Security & Trust
Your co-parenting history is sensitive. Here's how we protect it.
Encryption
All traffic is TLS 1.2+ in transit. Data at rest is encrypted at the storage layer.
Access control
Every database table enforces row-level security: a record is only readable by the circle members entitled to see it. Professional access is per-case, per-role, fully revocable.
Audit logs
Sensitive actions — exports, professional access, admin operations — are recorded with actor, timestamp, and target in a tamper-evident, fully logged trail. You can review your own circle's audit log at any time.
Authentication
Email/password with optional Google sign-in. Passwords are hashed with industry standards. Sessions are bound to the issuing device.
Data portability
You can export your circle's data as CSV/PDF at any time. Account deletion is one click — we remove your records on the deletion timeline disclosed in our Privacy policy.
Subprocessors
We use a small set of trusted vendors to operate the service:
- Supabase — PostgreSQL hosting, authentication, storage
- Stripe — subscription billing and payments
- Daily.co — encrypted video calls and call recording
- Cloudflare — global content delivery, DDoS protection, edge runtime
- Google & OpenAI — AI features (tone checks, content relevance). Your content is never used to train any model.
See the Privacy policy for the canonical list and data-processing scope.
Reporting a vulnerability
Found something? Email security@thecoparentcircle.com. We respond within two business days.