Security and your data

OurPath holds some of the most sensitive information a family has: where children are, what two parents say to each other, and what they spend. This page says plainly where that data lives, who can reach it, and what we don't collect at all.

Where it lives #

In the United Kingdom. Our database, file storage and backups run in AWS's London region (eu-west-2) via Supabase. Your family's data is not moved to the US or elsewhere for ordinary processing.

Our Path Digital Ltd is registered with the Information Commissioner's Office, registration number ZC250261, and is the data controller for your family's records.

Who can see what #

Your messages Your calendar Your costs Your drafts & private notes
You Yes Yes Yes Yes
Your co-parent Shared thread only Yes Shared costs only Never
A mediator or solicitor you've linked Read-only, and visible to both parents Read-only Read-only Never
OurPath staff Not in normal operation Not in normal operation Not in normal operation Never

Neither parent can see the other's drafts, private notes or payment details. Professional access is always visible to both parents, always read-only, and can be revoked by either of you.

Our staff do not read your messages as a matter of course. We don't have a support tool that opens your thread. Access to production data is restricted, logged, and only happens where it's necessary to fix a specific fault — and we'd tell you.

What we don't collect #

The technical part #

Your rights #

You can export everything, on any plan, including after you cancel. That export also serves as a subject access request under UK GDPR.

You can close your account at any time. When you do, your profile is anonymised — but the shared evidential record is not destroyed, because it belongs to both parents and to your children's history, not to whoever leaves first. Retention periods are set out in our data retention policy. We think this is the right answer and we'd rather explain it up front than surprise you with it.

Reporting a problem #

Found a vulnerability? security@ourpath.app. We'll acknowledge within two working days, we won't take legal action against good-faith research, and we'll credit you if you'd like.