NaviaCAIR
Your records · Privacy deep dive

Sharing and caregiver privacy

The companion to Share access & invite caregivers: that one shows you how to let someone in. This one answers the harder questions — what can they actually see, what stays private, and what changes the moment you take access away.

About 10 minutes For: whoever owns the record

Three things worth knowing first

  • Sharing grants access. It never transfers ownership. The record stays yours. Everyone else works in it as a guest, at a level you chose and can change.
  • Hidden is not deleted. When something isn't visible to someone, it is being withheld from them — not removed from your record. It's still there, and still yours.
  • Access is per record. Granting someone access to one person's record tells them nothing about any other record you manage. If you look after two people, that's two separate decisions.

“What can this person see?”

Everything follows from the access level you pick. The single biggest line is between processed content — AI summaries, the care picture, care plans, open items — and the original uploaded documents behind it.

Access levels you can grant through sharing, and what each one carries. These are the shipped defaults, applied as a set — you pick the level, not the individual permissions.
Level Summaries & care picture Original documents Add records Chat Export Manage access
CaregiverYesYesYesYesYesNo
GuardianYesYesYesYesYesYes
AdvocateYesNoNoYesNoNo
ViewerYesNoNoNoNoNo

Two things the table can't show

  • Nobody but you can delete. Deleting records isn't part of any level you can grant — not even guardian. That stays with the record's owner.
  • Guardian is caregiver plus one thing: the ability to manage who else has access. If you give someone guardian, they can invite and remove other people from your care team. Give it deliberately.

Care team · Ana Belova-Ferreira

Rai Okonjo-Lindqvist — caregiver · adult child

Can view · raw records · add records · chat · export

Wren Aleksandrov — advocate · professional

Can view · chat · no raw records

A schematic care team with two synthetic people at different levels. Each row spells out what that person can do.

Summaries versus the original documents

This is the distinction that makes limited access useful rather than merely restrictive.

Shown

What an advocate or viewer still sees

The AI-written summaries, the care picture assembled from them, care plans and follow-ups, open items, and structured values pulled out of your records — lab results and vitals, for instance. Enough to follow what is happening and be useful in a conversation.

Withheld

What they don't get

The uploaded files themselves and the raw text taken from them. Where a document would be, they see a short line saying raw records aren't visible at their level, with the summary underneath. Passages that would have quoted raw text directly are blanked out of the summary too — the sanitising is applied to the content, not just the file.

“What stays private?”

Beyond the access level, individual items carry their own visibility. Two people at the same level can see different things.

Per-item visibility

  • Shared with the care team — the default. Everyone with access to the record can see it.
  • Private — only the person who created it. Not the care team, and not the other party. A private note or appointment you write stays yours; one a caregiver writes stays theirs.
  • Shared with specific people — supported underneath, but the picker for choosing those people isn't in the app yet, so in practice today you are choosing between team-visible and private.

Conversations with the CAIR Agent

Chat is not automatically an open book to everyone on your care team. It follows the same per-item rule as notes and appointments.

How a conversation's visibility setting decides who can open it. The check runs after record access, so it can only narrow the audience, never widen it.
SettingWho can open it
Shared with care teamAnyone with access to the record.
PrivateOnly whoever started it.
Shared with specific peopleWhoever started it, plus anyone explicitly added. (No picker in the app yet.)

The questions people actually ask

  • Does giving someone access show them my old conversations? Only the ones already marked as shared with the care team. A private conversation stays private to whoever started it — changing someone's access level does not reach back and open it.
  • Is a private chat deleted? No. It is withheld from others and still fully yours.
  • What about after I remove someone? Record access is checked first, so once it's gone, every conversation in that record is closed to them — shared ones included.

Exports

Exporting is the one place where two permissions have to line up, and it catches people out.

A care-plan export needs both export rights and original-document access

The exported plan carries raw record text inside it, and there is no summary-only version yet. So the app requires both — and checks them separately. Someone without original-document access is refused even if export was switched on for them, with a message explaining that record exports are unavailable at their level.

In practice: caregivers and guardians can export; advocates and viewers cannot. There is no summary-only export for limited roles today.

Two different things called “export”

  • The Care Plan export — one care plan as a document to take to an appointment. Covered in Export the Care Plan.
  • A full copy of your account data — a different, account-level request, with its own rules. It covers your own account rather than records you have access to, and it honours the same raw-document rules the app enforces. Exporting a copy of your data covers what's in it and what it leaves out.

Removing someone's access

You can do this at any time, for any reason, without warning them. It takes about ten seconds.

Select the right record

Access belongs to one record, so start by making sure that record is the one selected at the top of the app. If you manage more than one person, removing someone from Ana's record leaves any access they have to Bo's record untouched.

Open Sharing

Go to app.naviacair.com/sharing. The Care team panel lists everyone with access, each with their level and a plain summary of what they can do. You'll only see this panel on records where you are allowed to manage access.

Press Remove, then confirm

Each member's row has a Remove button. Pressing it doesn't do anything yet — the row turns into a confirmation asking “Remove access?” with Yes, remove and No. Nothing happens until you choose.

Care team

Wren Aleksandrov — advocate · professional

Remove access?   [ Yes, remove ]   [ No ]

The inline confirmation. The owner's own row has no Remove button — you can't remove yourself this way.

On success you'll see “Access removed for {name}.” If something goes wrong you'll get a plain failure message and the person stays on the list — nothing is half-done.

Invitations and requests are cancelled separately

Someone who hasn't accepted yet isn't on the care team, so they have no row to remove. Instead:

  • A pending invitation has its own Revoke button, with its own confirmation — “Revoke invitation?” — and confirms with “Invitation revoked.” The emailed link stops working.
  • A pending access request is theirs, not yours: you decline it from your inbox, and the person who sent it can withdraw it from their side. See Requesting access to a patient.

“What changes when I remove them?”

Their access ends at the server the moment you confirm. Here is what that actually looks like from their side.

Gone

The record disappears from their app

It drops out of the patient selector, so they can no longer choose it. If they were helping only you, they're left with nothing to open.

Gone

Every part of the record is refused

Summaries, original documents, care plans, conversations, exports — all of it. Keeping a direct link doesn't help: the app answers as though the record simply isn't there, which is deliberate, so a removed person can't confirm it still exists.

Gone

A page they already had open

Anything already drawn on their screen stays drawn until the app next asks the server for something — a refresh, a navigation, or the next background fetch. There is no live wipe of another person's screen. The moment it does ask, it is refused. Treat “as soon as they reload” as the honest answer, not “instantly, everywhere”.

Stays

Anything they already took out of NaviaCAIR

A care plan they exported, a page they printed, a screenshot, notes they copied elsewhere. Removing access cannot reach those. This is the one limit worth understanding before you share with anyone.

Stays

What they contributed, and the fact that they had access

Records they uploaded, notes and conversations they created stay in your record, still attributed to them — removing someone doesn't erase their work from your care history. The access itself is marked as withdrawn rather than wiped, so the history of who had access, and when, remains.

A few edges worth knowing

  • You can't remove the last owner. A record must always have one; the app refuses and says so.
  • Changing your mind later is fine. Re-granting access reuses the same care-team entry rather than creating a second one, and you can bring someone back at a different level than before.
  • Removing twice is harmless. If it's already done, the app just confirms it's done.
  • Only someone allowed to manage access can remove people — you, or anyone you made a guardian.

Back to Your records · Share access & invite caregivers · All guides