Privacy policy.
Effective date: September 4, 2026
Your record lives on your device. The app has no accounts and nothing to sign into. Two things leave your phone on their own. One is an anonymous cryptographic fingerprint (a hash) used to prove when an entry was sealed, and a hash cannot be reversed into your content. The other is a count of which screens you use, which you can switch off in Settings. Neither carries a word you have written.
There is one feature that does send your entries to us, and you have to switch it on: sharing with your attorney. When you do, entries and attachments are encrypted on your phone before they are sent, to a key only your attorney holds. We store them and we cannot read them. Turn it on and we hold an unreadable copy; leave it off and we hold nothing at all.
The iPhone app measures subscriptions, counts which screens get used, and, only if you allow it when iOS asks, records which ad brought you here: see Advertising and measurement. The Android app has none of that, but reading text from a screenshot sends Google some technical diagnostics we cannot switch off: see Reading text from screenshots.
This marketing website is a separate thing, and it does use Google Analytics, with cookies off until you say otherwise. It also has three places that ask you for something: the Readiness Check quiz, which wants your email before it shows you your score and keeps your answers alongside it; the attorney access form; and the landing pages our advertisements point to. Details in The website below. Nothing the website measures touches the app or your record.
If someone comes to us with a subpoena, what we can hand over is limited to what we hold, which is nothing at all unless you switched on attorney sharing, and ciphertext if you did. That is a separate question from what you yourself can be required to produce in your own case, and the two get confused constantly. Both are answered in Legal process, subpoenas, and discovery.
Who we are
Documented ("we", "us") makes the Documented apps for iPhone and Android, and operates the documented.co website. This policy explains what information the apps and the website handle, and (mostly) what they deliberately don't.
Where the two apps differ, this policy says so. Most of it is the same on both.
The app
Your entries stay on your device
Everything you log in Documented (text, photos, video, voice recordings, receipts, message-thread captures, and the details of your entries) is stored locally on your phone. By default it stays there. We do not receive it, and there is nothing for us to read.
There is exactly one way your entries leave your device to us, and you have to turn it on yourself: sharing with your attorney. Until you connect an attorney, nothing you write is uploaded anywhere. If you never connect one, that stays true for as long as you use the app.
No account, no sign-up
Documented does not require an account. We do not collect your name, email address, phone number, or any other identifier to use the app.
Advertising and measurement (iPhone only)
The Android app has none of the four services described here. It carries no analytics SDK, no crash reporter, no advertising identifier and no attribution SDK. What it does carry is described under reading text from screenshots below.
The iPhone app uses four third-party services. RevenueCat records subscription events, such as a trial starting or a subscription renewing or being cancelled, so we can see how the business is doing. Meta receives those same subscription events, and, if you allow tracking when iOS asks you, an advertising identifier, so we can tell which ads bring parents to Documented. AppsFlyer counts installs, trials and subscriptions and records which ad brought each one, so we can compare one advertising channel against another on the same terms instead of taking each network's word for its own performance. It tells the network that delivered the ad that an install happened, and nothing more than that. Amplitude counts which screens get used and which steps people give up on, so we can find the parts that do not work and fix them.
None of the four receives your entries, your photos, your voice notes, your locations, or your children's names. Nothing you write in the app is part of this, and nothing you write leaves your phone.
If you decline the tracking request, no advertising identifier is collected and nothing is linked to you. Meta then receives nothing at all. RevenueCat and AppsFlyer still record that an install, a trial or a subscription happened, because that is how we count them, but with no identifier attached and nothing that points back to you. You can change your mind at any time in iOS Settings, under Privacy & Security, then Tracking.
That tracking request does not govern Amplitude, in either direction. Amplitude receives no advertising identifier and no IP address. What it does receive is linked to your subscription events from RevenueCat, so we can tell whether the people who find the app useful are the people who subscribe. That link is the only one: nothing here is combined with data from outside those two services, sold, or used to target advertising at you. Allowing or declining Apple's prompt neither switches it on nor switches it off. It is on from the start, we say so during setup, and it has its own switch: in the app, under Settings, then Privacy, then Product analytics.
Our App Store privacy label is "Data Used to Track You." Apple requires that label whenever an app may share an advertising identifier with a third party, and it applies whether or not you personally allow it.
This is a statement about the app. The documented.co website is measured separately and is described below. The two share nothing.
Reading text from screenshots (Android)
Both apps can turn a screenshot of a message conversation into an entry by reading the text in it. The reading happens on your phone. The screenshot is never uploaded for this, and no server sees it.
On Android this uses Google's ML Kit. The recognition itself is offline, but the component reports technical diagnostics to Google: your device make, model and Android version, the app's package name and version, how long the operation took, and the size and format of the image. It does not send the image, the text found in it, or anything you have written.
We would switch that reporting off if we could. Google provides no way to disable it for text recognition, so the honest position is to tell you it happens rather than to imply it does not. It is declared on our Google Play listing as diagnostics and a per-installation identifier.
iCloud sync (iPhone only)
If iCloud is enabled on your device, your record syncs automatically to your private iCloud database so it survives a lost or replaced phone. This sync happens between your device and your own Apple iCloud account, under Apple's iCloud terms and encryption. We have no access to your iCloud data. You can turn iCloud off for Documented at any time in iOS Settings, and you can remove the app's iCloud data in Settings → Apple ID → iCloud → Manage Storage.
The Android app has no sync and no cloud backup. It also excludes itself from Android's own backup, so nothing is copied to Google Drive. Your record lives on that phone and nowhere else, which is the more private arrangement and also the more fragile one: if you lose the phone, the record goes with it unless you have attorney sharing switched on.
Trusted timestamps (the one thing that leaves your phone)
When you seal an entry, the app computes a SHA-256 hash of it (a fixed-length cryptographic fingerprint) and sends only that hash to an independent RFC-3161 timestamp authority, which returns a signed proof of the time. The hash contains none of your content and cannot be reversed into it. The timestamp authority never receives your entries, media, location, or identity beyond the technical minimum any internet request involves (such as an IP address handled per that provider's own policy).
Location
On iPhone, adding a location to an entry is optional. If you grant location permission, the coordinates are attached to the entry on your device. You can decline or revoke the permission at any time; the app works fully without it.
The Android app does not do this at all. It asks for no location permission of any kind and cannot determine where you are.
One thing worth knowing on both: a photo you attach may carry coordinates of its own, in the metadata your camera writes into the file. We do not read or use that metadata, but we also do not strip it, because on a record of a handover the place a photo was taken can be the point of it. If a photo reaches your attorney through sharing, any metadata inside it goes too. Your phone's camera settings control whether that metadata is written in the first place.
The app lock
The lock uses your phone's own authentication: Face ID or Touch ID on iPhone, fingerprint or face unlock on Android, with your device passcode as the fallback. Biometric data is managed entirely by the operating system and never reaches us or the app itself. We never see it and cannot access it.
Exports are yours to control
When you export a PDF, you decide where it goes. The app hands it to your phone's share sheet and keeps no copy anywhere else. We never see an export.
Sharing with your attorney
This is the one feature that sends your entries to our servers, and it is off until you switch it on.
To connect an attorney you type their email address, which we use to look them up in the attorney directory. From then on, each entry you seal is encrypted on your phone before it is sent, using a key derived to that attorney's own public key. Attachments travel the same way. What arrives on our server is ciphertext, and only your attorney holds the key that opens it.
So we do hold a copy of shared entries, and we cannot read it. Those are two separate facts and both matter: the first is why there is something for us to delete if you ask, and the second is why a breach of our servers would not expose what you wrote.
You can disconnect an attorney at any time in the app's settings. Disconnecting stops anything further being sent. It does not by itself remove what was already delivered to them; see below.
Deleting your data
There is no account to close, because there isn't one. What deletion means depends on where the data is.
- On your phone. Deleting the app deletes the record stored on it. On Android nothing is backed up to Google Drive, so uninstalling removes it outright. On iPhone, if iCloud sync was on, remove the synced copy from your own iCloud account as described above.
- Anything shared with an attorney. Disconnect the attorney in the app to stop anything further being sent. To have what was already uploaded deleted from our servers, write to privacy@documented.co and we will remove it. You do not have to give a reason. We will confirm when it is done.
- If you never turned on attorney sharing, we hold nothing, and there is nothing on our side to delete.
Children's privacy
Documented is made for adults documenting their own parenting. The app is not directed at children, and we do not collect personal information from anyone, including children. Information about your children that you record stays on your device unless you choose to share it with your attorney, in which case it travels encrypted and only they can read it.
The website
documented.co is a static marketing site. It is not the app, it never receives anything from the app, and none of what follows applies to your record.
Analytics and cookies
The website uses Google Analytics 4 so we can see which pages people find useful and which ones fail them. Here is exactly how it is configured:
- Cookies are off until you accept them. Analytics loads in Google's Consent Mode with storage denied by default. Until you press Accept on the banner, no analytics cookie is written and no visitor ID is kept; we receive an anonymous, aggregate page count and nothing that follows you between visits.
- If you accept, Google Analytics sets its standard cookies (
_gaand similar) so returning visits can be recognised as returning. You can change your mind by clearing this site's cookies and site data in your browser, which brings the banner back. - If you decline, that choice is remembered locally and the banner stays gone. Analytics continues in its cookieless mode.
- No advertising signals, ever. Google's ad-related signals (
ad_storage,ad_user_data,ad_personalization) are denied permanently and are never granted, even if you accept. We run no remarketing and no cross-site tracking pixels, and no advertising platform receives anything from this site. The one thing we record about advertising is the click identifier described under Landing pages, which we keep ourselves and never pass on. - What we measure. Pages viewed, roughly where in the world the visit came from, what kind of device it was, and clicks on the App Store buttons. Analytics never receives your name, your email address, or anything you type into a field. One thing to know about page addresses: if you start the Readiness Check from the homepage, your answer to its first question is carried in the address of the page you land on, so analytics records it as part of that address.
All of this lives in one auditable file, /assets/analytics.js, if you would rather read the code than take our word for it.
The Readiness Check
The Readiness Check at /readiness is a short quiz that produces a Readiness Score out of 100. Before it shows you that score, it asks for your email address. This is what happens to what you give it.
- What we keep. The email address you enter, your score and band, and the answers you gave: your situation, how many children you have, how parenting time is split, whether you have been in a dispute you could not prove, whether there is a court matter, whether you are working with an attorney, how you record things today, how confident you are that you could show a judge where your children were last month, what you want a record to cover, and whether you could spend two minutes a day on it. The date of a court matter is asked but not kept.
- Where it goes. To a server we run, and nowhere else. It is not handed to an advertising platform, a data broker, or a mailing list provider, and we do not sell it or trade it.
- What we use it for. Understanding which gaps parents actually have so we can write better guidance, and writing to you about Documented. Your score and report are worked out in your browser and shown to you either way, so keeping your email is not what produces them. If you would rather not hear from us, tell us at the address below and we will stop.
- Deleting it. Write to privacy@documented.co and we will delete your entry and the answers attached to it. You do not have to give a reason.
- Leaving part way through. Your answers are not sent to us until you submit your email. Close the page before that and we hold no record of them. Analytics still records which step you reached, and, if you came from the homepage, the first answer carried in the page address described above.
Attorney portal access requests
The attorney page at /attorneys carries a form for requesting access to the portal where an attorney reads a client's record. It is the only form on this site that asks for your name.
- What we keep. Your name, your firm, your email address, the jurisdiction you practise in, and roughly how many custody matters you carry.
- Where it goes. To a server we run, which emails the request to us so that a person can read it and reply. It is not passed to anyone else, and it is not sold.
- What it is for. Deciding whether to grant portal access, and getting in touch with you about it.
- Deleting it. Write to privacy@documented.co.
Landing pages
Some of our advertisements point to pages under /lp/ that offer a record-keeping kit by email. Those pages ask for your email address and nothing else about you.
- What we keep. The email address you enter, which page you entered it on, and the click identifier described below.
- The click identifier. When you arrive from an advertisement, the link carries an identifier the advertising platform uses to mark which ad was clicked. The page strips it out of the address before analytics loads, so it is never sent to Google, and keeps it with your email so we can tell which advertisements are worth running. We do not send it back to the advertising platform.
- Where it goes. To the same server that holds Readiness Check entries. It is not sold and not handed to a data broker.
- Deleting it. Write to privacy@documented.co.
Also worth knowing
- Hosting. The site is served by Vercel, whose infrastructure may keep short-lived technical logs (such as IP addresses) to deliver and secure the site, per Vercel's privacy policy.
- Fonts. Pages load typefaces from Google Fonts, which means your browser requests font files from Google's servers, per Google's privacy policy.
Legal process, subpoenas, and discovery
Two different things get called "a subpoena for my notes", and they have opposite answers. This section separates them, because the difference decides what is actually at stake.
If someone serves us
We respond to valid legal process only, we read what is asked for, and we object to requests that are overbroad or that reach beyond what the process authorises. What we are able to hand over is limited by what we hold, which is very little by design:
- There is no account, so there is nobody to look up. We do not collect your name, email address or phone number to use the app, and we hold no user directory to search.
- If you never turned on attorney sharing, we hold nothing. Not your entries, not your media, not a record that you use the app. A demand for it returns nothing, because there is nothing.
- If you did turn it on, we hold ciphertext. Entries and attachments are encrypted on your phone to your attorney's own public key before they are sent. We can produce the encrypted bytes and nothing else, because we hold no key that opens them.
- The timestamp authority holds fingerprints, not content. Sealing sends a SHA-256 hash, which cannot be reversed into the entry it came from.
- iCloud is Apple's. If you use iCloud sync, that copy sits in your own Apple account under Apple's terms, and any demand for it is a matter between the requesting party and Apple, not us.
- The website is separate. If you gave us an email address through the Readiness Check, an attorney access request, or a landing page, that is what we hold about you and it is described above. It has no connection to your record.
Where process reaches something we actually hold, we will notify the person affected before we respond, so that they have the opportunity to object, unless the law or a court order forbids us from telling them.
If you are asked for your own record
This is the part no privacy policy can help with, so we would rather say it plainly than leave you to discover it later. If you are a party to a case, the other side can require you to produce relevant records that are in your possession or control, and a record of your own parenting is usually relevant. That request is served on you, not on us. Keeping the record on your device protects it from a breach, from a third party, and from us. It does not change what you may be required to hand over yourself, and encryption is not a legal privilege.
Our guide on whether a custody journal is discoverable explains how this works, when attorney-client privilege and work product can apply, and why deleting entries once a case is live is usually the most damaging thing a person can do. It is general information rather than legal advice. Documented is not a law firm, and questions about your own case belong with an attorney licensed where the case is.
Purchases
If you purchase a subscription, the transaction is processed by the store you bought it from: Apple through the App Store, or Google through Google Play. We receive no payment card details from either. Their handling of purchase data is described in Apple's and Google's own privacy policies.
Changes to this policy
If we change this policy, we will post the updated version here with a new effective date. Changes that would send more data off your device get called out prominently, not buried.
Contact
Questions about this policy or your privacy: privacy@documented.co.
Documented is not a law firm and does not provide legal advice. Records are tamper-evident, not tamper-proof.