Security & privacy of children's data
We treat children's data as the most sensitive thing we hold — because it is.
What we do
- Sensitive health details (conditions, medications) are encrypted at the column level, so a leaked database dump can't read them.
- Photos and documents live in private storage and are delivered through short-lived signed links — never a public URL. Group photos only reach families whose child consented.
- Every organization's data is isolated at the data layer. A parent can only ever see their own family's records.
- Payments run through Stripe; we never touch raw card numbers.
- We don't use children's data for advertising or model training.
Your data is yours
One click gives you a complete, machine-readable export of everything — during your subscription and after you cancel. Leaving is never held hostage.
Reporting a concern
Found a vulnerability or have a question? Email security@centerpilot.example and we'll respond promptly.
This page describes our approach; a full security whitepaper and incident-response summary are available on request.