01
Information We Collect
When you use the app, we collect:
- Account information: Your name, email address, and password (stored as a secure hash).
- Child profile data: Information you enter about your child, including name, diagnoses, medications, allergies, and care team details.
- Log entries: Behavioral incidents, medical events, IEP notes, phone logs, and any other records you create.
- Billing information: Payment is processed by Stripe. We never store your card number.
- Usage data: Basic server logs including IP addresses and browser type, used for security and debugging only.
02
How We Use Your Information
We use the information you provide solely to:
- Operate and maintain your account.
- Display your data back to you and authorized caregivers.
- Generate reports and exports you request.
- Send transactional emails (account verification, password reset, subscription receipts).
- Send optional newsletter emails if you have opted in.
We do not use your data for advertising and we do not sell it to third parties.
03
Data Storage & Security
Your data is stored on secured servers. We use industry-standard practices including:
- HTTPS encryption for all data in transit.
- Encrypted password storage (bcrypt hashing).
- AES-256-CBC encryption for sensitive fields at rest.
- Optional two-factor authentication for your account.
- Access controls so only you can view your records.
- Regular database backups.
No security system is 100% impenetrable. In the unlikely event of a data breach, we will notify you promptly.
04
Information Sharing
We share your data only in these limited circumstances:
- Stripe: Payment processing is handled by Stripe. We share only what is necessary to process your subscription.
- Legal obligations: We may disclose information if required by law or to protect the rights and safety of our users.
We do not share your child's records with any third parties for any other purpose.
05
Data Retention
We retain your data for as long as your account is active. If you delete your account, your data is permanently removed from our systems within 30 days, except where we are required to retain it for legal or financial compliance purposes.
06
Your Rights
You have the right to:
- Access and export all data you've entered (via the Reports section).
- Correct or update any information in your profile settings.
- Delete your account and all associated data at any time from your profile settings.
- Opt out of non-transactional emails via the unsubscribe link in any email we send.
- Contact us with any privacy concern via our contact page.
07
Children's Privacy
This app is intended to be used by adults (parents and caregivers) to maintain records about their children. We do not knowingly collect personal data directly from children. If you believe a minor has created an account without parental consent, please contact us and we will remove the account promptly.
08
Cookies
We use only essential cookies required to operate the application (session management and CSRF protection). We do not use advertising cookies or third-party tracking cookies.
09
Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date above and, for material changes, notify all account holders by email and in-app message at least 30 days before the changes take effect. Continued use of the app after changes constitutes acceptance of the updated policy.
10
Contact Us
If you have questions or concerns about this Privacy Policy, please
contact us. We aim to respond within 3 business days.