Privacy policy.
Effective date: August 12, 2026
Your record lives on your device. The app has no accounts. We never see your entries, your photos, or your children's information, and we built it that way on purpose. The only thing that ever leaves your phone automatically is an anonymous cryptographic fingerprint (a hash) used to prove when an entry was sealed. A hash cannot be reversed into your content. The app does measure subscriptions, and, only if you allow it when iOS asks, which ad brought you here. Details in Advertising and measurement below.
This marketing website is a separate thing, and it does use Google Analytics, with cookies off until you say otherwise. It also has three places that ask you for something: the Readiness Check quiz, which wants your email before it shows you your score and keeps your answers alongside it; the attorney access form; and the landing pages our advertisements point to. Details in The website below. Nothing the website measures touches the app or your record.
Who we are
Documented ("we", "us") makes the Documented iOS app and operates the documented.co website. This policy explains what information the app and the website handle, and (mostly) what they deliberately don't.
The app
Your entries stay on your device
Everything you log in Documented (text, photos, video, voice recordings, receipts, message-thread captures, locations, and the details of your entries) is stored locally on your iPhone. We do not operate servers that receive, store, or process your record. We cannot read, access, recover, or delete your entries, because they are never sent to us.
No account, no sign-up
Documented does not require an account. We do not collect your name, email address, phone number, or any other identifier to use the app.
Advertising and measurement
The app uses two third-party services. RevenueCat records subscription events, such as a trial starting or a subscription renewing or being cancelled, so we can see how the business is doing. Meta receives those same subscription events, and, if you allow tracking when iOS asks you, an advertising identifier, so we can tell which ads bring parents to Documented.
Neither service receives your entries, your photos, your voice notes, your locations, or your children's names. Nothing you write in the app is part of this, and nothing you write leaves your phone.
If you decline the tracking request, no advertising identifier is collected and nothing is linked to you. You can change your mind at any time in iOS Settings, under Privacy & Security, then Tracking.
Our App Store privacy label is "Data Used to Track You." Apple requires that label whenever an app may share an advertising identifier with a third party, and it applies whether or not you personally allow it.
This is a statement about the app. The documented.co website is measured separately and is described below. The two share nothing.
iCloud sync
If iCloud is enabled on your device, your record syncs automatically to your private iCloud database so it survives a lost or replaced phone. This sync happens between your device and your own Apple iCloud account, under Apple's iCloud terms and encryption. We have no access to your iCloud data. You can turn iCloud off for Documented at any time in iOS Settings, and you can remove the app's iCloud data in Settings → Apple ID → iCloud → Manage Storage.
Trusted timestamps (the one thing that leaves your phone)
When you seal an entry, the app computes a SHA-256 hash of it (a fixed-length cryptographic fingerprint) and sends only that hash to an independent RFC-3161 timestamp authority, which returns a signed proof of the time. The hash contains none of your content and cannot be reversed into it. The timestamp authority never receives your entries, media, location, or identity beyond the technical minimum any internet request involves (such as an IP address handled per that provider's own policy).
Location
Adding a location to an entry is optional. If you grant location permission, the coordinates are attached to the entry on your device and go nowhere else. You can decline or revoke the permission at any time; the app works fully without it.
Face ID / Touch ID
The app's biometric lock uses Apple's on-device authentication. Biometric data is managed entirely by iOS and never reaches us or the app itself.
Exports are yours to control
Nothing in your record is shared with anyone unless and until you choose to export it. When you export a PDF, you decide where it goes, the app hands it to the iOS share sheet and keeps no copy anywhere else.
Deleting your data
Deleting the app deletes the record stored on your device. If iCloud sync was on, you can remove the synced copy from your iCloud account as described above. Because we hold no copy, there is nothing for us to delete on our side.
Children's privacy
Documented is made for adults documenting their own parenting. The app is not directed at children, and we do not collect personal information from anyone, including children. Information about your children that you record stays on your device, under your control.
The website
documented.co is a static marketing site. It is not the app, it never receives anything from the app, and none of what follows applies to your record.
Analytics and cookies
The website uses Google Analytics 4 so we can see which pages people find useful and which ones fail them. Here is exactly how it is configured:
- Cookies are off until you accept them. Analytics loads in Google's Consent Mode with storage denied by default. Until you press Accept on the banner, no analytics cookie is written and no visitor ID is kept; we receive an anonymous, aggregate page count and nothing that follows you between visits.
- If you accept, Google Analytics sets its standard cookies (
_gaand similar) so returning visits can be recognised as returning. You can change your mind by clearing this site's cookies and site data in your browser, which brings the banner back. - If you decline, that choice is remembered locally and the banner stays gone. Analytics continues in its cookieless mode.
- No advertising signals, ever. Google's ad-related signals (
ad_storage,ad_user_data,ad_personalization) are denied permanently and are never granted, even if you accept. We run no remarketing and no cross-site tracking pixels, and no advertising platform receives anything from this site. The one thing we record about advertising is the click identifier described under Landing pages, which we keep ourselves and never pass on. - What we measure. Pages viewed, roughly where in the world the visit came from, what kind of device it was, and clicks on the App Store buttons. Analytics never receives your name, your email address, or anything you type into a field. One thing to know about page addresses: if you start the Readiness Check from the homepage, your answer to its first question is carried in the address of the page you land on, so analytics records it as part of that address.
All of this lives in one auditable file, /assets/analytics.js, if you would rather read the code than take our word for it.
The Readiness Check
The Readiness Check at /readiness is a short quiz that produces a Readiness Score out of 100. Before it shows you that score, it asks for your email address. This is what happens to what you give it.
- What we keep. The email address you enter, your score and band, and the answers you gave: your situation, how many children you have, how parenting time is split, whether you have been in a dispute you could not prove, whether there is a court matter, whether you are working with an attorney, how you record things today, how confident you are that you could show a judge where your children were last month, what you want a record to cover, and whether you could spend two minutes a day on it. The date of a court matter is asked but not kept.
- Where it goes. To a server we run, and nowhere else. It is not handed to an advertising platform, a data broker, or a mailing list provider, and we do not sell it or trade it.
- What we use it for. Understanding which gaps parents actually have so we can write better guidance, and writing to you about Documented. Your score and report are worked out in your browser and shown to you either way, so keeping your email is not what produces them. If you would rather not hear from us, tell us at the address below and we will stop.
- Deleting it. Write to privacy@documented.co and we will delete your entry and the answers attached to it. You do not have to give a reason.
- Leaving part way through. Your answers are not sent to us until you submit your email. Close the page before that and we hold no record of them. Analytics still records which step you reached, and, if you came from the homepage, the first answer carried in the page address described above.
Attorney portal access requests
The attorney page at /attorneys carries a form for requesting access to the portal where an attorney reads a client's record. It is the only form on this site that asks for your name.
- What we keep. Your name, your firm, your email address, the jurisdiction you practise in, and roughly how many custody matters you carry.
- Where it goes. To a server we run, which emails the request to us so that a person can read it and reply. It is not passed to anyone else, and it is not sold.
- What it is for. Deciding whether to grant portal access, and getting in touch with you about it.
- Deleting it. Write to privacy@documented.co.
Landing pages
Some of our advertisements point to pages under /lp/ that offer a record-keeping kit by email. Those pages ask for your email address and nothing else about you.
- What we keep. The email address you enter, which page you entered it on, and the click identifier described below.
- The click identifier. When you arrive from an advertisement, the link carries an identifier the advertising platform uses to mark which ad was clicked. The page strips it out of the address before analytics loads, so it is never sent to Google, and keeps it with your email so we can tell which advertisements are worth running. We do not send it back to the advertising platform.
- Where it goes. To the same server that holds Readiness Check entries. It is not sold and not handed to a data broker.
- Deleting it. Write to privacy@documented.co.
Also worth knowing
- Hosting. The site is served by Vercel, whose infrastructure may keep short-lived technical logs (such as IP addresses) to deliver and secure the site, per Vercel's privacy policy.
- Fonts. Pages load typefaces from Google Fonts, which means your browser requests font files from Google's servers, per Google's privacy policy.
Purchases
If you purchase a subscription, the transaction is processed by Apple through the App Store. We receive no payment card details. Apple's handling of purchase data is described in Apple's privacy policy.
Changes to this policy
If we change this policy, we will post the updated version here with a new effective date. Because the app is local-first, changes that would ever send more data off your device would be called out prominently, not buried.
Contact
Questions about this policy or your privacy: privacy@documented.co.
Documented is not a law firm and does not provide legal advice. Records are tamper-evident, not tamper-proof.