Legal

Privacy Policy

Version 0.9 (draft) · Prepared 3 August 2026 · Not yet in force
C.A.R.E. — Co-Parenting Access and Records Exchange · contact@thecareapp.ca

1. In short

C.A.R.E. is a record-keeping service for co-parents. The most important thing to understand about privacy in C.A.R.E. is this: information you record about a shared case is shared with the other parent, and it is permanent. Neither of you can delete it, and neither can we, other than in the limited circumstances described in section 12.

Your private information — contact details, address, preferences, private notes — is a separate matter. It is never shown to the other parent, and it is removed when you close your account.

2. Who we are

C.A.R.E. (Co-Parenting Access and Records Exchange) operates the C.A.R.E. mobile application and this website. For the purposes of applicable privacy legislation we are the organisation responsible for the personal information described in this policy.

Privacy enquiries: contact@thecareapp.ca. [for review — the registered legal entity name and address should be inserted here, together with the designated privacy contact required under PIPEDA]

3. Information we collect

3.1 Information you give us

  • Account information — your email address and password. We do not store your password; authentication is handled by our identity provider.
  • Profile information — your first, middle and last name, your role (parent or professional), telephone number, home address, and your currency and timezone preferences.
  • Professional information, if applicable — firm or practice name, office address, licence or bar number, licensing jurisdiction and area of practice.
  • Case content — expenses, payments, messages, attachments, receipts and the information you record about children.
  • Reports — the category, description and referenced messages when you report a concern.

3.2 Information generated by your use of the Service

  • Record entries — each action you take within a case creates a numbered, timestamped entry attributed to you.
  • Read receipts — when you read a message, the fact and time of reading is recorded and is visible to the sender. This cannot be disabled.
  • Device information for notifications — a push notification token identifying the device, so that we can deliver alerts.

3.3 What we do not collect

  • We do not collect the location of any user or of any child.
  • We do not collect payment card details. Any future payment processing will be handled by a regulated payment provider and card data will not reach our systems.
  • We do not use advertising identifiers or third-party advertising trackers.

4. How we use information

We use personal information to:

  • create and secure your account, and verify your email address;
  • operate the Service and maintain the case record;
  • make shared case information available to the other parent on that case;
  • send notifications about activity on your cases, according to your preferences;
  • send transactional email such as email verification and password reset;
  • review reports of harassment, safety concerns or misuse, and take appropriate action;
  • diagnose faults, maintain security, and prevent abuse; and
  • comply with legal obligations and respond to lawful requests.

We do not sell personal information. We do not use case content to train machine learning models. We do not display advertising.

5. The shared record

This is the section most people need to read carefully.

5.1 What the other parent sees

A case is shared. The other parent on your case can see everything recorded to that case: expenses, payments and their confirmations, messages and attachments, child information, and the entries showing when each of these occurred and who made them. They can see your first and last name.

5.2 It is permanent

Entries are appended and never altered or removed. A correction is recorded as an additional entry; the original remains and remains visible. This is a deliberate design decision: the purpose of the Service is to produce a record that neither party can revise after the fact.

5.3 The consequence for you

You should record information on a case on the understanding that it will be visible to the other parent indefinitely, that it may be exported by either of you, and that it may be produced in legal proceedings. You cannot withdraw it later. [for review — the adequacy of consent obtained at the point of recording, and whether an additional in-product acknowledgement is required]

6. What stays private

The following are never visible to the other parent:

  • your telephone number, home address and email address;
  • your notification settings, currency and timezone preferences;
  • your professional details, unless disclosed through professional access;
  • which messages you have privately marked for your own reference;
  • the existence or content of any report you make; and
  • private journal entries, where that feature is available, unless you share a specific entry deliberately.

These restrictions are enforced at the database level through row-level security policies, not merely by what the application chooses to display.

7. Children’s information

C.A.R.E. is not directed at children and children may not hold accounts. Information about children is collected from a parent, not from the child.

Information you record about a child — name, date of birth, and details such as allergies, medications, schooling and medical contacts — is shared with both parents on that case, on the basis that both need access to information affecting the child’s wellbeing. It is not disclosed outside the case except as described in section 9.

One parent maintains each child’s record; the other can view it and request changes. We do not verify parental status or authority. [for review — obligations where a parent’s authority to record a child’s information is restricted by court order, and any applicable requirements concerning children’s personal information in Ontario and in Florida]

8. Consent and legal basis

We collect, use and disclose personal information with your knowledge and consent, given when you create an account and accept our Terms of Service, and reaffirmed each time you choose to record information.

We rely on the following additional grounds where consent alone is not sufficient:

  • Performance of our agreement with you — operating the Service you have asked us to provide.
  • The rights and interests of a third party — specifically, the other parent’s interest in a complete and unaltered shared record, which is the basis on which we decline to delete case content at the request of one party.
  • Legal obligation — retention and disclosure required by law.

[for review — the characterisation of the third-party-interest ground under PIPEDA, and whether it adequately supports refusal of a deletion request in respect of shared case content]

9. Who we share with

9.1 The other parent on your case

As described in section 5.

9.2 Professionals you authorise

Where you grant a lawyer, mediator or parenting coordinator access to a case, they see the case content permitted by their role. You control whether to grant that access and may withdraw it.

9.3 Service providers

We use third-party infrastructure providers who process personal information on our behalf and on our instructions:

  • Google (Firebase Authentication and Cloud Functions) — account authentication, email verification and password reset, and scheduled server processes.
  • Supabase — database and private file storage for case records, messages, attachments and receipts.
  • Expo — delivery of push notifications to your device.
  • Our email delivery provider — transactional email sent from our domain. [for review — to be named once selected]

These providers are bound by their agreements with us to use the information only for the purposes of providing their service.

9.4 Legal disclosure

We may disclose personal information where required by law, by a court order or valid legal process, or where we believe in good faith that disclosure is necessary to prevent serious harm to a person, to investigate suspected illegal activity, or to protect our legal rights.

We do not proactively disclose case records to any party outside the case.

9.5 Business changes

If C.A.R.E. is involved in a merger, acquisition or sale of assets, personal information may be transferred as part of that transaction. We will give notice through the Service before your information becomes subject to a materially different privacy policy.

10. Where information is stored

Our service providers operate infrastructure in Canada and in the United States. Personal information may therefore be stored or processed outside your province or country, and may be accessible to law enforcement and national security authorities of those jurisdictions under their laws.

[for review — confirmation of the storage regions actually in use, and whether an express cross-border transfer notice is required for users resident in Ontario, in Quebec, and in Florida]

11. How long we keep it

11.1 While your account is open

We retain your information for as long as your account remains open.

11.2 When you close your account

Your private information — telephone number, home address, device tokens, preferences and professional details — is removed from active systems immediately.

Your name remains associated with the entries you made, so that the shared record remains intelligible to the other parent, in the way a name appears in a transcript.

We retain the residual private information necessary to permit reinstatement for a period of six years from closure, after which it is permanently deleted. During that period you may reopen your account by registering with the same verified email address.

11.3 The shared case record

The case record is retained independently of either individual account. One parent closing their account does not begin a countdown to deletion of the shared record, because that record is the other parent’s evidence as much as it is yours.

[for review — the retention period for a case record where both parents have closed their accounts, which we have not yet fixed. Options under consideration are a period running from the closure of the second account, or from the youngest child on the case reaching the age of majority.]

11.4 Reports

Reports and the record of any action taken on them are retained for as long as necessary for safety and compliance purposes, and are not deleted at the request of either party.

12. Your rights, and their limits

Subject to applicable law, you may:

  • Access the personal information we hold about you, and be told how it has been used and to whom it has been disclosed.
  • Correct inaccurate information in your profile. Note that case entries are corrected by addition, not by amendment (section 5.2).
  • Withdraw consent to optional processing, such as push notifications, at any time.
  • Close your account, with the consequences described in section 11.
  • Complain to us, or to the Office of the Privacy Commissioner of Canada (section 16).

12.1 The limits on deletion

We cannot delete shared case content at the request of one party. That content forms a record which the other parent is entitled to rely upon, and which may be required in legal proceedings. This is the principal limitation on your rights under this policy and we state it plainly rather than burying it.

If you believe your circumstances require earlier deletion of your private information, or if you consider that content on a case ought to be removed, contact us. We will consider each request having regard to our legal obligations and to the rights of the other parent, and we will explain our decision. [for review — the process for handling erasure requests, the grounds on which refusal is defensible, and the wording of our response]

13. Security

We protect personal information with measures including:

  • Row-level security in the database, so that access rules are enforced by the data layer rather than by the application. A parent cannot read another parent’s private profile even if a screen were to request it.
  • Private file storage. Receipts and attachments are not publicly accessible; they are retrieved only through short-lived signed links issued to members of the relevant case.
  • Cryptographic hashing of record entries and uploaded files, making subsequent alteration detectable.
  • Encryption in transit for all communication between the app and our services, and encryption at rest by our infrastructure providers.
  • Verified email addresses before an account can be used, and before a closed account can be reinstated.

No system is completely secure. If we become aware of a breach of security affecting your personal information, we will notify you and the relevant regulator where required. [for review — breach notification obligations under PIPEDA and any applicable Florida requirements]

14. This website

This website does not use advertising or analytics cookies and does not track visitors across sites. Web fonts are loaded from Google Fonts, which receives your IP address as part of that request.

Standard server logs may record IP addresses and request information for security and diagnostic purposes.

15. Changes to this policy

We may update this policy. Where a change is material we will give notice through the Service or by email before it takes effect. The version and date at the top of this page indicate the current revision.

16. Contact and complaints

For any privacy question, to exercise a right described above, or to make a complaint, contact us at contact@thecareapp.ca. We will respond within thirty days.

If you are not satisfied with our response, you may complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.

Notes for review. The matters most in need of counsel’s attention are: section 5.3 and section 12.1 (refusal to delete shared case content at one party’s request, and whether the third-party-interest ground in section 8 adequately supports it under PIPEDA); section 7 (recording children’s information without verifying parental authority, and the position where a court order restricts it); section 11.2 and 11.3 (the six-year retention period, and the unfixed retention period for a case record after both accounts close); section 10 (cross-border storage notice); and section 13 (breach notification). The identity of the legal entity, its address and the designated privacy officer must be inserted in section 2.