Privacy Policy
This policy explains, in plain English, what personal data The Coparent App uses, why it is needed, who processes it, how it is protected and how you can exercise your rights.
Who controls your data?
Pittance LTD, trading as The Coparent App.
Why is data used?
To provide, secure, support and improve the co-parenting service you ask us to deliver.
How do I contact you?
1. Who we are
Pittance LTD, trading as The Coparent App, is the controller of personal data processed to operate the service. Our registered details are Pittance LTD, 16 Brander Street, Burghead, IV30 5XD, Scotland, company number SC887446. Contact our privacy team at info@thecoparent.app.
Where a professional organisation independently decides why it uses information accessed through its professional portal, that organisation may also be a separate controller and should give you its own privacy information.
2. What personal data we collect
| Category | Examples | How it arises |
|---|---|---|
| Account and identity | Name, email address, account and family identifiers, authentication records | Registration, login and account administration |
| Family information | Co-parent details, children’s names and information you add about family arrangements | Information entered by you or your connected co-parent |
| Communications | Messages, original AI drafts, final sent messages, reactions and communication metadata | Messaging and AI-assisted communication |
| Plans and records | Calendar events, parenting arrangements, handover logs, proof photographs, diary or journal entries | Features used by the family |
| Financial records | Expense entries, amounts, categories and receipt images | Expense and receipt features |
| Files and media | Photographs, documents, call-related media and other uploaded files | Uploads and live communication features |
| Location | Location details deliberately added to a handover or location-sharing feature, plus related time data | Only when you choose or permit the relevant feature |
| Subscription | Product, entitlement, purchase and restoration status; app-store transaction references | Google Play or Apple billing and RevenueCat |
| Device and notification | Device identifiers, operating system, push token, notification delivery data and single-device protection records | App operation, security and notifications |
| Technical and support | IP address, logs, diagnostics, crash reports, performance data and support correspondence | Security, troubleshooting and support |
| Exports and deletion | Export requests, generated reports, delivery records and deletion audit records | When an export or account deletion is requested |
Please do not upload information that is unnecessary for co-parenting. Messages and original AI drafts may form part of a permanent family record and may appear in court-ready or professional exports.
3. Why we use data and our legal bases
| Purpose | Typical legal basis |
|---|---|
| Create and manage accounts; provide messaging, calendars, expenses, files, handovers, calls, exports and professional access | Performance of our contract with you |
| Process subscriptions and confirm entitlements | Performance of contract and legal obligations |
| Protect accounts, enforce single-device controls, prevent abuse and investigate security incidents | Legitimate interests in operating a safe and reliable service; legal obligations where applicable |
| Provide AI-assisted rewriting and communication-safety functions you enable or use | Performance of contract and legitimate interests in reducing harmful conflict |
| Send operational notifications and service messages | Performance of contract and legitimate interests |
| Provide support, diagnose faults and improve reliability | Legitimate interests |
| Meet accounting, legal, regulatory and dispute-resolution requirements | Legal obligation and legitimate interests |
If information reveals health, disability, ethnicity, religion, sexuality, abuse allegations or other special-category or highly sensitive matters, we process it only as necessary to provide the service you chose, establish or defend legal claims, protect vital interests where relevant, or under another lawful condition available under data-protection law.
4. How AI-assisted communication works
When an AI feature is used, message text and necessary context are sent securely to our AI processing service so it can analyse or suggest a calmer version. The Coparent App currently uses OpenAI as an AI service provider. The AI does not decide whether to send a message: the user keeps that decision.
Original AI drafts are retained in the family communication record. They are not shown in the everyday chat view, but they are included alongside the final message in appropriate court-ready and professional exports, with relevant AI or safety information where applicable. Do not type information you would not want retained in that record.
We do not use your family messages to create advertising profiles. Our use of an AI provider does not mean your message is public.
5. Push notifications and lock-screen privacy
If you enable notifications, the app sends a push token and operational delivery information through Expo and the platform notification service, including Google Firebase Cloud Messaging on Android and Apple Push Notification service on iOS. Notification previews can appear on a locked device depending on your device settings.
We deliberately use limited, generic preview wording for sensitive co-parenting activity rather than putting message text, children’s names, expense details or uploaded content on the lock screen. You can disable notifications or hide previews in your device settings. Opening a notification may route you to the relevant signed-in area of the app.
6. Voice and video calls
Voice and video calling uses Agora’s real-time communications service. Necessary account, session, device, network and call metadata is processed to connect and secure calls. Live audio and video content must pass through communications infrastructure during a call. Recording or transcription is not enabled unless the app clearly presents that feature and the necessary permissions and notices at the time.
7. Professional and third-party access
A family may authorise an eligible professional to use the read-only professional portal. Access is limited by product permissions and should only be granted to a person or organisation the family intends to involve. Professional access can expose family records and exports within the authorised scope.
We may disclose information where required by law, a valid court order or a lawful authority request, or where reasonably necessary to establish, exercise or defend legal claims or protect someone from serious harm. We do not sell personal data.
8. Service providers and data sharing
We use carefully selected providers to operate specific parts of the service. They process only the data needed for their role, subject to contractual and security controls where required.
| Provider or category | Purpose | Data that may be processed |
|---|---|---|
| Amazon Web Services (AWS), including Cognito, API Gateway, Lambda, DynamoDB, S3 and CloudWatch | Authentication, hosting, databases, file storage, processing, security and logs | Account, family, content, file, device and technical data |
| OpenAI | AI-assisted communication analysis and rewriting | Message text and necessary context submitted to the AI feature |
| Sentry | Crash, error and performance monitoring | Device, app, diagnostic and limited event context; we seek to minimise personal content |
| RevenueCat | Subscription entitlement and purchase management | App-user identifier, product, entitlement and transaction status |
| Google Play and Apple App Store | App distribution, billing and purchase processing | Store account, transaction, device and diagnostic data under their own terms |
| Expo, Google Firebase Cloud Messaging and Apple Push Notification service | Push-token registration and notification delivery | Push token, device/platform data and limited notification payload |
| Agora | Voice and video calling | Call participant/session identifiers, network/device data and live media needed to connect the call |
| Website, email and support providers | Website operation and responding to enquiries | Contact, web and support information |
Some providers also act as independent controllers for their own legally defined purposes, particularly app stores. Their own privacy notices apply to that processing.
9. How we protect data
Production app traffic carrying user data uses encrypted transport such as HTTPS/TLS or secure real-time protocols. Core service data and uploaded files are hosted on AWS services with server-side encryption at rest and access controls. Saved-account credentials use secure, operating-system-backed storage where implemented; some preferences and non-secret app state are stored in the app’s private device area.
We use authentication, role and family access checks, time-limited file links, logging, monitoring and single-device account protection. No online service can promise absolute security. The service is not end-to-end encrypted, because authorised systems must be able to process data for app features, exports, support and legally authorised access.
Read our plain-English security overview for more detail.
10. How long we keep data
We keep family and account records for as long as the family account is active and as needed to provide permanent record features. Because two parents can share one family record, retention and deletion decisions can affect both adults.
- Generated export links: normally time-limited and intended to expire after no more than seven days, although the underlying family record remains until deletion or another retention rule applies.
- Security, diagnostic and operational logs: kept for periods proportionate to troubleshooting, fraud prevention, security and legal requirements. Different log groups may use different configured periods.
- Subscription and accounting records: retained for applicable tax, accounting and legal periods.
- Support correspondence: retained while needed to resolve the request and for a reasonable period afterwards.
- Deletion and legal records: limited audit information may be retained to prove that a request was handled or to comply with law and defend claims.
Backups and distributed service copies may take additional time to cycle out, but are protected and not restored for ordinary use after deletion.
11. Account deletion
You can start account deletion from the app where available or contact info@thecoparent.app. We may need to verify your identity. The app explains the family-level effect before confirmation.
Because family records are shared, a valid deletion request may close both adult accounts and delete the shared family record, subject to the stated process and any legal exceptions. The current process provides a 14-day period before final deletion and sends the family export to both registered adults so neither parent silently removes the shared record. Do not rely on that export link indefinitely; download and store any copy you lawfully need.
We may retain narrowly limited information where required for legal obligations, fraud or security prevention, or the establishment, exercise or defence of legal claims. App-store subscriptions may also need to be cancelled separately in the relevant store.
12. International data transfers
Some providers process data outside the UK. Where required, we use recognised transfer safeguards such as UK adequacy regulations, the UK International Data Transfer Agreement or Addendum, and contractual and technical protections. Provider infrastructure locations can change, so contact us if you need current details for a particular processing activity.
13. Your data-protection rights
Depending on the circumstances, you may have rights to access, correct, erase, restrict or object to processing, receive portable data, and complain about how your information is used. Consent can be withdrawn where consent is the legal basis. These rights are not absolute, particularly where records are shared with another parent or needed for legal claims.
Contact info@thecoparent.app. We will normally respond within one month after verifying identity. You may complain to the UK Information Commissioner’s Office or the data-protection authority where you live.
14. Children’s information
The adult account holders provide information about children to manage family arrangements. Children do not need to create an adult subscription account. Adults should add only information that is relevant, accurate and appropriate, avoid unnecessary sensitive material, and consider the child’s privacy and welfare before sharing files or photographs.
15. Changes to this policy
We may update this policy when the product, providers or law changes. We will change the date at the top and provide additional notice where a change materially affects how personal data is used.
Questions or privacy requests
Email info@thecoparent.app or write to Pittance LTD, 16 Brander Street, Burghead, IV30 5XD, Scotland.