How The Coparent App protects your family record
Co-parenting records can contain deeply personal information. This page explains the safeguards we use, the services that help us operate the app, and the limits you should understand before adding information.
Encrypted in transit
User data travels over secure connections such as HTTPS/TLS and secure real-time protocols.
Encrypted at rest
Core data and uploaded files use AWS server-side encryption and service access controls.
Access controlled
Authentication, family membership and professional permissions determine who can reach a record.
Is data encrypted while it travels?
Yes. The production Android and iOS app uses encrypted network connections for user and device data. API requests and file links use HTTPS/TLS, and real-time communications use secure transport appropriate to the service.
We explicitly block cleartext HTTP traffic in the Android production configuration. Development tools can use local test addresses, but those addresses are not intended for the production release.
How is cloud data protected?
The core service runs on Amazon Web Services. Account data, family records and uploaded files are held in services including Cognito, DynamoDB and S3. Server-side encryption at rest is enabled for core storage, with identity and access policies limiting which application functions can reach each resource.
- S3 public-access blocking protects private file buckets.
- Uploaded files are accessed through authenticated app flows and time-limited links rather than permanent public URLs.
- DynamoDB and S3 maintain encryption at rest using AWS-managed or configured encryption controls.
- Operational logs are access controlled and should avoid unnecessary family content.
Encryption at rest protects the storage layer; it does not mean application servers are unable to process authorised data.
What is stored on the device?
The app stores the minimum local state needed for sign-in, reliability and a usable experience. Saved-account credentials use operating-system-backed secure storage where implemented. Some preferences, identifiers and non-secret application state use the app’s private storage area. Images and documents may be cached temporarily by the operating system or app so that they can be displayed.
A device sandbox prevents ordinary access by other apps, but sandboxing is not the same as separately encrypting every application file. Protect your phone with a strong passcode, biometrics and current operating-system updates.
How is account access controlled?
AWS Cognito provides authentication. The app checks the signed-in identity, connected family and role before returning records. Single-device account protection is designed to reduce silent account sharing and unauthorised parallel access.
Professional portal access is read-only and must be associated with an authorised family and professional account. A parent should only grant access to a professional they intend to involve. Support or engineering access is limited to legitimate operational needs.
Can sensitive information appear in notifications?
Push delivery uses Expo and the platform notification service, including Firebase Cloud Messaging on Android and Apple Push Notification service on iOS. We send the push token, routing information and limited preview text needed for delivery.
Notification previews deliberately use generic wording. Message text, children’s names, expense details and uploaded content are not placed in the lock-screen preview. Your phone still controls whether an app name and alert appear while locked; you can hide previews or turn notifications off in device settings.
What happens when AI assistance is used?
The text and necessary context are sent over an encrypted connection to the AI processing service so it can analyse or suggest a calmer version. The Coparent App currently uses OpenAI for this processing. The AI does not send the message; the user decides whether to send it.
Original AI drafts are retained in the communication and audit record. They are hidden from the everyday chat view but included alongside the final message in appropriate court-ready and professional exports, with relevant AI or safety information where applicable. This is an audit feature, so do not type content you do not want retained.
How are voice and video calls handled?
Calls use Agora’s real-time communications infrastructure. Necessary session, device and network information is processed to connect and secure the call. Live audio and video must pass through communications infrastructure while the call is active. We do not describe calls as end-to-end encrypted unless a specific independently verified call mode supports that claim.
How are files and court-ready exports protected?
Files are stored in private cloud storage and delivered through time-limited links. Generated court-ready reports are temporary delivery copies; the link is intended to expire within seven days. Anyone who downloads an export is responsible for protecting the downloaded copy.
Exports may contain messages, original AI drafts, final messages, calendar and expense records, files, handover data and other family information within the selected scope. Check the recipient before sharing.
How do you detect faults and security problems?
We use service logs and Sentry diagnostics to identify crashes, performance problems and suspicious activity. We minimise personal content in diagnostics where practical. Access to operational systems is restricted, and provider activity is reviewed as the product changes.
If we confirm a personal-data breach, we assess the risk, contain the incident and notify affected people and regulators where the law requires it.
What we do not claim
- Not end-to-end encrypted: authorised systems can process data to provide app functions.
- Not impossible to breach: no online system can promise absolute security.
- Not “court approved”: exports are designed to be clear and useful, but a court decides what evidence it accepts.
- Not a substitute for urgent help: if someone is in immediate danger, contact the appropriate emergency service.
What can I do to protect my account?
- Use a unique password and never share verification codes.
- Keep your email account and device secured with a passcode or biometrics.
- Install app and operating-system updates promptly.
- Hide notification previews if an alert could place you at risk.
- Upload only information that is relevant to co-parenting.
- Remove professional access when it is no longer needed.
- Report an unfamiliar login, device or export immediately.
Privacy, retention and deletion
Security and privacy overlap, but they are not the same. Our Privacy Policy explains data categories, purposes, providers, international transfers, retention, account deletion and your legal rights.
Report a security concern
Email info@thecoparent.app with “Security” in the subject. Please do not include passwords, verification codes or unnecessary family content.