Privacy Policy
- Effective Date:
- August 24, 2026
- Last Updated:
- August 29, 2026
- Version:
- 2026-03
Quiet Cards is operated by TOT Solutions, LLC.
Introduction
Quiet Cards is operated by TOT Solutions, LLC, a Tennessee limited liability company (“Quiet Cards,” “we,” “us,” or “our”).
Quiet Cards is designed to help caregivers create communication cards for people they care for. Because users may choose to provide personal, health-related, and other sensitive information about themselves or a loved one, we take the privacy and security of that information seriously.
This Privacy Policy explains what information Quiet Cards collects, how we use it, when information may be processed by service providers, and the choices available to you.
Privacy in Plain English
This section is a friendly summary. The detailed sections below control.
You decide what to add. Quiet Cards never requires you to fill in everything. A card can be created from very little information.
Some of what you save is just for you. Medications, allergies, other medical conditions, mobility or equipment details, physician information, and photographs are stored so you have them handy in one place. That reference information is not sent to the AI that helps write your card wording.
Information you provide is used to run the features you ask for. When you ask Quiet Cards to help write a card, the details that shape that card are used to write it. This includes things like the situation, how you want the person referred to, their relationship to you, a short condition description, the stage you selected, the behaviors and communication points you chose, and any notes you wrote for that card or saved as Card Creation Notes.
We do not ask for identity or financial information about your Loved One. Quiet Cards has no place to enter a Social Security number, driver's license, passport or other government identification number, bank account, or credit or debit card information for the person you care for. If you purchase a membership, your payment details are entered directly with our payment processor, Stripe, and are not stored by Quiet Cards.
Other users cannot see your information. Loved One profiles and saved cards are restricted to your own account.
Our internal Admin view is deliberately limited. It shows account information such as email address, membership status, and simple counts. It does not display Loved One profile details, card text, notes, medical or reference information, or photographs.
We are honest about staff access. Like any operator of a hosted service, we hold administrative credentials that could technically reach stored data. We restrict that access to what is needed to operate, support, and secure Quiet Cards, we do not browse Loved One details or card content, and administrative views of account information are recorded in an internal access log.
We do not sell Loved One information or card content, and we do not share it with advertisers.
You can delete your information. Individual cards and profiles can be deleted at any time, and your entire account can be permanently deleted from Settings.
No online service can promise perfect security. We describe the protections we use, and their limits, in the Security section below.
1. Information We Collect
Account Information
When you create a Quiet Cards account, we may collect or process:
your name or display name;
email address;
account and authentication information;
account identifiers;
confirmation that you are at least 18 years old; and
records of your acceptance of our Terms of Service and acknowledgment of our Privacy Policy, including the date and applicable document versions.
Quiet Cards uses Supabase Auth for account authentication. If you use Google sign-in, authentication is facilitated through Lovable's OAuth service. Quiet Cards does not store your password in its application database.
Loved One Information
You may create profiles for people you care for. You choose what to provide, and nothing beyond a name is required.
A profile has two kinds of information. The first shapes the cards you create:
name or preferred name;
relationship to you;
condition or diagnosis;
structured cognitive or dementia stage;
behaviors and communication tendencies you select or add, which is where preferences and sensitivities are captured; and
Card Creation Notes, which are free-text notes you write to guide card wording.
The second kind is saved for your reference only:
photograph;
free-text stage notes;
medications;
allergies;
other medical conditions;
mobility or medical equipment information; and
physician information.
Some of this information may be sensitive or health-related. Quiet Cards does not ask you to provide identity or financial information about a Loved One, such as a Social Security number, driver's license, passport or other government identification number, bank account information, or credit or debit card information.
Card Information
When you create and save Quiet Cards, we may collect or process information including:
the situation or custom situation description;
the Loved One associated with the card;
how the card should refer to that person;
selected communication points;
condition information;
notes or instructions you enter;
AI-generated card text;
card titles;
card design and appearance selections; and
card and stack organization information.
Basic Pack and Marketing Information
If you request the Quiet Cards Basic Pack, we collect the name and email address you provide in connection with that request.
Consent to receive ongoing marketing communications is separate from requesting the Basic Pack. If you choose to receive occasional Quiet Cards tips, updates, or offers, we record your marketing preference and the date of that consent.
You may unsubscribe from marketing communications or request removal of your Basic Pack lead information through the provided unsubscribe/removal process.
2. How We Use Information
We use information to:
create and maintain Quiet Cards accounts;
authenticate users;
provide and operate Quiet Cards;
create, save, organize, and display Loved One profiles, cards, and stacks;
personalize card creation;
generate card wording using information relevant to the requested card;
maintain account and service security;
provide materials you request;
send marketing communications when you have separately opted in;
respond to support, privacy, or account requests;
troubleshoot and maintain the service;
prevent misuse or abuse; and
comply with applicable legal obligations.
We do not use Loved One information for targeted advertising.
3. Artificial Intelligence and Card Creation
Quiet Cards uses artificial intelligence to help draft communication cards. Card-generation requests are routed through the Lovable AI platform and processed by Google Gemini as an application service request. This is not a personal consumer chatbot account, and the request is used to produce your card wording.
When you ask Quiet Cards to help write a card, the information that shapes that card is sent for processing. In plain terms, that is the details of the card you are creating plus the background you have saved about the person that helps the wording make sense. Specifically, this may include:
the situation, including a custom situation you describe;
the wording you chose for how the card should refer to the person;
the person's name or label and their relationship to you;
a short condition or diagnosis description;
the structured stage you selected;
saved behaviors and communication tendencies;
your saved Card Creation Notes;
the communication points you select for this card; and
any free-text notes you enter for this card.
The following information is not included in card-generation requests:
medications;
allergies;
other medical conditions saved for reference;
mobility aids or medical equipment information;
physician information;
free-text stage notes;
photographs;
your account email address and account identifiers; and
payment information.
This distinction is built into how the application works: reference information you save for your own convenience is separated from the information used for card writing. If you intentionally type sensitive or medical details into a card-creation field for a particular card, that text is part of what you asked us to write from, so it is included in that request.
Quiet Cards does not maintain separate content logs of AI prompts or AI responses. Our own AI usage records contain limited operational information such as the request type, the time, and whether the request succeeded, failed, or was blocked. If you choose to save a generated Quiet Card, the resulting card text is stored as part of that saved card, like any other content you save.
Even with content logging turned off, the AI platform records request metadata such as the time of the request, the model used, token counts, and cost. That metadata does not contain your card wording or Loved One information.
AI-generated content can contain mistakes, omissions, or inappropriate wording. You are responsible for reviewing generated content before using, displaying, printing, or sharing a card.
4. Service Providers
Quiet Cards relies on service providers to operate the application.
Current providers include:
Supabase
Provides database services, account authentication, and private file storage. Supabase stores account information, Loved One profiles, cards, stacks, photographs, and other application data necessary to provide Quiet Cards.
Cloudflare Workers through Lovable
Provides hosting, server-side functions, and request processing. Information may pass through this infrastructure as necessary to operate the application.
Lovable AI Gateway
Routes AI card-generation requests to the AI model provider.
Google Gemini
Processes card-generation requests and produces generated card wording.
These providers may process information as necessary to provide their respective services.
Provider systems may independently maintain technical, security, authentication, or request logs according to their own practices.
We do not sell Loved One health-related information.
We do not share Loved One health-related information with third-party advertising platforms for targeted advertising.
5. AI Provider Data Practices
Quiet Cards uses Google Gemini through the Lovable AI platform rather than a consumer AI account.
Quiet Cards has configured its AI integration so that the full content of AI requests and responses is not retained in the platform's AI debugging logs for new requests. Operational information such as status, model, timing, and token usage may still be recorded.
Our AI providers state that requests made through their application interfaces are not used to train their general AI models. We pass this along as their stated practice rather than as a guarantee from us.
Providers may process, and in some cases briefly retain, request information for purposes such as security, abuse prevention, and legal or regulatory compliance. Those provider-side practices and time periods are set by the providers and are not controlled by Quiet Cards, so we do not state a specific retention period here.
We do not sell AI request content and do not share it with advertisers. We do not claim zero data retention, and we do not claim that information could never be accessed by authorized personnel at a provider.
We will update this Privacy Policy if our AI provider, routing arrangement, or material data-processing practices change.
6. Medical Information Stored for Reference
Quiet Cards allows you to save certain medical-reference information in a Loved One profile, including medications, allergies, other medical conditions, mobility or medical equipment information, and physician information.
This information is saved to the Loved One's profile for your reference and is not automatically sent to the AI when creating cards.
Quiet Cards is not a healthcare provider, electronic medical record system, medical alert service, or emergency service.
Information stored in Quiet Cards should not be relied upon as a substitute for professional medical records, medical identification, emergency information, diagnosis, treatment, or advice from a qualified healthcare professional.
7. Information About Other People
Quiet Cards allows users to enter information about another person.
By providing personal information, photographs, health-related information, or other information about another individual, you represent that you have the right or appropriate authority to provide and use that information through Quiet Cards.
You are responsible for the information you choose to provide about another person.
We encourage users to provide only information reasonably necessary for their use of Quiet Cards.
8. Photographs and File Storage
Loved One photographs are stored using private Supabase Storage.
The storage bucket is not public. Quiet Cards accesses photographs using temporary signed URLs as necessary to display them within the application. The current implementation uses signed URLs that expire after approximately one hour.
Loved One photographs are not sent to the AI for card generation.
When you delete a Loved One profile, Quiet Cards removes the associated profile photograph from active storage.
When you delete your Quiet Cards account, Quiet Cards removes photographs stored in your account's photo-storage folder from active storage as part of the deletion process.
9. Technical Information, Logs, and IP Addresses
Quiet Cards does not store raw IP addresses or device fingerprints in its application database.
For purchases started before an account exists, Quiet Cards stores a hashed, non-reversible form of the IP address with the purchase record. It is used only to limit repeated checkout attempts and prevent abuse. The hash cannot be turned back into an IP address, and the raw address is never written to our database.
IP addresses may also be used temporarily in server memory to rate-limit public Basic Pack-related endpoints. Those addresses are not written to the Quiet Cards database.
Hosting, authentication, database, and infrastructure providers may independently process IP addresses, device information, request metadata, authentication records, or security logs as part of operating and protecting their services.
Quiet Cards has configured its AI integration so that AI provider response bodies are not written to its application error logs. Status codes may be logged for troubleshooting.
Provider-controlled log retention periods may vary and are not controlled by Quiet Cards.
Quiet Cards keeps limited account-linked records of AI card-generation activity for service security, abuse prevention, and usage management. These records contain the time of the request, whether it was an initial generation or regeneration, and whether the request succeeded, failed, or was blocked by a usage safeguard. These usage records do not contain prompts, generated card text, Loved One profile information, Card Creation Notes, medical information, or AI responses.
This refers to usage logging only. Card text that you choose to save is stored as saved card content, as described in Section 1.
10. Analytics, Advertising, and Tracking
Quiet Cards does not currently use:
Google Analytics;
Meta Pixel;
third-party advertising pixels;
behavioral advertising;
session replay;
third-party behavioral analytics; or
advertising SDKs.
Quiet Cards currently self-hosts its application fonts rather than loading them from Google Fonts.
If we introduce analytics, advertising technologies, or materially different tracking practices in the future, we will update this Privacy Policy and provide any notice or choices required by applicable law.
11. Local Device and Browser Information
Quiet Cards stores a small, specific set of items in your browser or device. The complete list is:
your sign-in session, issued by our authentication provider, so you stay signed in;
a cookie that remembers whether the application sidebar is open or collapsed;
a flag recording that you dismissed the prompt to add Quiet Cards to your home screen;
the identifiers of cards you viewed recently, so they are easy to find again; and
short-lived checkout values used to finish a purchase and attach it to your account.
We do not use browser storage for advertising, profiling, or cross-site tracking.
When you sign out, Quiet Cards clears its locally stored recently-used-card list.
Your browser, device, or operating system may independently retain cached information according to its own settings.
12. Data Retention and Deletion
We retain information as necessary to provide Quiet Cards and for legitimate operational, security, and legal purposes.
You may delete individual cards and Loved One profiles through available application controls.
When deleting a Loved One profile, you may choose to delete that person's associated cards or retain those cards without the Loved One association. The associated Loved One photograph is removed from active storage.
Account Deletion
You may permanently delete your Quiet Cards account through Settings.
Account deletion removes the account's information from the active Quiet Cards application, including:
stored photographs;
account profile;
Loved One profiles;
cards;
stacks;
stack memberships;
AI card-generation usage records; and
any Basic Pack lead record held under the same email address.
Quiet Cards also clears its local application cache and recently-used-card history and ends the authenticated session.
Account deletion is intended to be immediate in the application and cannot be undone. Deletion in the application does not instantly erase every copy everywhere. Backups, payment records, and email delivery logs age out on their own schedules, as described below.
Deleted information may remain temporarily in provider-controlled backups, recovery systems, security logs, or other systems where immediate deletion is not technically feasible. The current application configuration does not establish the retention periods for those provider-controlled systems.
Information that you have printed, photographed, screenshot, downloaded, exported, or otherwise shared outside Quiet Cards cannot be deleted by us.
Purchase and Payment Records
Quiet Cards keeps a record of each purchase, separate from your account. When you delete your account, we clear the personal details from that record, including the payment email address, purchase-claim tokens, and the hashed IP address.
We keep the remaining transaction information, such as the payment processor references, the item purchased, and the dates, because we are required to for tax and accounting, and because it is needed to handle refunds, chargebacks, and fraud claims. Purchase records that were never attached to an account have their personal details cleared automatically twenty-four months after the purchase, and the transaction information is kept only for as long as those tax, accounting, and dispute obligations require.
Payment card details are handled by Stripe and are never stored by Quiet Cards.
Basic Pack Lead Information
Basic Pack lead records are maintained separately from registered Quiet Cards accounts.
Deleting your Quiet Cards account also removes any Basic Pack lead record held under the same email address.
If you never created an account, you may request removal of your Basic Pack lead information at any time through the unsubscribe or removal process.
13. Marketing Communications
Requesting the Basic Pack does not require you to agree to ongoing marketing.
If you separately opt in to marketing communications, you may withdraw that consent using the unsubscribe mechanism provided.
Unsubscribing from marketing does not prevent Quiet Cards from sending communications necessary to provide a service you requested, administer your account, address security issues, or respond to you.
14. Security
We use administrative, technical, and organizational safeguards designed to protect information processed through Quiet Cards.
Current measures include authenticated access controls, private photo storage, server-side account deletion, reduced AI data transmission, and limiting unnecessary third-party requests.
However, no electronic transmission or storage system can be guaranteed to be completely secure.
You are responsible for maintaining the confidentiality of your login credentials and securing the devices through which you access Quiet Cards.
15. Security Incidents and Breach Notification
If we become aware of a security incident involving personal or health-related information, we will investigate the incident and provide notifications when required by applicable law.
The legal requirements applicable to consumer health information can depend on the nature of the service, information, and incident.
16. Administrative Access
To operate and support Quiet Cards, authorized administrative access may include account information such as email address, membership and status information, and simple counts of items in an account, for example how many cards or profiles exist. This is what the Quiet Cards Admin dashboard displays, and administrative access to it is recorded.
The Admin dashboard does not display Loved One profile details, card text, notes, medical or reference information, or photographs.
As with any hosted service, our infrastructure and service providers maintain systems that authorized personnel can technically access for maintenance, security, and support. We limit that access to what operating the service requires, and we do not use it to browse caregiver content.
17. Children's Privacy
Quiet Cards accounts are available only to individuals 18 years of age or older.
You may not create an account if you are under 18.
Quiet Cards is not directed to children and does not knowingly permit individuals under 18 to create accounts.
18. Your Choices
Depending on the feature involved, you may:
review and update Loved One information;
remove information from Loved One profiles;
delete cards;
delete Loved One profiles;
choose whether to retain associated cards when deleting a Loved One;
unsubscribe from marketing communications;
request removal of Basic Pack lead information; and
permanently delete your Quiet Cards account through Settings.
You may also contact us regarding privacy questions or requests.
19. Changes to This Privacy Policy
We may update this Privacy Policy from time to time as Quiet Cards, our service providers, or applicable requirements change.
When we update the Policy, we will revise the “Last Updated” date above.
If we make material changes to how sensitive information is collected, used, or disclosed, we will provide additional notice or obtain consent when required by applicable law.
20. Contact Us
Quiet Cards is operated by:
TOT Solutions, LLC
A Tennessee limited liability company
Email: tiffani@totsolutions.org
Mailing Address: PO Box 136232, Clermont, FL 34713
For privacy questions, account requests, or questions about this Privacy Policy, please contact us using the information above.
Contact
TOT Solutions, LLC
PO Box 136232
Clermont, FL 34713