Privacy policy
Last updated 8 October 2026
Two Front Doors is a shared calendar for separated parents. This page explains what personal data we hold, why, who else handles it, and what you can do about it. We’ve tried to keep it plain. If something is unclear, email hello@twofrontdoors.com.
1. Who we are
The controller of your personal data, meaning the organisation that decides how it is used, is Rankibl Ltd, a company registered in England and Wales (company number 11606978), 13 White Lion Park, Malmesbury, SN16 0QW, UK. We run Two Front Doors at twofrontdoors.com and app.twofrontdoors.com, and the phone apps.
Contact us at hello@twofrontdoors.com or by post at the address above. We follow UK data protection law: the UK GDPR, the Data Protection Act 2018 and the Privacy and Electronic Communications Regulations. We are registered with the Information Commissioner’s Office (ICO), the UK regulator, under number ZC268933. Two Front Doors is for people who live in the UK or the US. If you live in the US, section 10 has more for you.
2. The short version
- Your private events and your Google events can be seen by you and nobody else. Not the other parent, not helpers.
- Children are shown by their initials. Children don’t have accounts.
- For your calendar data we only ask Google for read-only access today, and only when you tap to connect.
- What we never do: show adverts, sell your data, use your data to train AI models, or show the other parent your private events, Google calendar, settings or messages to us. They see what you share in the family calendar and the few things listed in section 6.
- We count anonymous steps in the app and page views on this website to improve them. Nothing in those counts says who you are, and you can turn them off (see Usage statistics).
- You can disconnect Google at any time in the app, and delete your account yourself in the app’s Settings.
3. What we collect
Data you give us
- Account details. Your email address and display name. If you sign in with Apple or Google, they give us your name and an email address (Apple may give us a private relay address instead). Google also gives us a link to your profile picture, which we don’t use. See Signing in with Google.
- Your calendar. Events you create: title, date and time, and optionally place, notes and which child it is for. Each event is either shared with your family calendar or private to you. If you add a birthday, it is an event that repeats every year, and you can add the year of birth (see section 4).
- Your family set-up. The name and optional description of your family calendar, your children’s initials, your parenting arrangement (for example alternate weekends), swap requests and the other parent’s answers, pickup and drop-off details, and who you have invited as a helper.
- Child essentials, if you fill them in. The school’s name and phone number, the names and phone numbers of the child’s doctor (GP) and dentist, other key contacts, clothing and shoe sizes, and a note. We don’t collect allergies or medical notes. See section 4.
- Calendar links, if a parent adds one. The name a parent gives it (for example “Year 4” or “SJ swimming”), which children it is for, its web address, and the events we read from it (see Calendar links and your private calendar link below).
- School term dates, if a parent adds them. The names of your children’s schools (optional) and which of your children go to each, plus the dates of their school holidays and days off, with any names you give those days. Either parent can add and change them. We keep who last changed each school year and when, and show that to parents only. Helpers see the term dates of the schools their children go to. They appear on the family calendar for each person who keeps “Show term dates on my calendar” on. They are not copied to Google Calendar or put in file exports, and your private calendar link doesn’t carry them. They are deleted with the family calendar, or when a parent removes the school.
- Plan the year, if a parent uses it. Dates the parents add themselves (a name, one day or a few, whether it comes back every year, and which children it is for), and which rows either parent has marked “Needs a plan”. We don’t keep who added a date or marked a row. Yearly rules the parents agree, such as how Christmas goes each year: which holiday or date, which children, whether it keeps the same dates every year or the same part of the holiday, the times, and whose home it is in even and odd years. Only the two parents see these; helpers don’t. They never change the calendar: a plan is only ever a request the other parent accepts. They are not copied to Google Calendar or put in file exports, and your private calendar link doesn’t carry them. They are deleted with the family calendar, or when a parent removes the date.
- A screen for the children, if a parent makes one (see The children’s screen): a private link that the parent chooses the children for, kept only in a scrambled form we can’t turn back into the link.
- A view link for the other parent, if you make one while you are the only parent in a family calendar. It is a private link to a read-only page for the other parent. The page shows the family calendar’s name, your first name, the children’s initials, the next eight weeks of the arrangement (which home each child is at each day, with handover days and times), whether the arrangement is agreed yet and, only if you switch them on, the titles, dates and times of shared family events. It never shows notes, places, “only me” events, events from calendar links, essentials, term dates or helpers. The page has “Add to my calendar”, which gives the same eight weeks to a calendar app, and “Join”, which makes a parent invitation from you (it works once, lasts 7 days, and the page can make at most three a day). Anyone with the link can see the page, so send it only to the other parent. It stops working when you reset it or turn it off, when the other parent joins, or when you leave the family calendar, are removed, delete your account or have your account suspended. We store the link only in a scrambled form. Our database provider’s request logs record the “Add to my calendar” address when a calendar app uses it, as for your private calendar link. Nothing from the page is sent to our usage statistics.
- Home names, if a parent adds one: what the children call each parent’s home, such as “Dad’s”, up to 20 characters. Only the two parents see them, and they appear only on things made for the children: the printed month and the children’s screen. Names you type when printing a month for the children are never saved or sent to us: the printout is made on your device.
- Your private calendar link, if you turn on “Subscribe in Apple Calendar or Outlook”, and your choices for it.
- Google Calendar data, if you connect Google. See section 5.
- Preferences. How you want the calendar to look, such as your parenting-time colour and whether it shows the other parent’s time, and your reminder and notification settings (below). Nobody else can read these.
- Your country and region for bank holidays. We store your country and region for bank holidays (England and Wales, Scotland, Northern Ireland, the United States or none) and whether you want them shown, so the calendar can show the right holidays. The app first suggests a setting from your device’s time zone and language, and saves it when you create or join a family. You can change it at any time in Settings. Only you can see this setting; the other parent and helpers can’t. It is deleted with your account. See also Bank holidays below.
- Messages and reports. If you use “Contact support” in the app, we keep the topic, your words and, only if you tick the box, your app version and a short description of your device. If you report a family member or an invitation, we keep the category, your words and which member or invitation it is about. If you email us, we keep the email and our reply.
- Subscription details, if you subscribe. Which plan you have, where you bought it (App Store, Google Play or the web), whether you are in a free trial, when it renews or ends, and whether a payment failed or was refunded. We never see your card details. We don’t store the price you paid: we read it from RevenueCat only to put it in your subscription confirmation and renewal reminder emails. If you subscribe on the web, Stripe collects your card details, name, email address, billing country and, where tax needs it, your billing address.
Data other people give us about you
- The other parent or a helper can add events, notes and changes that mention you, and the person who invites you sees your display name once you join.
- If you are a parent who hasn’t joined yet, the parent who set up the family calendar may have entered the arrangement, including when the children are with you, and may send you a view link to it (see the view link above). We don’t hold your name or email address until you join. If you open the page, our hosting providers see your IP address, as with any web page (see Technical data below).
- Another member can report you to us if they are worried about misuse. You are not told about a report (see section 10).
- Apple, Google and Stripe tell us about your subscription through RevenueCat, as described above.
Data collected as you use the service
- Technical data. Our hosting and database providers see your IP address and browser or device type when you use the app, and keep ordinary server logs.
- Error reports. If the app crashes, a report goes to Sentry. Error reporting is designed to exclude event text, children’s details and Google tokens.
- Stored on your device. The app keeps your sign-in session and a copy of your calendar in your browser or on your phone, so it opens quickly and works when your connection drops. This is needed for the app to work, so we don’t ask first. The child essentials page is not kept on your device.
Reminders and notifications
- Reminders on your phone. If you allow notifications, your phone schedules event reminders itself. They say “Reminder” and the event’s start time, never its title, place, notes or a name.
- Update notifications. If you allow notifications, we can tell you when the other parent asks for a change, answers one of yours, or when a shared plan you can see is added or changed. You choose which of these you get, and whether they arrive as they happen or in one daily or weekly summary. They say things like “A shared plan was added or changed.” and never include an event name, a place, a child’s initials or anyone’s name.
- Handover reminders. If you are a parent and switch them on, we remind you of handovers where the children come to or leave your home overnight, the evening before or a few hours before. They say “Handover tomorrow. 3 things on the list.” and nothing else: never a time, a name, a child’s initials or what is on the travel list. To work out when to send them, our server reads your family’s arrangement as your calendar shows it (never a change that hasn’t been agreed) and how many things are on each child’s travel list (a number, not the items). The other parent isn’t told whether you have them on.
- Plan ahead. If you are a parent, we tell you when a date in Plan the year that a parent marked “Needs a plan”, or one with a yearly rule, is coming up with no plan (12 weeks ahead for Christmas and the summer and 6 for everything else, unless you choose otherwise). It says “A school holiday in 6 weeks has no plan yet.” and nothing else: never a date, a name or a child’s initials. To work out when to send it, our server reads what your Plan the year shows: your family’s arrangement as your calendar shows it, changes waiting for an answer, school holidays, the dates the parents added (not their names), the marks and rules, your children’s initials, and the title of a child’s birthday event (such as “SJ’s birthday”) only when a mark or a rule is on it; never the title of any other event. It keeps none of it. It is on unless you switch it off in Settings, and the other parent isn’t told whether you have it on.
- Push tokens. To send notifications to your phone, we store a push token for each of your phones (a code from Apple or Google, passed through Expo). It is deleted when you sign out on that phone, turn notifications off, or delete your account.
- Emails instead. If you use the web app and switch on reminder emails or update emails (“Email me instead”, which also covers handover reminders and plan-ahead notices), we send the same short sentences to your sign-in address, with a link that asks you to sign in. We store your choices and the time zone your browser reports, so “15:15” means your 15:15.
- What we keep to send them. A short list of what is waiting to be sent, and a log of reminder emails, handover reminders and plan-ahead notices already sent so you don’t get one twice. Both hold identifiers and times only, never event text. See section 9 for how long.
Usage statistics in the app
The app tells us when someone reaches a step. The steps are:
- opening the app (
app_opened) - signing in (
signed_in) - creating a family calendar (
family_created) - sharing an invitation (
invite_shared) - the second parent joining (
second_parent_joined) - setting up an arrangement (
arrangement_set_up) - adding a first event (
first_event_added) - connecting Google (
google_connected) - switching on “Add family plans to Google” (
export_enabled) - opening the subscription screen (
subscription_viewed)
For second_parent_joined, the app of the parent who sent the invitation records the step the next time it opens the Family tab after the other parent has joined; nothing about the other parent is sent, and it is not sent from the other parent’s device. We use the counts to see where people get stuck and to improve the app. Nothing is sent from the view link page or the children’s screen.
This is on unless you turn it off. The first time you open the app, a short notice tells you about it, with a “Turn off” button. Nothing is sent until you tap “OK” on the notice or, if you don’t answer it, until the next time you open the app. You can turn it off, or back on, at any time with “Share anonymous usage statistics” in Settings, Privacy. Turning it off is free and changes nothing else in the app. If you said no when an earlier version of the app asked, your answer still stands. In the web app, if your browser sends a Global Privacy Control or Do Not Track signal, statistics are off unless you turn them on in Settings.
- What is sent. The name of the step from the list above, the time it happened, the kind of device (iPhone, Android or web), the app version, and the random code described below. Nothing else.
- What is never sent. Your name, email address, account ID or family ID; event titles, places, notes or times; children’s initials or essentials; anything from Google; anything typed or tapped in the app. We don’t use cookies, session recordings or automatic capture of what you tap.
- Your IP address. Like any server, PostHog receives your IP address with each request, because that is how the internet works. We ask it not to record the address, its location look-up is switched off, and the project is set to discard IP addresses rather than store them.
- Not linked to you. Each device makes its own random code, which is not connected to your account or to your other devices. It is made and kept on your device only once the app starts sending statistics. It is replaced with a new one whenever your session ends (you sign out, the app signs you out because your access was removed or has expired, or a different account signs in on the same device), so the next person to use the device starts afresh. It is deleted when you turn statistics off. Steps recorded before a code was replaced or deleted stay with PostHog under the old code, which nothing connects to you.
- Your setting belongs to the device. Whether statistics are on or off, and whether the notice has been shown, is remembered on the device, not in your account, so it applies to everyone who uses the app on that device and does not follow you to another one. If you share a phone or computer, the setting there applies to whoever uses it next, until someone changes it in Settings, Privacy.
- Why we don’t ask first. UK law (the Privacy and Electronic Communications Regulations, as changed by the Data (Use and Access) Act 2025) allows information to be kept on a device without asking when its only purpose is to collect statistics about how a service is used so it can be improved, as long as we tell you clearly and give you a simple, free way to turn it off. We use these counts for nothing else: not for advertising, and not to track or monitor anyone. PostHog may use them only to provide its service to us.
- Who handles it. PostHog, on its EU cloud, on our behalf (see section 7).
Our website
This website, twofrontdoors.com, sets no cookies for visitors and runs no advertising tags. Our web host, GoDaddy, keeps ordinary server logs, which include your IP address, the page you asked for and your browser type. The parenting time calculator works out the answer on our server and stores nothing, but what you enter is part of the page address, so it can appear in those logs. Only people who run the site (who sign in to edit it) get sign-in cookies.
We count page views on this website with PostHog, on its EU cloud, so we can see which pages help people and improve them. It is set up so that nothing is kept on your device: no cookies, no browser storage and no code that follows you from page to page, so each page view is counted on its own and visits can’t be joined up. (When it starts, the counting code saves a test value in your browser’s storage and removes it straight away, to check that storage works.) What is sent: the page address without anything after a “?” or “#” (so your answers to the parenting time calculator and anything you search for are never sent; we only count that a calculator result was shown), the name of the website that linked you here (just its name, such as www.google.com, never the full address, and only if it is another website), your browser, operating system and kind of device, the time, a random code made for that one page view, and the name and version of the counting code. Your browser makes more available, such as your screen size, language and the page title; the counting code removes all of it before anything is sent. Like any server, PostHog receives your IP address with each request; the project is set to discard it. We don’t record what you click or type, there are no session recordings, and no profile is made of any visitor.
The analytics doesn’t run if your browser sends a Global Privacy Control or Do Not Track signal, or if JavaScript is off. To turn it off on this browser, use the button below. Remembering that choice means saving one small value in your browser’s storage for this website (named tfd-analytics-off). We save it only when you turn analytics off, it is used for nothing else, and clearing this website’s data in your browser removes it, which turns analytics back on.
Calendar links and your private calendar link
- Calendar links. A parent can link a school’s, club’s or team’s published calendar by pasting its web address. Our servers read that address when it is added, every 6 hours and when a parent taps “Try again”. We store the title, place and times of its events for six months back and eighteen months ahead, and never their descriptions, attendees or organisers. Each read replaces the last. The events show, read-only, for both parents and for helpers whose children the link is for. Once added, nobody can see the address in the app again, not even the parent who added it, because it can act as a key to that calendar. The app shows only the website’s name, such as calendar.google.com. When we read a link, the website that publishes the calendar sees a request from our servers, but nothing about you or your family.
- Your private calendar link. If you turn on “Subscribe in Apple Calendar or Outlook” for a family calendar, we create a secret link for you. Your calendar app uses it to fetch the family plans you can see in Two Front Doors, including events from calendar links, and parenting time and children’s initials only if you choose. Your “only me” events are never included. Anyone who has the link can read those plans, so keep it private. You can reset it (the old link stops working straight away) or turn it off at any time in Settings. We store only a scrambled form (a cryptographic hash) of the link, your choices and a count of recent requests to limit misuse. Our database provider’s request logs record the link when your calendar app uses it; only we can see those logs, and they expire on the schedule in section 9. If you add the link in Outlook.com or Outlook on the web, or your Apple calendars sync through iCloud, Microsoft’s or Apple’s servers fetch the link and keep it and the plans it carries, under their own terms. Changes you make there don’t come back to Two Front Doors.
Bank holidays
Once a week our server downloads the UK government’s public list of bank holidays from www.gov.uk. The request contains nothing about you or your family. US federal holidays are worked out in the app, so nothing is fetched for them.
What you type is up to you
Some fields are free text: event titles, places and notes, a birthday typed by name, the family calendar’s name and description, calendar link names, school and day-off names, travel list items, dates added to Plan the year, home names, the essentials page’s contacts and note, support messages and reports. They can contain whatever people type, including names. Events read from a calendar link contain whatever the school or club published, which may include names. We treat all of it as your content: we store it, show it only to the people who can see it, and use it for nothing else. Please use your children’s initials, not their names, wherever you type about them.
Sensitive information
We don’t ask for health information, religion or other sensitive information. The essentials page holds the names and phone numbers of a child’s doctor and dentist, but nothing about the child’s health. Please don’t type health details into notes, travel lists or event titles. If someone types sensitive information anyway, we keep it like the rest of that text, show it only to the people who can see it, and use it for nothing else. We don’t use advertising trackers, and the only analytics we use are the anonymous usage statistics and website page counts above, which you can turn off.
What you must give us
To have an account, we need an email address (or an Apple or Google sign-in). Everything else is optional. Without it, the parts of the app that need it don’t work: for example, reminders need notifications on.
4. Children’s data
Two Front Doors is for adults. Children don’t have accounts and we never contact them. The one part made for children to look at is the children’s screen, described below, which a parent sets up. It asks the child for nothing; the only data it sends us is the technical data any web page sends, described below. Children appear in the calendar only as labels that a parent creates. For each child we hold:
- their initials (one to three letters, for example “SJ”) and an optional colour;
- which events, parenting time, pickups and calendar links you tag with that child.
We don’t hold children’s names. The app asks for initials and refuses anything longer than three letters. Only a parent can add a child or change their initials, on the Family tab. Free text is different: see What you type is up to you, and please use initials there too.
Some things are optional and only stored if a parent adds them:
- Birthdays. A birthday is a yearly event. The app asks for a child’s initials, and uses them in the title (“SJ’s birthday”) when you pick a child. If you add a year of birth, we store it with that event so the app can show the age. Only the people who can see the event can see it, and it is never included in calendar exports, Google Calendar copies, reminders or notifications.
- Child essentials. One optional page per child: the school’s name and phone number, the names and phone numbers of the child’s doctor (GP) and dentist, up to 10 other key contacts (a name, and if you add them, their role and phone number), clothing and shoe sizes, and a note. Both parents can see and change it. A helper sees it only for the children they help with.
- Allergies and medical notes. We don’t collect children’s allergies or medical notes at the moment. Please don’t type health details into notes, travel lists or event titles. If we turn this on later, we will ask for explicit consent first and update this policy.
The essentials page is used only to show it to the family members described above. It is not included in calendar exports, Google Calendar copies, notifications, analytics or error reports, and we keep no history of earlier versions. It is deleted when the child or the family calendar is deleted, and a parent can clear any field at any time.
We don’t collect children’s full names, photos or locations, and the app has no fields for them. If you type a child’s details into an event title or notes, we store that like any other event text, and it is visible to whoever can see that event. Please only enter what you are comfortable sharing with the people in your family calendar.
If you believe a child has signed up for an account, tell us and we will remove it.
The children’s screen
A parent can make a private link to show on a tablet or old phone at home, so the children can see where they sleep. The screen shows, for each child the parent chooses, by their initials:
- which home they sleep at tonight, and how many sleeps until the next home;
- the next two weeks as a row of houses in each home’s colour, with handover days and times;
- their school’s holidays and, only if the parent who made the link switches on “Show birthdays”, that child’s own birthday.
It never shows events, notes, places, essentials, health details, private events, the family calendar’s name or anyone’s name. Homes are shown by the names the parents give them (such as “Dad’s”) or as “the green house” and “the orange house”. Anyone who can see the screen, or who has the link, sees what it shows, so please keep the link to your own household.
The screen asks the child for nothing and has no account, cookies, usage statistics, error reports or tracking. When it loads and when it updates, our hosting providers (Vercel and Supabase) receive the device’s IP address, as with any web page, and keep it in their request logs for a short time for security and to stop misuse (see Server logs in section 9). Nothing else about the device or the child reaches us. Names you type on the screen for the children or the homes stay in that device’s browser and are never sent to us. Each parent can make one link per family calendar; the other parent can see that it exists and which children it is for. The parent who made it can make a new link (the old one stops at once) or turn it off at any time, and it stops working when that parent leaves the family calendar, is removed or deletes their account. Either parent can also email us and we will turn the link off.
5. Google Calendar data
Connecting Google is optional. It lets you see your own Google Calendar events next to your family plans, only on your own screen. You choose which calendars to show.
The permissions (scopes) we ask for
See the list of your calendars
https://www.googleapis.com/auth/calendar.calendarlist.readonly
Why: so we can show you your calendars and let you pick which ones to display. We read each calendar’s name and ID.
See events on the calendars you choose
https://www.googleapis.com/auth/calendar.events.readonly
Why: so we can show those events in your calendar view. We only fetch events from calendars you have switched on, for a window running from six months ago to eighteen months ahead. This permission is read-only: it can’t create, change or delete anything.
Google asks you to allow both of these together on its consent screen, and the app won’t connect unless you do.
One more, only if you switch on “Add family plans to Google”
Manage a calendar created by the app
https://www.googleapis.com/auth/calendar.app.created
Why: “Add family plans to Google” is optional and off until you switch it on. When you do, Google asks you for this permission, and Two Front Doors creates one separate calendar called “Two Front Doors” in your Google account and keeps copies of the family events you can see on it, and your parenting time if you choose. The permission only covers calendars the app itself creates. It can’t see or change your other calendars. Changes you make to the copies in Google are not copied back into the app.
We don’t ask for any permission that can change who a calendar is shared with, and the app never changes sharing settings on any calendar. When you connect, Google also tells us the email address of the account you connected, which we show so you know which account is linked.
What we store from Google
For each event on a calendar you have switched on, we store a read-only copy holding:
- the event title, and the first 500 characters of its description;
- the start and end, time zone and whether it lasts all day;
- repeat rules, status, when Google last changed it, and a link back to it in Google Calendar.
We deliberately don’t store guest lists, video-call details or attachments, or any description past 500 characters.
If you switch on “Add family plans to Google”, we also keep which Google event is the copy of which family event, as identifiers only, and your choices for it. When you switch it off or disconnect Google, you choose whether we delete the “Two Front Doors” calendar from your Google account or keep it; if you have added events of your own to it, we delete only our copies. If you keep it, the copies already in it stay in your Google account as they are and are no longer updated or removed by the app. When you delete your Two Front Doors account, you get the same choice.
How we store and protect it
- Google’s access tokens are encrypted, with the key held separately in Supabase Vault. They live only on our servers. The app on your phone or browser never receives them, and our database is set up so that it can’t be asked for them.
- Your copied events sit in a table that only you can read. The other parent, helpers and other users can’t see them.
- The service is designed to keep event text and tokens out of our logs, error reports and analytics.
- Copies of your Google events stay until you disconnect Google in the app. If access stops working (for example you remove it in your Google account) and isn’t restored, we purge the copies 7 days later.
How we use it, and what we don’t do
- We use Google data only to show your events to you inside Two Front Doors.
- We don’t sell it, use it for advertising, or use it to train AI or machine learning models.
- We don’t share it with the other parent, helpers or anyone else.
- Nobody at Two Front Doors reads your Google data, unless you ask us to look at a support problem, or we must to keep the service secure or to obey the law.
- Only our service providers listed in section 7 handle it, and only to run the service.
Google API Services User Data Policy. Two Front Doors’ use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Signing in with Google
If you choose “Continue with Google” to sign in, we ask Google for three basic permissions: openid, email and profile. They tell us who you are (your Google account’s email address and name) so we can create or find your account. They give no access to your calendar, and they are separate from the calendar connection above. Signing in with Google doesn’t connect your calendars.
How to disconnect Google
- In Two Front Doors: open Settings, find “Your Google calendars” under Google Calendar, and choose “Disconnect Google”. We cancel our access at Google, then delete your copied events, your calendar choices and our stored tokens. Nothing in your Google Calendar changes. If Google can’t be reached at that moment, we still delete our copies and tell you to finish in step 2.
- In your Google account: go to myaccount.google.com/permissions, choose Two Front Doors, and select “Delete all connections”. Our stored tokens stop working straight away.
When you delete your account (see section 9), we also revoke our access at Google and delete what we hold from Google.
6. Who can see what
| Data | You | The other parent | Helpers |
|---|---|---|---|
| Private events | Yes | No | No |
| Your Google events | Yes | No | No |
| Shared events | Yes | Yes | Yes, and only for the children they are allowed to see |
| Parenting arrangement | Yes | Yes | As coloured days only, for children they can see |
| Swap requests | Yes | Yes | No |
| Children’s initials | Yes | Yes | Yes, for children they can see |
| Child essentials (school, doctor and dentist, contacts, sizes, note) | Yes | Yes | Yes, for children they can see |
| Members’ display names | Yes | Yes | Names and roles |
| Calendar links: name, children and events read from them | Yes | Yes | Yes, for links tagged with children they can see |
| A calendar link’s web address | No (not after it is added) | No | No |
| Your private calendar link | Yes, and anyone you give it to | No | No |
| School term dates: schools, children, holiday dates, and who last changed them | Yes | Yes | Yes, for schools their children go to, but not who last changed them |
| Plan the year: dates the parents add, rows marked “Needs a plan”, and yearly rules | Yes | Yes | No |
| Home names (what the children call each home) | Yes | Yes | No |
| The children’s screen | Yes, and anyone who can see the screen or has the link | That it exists, which children it is for and whether it shows birthdays | No |
| A view link and what it shows, before the other parent joins | Yes, while it is on | Yes, once you send it, and anyone else who has the link | No |
| Change history (who changed what, and when) | Yes | Yes | For events they can see |
| Whether the family is covered by a subscription | Yes | Yes, and the date cover ends if it won’t renew | Only whether adding plans is paused, and the date cover ends if it won’t renew |
| Your own subscription (plan, store, renewal, payment problems) | Yes | No | No |
| Your reminder and notification settings | Yes | No | No |
| Your bank holiday setting, and your choice to show term dates on your calendar | Yes | No | No |
| Your support messages and reports | Yes | No | No |
- Subscriptions. If you pay, the other parent sees that the family is covered by the other parent. If your subscription won’t renew, or the store reports a payment problem, the other parent and helpers see “Covered until” and the date. They never see your plan, price, store or payment details.
- Our staff. A small number of authorised staff at Rankibl Ltd can look up an account and its subscription and billing status, and which family calendars it belongs to, shown by an ID, the date it was made and how many parents, helpers, children and pending invitations it has, but not its name. Only some of them can see the names and email addresses of a family’s members. They do this to answer support requests, manage subscriptions (for example to give free access), and keep the service safe, for example by signing someone out of every device, suspending sign-in, removing a helper, or deleting an account when asked. They can never see your calendars: not event titles, places or notes, not your children’s initials, birthdays or essentials, school term dates, anything from Google, or your calendar links. They see that a support message or report was sent, its topic and when, but what you wrote is read only in our support mailbox. Staff must use two-step sign-in, and every lookup and change they make is recorded in an access log (see section 9).
- Invitation links. Anyone who holds an invitation link can see the name of the family calendar, the name of the person who invited them and the role offered, before they sign in. A link works for one person and expires after 7 days.
- Exports. Parents and helpers can export a family calendar as an ICS or CSV file (today as a download in the web app). Events read from calendar links are not in exports or Google copies, but they are in your private calendar link. An export carries shared event text and children’s initials out of the app, and once you have the file it is yours to look after. A helper’s export only includes the children they can see. Your own “only me” events are included only if you choose to add them, and only yours: nobody’s private events are ever in another person’s export.
- Copies in other people’s Google calendars. With “Add family plans to Google”, each family member can copy the shared events they can see into a calendar the app creates in their own Google account, and parenting time too if they choose (without children’s initials unless they turn them on). A helper’s copy only includes the children they can see, and nobody’s “only me” events are ever copied. The copy sits in their Google account under Google’s rules. The app never shares that calendar with anyone, but we can’t control who they share it with in Google. When someone can no longer see an event (for example it is deleted or moved to “only me”, a helper’s children change, or they leave the family, are removed or delete their account), the app deletes their copy the next time it can use their Google connection. Copies stay in that person’s Google account until they delete them in two cases: if their Google connection stops working and they never reconnect, and if they switch the feature off or disconnect Google and choose to keep the calendar, after which the app no longer updates or removes anything in it.
7. Who else handles your data
We use these providers to run the service. They handle personal data on our behalf, under a contract with us, and only for that purpose. We don’t sell your data to anyone.
| Provider | What it does for us | Data it handles |
|---|---|---|
| Supabase | Database, sign-in and server functions | Your account, calendar, family set-up, child essentials, settings and stored Google data (tokens encrypted) |
| Vercel | Hosts the web app at app.twofrontdoors.com | Technical request data such as IP address and browser type |
| Resend | Sends our emails: your sign-in code, reminder, update, handover reminder and plan-ahead emails if you switch them on, your subscription confirmation and yearly renewal reminder, a warning before we delete an account nobody has used, the emails that tell us about a support message or a report, and the beta sign-up emails (the confirmation link to you, and a notice of each confirmed sign-up to us) | Your email address and the email itself: the code, the short reminder or update sentence, your plan, its price and renewal date in a subscription email, what you write in a support message or a report (which we receive by email), and for the beta, your answers in the notice to us |
| Expo | Passes update notifications, handover reminders and plan-ahead notices to Apple’s and Google’s push services | Your phone’s push token and the short notification sentence |
| GoDaddy | Hosts this website, twofrontdoors.com | Technical request data such as IP address, the page asked for and browser type |
| Google Workspace | Hosts our hello@twofrontdoors.com mailbox | Emails you send us, your email address, and our replies |
| Sentry | Error reporting, so we can fix crashes | Technical details of errors. Reports are designed to exclude event text and tokens. |
| PostHog (EU cloud) | Counts steps in the app and page views on this website, so we can see where people get stuck and improve them, unless you turn it off (see section 3) | In the app: the step name, the time, device type, app version and a random code that isn’t linked to your account. On this website: the page address without its query, the linking website’s name, browser, operating system, device type, the time and a random code for that one page view. It also receives your IP address with each request, but is set not to store it. Never your name, email or calendar content. |
| RevenueCat | Keeps track of subscriptions bought in the phone apps and on the web, and tells our server who is subscribed | A random customer code we create for billing (not your account ID, name or email), your subscription details, and for web purchases your email address |
| Stripe | Takes payment for subscriptions bought on the web, through RevenueCat | Your name, email address, card details, billing country and, where tax needs it, your billing address. Stripe also uses payment data to prevent fraud, as an independent controller under its own privacy policy. |
| Google sign-in and the Google Calendar connection, only if you use them | What you allow on Google’s consent screen. Google is also responsible for your Google account under its own privacy policy. |
Some organisations handle your data under their own privacy policies, not as our providers. If you use Sign in with Apple, Apple provides your name and email or relay address. If you subscribe in a phone app, Apple or Google takes the payment, keeps its own records of it, and tells RevenueCat about the purchase but not your card details. Notifications reach your phone through Apple’s or Google’s push service. If you add your private calendar link to Outlook.com or iCloud, Microsoft or Apple fetch and keep it under their own terms. Websites that publish the calendars parents link to see only a request from our servers.
Supabase, Vercel, Resend, Expo, GoDaddy, Google, Sentry, PostHog, RevenueCat and Stripe are US companies or part of US groups, so your data may be processed in the United States. Each transfer out of the UK is protected in one of two ways:
- The UK–US data bridge. Vercel, Resend, Expo, GoDaddy, Google, Sentry, PostHog and Stripe have each certified to the UK Extension to the EU–US Data Privacy Framework, which UK law treats as giving adequate protection. PostHog keeps the usage statistics and website page counts on its EU cloud.
- Standard contractual clauses. RevenueCat and Supabase are each covered by the UK International Data Transfer Addendum to the EU standard contractual clauses, which is part of their data processing agreements with us. Our database is hosted in London, in the UK (Amazon Web Services, eu-west-2). The clauses cover Supabase staff outside the UK who may access it to support and run the service.
If a provider’s certification lapses or changes, we rely instead on the UK Addendum to the EU standard contractual clauses or the ICO’s International Data Transfer Agreement, as applicable. Email us if you would like a copy of the safeguards for a provider.
Requests from courts, police and solicitors
Family calendars sometimes matter in disputes between parents. This is what we do when someone asks us for a family’s data.
- We only hand over a family’s data when the law requires it, for example a court order, or a request from the police or another public body with the legal power to require it. A solicitor’s letter, or one parent asking about the other, is not enough.
- If we believe someone’s life or safety is at serious and immediate risk, we may share what is needed to protect them.
- We check each request and give only what it covers.
- We tell the people whose data it is, unless the law stops us or telling them could put someone at risk.
- We don’t prepare statements or evidence for either parent or their solicitor unless a court orders us to.
- Each parent can export the plans they can see (see Exports in section 6) and ask for a copy of their own data (section 10).
8. Why we use your data
| What we do | Our lawful basis under UK GDPR |
|---|---|
| Run your account and calendar, show it to the people you choose, send sign-in codes, read the calendar links a parent adds, show the bank holidays you choose and the school term dates a parent adds, provide your private calendar link, and send the reminders and notifications you switch on | Contract: it is needed to provide the service you asked for (Article 6(1)(b)) |
| Hold children’s initials, birthdays and essentials that a parent adds, and show them to the family | Legitimate interests: helping both parents and the helpers they choose look after the children (Article 6(1)(f)). Parents choose what to add, and it is shown only as described in section 4 |
| Show the children’s screen a parent makes | Legitimate interests: helping children know which home they sleep at, which a parent chooses to show them (Article 6(1)(f)). It shows only the homes, school holidays and, if the parent switches them on, birthdays. It asks nothing of the child (the only data it sends is the device’s IP address, kept briefly in request logs), and the parent who made it can turn it off at any time, or either parent can ask us to |
| Show the view link a parent makes for the other parent before they join | Legitimate interests: letting the other parent see the plan for their children, and decide whether to join, without needing an account first (Article 6(1)(f)). It shows only what is listed in section 3, the page itself tells the other parent this, and it stops when the other parent joins or the parent who made it turns it off |
| Take payment for a subscription, check who is subscribed, and handle renewals, cancellations and refunds | Contract: it is needed to provide the subscription you bought (Article 6(1)(b)) |
| Connect to your Google Calendar | Your consent, given on Google’s consent screen. You can withdraw it at any time by disconnecting (Article 6(1)(a)) |
| Count anonymous usage steps in the app and page views on this website | Legitimate interests: understanding how people use the app and this website so we can improve them (Article 6(1)(f)). The counts can’t identify you and are used for nothing else. Regulation 6 of the Privacy and Electronic Communications Regulations also applies to both: the app keeps a random code on your device, and on this website the counting code reads details from your browser (such as its type) and briefly saves and removes a test value. Its exception for statistics about how a service is used lets us do this without asking first, because we tell you and you can turn it off at any time (in the app in Settings, Privacy; on this website with the button in section 3). The value this website saves when you turn analytics off is strictly necessary to respect your choice |
| Keep the service and this website secure, keep server logs, fix errors, and answer support messages and emails | Legitimate interests: keeping a service that holds family information safe and working, and helping you when you ask (Article 6(1)(f)) |
| Receive and act on reports of misuse, and keep them | Legitimate interests: protecting the people in a family calendar, including children, from harassment and misuse (Article 6(1)(f)) |
| Keep the beta sign-up list | Your consent (Article 6(1)(a)), see Beta sign-ups |
| Keep tax and accounting records of web sales, and answer lawful requests | Legal obligation (Article 6(1)(c)) |
| Share what is needed when someone’s life or safety is at serious and immediate risk | Vital interests (Article 6(1)(d)) |
Where we rely on legitimate interests, we have weighed them against your rights, and you can object (see section 10). We don’t make decisions about you by automated means that have legal or similarly significant effects.
9. How long we keep it
| Data | How long |
|---|---|
| Your private events, calendar choices, display preferences (including your bank holiday setting), and reminder and notification settings | Until your account is deleted |
| An account nobody uses | If an account isn’t used for 12 months and no subscription that is still running covers it (your own, or the other parent’s for your family calendar), we delete it as described in “Deleting your account” below, keeping your “Two Front Doors” calendar in Google if you have one. An account is used when someone signs in to it, or opens the app or web app while signed in. We email the sign-in address at least 30 days before, and using the account in that time keeps it. We keep a record that we sent that email (an ID and a date) until the account is used again or deleted. We also keep the date each account was last used, until the account is deleted. |
| Subscription emails we have sent | A record that we sent your subscription confirmation or a renewal reminder (an ID and the dates), so you don’t get the same email twice. Deleted with your account. |
| Push tokens for your phones | Until you sign out on that phone, turn notifications off, or delete your account |
| Copies of your Google events, and Google tokens | Until you disconnect Google in the app or your account is deleted. If Google access stops working and isn’t restored, the copies are purged 7 days later. |
| Shared events (including birthdays and any year of birth), arrangements, swap requests and children’s initials | For as long as the family calendar exists. A shared event you delete can be restored for 30 days, after which it is permanently removed (with its repeat series and changed dates). An event that a parent moves to “only me” is removed from the family calendar straight away and can’t be restored. |
| Child essentials | Until a parent clears them, the child is removed or the family calendar is deleted. |
| Change history (who changed what, and when) | For as long as the family calendar exists. It records IDs and field names, never event text. |
| A family calendar with no members left | Deleted automatically 30 days after the last member leaves or deletes their account, with everything in it. |
| Expired or cancelled invitations | Deleted after 90 days. Invitation links stop working after 7 days. |
| Notifications waiting to be sent, and the logs of reminder emails, handover reminders and plan-ahead notices sent | Notifications: 3 days after sending, or 10 days if never sent. Reminder email and handover reminder logs: 7 days. Plan-ahead log: a month after the date it was about. |
| Subscription details in our database, and your billing customer code | Until your account is deleted. If you were the paying parent, the record that your subscription covers a family calendar is removed at the same time. Notices we receive from RevenueCat (an ID, a type and our result only) are deleted after 90 days. |
| Payment and invoice records (web purchases) | Kept in Stripe for 6 years after the end of the financial year they belong to, because UK tax law requires it. They are not removed when you delete your account. Apple and Google keep records of store purchases under their own policies. |
| RevenueCat’s records | RevenueCat keeps a record for each billing customer code: purchases, renewals, refunds and, for web purchases, the email address. When you delete your account, we delete our link between you and that code straight away, and ask RevenueCat to delete its record 30 days later, or once any subscription you still have has ended, whichever is later. |
| Calendar links, their addresses and the events read from them | Until a parent removes the link, the parent who added it leaves, is removed or deletes their account, or the family calendar is deleted. The events are replaced on every read. |
| School term dates (schools, children, holiday dates, and who last changed each school year) | Until a parent removes the school or the family calendar is deleted. |
| Plan the year (dates the parents add, rows marked “Needs a plan”, and yearly rules) | Dates: until a parent removes the date, or the family calendar is deleted. Marks: until a parent clears the mark, the holiday, day off, school, birthday or date it is on is removed, or about a year after its school year ends, whichever comes first. Yearly rules, including ended ones and ones never agreed: until the family calendar is deleted, like the arrangement and its proposals. A rule ends only when one parent proposes ending it and the other accepts; if the school, birthday or date it is for is removed, the rule stays (shown as having no date) until it is ended that way. |
| Home names | Until the parent removes it, leaves the family calendar or deletes their account, or the family calendar is deleted. |
| Travel lists (things that go back and forth, and where things are) | Until a parent removes the item, the child is removed or the family calendar is deleted. We keep where an item is and the day it last moved, but not who moved it or the time. |
| Your ticks on a travel list | 30 days after the handover they were for. Deleted sooner if you untick them, the item is removed, you leave or are removed from the family calendar, or you delete your account. Only you can see them. |
| Your choice to show term dates on your calendar | Until you change it or delete your account. |
| Your private calendar link | Until you reset it or turn it off, leave or are removed from the family, or delete your account. After that we keep only its scrambled form and the date it ended, with nothing that identifies you or the family, for 90 days, so that calendar apps still using it receive an empty calendar and remove the plans they copied. |
| A children’s screen link | Until you make a new one or turn it off, or you leave the family calendar, are removed or delete your account. After that we keep only its scrambled form and the dates it was made and ended for 90 days, so the screen can say the link no longer works, then delete it. |
| A view link you send the other parent before they join | Until you reset it or turn it off, the other parent joins, or you leave the family calendar, are removed, delete your account or have your account suspended. After that we keep only its scrambled form and the dates it was made and ended, with nothing that identifies you or the family, for 90 days, so that the page says the link no longer works and calendar apps still using it remove the plans they copied. When it stops working, any join link made from it that hasn’t been used stops working too. A record of which join link was made from it and when, with no other details, is kept for 8 days, to limit how many can be made and to stop them working with it. |
| Completed background jobs | 7 days |
| Jobs that failed or are parked | Until we resolve them, or the account or family calendar they belong to is deleted. They hold IDs only, never event text. |
| Messages you send us with “Contact support” | 12 months after you send them, or until your account is deleted, whichever is first. The email we receive when you send one is kept for the same period, then deleted. If we replied by email, see “Support emails” below. |
| Reports you make about a family member or an invitation | 24 months after you send them, or until your account is deleted, whichever is first. Your own words, and the email we receive when you send a report, are kept for that period, then deleted. They may name the person you reported. Your report stays for that period even if the person you reported deletes their account, or the family calendar is deleted after its last member leaves. Only you and we can see a report; the person reported, the other parent and helpers never can. We email each one to ourselves so we can act on it. |
| Our staff access log (who at Two Front Doors looked up or changed what, and when) | 24 months, then deleted. It records our staff member, what they did, the IDs of the account or family calendar it was about, and the reason they gave. Staff are asked not to put names or details in a reason, but a reason may still mention you. It can’t be changed, and it isn’t removed when you delete your account: it keeps your account ID (with nothing else about you) for the rest of the 24 months, as our record of what staff did. Whether a support message or report has been dealt with is kept with it, and deleted with it. |
| Support emails | 2 years after the last message in the conversation, then deleted |
| Server logs | Our hosting providers (Supabase, Vercel and GoDaddy) keep ordinary request logs, which include IP addresses, for a limited period set by their service, then delete them. Supabase’s logs also record private calendar links when calendar apps use them. We don’t keep our own copies. |
| Sign-in audit logs | Supabase, our sign-in provider, logs sign-in events such as signing in and out, with your account ID and email address and sometimes your IP address. Supabase keeps these logs for no more than 7 days on the plans we use, and we don’t keep a copy in our own database. They are not removed when you delete your account; they expire on that schedule. |
| Anonymous usage statistics and website page counts | In the app, the random code on your device is deleted when you turn statistics off, and replaced (the old one is discarded) whenever your session ends. Whether statistics are on or off, and whether the notice has been shown, is kept on the device until you change it or clear the app’s data. On this website nothing is kept on your device, except the value that remembers you turned analytics off, which stays until you clear this website’s data in your browser. The counts we already received can’t be tied back to you, and PostHog’s free plan, which we use, keeps them available for 1 year. |
| Backups | Supabase backs up our database once a day and keeps each backup for 7 days. Deleted data leaves the backups when they expire, so it is gone from them within 7 days of being deleted. We use a backup only to recover from a fault. |
Deleting your account
You can delete your account yourself in the app: open Settings, choose “Delete my account”, and confirm. If you last signed in more than 10 minutes ago, you are asked to sign in again first, so that nobody else holding your phone can do it. It happens straight away. If you can’t use the app, email hello@twofrontdoors.com from the address you signed up with and we will delete it for you within 30 days and confirm by email. What happens:
- We delete your private events, copies of your Google events, calendar choices, preferences, reminder and notification settings, push tokens and device details, your support messages and the reports you made, your private calendar links, the calendar links you added (with their addresses and events), and your sign-in. We also revoke our access at Google, and on an iPhone that uses Sign in with Apple, we ask Apple to revoke it too.
- If you added family plans to Google, you choose whether we delete the “Two Front Doors” calendar from your Google account or leave it there, as when you switch that feature off.
- You leave every family calendar you belong to. What you added to a shared family calendar stays there, so the other parent doesn’t lose their history. It is kept without your identity and shows as “Former member”. This includes children’s essentials you entered. Changes you proposed that were still waiting for an answer are withdrawn.
If you were the only parent in a family calendar, its helpers lose access at the same time, and we delete the family calendar 30 days later. If something stops the deletion part-way (for example, a connection drops), we finish it automatically in the background. Deleting your account doesn’t cancel a subscription, whether you bought it in an app store or on the web, so cancel it as well (see Paid plans in the terms). Sign-in audit logs, server logs, payment records, our staff access log, and any backups we add, are covered in the table above: deleted data leaves them when they expire.
Leaving a family calendar
You can leave a family calendar from the Family tab and keep your account. What you added to it stays there and shows as “Former member”. Calendar links you added to it are deleted, with their addresses and events, and your private calendar link for it stops working. If you copy family plans to Google, your copies of that family are deleted the next time the app can use your Google connection; if the connection has stopped working, they are deleted when you reconnect (and stay in your Google account if you never do). If you were its only parent, its helpers lose access too, and the family calendar is deleted 30 days later.
10. Your rights
Under UK GDPR you have the right to:
- ask for a copy of your personal data;
- have wrong data corrected;
- have your data deleted;
- restrict how we use it;
- object to how we use it where we rely on legitimate interests (for usage statistics, simply turn them off as described in section 3);
- receive data you gave us in a portable format;
- withdraw consent at any time, for example by disconnecting Google. This doesn’t affect what we did before.
Email hello@twofrontdoors.com. We will reply within one month. If a request is complex, we may take up to two more months and will tell you why within the first month. We may need to check it’s really you first. You can also delete your account yourself in the app, as described in section 9. Parents can ask for their children’s data on their behalf.
We can only give you your own data, not anything that belongs to someone else, such as the other parent’s private events. Where your data is mixed with someone else’s, the law lets us hold back what would identify them. In particular, if someone has reported misuse and the report is about you, we will not tell you who made it or show you their words where that would identify them or put anyone at risk, unless they agree. We look at each request on its own facts.
Complaints
If you are unhappy with how we have handled your data, please tell us first by emailing hello@twofrontdoors.com with “Complaint” in the subject, or using “Contact support” in the app. We will acknowledge your complaint within 30 days, look into it, and tell you the outcome without undue delay.
You can also complain to the Information Commissioner’s Office, the UK regulator, at ico.org.uk/make-a-complaint or on 0303 123 1113.
If you live in the US
You have the rights in this section wherever you live, including the rights to know what we hold, to correct it, to delete it and to get a copy you can take elsewhere. We won’t treat you differently for using them.
What we don’t do:
- We don’t sell your personal information.
- We don’t share it for targeted advertising, and we have no advertising partners.
- We don’t use it to train AI models.
- We don’t collect your location.
We don’t intentionally collect consumer health data, and we ask you not to type health details anywhere in the app. The only health-related fields are the names and phone numbers of a child’s doctor and dentist, which you can leave empty. If you live in Washington or Nevada, or anywhere else, and want anything health-related that you or the other parent typed deleted, email us and we will delete it, including from backups, within 45 days.
Children don’t have accounts, and we don’t knowingly collect personal information from children under 13. The children’s screen asks a child for nothing. When it loads, the device’s IP address reaches our hosting providers so the page can be shown and the service protected, and for nothing else (see The children’s screen).
The web app and this website treat a Global Privacy Control signal as a request to turn usage statistics off (see Usage statistics).
To make a request, email hello@twofrontdoors.com, or delete your account yourself in the app. Someone you authorise can ask for you; we may ask them for your signed permission and ask you to confirm who you are. We answer within 45 days. If we need longer, we tell you why within those 45 days and take at most 45 more.
If we turn down your request, in whole or in part, we tell you why. You can appeal by emailing us with “Appeal” in the subject. We answer within 45 days and tell you what we decided and why. If you are still unhappy, you can complain to your state’s attorney general.
11. Security
- Data travels over encrypted connections (HTTPS).
- Private and shared data are kept in separate tables with separate access rules, and the rules are checked on every request rather than trusting the app.
- Google tokens are encrypted and never sent to the app.
- We test these access rules with automated tests that use made-up families, never real data.
No online service is completely secure. If a breach puts your data at risk, we will tell you and the ICO where the law requires it.
Beta sign-ups
This section applies only if you fill in the form on our beta page. It is separate from having an account: you don’t need an account to sign up, and signing up doesn’t create one.
Filling in the form isn’t enough. We email the address you gave with a link, and you are only on the list once you open it. Until then we hold your answers for 48 hours and then delete them.
| What we collect | Why |
|---|---|
| Your name and email address | To send the confirmation link, to reply to you, and to email you if you are chosen |
| Whether you use an iPhone, an Android phone or both | To choose a mix of phones, and to send the right install link |
| How many children you share (a number; no names, ages or other details) | To choose a mix of family sizes |
| Which parenting arrangement is closest to yours, and whether the other parent would join | To choose a mix of arrangements, and to know whether both parents can try it together |
| That you opened the confirmation link, and when | It is our record of your consent |
| A keyed hash of your IP address (not the address) | To stop one connection from sending the form over and over. It is made with a secret key that only we hold, so nobody without the key can turn it back into your address, but someone who holds the key could test a guess against it. We delete it after one day |
- Our basis is your consent, which you give by opening the confirmation link. You can withdraw it at any time by emailing hello@twofrontdoors.com; we delete your sign-up and stop emailing you.
- How long we keep it. If you never open the link, your answers are deleted within about 2 days. Once you confirm, we keep your sign-up until the beta ends and for three months after, then it is deleted automatically. The automatic deletion runs from the end date we set for the beta; until we have set one, your sign-up is deleted 12 months after you confirmed it. If you ask us to delete it sooner, we do.
- Who sees it. Only the people who run Two Front Doors. We use it to choose testers and to email testers about the beta, and for nothing else. We don’t sell it or share it, and it is never joined to an account or to anything a family puts in the calendar.
- Copies elsewhere. Each time someone confirms, we get an email with their answers in our hello@twofrontdoors.com inbox (held by our email provider, Google Workspace, section 7). Resend, which sends the emails, keeps a log of them for a limited time under its own rules. Deleting a sign-up from our list doesn’t remove these copies by itself; if you ask us to delete your sign-up, we also delete the notice email from our inbox, and Resend’s log expires on its own schedule.
- Who handles it for us. Supabase stores the sign-ups, and Resend sends the confirmation email to you and the notice to us. Both are listed in section 7. Supabase also keeps ordinary request logs, which can include IP addresses, for a limited time under its own rules.
- Please don’t put anyone else’s details in the form, or anything about your children beyond how many there are.
12. Changes to this policy
If we change how we use personal data, we will update this page and the date at the top. If a change matters to you, for example a new Google permission or a new provider, we will tell you in the app or by email before it starts. We keep a list of each version of this policy below, with its date and a line on what changed. Email us for a copy of an earlier version.
Past versions
- 8 October 2026: accounts nobody uses, the view link, requests from courts and police and a section for the US added; subscription emails and RevenueCat records explained; allergies and medical notes removed; usage statistics and the children’s screen made clearer.
- 6 October 2026 and earlier: before this list started. Ask us for a copy.
Questions about any of this? hello@twofrontdoors.com.