Denly · Version 1.8 · Effective September 20, 2026
Denly Privacy Policy
What Denly collects, why we collect it, who receives it, and how long we keep it.
Version 1.8 · Effective: September 20, 2026
This Privacy Policy describes how GuildStack Labs LLC (“we,” “us,” “our”) collects, uses, and discloses your personal information when you use our mobile application, Denly (the “Service”).
Denly is a co-parenting app for separated parents: a shared calendar, shared expenses, documents, and messages.
Where Denly is offered. Denly is currently available only to residents of the United States, and your data is stored and processed in the United States. Denly is not directed to, or intended for, users in the European Union, the European Economic Area, the United Kingdom, Canada, or other jurisdictions. If we expand Denly to other regions, we will first update this policy to cover the additional rights and cross-border transfer protections that apply there.
1. The Short Version
- We do not sell your data, use it for advertising, or use it to train AI models.
- We collect what Denly needs in order to work. Analytics are off until you turn them on (Section 12).
- You can export or delete your data from inside the app (Section 8).
- Your data is encrypted in transit and at rest (Section 11).
The rest of this policy is the detail behind those four statements.
2. Information We Collect
A. Information You Provide
When you create an account or use Denly, you provide us with:
- Account Information: Email address and display name. You sign in with Sign in with Apple or Sign in with Google (OAuth). Denly does not create or store a password for you, so there is no password for us to lose. If you sign in with Apple, we also keep an encrypted token that Apple issues to Denly. Its only use is to tell Apple to disconnect Denly from your Apple ID when you delete your account, and we delete it at that point.
- Profile Information: Your display name. Denly does not collect a profile photo. Other members see your initials.
- Den Data:
- Children’s profiles: Names, birthdates, and other details you choose to add.
- Calendar events: Titles, dates, times, locations, and descriptions.
- Expenses: Amounts, categories, descriptions, receipts (images/PDFs), and settlement status.
- Documents: Files you upload to the shared vault, including any you save to a child’s Medical folder (see “Health information” below).
- Messages: The message thread between Den members. Messages are permanent by design. Once sent, a message cannot be edited or deleted, and it remains part of the Den’s record until the Den is deleted (see Section 7).
Health information. Denly has no dedicated health fields. The one place designed to hold health information is a child’s Medical folder in the vault (records, prescriptions, insurance cards). Saving documents there is optional and turned off until you give explicit, opt-in consent, separate from your acceptance of these terms. Each parent confirms for their own account. You can withdraw that consent at any time in Settings > Privacy. Withdrawal stops new saves and edits in the Medical folder but does not delete what is already stored; to remove existing documents, delete them from the folder. A deleted document’s file is permanently removed seven days later (Section 7). Health details can also appear in free text you write elsewhere, such as a calendar event, an expense description, or a message. That content is not scanned and is not gated by the health consent. It is handled like any other Den data.
- Payment Information: We do not store credit card details. Subscriptions are purchased through Apple’s App Store (In-App Purchase), using the Apple ID signed in on your device. Apple receives the purchase and a randomly generated identifier for your Den, not your name or email. We receive back transaction identifiers, the product purchased, purchase and renewal dates, price, and the App Store storefront. We never receive your card details, name, or email through this flow. See Apple’s privacy policy at https://www.apple.com/legal/privacy/ for how Apple handles payment data.
B. Information Collected Automatically
- Device Information: A push notification token for your device, and whether it runs iOS or Android. Messages and audit log entries also note the app version and platform they came from. Device model and operating system version are collected only as part of analytics, and only if you turn analytics on (Section 12).
- Log Data: IP address and access times (for debugging and security). Access times (sign-ins, session refreshes, and push-token registrations) are also how we determine whether a Den’s admin has stopped using Denly when the other co-parent asks to take over the admin role (see D below and Section 6 of our Terms of Service).
- Usage Data: Analytics are off by default. Only if you turn them on (Settings > Privacy > Analytics; see Section 12) do we collect anonymous statistics about how you use the app (e.g., “created an event”) and reports of errors in the app, to help us improve features.
C. Hardship Exemption Requests
If you request a hardship exemption through the form on our Transparency page, we collect the email address you provide and the short description of your situation you choose to share. We use this only to review and administer your waiver and to contact you about it (including renewal). We do not require or ask for income documentation or other proof, and we do not use this information for any other purpose. We retain hardship requests for as long as a related waiver is active and for up to 24 months after it lapses so we can administer renewals, after which they are deleted. A request we have not acted on is deleted after 180 days.
To limit abuse of the form, we also keep a keyed, one-way hash of the internet address each request came from, for up to 48 hours. We do not store the address itself.
D. Admin Role Requests
If you ask us to move a Den’s admin role to you because its admin has stopped using Denly (Section 6 of our Terms of Service), the request reaches us as an email from the address you signed in with, containing your Den’s identifier and nothing else. We use it only to confirm you are a co-parent in that Den and to administer the request. The decision rests on the admin’s server-side activity records, never on anything you tell us about them. We keep the request while it is open and for up to 24 months after it closes, after which it is deleted.
3. How We Use Your Information
We use your information only to:
- Provide, operate, and maintain the Service
- Facilitate coordination between co-parents (sharing events, expenses, etc.)
- Send you technical notices, updates, and security alerts
- Respond to your comments and customer support requests
- Detect, prevent, and address technical issues and fraud
- Administer Den roles, including determining, from server-side activity records only, whether a Den’s admin has stopped using Denly when the other co-parent asks to take over the role
We do not use your data for:
- Targeted advertising
- Training artificial intelligence models
- Selling to data brokers
4. How We Share Your Information
With Your Co-Parent and Den Members
When you join a Den, data is shared with other Den members based on their role. You control who joins your Den through invite codes.
| Role | What they can see |
|---|---|
| Co-parents | Everything: calendar events, expenses, settlements, messages, documents (including the Medical folder), and children’s profiles |
| Guests (grandparents, nannies) | Calendar events in full, including locations and notes, plus children’s names and birthdays so the schedule makes sense. Guests cannot see messages, expenses, settlements, or documents (including the Medical folder) |
| Counsel (attorneys, mediators, therapists) | Read-only access to everything. Counsel cannot create or change anything |
Photos you upload. When another member opens a photo you uploaded (a message photo, a receipt, or a photographed vault document), they receive a copy that does not contain the information embedded in your file, such as the location where the photo was taken (EXIF data). This applies to every other member, including counsel. The copy may be smaller than your original. Only you receive your original file, in the app and in your own data export (Section 8). What is visible in the picture itself is shared as it is, and PDF files are shared as you uploaded them.
All Den members can see each other’s display name and role. Each record also carries the email address of the member who created it, so a member who can see a record can see its author’s email address. These role limits are enforced by our servers as well as by the app’s interface, so they hold even outside the app.
When a co-parent asks to take over the admin role of a Den whose admin has stopped using Denly, the Den’s audit log records the request, its outcome, and the date the former admin was last active in Denly. Those entries are readable by the Den’s co-parents and counsel. A data export includes the audit entries its requester created (Section 8), so they appear in the requesting co-parent’s export. The admin is told who made the request.
Legal Process and Government Requests
Records kept in Denly sometimes end up in family-law disputes, so we may receive subpoenas, court orders, or other legal demands for user data. How we handle them:
- We require valid legal process. We disclose personal data to law enforcement, courts, or other parties only when we are compelled by a subpoena, warrant, court order, or other legal process that we reasonably believe to be valid, or where disclosure is otherwise permitted or required by law (for example, to address an imminent risk of serious harm).
- We tell you where we can. Where we are legally permitted to do so, we will make reasonable efforts to notify the affected user before disclosing their data, so they have an opportunity to object. We will not give notice where a law or court order prohibits it, or where we believe notice would create a risk of harm.
- What we can and cannot produce. We can only produce data we actually hold, in the form we hold it. We never hold your Apple or Google password, because Apple and Google handle authentication. The only sign-in item we hold is the encrypted Apple token described in Section 2. Content that has passed our retention and deletion periods (Section 7) no longer exists to produce. We do not decrypt, reconstruct, or fabricate data we do not have.
- We do not volunteer your data. We do not proactively share user data with government agencies, and we do not sell data to anyone.
If you are involved in a legal matter and need your own records, you can export them yourself from within the app (Section 8). You do not need a subpoena to obtain your own data.
5. Third-Party Service Providers
We use a small number of infrastructure providers to operate Denly. Each receives only the data described in the table below, and handles it under its own published terms.
| Provider | Purpose | Data They Receive |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, file storage, and serverless functions, hosted in the United States | All application data, encrypted at rest (AES-256) and in transit (TLS) |
| Apple (App Store) | Subscription purchases, via In-App Purchase | The purchase and a randomly generated identifier for your Den (not your name or email). We receive back transaction identifiers, the product purchased, dates, price, and storefront from Apple; we never receive your card details |
| PostHog (PostHog Inc.) | Product analytics, only when you have enabled analytics (see Section 12) | Anonymous product-usage events and error reports tied to a pseudonymous identifier, along with device model and operating system version. We do not put your name, email, children’s data, or other personal content in analytics events |
| Apple / Google (OAuth sign-in) | Authentication through “Sign in with Apple” and “Sign in with Google” | Confirms your identity and returns your email and name. Because sign-in is OAuth-only, we never receive or store a password |
| Apple (APNs) / Google Firebase (FCM) | iOS and Android push notifications | Device tokens and the notification itself. By default a notification says only that there is a new update. If you turn off Hide content on lock screen in Settings > Notifications, it includes content such as an event title, an expense description, or the start of a message |
| Expo (650 Industries, Inc.) | Push notification delivery. Expo’s push service relays each notification to Apple or Google | Your device’s push token, the notification as described in the row above, and internal identifiers for the Den and the record the notification is about |
| Timestamping authorities (e.g., FreeTSA, DigiCert) | Independent, once-daily timestamping of record integrity | Only a cryptographic hash, a one-way fingerprint of record history. They never receive your content, your personal information, or any data that can be turned back into your records |
| Expo (650 Industries, Inc.) | App updates. Each time the app launches, it checks Expo’s update service for a newer version of our app code | The app’s project identifier, version information, and platform. Expo’s servers see your device’s IP address as part of serving the request. No account data or content is sent, and these requests are not linked to your identity |
| GitHub (GitHub, Inc.) | Encrypted database backups, for disaster recovery | A periodic backup of our database, encrypted before upload with a key only we hold. GitHub stores the encrypted file for up to 90 days and cannot read its contents |
| Backblaze (Backblaze, Inc.) | Backup copies of uploaded files, for disaster recovery, stored in the United States | Copies of the files you upload (message photos, expense receipts, and vault documents, including any in a Medical folder). They are encrypted before upload with a key Backblaze never receives, so Backblaze stores the files and cannot read their contents. File names in the backup are internal identifiers and contain nothing you wrote. The files are held in a private storage bucket that only we can access. A file deleted from Denly is removed from the backup at the next nightly run. Backblaze keeps the earlier copy for up to 90 days and then permanently deletes it |
Note: Fonts are self-hosted within the app. No requests are made to external servers for font loading.
Supabase uses sub-processors including Amazon Web Services (AWS) and Google Cloud Platform. Their data handling is governed by Supabase’s Data Processing Agreement.
We do not share your data with any other third parties.
6. Where Your Data Is Stored
Your data is stored on Supabase infrastructure in the United States, and Denly is offered only to residents of the United States. Backup copies of uploaded files are stored by Backblaze, also in the United States. Supabase maintains SOC 2 Type II compliance.
Because we offer Denly only in the United States, we do not currently transfer your data to the EU/EEA, UK, or Canada, and we do not rely on international transfer mechanisms such as Standard Contractual Clauses. If we expand Denly to other regions, we will update this policy to describe the applicable cross-border transfer protections before doing so.
7. Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Den closure: When a Den is closed, all data scoped to that Den (calendar events, expenses and settlements, messages, uploaded documents and files, and logs scoped to that Den, including its audit log) enters a 30-day grace period and is then permanently and irreversibly deleted, apart from the minimal record of deletion described below. If you need your records, export them (Section 8) before closing the Den.
- Account deletion: When you delete your account, your name and email address are removed from your profile right away and replaced with anonymous placeholders, and your name is removed from the shared records you contributed to. After a 30-day grace period, your sign-in is permanently disabled and cannot be restored. What remains is an anonymous placeholder with no personal information, which exists so that shared records you contributed to still have an author entry.
- Shared Den data: Events, expenses, documents, and messages you contributed to a Den remain for other members after you leave or delete your account. If you leave a Den, your name stays on the records you created. If you delete your account, your name is removed from them (anonymized). Children’s profiles remain with the other co-parent as well, because they are shared Den records about the children and not either parent’s personal profile. Your co-parent’s records belong to them too.
- Messages: The message log is immutable by design. Individual messages cannot be edited or deleted, and they are retained until the Den is deleted. The one exception is content the law requires us to remove (see Section 4 of our Terms of Service).
- Confirmed settlements: Settlement records that have been confirmed by both parties are immutable by design. They cannot be modified or deleted and are retained until the Den is deleted.
- Audit logs: Retained for security and accountability for as long as the Den exists. Admin-role changes (transfers, and takeover requests with their outcomes) are among the logged actions. A Den’s audit log is part of that Den’s records: it is included in exports, and it is permanently deleted with the Den after the 30-day grace period. Account-level entries that do not belong to a Den (for example, the record that an account deletion was requested) are retained, attached to the anonymized profile.
- Record of deletion: When a Den is permanently deleted, we keep a minimal internal record that the deletion took place: the Den’s internal identifier, the dates it was created, closed, and deleted, how many records of each type were removed, and a one-way cryptographic fingerprint of the final state of its message and audit records. This record contains no content and no personal details. It holds no names, emails, messages, children’s information, or files, and none of the details of any event, expense, or document, and it cannot be used to reconstruct any of them. We keep it so that we can demonstrate a deletion happened, and so that an export you saved earlier can still be checked for authenticity after the Den is gone.
- Scheduled deletion: Automated jobs carry out the deletions above once the 30-day period ends. The job for closed Dens runs daily, and the job for deleted accounts runs weekly.
- Deleted vault documents: When you delete a document from the vault, it disappears from the Den right away. Seven days later its file is permanently removed from our storage, together with its title, description, and file name. This applies to every vault folder, including Medical. You can delete your own documents even while a Den is read-only. We keep a minimal record that the document existed: who uploaded it, when it was uploaded and deleted, its folder, file type and size, and a one-way cryptographic fingerprint of the file, so that an export saved earlier can still be checked. If the same file is also attached to a message or an expense, the file stays, because that record still uses it. If we are legally required to preserve a Den’s records, removal waits until that requirement ends.
- Backups: We keep two kinds of backup for disaster recovery (see Section 5). Backups of our database are encrypted with a key only we hold and kept for up to 90 days. Backup copies of uploaded files are encrypted before upload with a key the storage provider never receives. They are removed at the next nightly run after the file is deleted from Denly, and the earlier copy is kept for up to 90 days after that. Data deleted from our live systems may therefore persist in backups until those periods end, after which it is gone from backups too. Backups are used only to recover from system failure. We do not restore them to resurrect individually deleted data.
8. Your Rights
All Users
You can exercise these rights directly within the app, no email required:
- Access your data: Settings > Privacy > Download My Data. This exports a ZIP containing your data as JSON records, your uploaded files exactly as you uploaded them, including any metadata embedded in photos such as location (EXIF) data, and, if you are a co-parent, the integrity-verification materials for your Den’s records. The export contains the records you created and the files you uploaded. Records other members created, including their messages, are not included. For those, the export carries only the integrity fingerprints. You can request one export every seven days, and the download stays available for 72 hours.
- Correct your data: Settings > Personal Info (edit your display name). Your email address comes from Apple or Google and cannot be changed in Denly.
- Delete your account: Settings > Danger Zone > Delete account. You confirm by typing DELETE. If you are the admin of a Den that has other members, you first transfer the admin role to the other co-parent. If you can no longer access the app, you can also request deletion by emailing privacy@guildstacklabs.com.
- Control analytics: Settings > Privacy > Analytics toggle (off by default for new accounts)
Where you have contributed data to a shared Den, or to a settlement both parties have confirmed, deleting your account removes your personal references but does not erase the underlying shared record. Those records are anonymized rather than deleted, as described in Section 7 (Data Retention).
California Residents (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt out of the sale of personal information. We do not sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- Right to non-discrimination. We will not treat you differently for exercising your privacy rights.
Nebraska Residents (Nebraska Data Privacy Act)
- Right to access. Confirm whether we process your personal data and request a copy
- Right to correct inaccurate personal data
- Right to delete personal data you have provided or that we have collected about you
- Right to data portability. Receive your data in a portable format
- Right to opt out of the sale of personal data. We do not sell personal data, so there is nothing to opt out of
- Sensitive data consent. We store documents in a child’s Medical folder only with your explicit consent, which you may withdraw at any time (see Section 2, “Health information”)
To exercise these rights, use the in-app tools in Settings > Privacy or email privacy@guildstacklabs.com.
Appealing Our Decision
If we’re unable to fulfill a privacy request, we’ll explain why in writing. You can appeal our decision by emailing privacy@guildstacklabs.com with the subject line “Privacy Appeal.” We’ll respond within 30 days. If you’re still not satisfied after our appeal response, you may contact the Nebraska Attorney General’s office or your own state’s attorney general.
9. Consumer Health Data (Washington, Nevada & Similar State Laws)
If you are a resident of Washington, Nevada, or another state with a consumer health data law, this section serves as our Consumer Health Data Privacy Policy and applies to “consumer health data” as those laws define it.
Categories of consumer health data we collect. Documents you choose to save to a child’s Medical folder in the Info vault, such as medical records, prescriptions, and insurance cards. Denly has no structured health fields. Health-related details may also appear incidentally in free text you write elsewhere (calendar events, expense descriptions, messages); that content is not scanned, is not separately gated, and is handled like any other Den data.
How we collect it. We collect this data only when you, the account holder, enter or upload it. We do not buy it and we do not collect it from outside sources.
Why we collect it and how we use it. Solely to provide the Denly co-parenting service, so that you and the people you authorize can coordinate your children’s care. We do not use it for advertising and we do not use it to train AI models.
How it is shared. Consumer health data is shared only with the Den members you authorize, according to their role (see Section 4), and with the infrastructure providers that store and process it on our behalf (see Section 5), including the backup copy of uploaded files held by Backblaze. We do not sell consumer health data, and we do not share it for targeted advertising.
Consent. The Medical folder stays closed until you give affirmative, opt-in consent that is separate from your acceptance of our Terms; each parent consents for their own account. We share this data only as needed to provide the service at your direction. You can withdraw consent at any time in Settings > Privacy. Withdrawal stops new saves and edits to the Medical folder; it does not delete documents already stored (delete those from the folder; the file is permanently removed seven days after you delete it, as described in Section 7) and does not affect processing that already took place.
Your rights. You may (1) confirm whether we collect, share, or sell your consumer health data and access that data; (2) withdraw your consent; and (3) have your consumer health data deleted. To exercise these rights, use the in-app tools or email privacy@guildstacklabs.com. We will respond within 45 days (extendable once where the law allows), and you may appeal a denial as described under “Appealing Our Decision” above. Because some shared and confirmed-settlement records are anonymized rather than erased (see Section 7), a deletion request removes your personal health data and your personal references, but anonymized records may remain.
No sale. We do not sell consumer health data and do not seek authorization to do so.
10. Children’s Privacy
Denly is for adults only. You must be at least 18 years old to create an account.
Children do not create accounts, do not interact with the service, and do not provide their own personal information. All data about children is entered by their parents or legal guardians who are the account holders.
We do not knowingly collect personal information from children under 13 (or under 16 in jurisdictions where applicable). Parents control all children’s data within the app and can modify or delete it at any time.
If you believe a child under 13 has created a Denly account without parental consent, contact us at privacy@guildstacklabs.com and we will delete the account.
11. Security
How we protect your data:
- Encryption in transit: All data is transmitted over TLS (HTTPS)
- Encryption at rest: All stored data is encrypted using AES-256 via Supabase
- Row Level Security (RLS): Database-level policies isolate each Den’s data, so one family cannot access another family’s data
- Audit logging: Significant actions within a Den are logged for accountability
- Rate limiting: Authentication attempts and invite code entries are rate-limited to prevent brute-force attacks
- File validation: Uploaded files are validated using magic-byte signature checking to prevent malicious uploads
- Incident response: We maintain a documented incident response procedure. In the event of a data breach affecting your personal information, we will notify affected users and, where required, the appropriate regulators (such as state attorneys general) without unreasonable delay and within the timeframes required by applicable US federal and state breach-notification laws.
No system is 100% secure. If you discover a security vulnerability, please report it to privacy@guildstacklabs.com.
12. Analytics
Analytics is off by default (opt-in). New accounts start with analytics disabled, and we collect no usage analytics unless you turn it on. Your analytics preference is stored in your profile and gates all collection. You can change it at any time: Settings > Privacy > Analytics.
Who processes it. When you enable analytics, we use PostHog (PostHog Inc.) to collect anonymous product-usage data and error reports that help us improve the app. Events are tied to a pseudonymous identifier, not to your name or email.
What we collect. Two kinds of events, both gated on your consent:
- Product-usage events: anonymous signals about how the app is used (for example, “created an event” or “opened the calendar”), never the contents of what you created.
- Error reports: when something fails inside the app, a report of the error, with your device model and operating system version. Denly strips personal details such as names, email addresses, and file names from the report before it leaves your device. Crashes below the app’s own code, in the operating-system layer, are not collected.
No personal content in analytics. We do not put your name, email address, children’s information, message contents, documents, or other personal content into analytics event properties. An analytics event records that something happened, never what was in it.
We will update this policy before materially expanding what we collect or adding a new analytics processor.
13. Calendar Integration
Denly offers one optional calendar integration:
- Device calendar sync: You can sync Denly events to your device’s native calendar (iOS Calendar, Google Calendar). This requires explicit permission. Once synced, that event data is subject to your device’s privacy settings and to the calendar service’s own privacy policy.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notice or email before the changes take effect. You consent to receive this policy and any privacy notices electronically, as described in the Terms of Service (Section 3, Electronic Communications and Notices).
Your continued use of Denly after the effective date of any changes constitutes your acceptance of the updated policy. If you disagree with the changes, you may delete your account.
Previous versions of this policy are available from GuildStack Labs on request.
15. Contact Us
For any questions about this Privacy Policy or your personal data:
Email: privacy@guildstacklabs.com Data controller: GuildStack Labs LLC
Version History
We keep a record of material changes to this Privacy Policy so you can see what changed and when. The current version and effective date are shown at the top of this page. The summaries below are for convenience. The text of this policy is what governs.
| Version | Effective | Summary of changes |
|---|---|---|
| 1.8 | September 20, 2026 | Three changes to how uploaded files are handled, each already in effect. Other members no longer receive your original photo (Section 4): when another member, including counsel, opens a photo you uploaded, they receive a copy without the information embedded in your file, such as location (EXIF) data; the copy may be smaller than your original; only you receive the original, in the app and in your own export; PDF files are shared as uploaded. Deleted vault documents are removed (Sections 2, 7, and 9): seven days after you delete a vault document, its file, title, description, and file name are permanently removed, in every folder including Medical; we keep a minimal record that the document existed, including a one-way fingerprint of the file; a file also attached to a message or an expense stays; you can delete your documents while a Den is read-only; removal waits if we are legally required to preserve the Den’s records. Backup copies are encrypted before upload (Sections 5 and 7): the Backblaze copies of uploaded files were encrypted with keys Backblaze manages; they are now encrypted before upload with a key Backblaze never receives, so Backblaze cannot read them. This is a material change. |
| 1.7 | September 19, 2026 | Accuracy corrections from a line-by-line check of this policy against the app. Removed statements that were not true: Denly does not collect a profile photo (Sections 2 and 4); it does not store device model or operating system version outside of opt-in analytics (Section 2B); analytics has no subscription-funnel or server-side purchase events, and what it calls crash reports are error reports from the app’s own code (Sections 2B, 5, and 12); there is no way to hide a message from your own view (Section 7); leaving a Den does not remove your name from your records, only deleting your account does (Section 7); and account deletion is under Settings > Danger Zone and is confirmed by typing DELETE, not by signing in again (Section 8). Added what was missing: Expo relays push notifications and receives the push token, the notification, and internal Den and record identifiers, and notifications hide their content by default (Section 5); we keep an encrypted Sign in with Apple token, used only to disconnect Denly from your Apple ID at account deletion (Sections 2 and 4); a record carries its author’s email address (Section 4); guests see calendar events in full (Section 4); and a data export contains the records and files of the person who requested it, not other members’ records, limited to one every seven days and available for 72 hours (Sections 4 and 8). The Version History now states that its summaries are for convenience and the text of the policy governs. The app’s behavior did not change. This policy now describes it accurately. |
| 1.6 | September 19, 2026 | Corrects a statement about our providers. Sections 5 and 6 said that every infrastructure provider is bound by a data processing agreement. That was not true of every provider in the table: the timestamping authorities, for example, receive only a hash and have no customer agreement with anyone, and we had not confirmed one for each of the others. The sentence now says what is true of all of them: each receives only the data described in the table and handles it under its own published terms. The statement about Supabase’s Data Processing Agreement, which is part of Supabase’s terms, is unchanged. Nothing about what we collect, who receives it, or how it is protected has changed. |
| 1.5 | September 19, 2026 | Backups, deletion, and plain language. Adds Backblaze to Section 5: backup copies of uploaded files, stored in the United States, encrypted at rest with keys Backblaze manages, with deleted files’ earlier copies kept up to 90 days; Sections 6, 7, and 9 updated to match. Corrects the audit log retention statement (Section 7): a Den’s audit log is deleted with the Den, which the Den-closure bullet already said; account-level entries stay with the anonymized profile. Corrects the account deletion statement (Section 7): your name and email are removed at once and sign-in is permanently disabled after 30 days, but an anonymous placeholder with no personal information remains. Adds the record of deletion (Section 7): a content-free internal record that a Den was deleted. Replaces the “soft-deleted data” bullet with the actual schedule of the deletion jobs. Section 2C now states that unhandled hardship requests are deleted after 180 days and that the form keeps a one-way hash of the submitting address for up to 48 hours to limit abuse. Section 1 is now a short summary, and wording was simplified throughout with no other change to what we collect or how we use it. The effective date shown for version 1.4 was corrected to the date it was published. |
| 1.4 | September 14, 2026 | Den administration disclosure. States that access times (sign-ins, session refreshes, push-token registrations) are also used to determine whether a Den’s admin has stopped using Denly when the other co-parent asks to take over the admin role (Section 2B), adds Admin Role Requests to the data inventory (Section 2D: the request email and Den identifier, kept up to 24 months after the request closes), adds administering Den roles to how we use your information (Section 3), and discloses that a takeover request, its outcome, and the date the former admin was last active appear in the Den’s audit log, visible to co-parents and counsel and included in exports (Section 4). Notes admin-role changes among the retained audit-log actions (Section 7). |
| 1.3 | September 3, 2026 | Payment processor update. Subscriptions are now purchased through Apple (App Store In-App Purchase) instead of a Stripe checkout. Apple receives the purchase and a randomly generated identifier for your Den, and we receive back transaction identifiers, product, dates, price, and storefront, never card details, name, or email. Replaces the Stripe row in the Section 5 processor table with Apple (App Store); Stripe no longer processes Denly payments. |
| 1.2 | August 27, 2026 | Health-data accuracy update. States the actual scope of the health consent: it gates saving documents to a child’s Medical folder, is opt-in and per-account, and withdrawal stops new saves and edits without deleting existing documents. Removes references to structured health fields (allergies, medications, provider contacts) that the app does not have. Discloses that health details may appear incidentally in free-text elsewhere (calendar events, expense descriptions, messages), which is not scanned or separately gated. Section 4 role table updated to match. |
| 1.1 | August 6, 2026 | Accuracy and disclosure update. Adds messages to the data inventory and retention sections (the message log is immutable by design; hiding a message does not remove it from the record or exports). Adds two processors to Section 5: Expo (app-update checks on launch: version metadata only, request IP visible to Expo, never linked to identity) and GitHub (encrypted database backups, unreadable by GitHub, kept up to 90 days), with a matching Section 7 note that deleted data may persist in encrypted backups up to 90 days. Documents that data exports include uploaded files exactly as uploaded, with embedded photo metadata (EXIF) intact, plus integrity-verification materials. Clarifies that children’s profiles remain with the other co-parent after account deletion (they are shared Den records). Removes the ICS calendar-feed description (that feature does not exist; only device calendar sync is offered). Corrects the Section 4 role table to match server-enforced access: Guests see calendar events plus children’s names and birthdays only (not care or medical information, which the previous version overstated), Counsel is strictly read-only, and these limits are enforced server-side. |
| 1.0 | July 17, 2026 | First versioned edition. Clarifies OAuth-only sign-in (no passwords stored); adds Stripe, PostHog, and independent timestamping authorities to the list of processors (timestamping receives only a cryptographic hash, never content); adds a Legal Process and Government Requests section; documents hardship-request data and its retention; states the 30-day permanent-deletion policy for closed Dens covering files, records, and Den-scoped logs; and describes product-usage and subscription-funnel analytics events with no personal content in event properties. |