Skip to content
Legal & Trust

Security

How we protect your account and your data.

Last updated: July 23, 2026

What leaves your device, and what never does

This is the plain-language version of our architecture, not just a policy promise. These items are structurally never collected — there's no setting that turns them on, on any plan, on any device:

  • Camera or microphone recording
  • Screen contents or screen recording
  • Keystrokes
  • Website or application browsing history
  • Advertising or third-party tracking data

What does sync to your account, and only this: your identity and email (so you can log in on another device), your trial/subscription status (so billing works), and aggregate routine completion counts (so your reports and streaks show up). No screen content, ever, travels with any of it.

Child Mode is held to the same rule, without exception. No camera, microphone, voice recording, screen recording, website tracking, keystroke tracking, application tracking, or advertising data is accepted for a child profile. Family reports contain aggregate routine completion — not screen content, not browsing history, not app usage.

Infrastructure

The service runs on a controlled, self-hosted stack — a DigitalOcean VPS managed with Coolify, PostgreSQL for data, Redis for caching and background jobs, and Cloudflare for DNS and object storage. This gives us strong operational control over how data is handled.

Encryption in transit

Traffic to the website and app is protected with TLS. We configure secure HTTP headers to reduce common web risks.

Payments

Payments are handled by Stripe, a PCI-DSS Level 1 certified provider. We never store full card numbers on our servers.

Data protection

We follow the principle of least privilege for access to production systems and limit the personal data we collect in the first place — no screen contents, browsing history, or keystrokes.

Backups & recovery

We take regular PostgreSQL backups and test restores so we can recover data if something goes wrong.

Monitoring

We use error monitoring and uptime checks to detect and respond to issues quickly.

Responsible disclosure

If you believe you've found a security vulnerability, please email security@protectyoureyes.app. We appreciate responsible disclosure and will work with you to resolve valid issues.

This page is provided as a starting template for the Chapter 5 website scaffold and is not legal advice. Please have counsel review and adapt it before launch.