OurPath Privacy Policy
Effective from 19 September 2026. Version 1.1.
This policy explains what Our Path Digital Ltd does with personal data in OurPath — yours, your co-parent's, and your children's. It is longer than we would like, because separated families are a harder privacy problem than most apps have, and we would rather answer the difficult questions here than have you discover the answers later.
At a glance #
What we do with your data. We use it to run your family's arrangement: the shared calendar, the message thread, the record of children's costs, the parenting plan, and the exports you can hand to a solicitor. That is nearly all of it.
Where it lives. In the United Kingdom, on AWS infrastructure in London (eu-west-2). Some limited processing happens outside the UK, and section 15 names every instance and the legal mechanism for each.
Three things that surprise people, so we are saying them first:
- Shared records are permanent, and closing your account does not erase them. Messages, expenses and agreements belong to the family record, not to one parent. Your profile is deleted; the record survives for your co-parent and for any legal proceedings. Sections 9 and 10.
- Your co-parent never sees your drafts, your private notes, your address, your phone number, your location or your payment details. Not by default — not at all. Section 6.
- The text of a message you are composing is sent to our AI provider so that tone assist can offer a calmer version. It is not used to train AI models and it is not stored by the provider. Section 12.
What we never do. We do not sell your data. We do not use your family's content for advertising. We do not share your location or phone number with your co-parent. We do not read your messages for analytics. We do not train AI on your family.
If you are unhappy with us, you can complain to us directly at hello@ourpath.app — we have a formal complaints process and we will respond — and you can complain to the Information Commissioner's Office at any time. Section 19.
1. Who we are #
Our Path Digital Ltd is the data controller for personal data processed in OurPath. That means we decide how and why it is used, and we are the organisation accountable for it.
| Controller | Our Path Digital Ltd |
| Company number | 17406043 |
| Registered office | Chapel House, 22 Warrington Road, Lymm, Cheshire, WA13 9BG |
| ICO registration | ZC250261 |
| Privacy contact | hello@ourpath.app |
| Postal | Data Protection, Our Path Digital Ltd, Chapel House, 22 Warrington Road, Lymm, Cheshire, WA13 9BG |
| Data Protection Lead | Mirza Saeed, Director |
We are registered with the Information Commissioner's Office as a data controller. Registration is a legal requirement and a fee payment; it is not an endorsement of us by the ICO and we do not present it as one.
We do not have a Data Protection Officer, and we are not required to appoint one. Article 37 of the UK GDPR requires a DPO where an organisation is a public authority, or where its core activities consist of large-scale monitoring of individuals, or large-scale processing of special category or criminal offence data. We have assessed our processing against each of those tests, documented the assessment, and none of them applies to us at our current scale and in our current form. We keep that assessment under review and we will appoint a DPO if it changes.
The Data Protection Lead named above is the person accountable for data protection at OurPath, and is who you reach when you write to hello@ourpath.app. We also maintain a Data Protection Impact Assessment covering the processing described in this policy, which is reviewed at least annually and whenever we materially change a feature that touches your family's data.
2. What this policy covers #
This policy covers:
- the OurPath mobile app (iOS and Android);
- the OurPath web portal;
- the OurPath website at ourpath.app, including the free tools and guides;
- the professional portal used by mediators, solicitors and other professionals.
It covers personal data about four groups of people:
| Group | Are they our user? | Notes |
|---|---|---|
| Parents | Yes | The two parents in a family, each with their own account |
| Children | No | Children do not have OurPath accounts. We hold data about them, entered by their parents. Section 7 |
| Professionals | Yes | Mediators, solicitors and others using the professional portal |
| Other people | No | Schools, GPs, childminders, new partners, emergency contacts — named by parents in the Info Bank or in messages. Section 8 |
3. Our role, and the mediator's role #
We are the controller for all personal data in OurPath. That is true whether you signed up yourself or a mediator created your family and invited you.
A mediator or solicitor who uses OurPath with your family is a separate, independent controller for their own case file and their own professional records. They are not our processor and we are not theirs. Their handling of your data in their own systems is governed by their own privacy notice and their own professional obligations, not by this policy.
What that means in practice: if you want to know what your mediator holds about you, ask your mediator. If you want to know what OurPath holds about you, ask us.
If we ever license OurPath to an organisation under a business agreement where that organisation determines the purposes of processing, our role may differ. We will say so clearly at the time and put the appropriate agreement in place; that is not how OurPath works today.
4. The personal data we collect #
4.1 Data you give us when you sign up #
- Name (and the display name your co-parent sees)
- Email address
- Password (stored only as a cryptographic hash — we never see or hold it)
- Where you choose to sign in with Apple or Google, the identifier and email address those services return to us
- Optional profile photo
- Your relationship to the children in the family
4.2 Data about your family and your arrangement #
- Your children: names, dates of birth, which parent they mainly live with
- Your parenting plan: every section you complete, every version, and each parent's acceptance
- Your calendar: the schedule generated from the plan, handover times and places, one-off events, swap requests and the responses to them
- Your local authority, so that we can apply the correct school term dates
4.3 Messages #
The content of every message sent in your family thread, the time our servers received it, and when it was first opened.
4.4 Costs and expenses #
Amounts, categories, descriptions, dates, which child a cost relates to, receipts you upload, the split you agreed, and every approval, decline, settlement and confirmation.
4.5 The Info Bank #
Information about your children that you choose to record: medical information including allergies, conditions and medication; GP, dentist and hospital details; school, teachers and term arrangements; clothing and shoe sizes; emergency contacts; childcare providers; documents you upload.
You decide what goes in here. We ask you to put in what is useful for parenting across two households, and no more.
4.6 Payment data #
We use Stripe to take payments on our website. We never see or store your full card number. We hold the last four digits, the card type, the expiry, your billing country and postcode, our own subscription and invoice records, and the outcome of each payment. Where you subscribe through the Apple App Store or Google Play, those companies take the payment and we receive only a subscription status and an anonymous identifier.
4.7 Data we generate about how you use OurPath #
- IP address, device type, operating system, app version
- Login times, session activity and security events
- Privacy-first product analytics: which screens are reached, whether onboarding was completed, whether a plan was accepted, whether an export was generated
- Error and crash reports
- Push notification tokens
Our analytics never include message content, expense descriptions, Info Bank content, or any data about a child. We measure whether people completed onboarding, not what they wrote.
4.8 Data your co-parent creates #
Anything your co-parent puts into the shared record is also data about you, and about your children. You will be able to see it, because it is shared. Section 9 explains what this means for both of you.
4.9 Data from professionals #
Where a mediator or solicitor sets up your family, they give us your name and email address and the content of the parenting plan they build with you.
4.10 Data from our website #
If you use our free tools, read our guides or join a waiting list, we may collect what you enter and standard web analytics data. Our Cookie Policy covers this.
5. Special category and sensitive data #
Some of what you put into OurPath is special category data under UK GDPR — data that gets extra legal protection. In this product that will typically include:
- health data: a child's allergies, conditions, medication, immunisations, appointments, or a parent's health mentioned in a message about why a handover changed;
- religious or philosophical beliefs: religious holidays, observance, schooling choices;
- racial or ethnic origin: heritage, language, cultural arrangements;
- occasionally sex life or sexual orientation, or trade union membership, where mentioned in free text.
It will also frequently include data that is not technically "special category" but is every bit as sensitive: allegations about the other parent, information about domestic abuse, safeguarding concerns, details of court proceedings, and financial hardship.
Be aware of where it goes. Free-text fields — messages, expense descriptions, plan notes — cannot be filtered. If you type it, it becomes part of the permanent shared record and your co-parent can see it.
Our lawful conditions for processing this data are set out in the table in section 11. In summary, our primary condition is Article 9(2)(f) UK GDPR — processing necessary for the establishment, exercise or defence of legal claims, which is the honest description of what an evidential co-parenting record is for. We rely on explicit consent only where consent is genuinely free and specific, which it rarely is for information that arrives incidentally inside a message.
6. What we do not collect, and what we never expose #
This section exists because in this product, what we refuse to build matters as much as what we build.
We do not collect:
- your location, at any time, in any form. There is no location feature, no GPS check-in and no geofencing. It is not switched off by default; it does not exist.
- your full card number
- your contacts, your photo library, your call logs, your other messaging apps
- biometric data (a device fingerprint or face unlock is verified by your device, and we never receive it)
We never expose to your co-parent:
- your home address or your postal address
- your phone number
- your location, ever
- your draft messages or anything you typed and did not send
- your private notes
- your payment details, card, bank or billing address
- whether a message of yours was flagged by tone assist, or that a rewrite was suggested
We never:
- sell personal data, to anyone, for any price
- use your family's content to target advertising
- read your messages for analytics or product research
- allow our AI provider, or anyone else, to train models on your family's data
- give one parent information about the other beyond what the product already shows both of you, except where the law requires it
7. Children's data #
Children are not our users. They are, however, the people OurPath is about, and the data we hold about them is some of the most sensitive in the product. This section sets out our position in full.
7.1 The child is a data subject #
A child has their own data protection rights, whether or not they have an account and whatever their age. Those rights belong to the child, not to either parent.
7.2 What we hold about children #
Names, dates of birth, where they live and with whom, their schedule and its history, their school and teachers, their GP and dentist, their allergies, conditions and medication, their clothing sizes, their emergency contacts, costs recorded against them, documents parents upload about them, and anything either parent writes about them in a message or a plan.
7.3 Why we hold it, and our lawful basis #
We hold it because it is necessary to provide the service to the parents under our contract with them (Article 6(1)(b)), and because we and the parents have a legitimate interest in children's arrangements being documented, coordinated and capable of being evidenced (Article 6(1)(f)). Where the data is special category — and health data about a child frequently is — we rely on Article 9(2)(f), the establishment, exercise or defence of legal claims.
7.4 Who enters it, and on what authority #
The parent entering data about a child does so in exercise of their own parental responsibility. By entering it, that parent confirms to us that they have the authority to do so. We do not, and cannot, verify parental responsibility, and we do not adjudicate between parents about whether a particular piece of information should have been entered.
7.5 When parents disagree #
This is the hard case, and none of our competitors' policies answer it, so here is ours.
- We will not take sides between two parents with parental responsibility about what may be recorded about their child. Deciding that is not our role and we are not equipped to do it.
- One parent objecting does not erase the other parent's record. Where a shared record exists, it stays, for the reasons in section 10.
- Either parent can ask us to remove Info Bank content they believe is inaccurate or inappropriate. Where a factual error is clear — a wrong date of birth, a wrong school — we will correct it. Where the dispute is about judgement rather than fact, we will tell you both that we are not able to resolve it and that the route is mediation, a solicitor or, ultimately, a court.
- Where an objection raises a safeguarding concern, we treat it under our Safeguarding Statement, not as a data dispute.
- A court order directed at us will be complied with. See section 14.
7.6 Children's own rights #
A child can ask us for a copy of the personal data we hold about them, or ask us to correct it. We will deal with such a request:
- directly with the child, where they are old enough to understand what they are asking for. In line with ICO guidance there is no fixed age; in practice we expect this to be from around 12, judged case by case.
- through a parent, for a younger child, where the parent is acting in the child's interests and we are satisfied they hold parental responsibility.
In either case we will consider the child's best interests, and we will not disclose information that would identify the other parent or reveal their private data without careful consideration — the same limitation that applies to a parent's own request in section 18.
We will not provide a parent with a child's data where doing so would put the child at risk.
7.7 What we commit to #
Account holders on OurPath must be 18 or over, and OurPath is not a service designed for or likely to be accessed by children. We nonetheless choose to apply the standards of the ICO's Age Appropriate Design Code (Children's Code) and the children's higher-protection duty under the Data (Use and Access) Act 2025 to the children's data we hold. Specifically we commit to:
- the best interests of the child as a primary consideration in how we design features touching children's data;
- data minimisation — we ask for the least we can and the Info Bank is entirely optional;
- no profiling of children, ever, and no use of children's data for marketing, advertising or product recommendations;
- a completed Data Protection Impact Assessment covering children's data, reviewed at least annually and whenever we materially change a relevant feature;
- no children's accounts unless and until we have designed for them properly, which would be a deliberate decision announced in advance, not a quiet feature release.
7.8 Children's data after a parent leaves #
Data about a child remains in the family record when a parent closes their account, because it is the other parent's record too, and the child's arrangements continue. See section 10.
8. Other people named in your account #
You will name people who are not OurPath users: schools, teachers, GPs, dentists, childminders, grandparents, new partners, emergency contacts.
We process their data because it is necessary for the legitimate interests of you and your co-parent in coordinating your children's care (Article 6(1)(f)). We hold the minimum you enter and we do not contact them, market to them, or share their data with anyone.
Please only enter what you need. A childminder's phone number is useful; her opinion of your ex is not, and it becomes a permanent record you cannot remove.
If someone named in your account contacts us about their data, we will deal with their request under section 18, taking account of the fact that removing them may affect your family's arrangements.
9. Shared data, two households, and what your co-parent can see #
This section describes the single biggest difference between OurPath and an ordinary app.
9.1 What is shared #
| Shared with your co-parent | Private to you |
|---|---|
| Messages you send | Draft messages you do not send |
| Expense entries, approvals, declines, settlements | Your payment and card details |
| Swap requests and responses | Your private notes |
| Parenting plan versions and acceptances | Your home address and phone number |
| Changes to the money agreement | Your device and login data |
| Info Bank entries and documents | Whether tone assist flagged a message of yours |
| Calendar events and history | Your account settings |
| Which professionals have access, and when | Your location — which we do not have at all |
9.2 Shared records are permanent #
Shared records are append-only. They cannot be edited or deleted — by you, by your co-parent, or by us. The permission to change or remove them is revoked at the database level for every account including our own. Each record is timestamped by our servers and cryptographically chained to the one before it, so alteration would be detectable.
This is a deliberate design choice and it is what makes the record worth having. It also means:
- you cannot take back a message you regret;
- your co-parent cannot delete one they regret either;
- neither of you can quietly change what was agreed;
- we cannot alter your records, even if one of you asks, even under pressure.
9.3 What this means for your privacy rights #
Because a shared record concerns two adults and their children, no one person has sole control of it. When you exercise a data protection right over a shared record, we have to weigh your rights against your co-parent's. Sections 10 and 18 explain how.
10. Deleting your account, and the two-parent problem #
10.1 What we delete when you close your account #
Your display name and profile, your photo, your contact details, your account settings, your drafts and private notes, your payment details held by us, your device tokens and your session data. These are deleted or irreversibly anonymised.
10.2 What we keep, and the legal basis for keeping it #
We keep the shared record your family created. In the retained record your name is replaced with a neutral label such as "Parent A".
We rely on two provisions of UK GDPR:
- Article 17(3)(e) — erasure does not apply where processing is necessary for the establishment, exercise or defence of legal claims. Family proceedings, Child Maintenance Service disputes, enforcement applications and variation applications frequently turn on what was agreed and what happened, sometimes years afterwards. A record that one parent can destroy on the eve of proceedings is not a record.
- Article 17(1)(c) / 21(1) — our legitimate interests, and those of your co-parent and your children, in maintaining a complete and reliable record override the interest in erasing one side of it. Your co-parent's data protection rights in their own record are not extinguished by your decision to leave.
10.3 How long we keep it #
Seven years from the last activity in the family, after which the shared record is permanently deleted. The Data Retention and Deletion Policy sets out every retention period in full, with the reasoning.
We chose seven years because it covers the limitation period for most civil claims in England and Wales with a margin, and because family proceedings concerning a child can revisit historical arrangements years later. We considered indefinite retention, which several competitors effectively operate, and rejected it as incompatible with the storage limitation principle.
10.4 Deleting the shared record #
The shared record is deleted where both parents ask us to and no legal reason to retain it applies; where a court orders it; or when the seven-year retention period expires.
If you ask us to erase shared records and we cannot, we will:
- tell you within one month, in writing;
- tell you exactly what we have deleted and what we have kept;
- explain the specific legal basis for keeping it;
- tell you how to complain to us and to the ICO.
We will not be vague about it and we will not make it difficult.
10.5 Death and incapacity #
If we are told with reasonable evidence that a parent has died, we freeze their account and preserve the record as it stood. The surviving parent keeps access and export rights. We do not delete the record, because it may matter for the children, for the estate, and for any proceedings.
For a parent who lacks capacity, we will consider requests from a person with proper legal authority — an attorney under a lasting power of attorney, or a court-appointed deputy — on production of evidence of that authority.
11. Why we use your data, and our lawful basis #
| # | What we do | Data used | Article 6 basis | Article 9 condition (special category) |
|---|---|---|---|---|
| 1 | Create and run your account | Identity, contact, credentials | Contract | — |
| 2 | Run your family's calendar and generate it from your plan | Plan, children, schedule, local authority | Contract | 9(2)(f) where health or belief data is involved |
| 3 | Deliver messages between parents and keep the thread | Message content, metadata | Contract | 9(2)(f) |
| 4 | Record, approve and settle children's costs | Expense data, receipts, splits | Contract | 9(2)(f) where a cost reveals health data |
| 5 | Build, propose, version and accept parenting plans | Plan content, acceptances | Contract | 9(2)(f) |
| 6 | Hold Info Bank information about your children | Medical, school, contacts, documents | Contract; legitimate interests (coordinating care across two households) | 9(2)(f); 9(2)(a) explicit consent where you choose to add health information beyond what the service requires |
| 7 | Maintain records as append-only, tamper-evident and exportable | All shared records | Legitimate interests — providing a reliable, neutral record that either parent or a court can rely on, which cannot be achieved if either parent can alter it | 9(2)(f) — establishment, exercise or defence of legal claims |
| 8 | Generate certified exports and operate the public verifier | Shared records, export metadata | Contract; legitimate interests | 9(2)(f) |
| 9 | Provide tone assist | Text of the message you are composing | Legitimate interests — reducing conflict between parents, a benefit to both of them and to their children. You can decline every suggestion and the feature never blocks you | 9(2)(f) where the draft contains special category data |
| 10 | Send service notifications (new message, swap, expense, plan) | Contact details, event metadata | Contract | — |
| 11 | Take payment, manage subscriptions, recover failed payments | Payment and subscription data | Contract; legal obligation (tax) | — |
| 12 | Keep accounting and tax records | Invoices, transactions | Legal obligation (Companies Act 2006, tax law) | — |
| 13 | Provide customer support | Whatever you tell us, account data | Contract; legitimate interests | 9(2)(f) where relevant |
| 14 | Keep the service secure and prevent fraud and abuse | Technical, security and usage data | Recognised legitimate interests (network and information systems security, DUAA 2025); legal obligation | — |
| 15 | Understand how OurPath is used and improve it | Privacy-first funnel analytics — never content, never children's data | Legitimate interests — improving a product people rely on, using the least intrusive data that answers the question | — |
| 16 | Send you marketing about OurPath | Email address, marketing preferences | Consent — or the soft opt-in for existing customers, always with a one-click unsubscribe | — |
| 17 | Comply with court orders, legal process and regulators | Whatever is lawfully required | Legal obligation | 9(2)(f) |
| 18 | Act on a safeguarding concern | Relevant records | Legal obligation; vital interests (Article 6(1)(d)) where there is a risk to life; legitimate interests | 9(2)(c) vital interests; 9(2)(f) |
| 19 | Handle a business sale or reorganisation | Account and subscription data | Legitimate interests — and only with the protections in section 13 | — |
Where we rely on legitimate interests, we have carried out a balancing assessment weighing our interest against your rights. You can ask us for a summary of any of them at hello@ourpath.app, and you have the right to object — section 18.
12. AI and automated processing #
12.1 What we send to our AI provider, and what we do not #
Tone assist is the only feature that sends your content to an AI provider. When you compose a message and tone assist runs:
- what is sent: the text of the message you are composing, and nothing else;
- what is not sent: your name, your co-parent's name, your children's names as identifiers, your account details, your message history, your calendar, your expenses, your Info Bank, or anything from your profile.
Our provider is Anthropic PBC (United States). Section 15 sets out the transfer mechanism.
12.2 Our commitments #
- Your content is not used to train AI models — not by us, not by Anthropic. This is a contractual term of our agreement with them, not a hope.
- Your content is not retained by the provider beyond the short period needed to process the request and meet their abuse-monitoring obligations, as set out in our agreement with them.
- Drafts are never stored by us. If you do not send it, we do not keep it.
- The result is never shown to your co-parent. They are not told a message was flagged or rewritten.
- If the AI service is unavailable, your message sends normally. Tone assist never blocks you.
12.3 No automated decisions about you #
We do not make decisions about you by solely automated means that produce legal effects or similarly significantly affect you (Article 22 UK GDPR). Tone assist offers a suggestion; you decide. Entitlement and subscription states are set by rules you can see, and a human reviews any account restriction before it takes effect.
If that ever changes, we will update this policy before it does, tell you, and put in place the safeguards the law requires — including the right to obtain human intervention, to express your view, and to contest the decision.
12.4 A tone score is not evidence #
Tone assessments do not appear in exports, are not part of the shared record, and are not a finding about any parent's conduct. Neither parent may present one as evidence of anything.
13. Who we share your data with #
We share personal data with:
Our service providers (sub-processors). They process data on our instructions, under contract, and may not use it for their own purposes. Every one of them is named, with its role, location and transfer mechanism, on our Sub-processor list. We keep that page current and we will give notice before adding a new sub-processor that processes family content.
Professionals you or your co-parent have authorised. A mediator or solicitor with access sees the records described in the Terms. Both parents always see that they have access.
Courts, regulators and law enforcement, where legally required — section 14.
Our professional advisers — accountants, lawyers, insurers — where necessary and under a duty of confidentiality.
A buyer, in a business sale or reorganisation. If we are acquired or merge, personal data may transfer to the acquirer. We will tell you beforehand, the acquirer will be bound by this policy until it is lawfully changed, and any material change to how your data is used will be notified with the right to object or close your account. Due diligence before a sale is conducted on anonymised or aggregated information wherever possible; we do not hand a prospective buyer your family's messages.
We do not share your data with advertisers, data brokers, or anyone else for their own marketing.
14. Court orders, law enforcement and legal proceedings #
This product is used by families where proceedings are a real possibility, so we set out our approach plainly.
We require valid legal process. We do not disclose personal data on an informal request, from a party, a solicitor, an employer, or the police, unless there is a lawful basis and proper process — a court order, a witness summons, a statutory power properly exercised, or a genuine risk to life.
We disclose the minimum required by the order, not everything we hold.
We tell the affected parents in advance, wherever we are lawfully permitted to, so you can take advice and challenge the order if you wish. Where a disclosure affects both parents' data, we tell both — not only the one who asked.
We will not tell you where we are legally prohibited, or where we reasonably believe that notice would put a child or another person at risk.
We do not act as an expert witness. We provide records; we do not interpret them or opine on your case. Requests relating to proceedings go to legal@ourpath.app.
The better route is usually the export. Any parent can generate a certified, hash-verified export of their own family's records, free, at any time, without involving us. Most requests we receive would have been answered faster by the person doing that.
15. Where your data is stored, and international transfers #
Your data is stored in the United Kingdom. Our database, file storage and backups run on Supabase infrastructure hosted in AWS London (eu-west-2).
Some processing necessarily involves transfers outside the UK. Every one is listed below, and every one is covered by a lawful transfer mechanism.
| Processing | Provider | Where | Mechanism |
|---|---|---|---|
| Database, authentication, storage, backups | Supabase | United Kingdom (AWS eu-west-2) | No restricted transfer for data at rest. Limited support access from outside the UK under the UK Addendum to the EU SCCs |
| Tone assist | Anthropic PBC | United States | UK Addendum to the EU SCCs, plus a completed transfer risk assessment. Anthropic does not rely on the UK Extension to the Data Privacy Framework |
| Payments, where we bill you directly | Stripe | United States / EEA | UK Extension to the EU–US Data Privacy Framework, with SCCs plus UK Addendum as a backstop |
| Web and portal hosting, and DNS | Netlify | United States / EEA edge | UK Addendum to the EU SCCs |
| Bot protection on our forms | Cloudflare (Turnstile) | United States / edge | UK Addendum to the EU SCCs |
| Transactional email | Plus Five Five / Resend | EU sending region (eu-west-1); US company access | UK Addendum to the EU SCCs |
| Marketing email | Brevo | European Union | EU — adequacy regulations apply; no additional mechanism required |
| Our own mailboxes, including hello@ourpath.app | Zoho | European Union | EU — adequacy regulations apply |
| Push notifications | Expo, Apple (APNs), Google (FCM) | United States | UK Addendum to the EU SCCs; Apple and Google as listed on the Sub-processor page |
| App store billing | Apple Distribution International Ltd; Google Commerce Ltd | Ireland | EU — adequacy regulations apply |
| Error monitoring | Google LLC (Firebase Crashlytics) | United States | UK Addendum to the EU SCCs |
| Product analytics | Google LLC (Google Analytics for Firebase) | United States | UK Addendum to the EU SCCs |
Where we rely on the UK Addendum to the EU Standard Contractual Clauses (or the UK International Data Transfer Agreement), we have completed a transfer risk assessment for each transfer, and we keep those assessments under review. You can ask us about any of them at hello@ourpath.app.
16. How long we keep data #
The full table, with reasoning, is in our Data Retention and Deletion Policy. The headline periods:
| Data | Retained for |
|---|---|
| Shared evidential records (messages, expenses, swaps, plan versions) | 7 years from the last activity in the family, then permanently deleted |
| Account and profile data | Life of the account; deleted or anonymised on closure |
| Draft messages | Never stored |
| Tone assist content | Not stored by us; not retained by the provider beyond processing |
| Payment and invoice records | 6 years from the end of the relevant financial year (tax law) |
| Info Bank content and documents | With the family record; deletable by either parent at any time while the account is open |
| Security and access logs | 12 months |
| Product analytics | 25 months, then aggregated |
| Marketing contacts | Until you unsubscribe, then 2 years on a suppression list so we do not contact you again |
| Support correspondence | 3 years |
| Backups | 35 days rolling, then overwritten |
Where a complaint, dispute or legal claim is live or reasonably in prospect, we will keep the relevant data until it is resolved, and we will tell you if that applies to you.
17. How we keep your data secure #
- Encryption in transit (TLS) and at rest across the database, file storage and backups.
- Row-level security in the database, enforcing that no family's data can be reached from another family's session. This is tested by automated tests that block our release pipeline — a leak between families is treated as an existential defect, not a bug.
- Append-only, hash-chained evidential tables, with update and delete permissions revoked from every application role, including ours.
- Access control for our own staff on a least-privilege basis, with access logged. Our staff cannot read message content in the ordinary course of their work, and do not do so for analytics or product research. Where an engineer needs access to diagnose a specific fault, it is authorised, time-limited and recorded.
- Multi-factor authentication on our administrative systems.
- Point-in-time recovery and nightly backups, tested.
- Breach response: we will notify the ICO within 72 hours where a personal data breach is likely to result in a risk to people's rights and freedoms, and we will tell you without undue delay where the risk to you is high. We will tell you what happened, what we are doing, and what you should do.
No system is perfectly secure. We would rather tell you what we do and how we would handle a failure than promise you something nobody can promise.
18. Your rights #
You have the following rights over your personal data. They are free to exercise and we will respond within one month, which we may extend by up to two further months for complex requests — we will tell you if that happens and why.
Where we reasonably need information to confirm your identity, or need you to clarify what you are asking for, the clock pauses until you give it to us. We will only ask where it is genuinely necessary.
| Right | What it means | How it works here |
|---|---|---|
| Access | A copy of the personal data we hold about you | Use the export feature for the fastest answer, or ask us. We may redact information that would identify your co-parent or another person, or reveal their private data, where we cannot disclose it without unfairly affecting them |
| Rectification | Correct inaccurate data | We will correct your profile, your children's details and factual errors in the Info Bank. We cannot alter shared records — they are append-only. You can add a correction to the record instead, which is the right remedy for a disputed fact |
| Erasure | Delete your data | Applies fully to your profile, drafts, notes and private data. Does not apply to shared records while section 10.2 applies. We will tell you exactly what we deleted and what we kept |
| Restriction | Limit how we use your data while something is resolved | Available, for example while you dispute accuracy |
| Portability | Get your data in a portable format, or have it sent elsewhere | The export feature provides this, free, permanently |
| Objection | Object to processing based on legitimate interests, including profiling | We will stop unless we have compelling legitimate grounds that override your rights, or need the data for legal claims. You can always object to marketing and we will always stop, immediately |
| Withdraw consent | Where we relied on consent | Withdrawing does not affect processing before you withdrew |
| Automated decisions | Not to be subject to solely automated significant decisions | We do not make any — section 12.3 |
To exercise any right: email hello@ourpath.app, or write to us at the address in section 1.
The limits are real and we would rather be honest about them. In a two-parent record, your rights and your co-parent's rights are in genuine tension. We do not resolve that tension by favouring whoever asks first. We resolve it by applying the law, telling both of you what we have done, and telling you how to challenge us.
19. Complaints #
Complain to us first, if you are willing. Email hello@ourpath.app or use the complaints form at ourpath.app/legal/privacy-complaint.
We will:
- acknowledge within 30 days (usually far sooner);
- investigate properly;
- tell you the outcome without undue delay, with our reasoning.
You can also complain to the Information Commissioner's Office, at any time, whether or not you have complained to us:
Information Commissioner's Office Wycliffe House, Water Lane, Wilmslow, Cheshire SK9 5AF Helpline: 0303 123 1113 ico.org.uk/make-a-complaint
We would appreciate the chance to put things right first. You are under no obligation to give us one.
20. Cookies #
Our Cookie Policy explains what we use on the website and in the app, and how to control it. We do not use advertising cookies and our cookie banner does not block the page or make rejection harder than acceptance.
21. Changes to this policy #
We will update this policy when the service, the law or our providers change.
- For material changes we give at least 30 days' notice by email and in the app, and explain what changed and why.
- Minor corrections are made with the version history updated.
- Previous versions are kept at ourpath.app/legal/privacy/archive.
Version history #
| Version | Date | Change |
|---|---|---|
| 1.1 | 19 September 2026 | First published |
Our Path Digital Ltd · Registered in England and Wales, company number 17406043 · Registered office Chapel House, 22 Warrington Road, Lymm, Cheshire, WA13 9BG · ICO registration ZC250261