Privacy
Plain-English privacy.
This page is the human-readable version of what we actually do with your data. It is intentionally short. Anything not said here is not being done in secret somewhere else.
This document needs lawyer review before public launch. The commitments below are real; the language may tighten.
What data we collect, and how.
You give us this information directly when you use the app:
- Account. Email, display name, locale, the country you sign up from.
- The children you add. First name (or a nickname), date of birth, pronouns, profile colour.
- The structured profile you build. Diagnoses, sensory profile, communication style, triggers, strengths, current supports, anything else you choose to record.
- Your conversations with Parenta. The text of every prompt and reply, plus any voice notes (stored as both the original audio and the transcript) and photos you upload.
- The issues, strategies, and wins you've saved.
The app also generates this on its own:
- Operational telemetry. Rough usage counts, error reports, AI cost ledger entries (for our own billing). No content of your conversations is in this telemetry.
We do not collect contacts, location, the device's photo library beyond what you explicitly upload, microphone audio beyond what you record into a voice note, or any background identifiers for advertising.
How we use it.
- To generate the parenting replies you ask for.
- To save your conversations and let you come back to them.
- To improve the product (aggregated usage patterns; never the content of your conversations).
- To bill you and prevent fraud.
- To respond to you when you contact support.
That is the complete list. We do not use your data for anything else.
What we send to third-party AI services, and when.
This is the section Apple specifically asks us to be clear about. Parenta relies on two AI services to function. You'll see a one-time consent screen inside the app the first time you use a feature that calls either of them. Nothing is sent until you accept.
1. Anthropic (Claude) — generates the parenting replies.
What we send. The text of your prompt for that turn, plus the relevant portion of the conversation history and the relevant fields from your child's structured profile (e.g. age, diagnoses, triggers — only what's needed to make the reply useful). If you upload a photo and ask a question about it, the photo is included.
What we do not send. Your email, your real name, your billing details, your account ID in plain form, or telemetry. Profiles are referenced by pseudonymous IDs.
Who they are. Anthropic, PBC, the company behind the Claude family of models. Based in San Francisco, USA.
What they're allowed to do with it. Process the request, return a reply, and retain it only for the short operational window their API requires. They are contractually prohibited from training any model on your prompts, your replies, or any content you send. This is enforced by our commercial agreement with Anthropic, not a hope.
2. OpenAI — transcribes voice notes only.
What we send. The audio file of a voice note you recorded. Nothing else — no profile data, no conversation history, no identifiers beyond what's needed to authenticate the request.
What we get back. The text transcript.
Who they are. OpenAI, OpCo LLC. Based in San Francisco, USA.
What they're allowed to do with it. Transcribe and return. OpenAI's API terms prohibit training on data sent via the API, and we are on the API (not consumer ChatGPT).
Your consent, specifically.
The first time you use a feature that needs Anthropic or OpenAI, the app shows you a consent screen that names the provider, lists what will be sent, and asks you to accept. You can also revoke consent at any time from Settings → Privacy. If you revoke, the relevant feature stops working — we don't have a way to give you AI replies without using an AI service — but no further data is sent.
Equal protection.
Apple's guidelines (5.1.1, 5.1.2) require us to confirm that any third party we share personal data with offers protection at least equivalent to ours. Both Anthropic and OpenAI are bound by Data Processing Agreements with us that mirror our own commitments: no training on your data, encryption in transit and at rest, GDPR-equivalent processing, breach notification, and deletion on request.
The other third parties we use (not AI).
Each one is named, each one is scoped to a specific job:
- Clerk — handles your sign-in, password, and session.
- Cloudflare R2 — stores binary files (voice notes and photos).
- Neon / Railway — runs our database and our servers.
- Sentry — collects crash reports so we can fix bugs. Configured to strip personally identifiable information from payloads.
- Stripe — processes payments. We never see your full card number.
What we will not do.
- We will not sell your data.
- We will not use your conversations to train AI models, ours or anyone else's.
- We will not allow any third party we use to train their models on your data.
- We will not show your data to a human at Parenta unless you've asked us to (e.g. a support ticket) or unless we are legally required.
- We will not run third-party advertising or marketing pixels on this site or in the app.
Children.
Parenta is designed for the caregiving adult, not the child. We do not knowingly accept accounts from anyone under 18. We do not market to children. The data you give us about your child is used to make the replies you get back better — it is not used to build any external profile of your child, and it is not shared with anyone outside the third parties named above.
Under COPPA (US) and the UK / EU equivalents, we treat data about children that you choose to share as data you control. You can export or delete it at any time, and we will not condition use of the product on you sharing more than you want to.
GDPR posture.
We treat all users as if GDPR applies, regardless of where they live. That means: a lawful basis for everything (consent for the AI processing described above; contract performance for the rest), the right of access, the right of rectification, the right of erasure, the right of portability, and the right to complain to your supervisory authority.
Export and deletion — guaranteed.
From inside the app, in your account settings:
- Export — you can download a structured JSON of every conversation, profile, issue, strategy, voice note, and photo we hold for you. Within 30 days.
- Delete — you can permanently delete your account. Within 30 days, every record is purged from primary storage; encrypted backups roll off within 90 days. We also instruct Anthropic and OpenAI to delete any residual operational copies they hold under their API terms.
You don't need to email us to do either. If something blocks you, write to privacy@parenta.app
Security in one paragraph.
Data in transit is encrypted with TLS. Data at rest is encrypted at the storage layer. Voice notes and photos are stored in private buckets and only accessible via short-lived signed URLs. Production access is limited to a small number of named engineers, audit-logged.
Changes to this policy.
If we change anything material on this page, we'll email everyone with an active account at least 30 days before the change takes effect.
Last updated: 25 May 2026.