Security & Trust

Your co-parenting history is sensitive. Here's how we protect it.

Encryption

All traffic is TLS 1.2+ in transit. Data at rest is encrypted at the storage layer.

Access control

Every database table enforces row-level security: a record is only readable by the circle members entitled to see it. Professional access is per-case, per-role, fully revocable.

Audit logs

Sensitive actions — exports, professional access, admin operations — are recorded with actor, timestamp, and target in a tamper-evident, fully logged trail. You can review your own circle's audit log at any time.

Authentication

Email/password with optional Google sign-in. Passwords are hashed with industry standards. Sessions are bound to the issuing device.

Data portability

You can export your circle's data as CSV/PDF at any time. Account deletion is one click — we remove your records on the deletion timeline disclosed in our Privacy policy.

Subprocessors

We use a small set of trusted vendors to operate the service:

  • Supabase — PostgreSQL hosting, authentication, storage
  • Stripe — subscription billing and payments
  • Daily.co — encrypted video calls and call recording
  • Cloudflare — global content delivery, DDoS protection, edge runtime
  • Google & OpenAI — AI features (tone checks, content relevance). Your content is never used to train any model.

See the Privacy policy for the canonical list and data-processing scope.

Reporting a vulnerability

Found something? Email security@thecoparentcircle.com. We respond within two business days.