Privacy
Last updated October 2026 · plain-language summary
What we collect
Your name and email (to create your account), and whatever you choose to enter about the people you care for — appointments, documents, funding details, and notes. We don’t collect anything beyond what the app’s features need.
Who can see it
Private household records are protected by account permissions and database access rules. Household co-owners have full access to existing and future household records and sharing controls. Owners invite them through a separate, email-bound acceptance flow and can remove invited members; the household creator remains in place. Limited document recipients use separate sign-ins and see only their recipient-specific shared text space, including the person’s displayed name. They do not join your private household. Owners choose view-only or contributor access, an expiry, and what text to add. Sharing activity records invitations, acceptance, revocation, additions and withdrawals; it does not record every view. Professional labels are not verified credentials. Nothing is sold or used for advertising.
Where it’s stored
Data lives in a managed Postgres database (Supabase), with database-level access rules enforcing the sharing model above on every request — not just in the app’s interface. The production database is hosted in Canada Central. Original-file uploads remain unavailable pending verified file backup and recovery.
Your rights
You can export or delete your household’s data on request. Revoking a share blocks subsequent reads and contributions, but cannot recall text already viewed or copied. Closing your account removes your access; contact us if you want your data permanently deleted.
Questions
This is an early product built by one family for others like it. If you have privacy questions or concerns, reach out directly — we’d rather hear them than have you guess.