Enlightened Parent
Privacy Policy
Last updated: July 11, 2026. Effective: July 11, 2026.
Who we are
Enlightened Parent (“the app”, “we”, “us”) is operated by Parallel Works, LLC, a Maryland limited liability company. For privacy questions, write to privacy@parallelworks.ventures.
The short version
- The app is a private operating system for one family. The account holders are adults; children do not have accounts.
- We do not sell your data, and we do not run ads. We use two privacy-respecting services to keep the app working: anonymous product analytics and crash reporting. Neither receives your name, your care log, or your child’s information (see “Where your data lives” below).
- We do not track you across other companies’ apps or sites, and we use no advertising networks or data brokers.
- Your family’s data lives in the United States, visible only to your own family plus any time-boxed caregiver link you create.
- You can export everything you have written, plus your photo, video, and voice-note files, as one archive any time, and delete your account from within the app.
What the app holds
We collect only what features need. Nothing is sold, rented, or shared for advertising. What we store:
- Account: your email address (to sign you in via one-time passcode; we store no password), and the display name and avatar color you choose.
- Your kids’ profiles: given name, birthdate (age is computed, never stored static), pronouns, avatar, and an optional profile photo. Children’s caregiver notes are encrypted at rest.
- Care entries: tap-to-log records of sleep, feeding, diapers, optional moments (note or photo), free-form notes you label in your own words, and keepsakes you capture. Notes and photos are free-form, so they may include health-related details you choose to add (for example a note or photo about a rash or a doctor visit). The app has no structured medical fields, does not diagnose, and is not medical advice. These are private records you keep about your own child. This content is never processed by AI and never shared for any purpose beyond the family access described below.
- Household notes: the shared to-do and to-discuss items you keep as a family, with any tags you add.
- Private adult notes: moments (short notes or photos) parents capture in the care log. There is deliberately no screen that shows counts or assigns blame.
- Caregiver contacts: extended family, providers, and local families you add, with optional notes.
- Push tokens: stored only if you turn notifications on, to send the reminders you asked for. Tied to your device; revocable any time.
- Caregiver-link open counts: when someone opens a link you created, we record a one-way salted hash of the visitor’s IP so you can see “opened N times” without us storing the raw address.
Who can see it
Access is enforced at the database layer (row-level security), not just in the UI:
- You: full access to your own data.
- Your co-parent: read/write on shared family data; cannot see your private reflections.
- A caregiver (time-boxed link): you choose exactly what it shows and when it expires; defaults to read-only; never exposes relationship or private adult content; and never includes entries you save for the doctor (notes or photos you flag as medical), which stay with the parents. Auto-expires and revocable any time.
- Extended family, providers, and shared circles you connect in Village: read-only, scoped to what you explicitly allow.
- Us (the operator): only to run and support the service. For encrypted columns we hold the operating key; see “Security” below.
We never share your data with a third party for that party’s own purposes, and never for advertising.
Where your data lives
Your family’s data, the care logs, kids’ profiles, notes, and files, is stored in the United States. We use a managed database, authentication, and file-storage provider (Supabase) in the US, and a US hosting provider (Vercel) for the app itself. When you enable notifications, your device’s push service (Apple or Google) delivers them.
To keep the app reliable we also use two operational services: anonymous product analytics (PostHog, in the US) and crash and error reporting (Sentry, in the EU). Both are configured to strip out personal and health details. They never receive your name, your care log entries, your child’s data, or anything you write in the app, only anonymous usage counts and technical diagnostics that help us find and fix problems. We use no advertising network and no data broker.
Children’s information
- Children have no accounts and do not use the app. The account holder is the parent.
- All child information is entered by the parent for the family’s own use.
- Children’s records are reachable only by the family’s adults and by a parent-created, time-boxed caregiver link with an explicit allowlist. Links default to read-only, auto-expire, are revocable, and never carry private adult content.
- We never use a child’s information for advertising, commercial profiling, or model training.
Because the people who enter and control children’s data here are the children’s own parents, and we do not collect personal information directly from children, this is parent-entered family data rather than data gathered from a child. If you believe a child’s information reached us another way, contact us and we will delete it.
Security
- Row-level security on every table: data is reachable only through the access tiers above, enforced below the app layer.
- Encryption at rest for sensitive columns. Those columns are encrypted with a single server-held key, which means the operator could in principle decrypt them. A per-family-key design is planned for a future release.
- Encryption in transit: all traffic uses HTTPS.
- Caregiver links use 256-bit random tokens, are time-boxed, auto-expire, and are revocable.
No storage or transmission method is perfectly secure; we cannot guarantee absolute security.
Export and deletion
We keep your data while your account exists.
- Export: download everything as one archive any time from inside the app (Me → Export my data). It contains a complete JSON record of your data, spreadsheet-ready CSV copies of your care log, and your photo, video, and voice-note files. Your partner’s private data is not included.
- Delete your account: from inside the app (Me → Delete my account). We delete or irreversibly de-identify all your data within 30 days, except where law requires retention.
Changes and contact
Material changes update the “Last updated” date and, where appropriate, are notified in the app. For privacy questions, write to privacy@parallelworks.ventures.