Security and your data
OurPath holds some of the most sensitive information a family has: where children are, what two parents say to each other, and what they spend. This page says plainly where that data lives, who can reach it, and what we don't collect at all.
Where it lives #
In the United Kingdom. Our database, file storage and backups run in AWS's London region (eu-west-2) via Supabase. Your family's data is not moved to the US or elsewhere for ordinary processing.
Our Path Digital Ltd is registered with the Information Commissioner's Office, registration number ZC250261, and is the data controller for your family's records.
Who can see what #
| Your messages | Your calendar | Your costs | Your drafts & private notes | |
|---|---|---|---|---|
| You | Yes | Yes | Yes | Yes |
| Your co-parent | Shared thread only | Yes | Shared costs only | Never |
| A mediator or solicitor you've linked | Read-only, and visible to both parents | Read-only | Read-only | Never |
| OurPath staff | Not in normal operation | Not in normal operation | Not in normal operation | Never |
Neither parent can see the other's drafts, private notes or payment details. Professional access is always visible to both parents, always read-only, and can be revoked by either of you.
Our staff do not read your messages as a matter of course. We don't have a support tool that opens your thread. Access to production data is restricted, logged, and only happens where it's necessary to fix a specific fault — and we'd tell you.
What we don't collect #
- No location data. Not stored, not optional, not built.
- No phone numbers exchanged between parents.
- No message content in analytics. Our product analytics are funnel events — did onboarding complete, was a plan accepted. Never what anyone wrote, never anything about a child.
- No advertising, no data sales, no third-party trackers selling your behaviour on.
The technical part #
- Encrypted in transit (TLS 1.2+) and at rest (AES-256)
- Row-level security in the database, so one family's data is structurally unreachable from another family's session — and this is covered by automated tests that block a release if they fail
- Evidential records are append-only with update and delete permissions revoked at the database layer. How that works →
- Point-in-time recovery plus nightly backups
- Optional biometric or PIN lock on your device
- Sign in with email and password, a magic link, Apple or Google
Your rights #
You can export everything, on any plan, including after you cancel. That export also serves as a subject access request under UK GDPR.
You can close your account at any time. When you do, your profile is anonymised — but the shared evidential record is not destroyed, because it belongs to both parents and to your children's history, not to whoever leaves first. Retention periods are set out in our data retention policy. We think this is the right answer and we'd rather explain it up front than surprise you with it.
Reporting a problem #
Found a vulnerability? security@ourpath.app. We'll acknowledge within two working days, we won't take legal action against good-faith research, and we'll credit you if you'd like.