Private by default. No ads. No selling family data. No AI training on family data.
1. Where data is stored
The verified primary host is information awaiting verification in information awaiting verification. Encrypted backups use information awaiting verification in information awaiting verification.
Cloudflare provides authoritative DNS and can process network traffic when proxy features are enabled. Stripe processes payments separately. We do not claim that every metadata item remains exclusively in the primary hosting country.
2. Encryption in transit
Production traffic must use HTTPS between users and the public endpoint, and protected transport or a private loopback connection between internal components. HSTS is enabled only after the HTTPS path and rollback procedure are validated.
3. Application and backup encryption
Selected family fields such as display labels, titles, locations, notes and comments are encrypted with authenticated encryption at application level. Dates, times and statuses needed for coverage calculations remain queryable.
Backups are encrypted before leaving the host. Key custody, rotation, restore testing and the consequence of key loss are documented in docs/KEY_MANAGEMENT.md.
4. Household isolation and administration
Every private operation must verify active household membership and role on the server. Invitation and reset tokens are stored as hashes and expire.
The admin dashboard exposes operational aggregates, not family content. Owner administration requires a recent single-use code sent to the verified email address. Any future support access to content must be explicit, time-limited, visible, revocable and audited.
5. Accounts and sessions
Passwords use a modern memory-hard hash, sessions are server-side and cookies are Secure, HttpOnly where applicable and SameSite in production. Users can revoke sessions and administrators use multi-factor authentication once the corresponding controls are verified.
6. Logging and monitoring
Audit records contain safe metadata rather than family text. Logs must redact credentials, cookies, one-time links and payment secrets. Health checks, dependency review, failed webhooks, backup failures and critical application errors are monitored.
7. Backups and recovery
SQLite backups use a consistent backup mechanism rather than copying a live database. Encrypted backups rotate under a documented retention schedule. Restore drills verify database integrity, key availability and sample decryption in an isolated environment.
8. Incident response
We detect, contain, preserve evidence, assess privacy risk, restore safely and document lessons learned. Authorities and affected users are notified when required. See docs/SECURITY_INCIDENT_RESPONSE.md.
9. Your controls
Use minimal child labels, review household members, remove obsolete access, export important plans and delete content you no longer need. Do not store medical files, identity documents or emergency-only information.
10. Honest limitations
CampGrid does not promise absolute security, zero risk or end-to-end encryption. Server-side processing is required to calculate coverage. No application should be the sole source of critical child-safety information.
11. Report a concern
Report a suspected vulnerability or account incident to jlr.venturescorp@gmail.com. Do not access other users' data, disrupt service or publish sensitive details before coordinated remediation.
This initial document requires review by a qualified professional. Mandatory consumer rights continue to apply.