Back to the full Privacy Policy
App Store Privacy Disclosure

Apple App Privacy & Google Play Data Safety — Reconciled Disclosure

Effective: February 21, 2026 · Last updated: March 4, 2026

This page is the single reconciled short-form statement referenced from both the App Store and Google Play listings. Every answer given in App Store Connect (App Privacy) and Google Play Console (Data Safety) matches the categories, purposes, and linkage flags on this page. The full 32-section policy lives at /privacy.

1. Headline commitments

  • No tracking across other apps or websites. SA CoParents does not use IDFA, GAID, cross-app cookies, or third-party advertising SDKs. Both the Apple “Tracking” and Google “Data shared with third parties for advertising” answers are No.
  • No AI model training on user data. Reflections, assessment answers, and family-violence screens are never used to train the AI models that generate summaries. LLM calls are transient and no user content is retained by the provider beyond the request.
  • Encrypted in transit and at rest. TLS 1.2+ in transit; database encrypted at rest by the managed provider. Emails to reviewers can additionally be routed through the Virtru Hosted Gateway when the flag is enabled and a BAA is in place with the receiving practice.
  • Delete anytime. Parents can delete their account and every artefact from /account → Delete my account. Full deletion completes within 30 days.
  • Children under 13 are not the primary users. SA CoParents is for the adult parent. Information about a child (name, needs, medical/educational context) is entered by the parent and treated as their content, not directly collected from the child.

2. Data we collect (both stores)

Every row below lists a single data type, why we collect it, and the exact category to select in both App Store Connect and Google Play Console. If a data type does not appear on this list, we do not collect it.

Data typePurposeApple categoryGoogle categoryLinked?Tracking?Optional?
Email addressSign-in, six-digit verification codes, password reset, reviewer share notifications.Contact Info → Email AddressPersonal info → Email addressYesNoNo
Parent / co-parent display namePersonalises reports and identifies which parent authored a shared artefact.Contact Info → NamePersonal info → NameYesNoYes
Assessment answers, reflections & journal entriesGenerate the parent's reports, coaching, and joint alignment artefacts.User Content → Other User ContentApp activity → Other user-generated contentYesNoNo
Child health, education, and psychological context
Treated as PHI (Texas HB 300 §181.006). Never used for advertising, analytics, or model training.
Special Needs, Medical Deep-Dive, Educational Deep-Dive, and Psychological Deep-Dive modules — used only to generate care-plan artefacts the parent chooses to view or share.Health & Fitness → Health (self-reported, child-centered)Health and fitness → Health infoYesNoYes
Family-violence safety screen responses
Safety data is never sent to third parties without a court order or the parent's explicit consent.
Route the parent to the appropriate communication pathway (co-parent, parallel, or safety-first) and to Texas crisis resources.Sensitive Info → Other Sensitive InfoPersonal info → Other infoYesNoYes
Device identifiers (session / PWA install)Keep the parent signed in across the web app and PWA, and detect logged-out states.Identifiers → User IDApp info and performance → Diagnostics (session identifier only)YesNoNo
Product-analytics events (PostHog, self-hosted)
Parents can opt out via the account marketing/analytics toggle at any time.
Aggregate, de-identified funnel and reliability metrics. No PHI or assessment content is ever emitted.Usage Data → Product InteractionApp activity → App interactionsNoNoYes
Crash and performance diagnosticsDetect production errors and route them to on-call engineers.Diagnostics → Crash Data / Performance DataApp info and performance → Crash logs / DiagnosticsNoNoNo

“Linked?” matches Apple’s “Data Linked to You” and Google’s “Personal info collected” flag. “Tracking?” is No for every row — SA CoParents does not track parents across apps or websites owned by other companies.

3. Data we do NOT collect

  • Precise or approximate location.
  • Contacts, calendar, photos, or files from the parent's device.
  • Advertising identifiers (IDFA / GAID).
  • Audio or microphone recordings.
  • Financial information — the app is free; there is no payment collection.
  • Purchase history from other apps.
  • Browsing history outside SA CoParents.

4. Data sharing

Data is shared only when the parent explicitly initiates the share from within the app, or when required by law:

  • With a co-parent — only after the parent creates a compare share and their co-parent accepts. Parents never share passwords; each parent signs in with their own credentials.
  • With a mediator, attorney, therapist, or pediatrician — only via a time-limited share token or PDF the parent personally mints. Revocable at any time from /account.
  • With service providers necessary to run the app (MongoDB hosting, Resend transactional email, PostHog product analytics, LLM providers). Contracts forbid secondary use of user content.
  • When required by law — a valid subpoena or court order for a specific user record.

5. Parent controls

  • View, revoke, or re-send active share links from /dashboard → Share management.
  • Turn off product analytics from /account.
  • Export the accounting-of-disclosures log (every access to the parent’s PHI) from /data-retention.
  • Delete the account and every artefact from /account.
  • Contact the Privacy Officer at mattsossi@bsossi.com or 210-224-1667.

6. Store-console quick answers

Copy these answers verbatim into each console when re-submitting the app:

Apple App Privacy → Do you or your third-party partners use data for tracking? No.

Apple App Privacy → Data used to track you: None.

Apple App Privacy → Data linked to you: Contact Info (Email, Name), User Content, Health & Fitness (self- reported, child-centered), Sensitive Info (safety screen), Identifiers (User ID), Usage Data (Product Interaction).

Apple App Privacy → Data not linked to you: Diagnostics (Crash / Performance).

Google Play Data Safety → Does your app collect or share any of the required user data types? Yes — see the table above.

Google Play Data Safety → Is all of the user data collected by your app encrypted in transit? Yes (TLS 1.2+).

Google Play Data Safety → Do you provide a way for users to request that their data be deleted? Yes — in-app at /account.

Change log

  • March 4, 2026 — Initial reconciled Apple + Google disclosure created; matches the full policy at /privacy (dated Feb 21, 2026).

SA CoParents · 16607 Blanco #703, San Antonio, Texas 78232 · mattsossi@bsossi.com

© 2026 SA CoParents · All rights reserved.