Security
Each household's data is separated in the database itself. The rule is evaluated on every query, so a bug in the application cannot expose another household's content.
Data separation
Every database query passes through rules that check you are a member of the household in question. Those rules apply regardless of what the application or the browser sends.
Relationships between records are constrained so an event cannot reference a person from another household, and a record's household cannot be changed after the fact.
Sign-in
Sign-in uses a Google account. We neither store nor process any passwords. You can sign out at any time from the menu in the app.
Invitations
An invitation is a one-time link with a 256-bit random code, valid for seven days. Only its hash is stored, so the link cannot be reconstructed even from a copy of the database. An invitation addressed to a specific email can only be accepted by someone signed in with that email.
Privacy inside a household
A personal event can be shared as busy time only. Hiding the title and location is done by the database, not by the application — the content is not returned to other members even on a direct query.
Browser protection
The site sends security headers including a content security policy, which limits where scripts may load from and where the page may send data, and prevents the page being framed by another site.
Reporting vulnerabilities
If you find a security problem, write to our contact address. Please give us time to fix it before disclosure. We value these reports and we answer them.