and the version and time of the health data notice you agreed to. The birth date and the country are what our rules read on every order, the language is your browser's, kept so your documents can be read to you in it, and the consent record shows that you agreed.

Your orders. Each order holds the brief your assistant sent and the document written for it. A brief may carry health data: the health declaration and the diagnoses, medications, conditions and lab values you told your assistant about. That is covered by the health data notice.

Your payments. Your credit, its deposits and charges, and a receipt for each deposit with the amount, the VAT, your country and, for a business, the VAT number. The card details stay with Mollie.

Your assistants. Which assistants you have allowed to act for you, so you can see and revoke them.

Organisations. For an organisation account: the company's name, country, VAT number, the email and password of the account, its API keys in hashed form, its webhook address, its payments, and for each of its clients the reference it gave, the birth date, country and language, and the orders.

Professionals. For a professional: name, email, hashed password, country, languages, professions, the countries where they hold a credential, whether they are a contractor or an employee, the orders they took, and what they earned and were paid.

Applications and messages. When you apply to write for us or write to us through the contact page, we receive what you send by email: your name, email and message, and for an application your LinkedIn profile, your certifications and your education.

Technical data. Our host keeps short-lived request logs with IP addresses and times, to run and protect the service.

Legal bases

PurposeLegal basis
Running your account and delivering your ordersContract, article 6(1)(b) of the GDPR
Health data in your briefsYour explicit consent, article 9(2)(a)
Receipts, bookkeeping and taxA legal obligation, article 6(1)(c)
Security, preventing abuse, handling disputesOur legitimate interest, article 6(1)(f)
Contracting and paying professionalsContract, article 6(1)(b), and legal obligation for payments
Assessing applications and answering messagesOur legitimate interest, article 6(1)(f), or steps before a contract

Who sees it

The professional who takes an order reads its brief with your age and language, never your name, your email or your account. Professionals are bound by confidentiality in their agreement with us.

Our staff do not read briefs or documents. The tools we operate the service with do not show them, and the data is sealed in the database. A person reads an order only when you ask us to, or when we must to investigate abuse or answer an authority.

The companies we use to run the service, each bound by an agreement with us:

Sub-processorWhat it doesData it handlesWhere
Fly.io, Inc.Hosting of the service and its databaseEverything the service stores, briefs and documents sealedAmsterdam, the Netherlands. A US company: Standard Contractual Clauses
Mollie B.V.PaymentsThe amount, the payer's country and what the card or bank provides. Never a brief or a documentThe Netherlands
Plus Five Five, Inc. (Resend)Sending emailThe recipient's email and the message: receipts, notices that a document is ready, messages to us. Never a brief or a documentUnited States: Standard Contractual Clauses
Apple Inc. and Google LLCSign in with Apple and Google, each as its own controllerA stable account identifier and, when shared, an emailTheir own terms and safeguards

Authorities, when the law requires it.

We do not sell your data, we do not share it for advertising, and we do not use your briefs or documents to train AI models.

Where it is kept

The service and its database run in Amsterdam, in the European Union. Briefs, drafts and documents are encrypted in the database with a key kept outside it, and every connection is encrypted. When a company we use is outside the EU, the transfer is covered by the European Commission's Standard Contractual Clauses.

How long

DataKept
Your account, orders, briefs and documentsUntil you delete your account
Receipts, charges and the order records the books need, without your name or emailSeven years after the end of the year, as Swedish bookkeeping law requires
The record of your health data consentAs long as the order records it covers
Sessions30 days
Applications we decline, and messages to usTwelve months after the last contact
A professional's earnings and payoutsSeven years, as bookkeeping law requires
Request logs at our hostA short time, under the host's own rules

When you delete your account, your identity, email, sessions and assistant access are removed, and every brief, draft and document is erased. What stays is what the books need: amounts, dates, country, currency and the kind of order, no longer linked to you by name or email.

Cookies

We set one cookie when you sign in, to keep you signed in: cr_session for clients and cr_pro for professionals. It is strictly necessary and needs no consent. We use no analytics, advertising or tracking cookies. The sign-in page loads Apple's and Google's sign-in, and those companies may set cookies of their own under their policies when you use them.

Decisions made by rules

Every order passes rules before a professional sees it: your age, your country and your answers on the health declaration. An order that fails a rule is refused automatically and you are told why. If you think a refusal is wrong, write to us and a person looks at it.

Your rights

You may ask for a copy of your data, have it corrected, have it erased, have its use restricted, object to processing based on our legitimate interest, and receive the data you gave us in a machine-readable form. You may withdraw your health data consent at any time by deleting your account; that does not affect what was done before. Most of this you can do yourself through your assistant or your account page; for the rest, write to us and we answer within a month.

You may also complain to the Swedish Authority for Privacy Protection (IMY), imy.se, or to the authority where you live.

Changes

When this policy changes, we update the date above, and for a change that matters we tell you by email or when you next sign in.

Care MCP

Care MCP by Portfoliobox

Personal training and nutrition plans from certified professionals, ordered by your AI agent over MCP or our API.

For AI

  • llms.txt
  • sitemap.xml

Service

  • Personal
  • Professionals
  • Organisations
  • Pricing

Documentation

  • MCP
  • API
  • Learn
  • FAQ

Company

  • About
  • Contact
  • Security
Terms of servicePrivacy policyHealth data noticeOrganisation termsData processing agreementProfessional agreementSub-processors

Portfoliobox Stockholm AB, Rånövägen 30, 168 39 Bromma, Sweden. Org. no. 556894-4382, VAT no. SE556894438201. caremcp@portfoliobox.net.