Coparenta · Privacy

Privacy Policy

Last updated: September 18, 2026

Citește în română →

This English version is a translation provided for your convenience. In case of any discrepancy, the Romanian version at coparenta.ro/privacy prevails as the legally binding text.

1. Who we are

Coparenta is an app for coordinating child custody and daily life between separated or divorced parents. Data Controller within the meaning of the General Data Protection Regulation (GDPR, EU Regulation 2016/679):

COPARENTA S.R.L. (formerly PACSUNA CARTIE S.R.L.), a limited liability company registered in Romania.
Trade Register no.: J2021003293220 · Unique registration code (CUI): 44983034 · Share capital: RON 200
Registered office: Str. Iazului nr. 17M, sat Horpaz, com. Miroslava, jud. Iași, Romania
Contact: contact@coparenta.ro

This policy explains in plain language what data we collect about you and the children in your family, why, with whom we share it, and what rights you have.

2. The data we collect

2.1 Data about parents (adult users)

  • Email — for authentication with a code sent to your email (passwordless)
  • Display name (which you choose)
  • Identification colour in the calendar
  • Preferences — time zone, quiet hours for notifications
  • Push notification tokens (anonymous device identifier) — to send you notifications
  • Payment details, if you choose to fill them in — IBAN and account holder name, or your Revolut username. They are optional and serve a single purpose: letting the other parent settle an expense. Coparenta does not initiate or process payments; the details are shown to the other parent in your family so they can copy them into their own banking app.

2.2 Data about children (GDPR-K data)

Data about children is entered by you, as the legally responsible parent. Coparenta does NOT collect data directly from children and does NOT allow children to register as users.

  • Child’s first name
  • Age or date of birth (your choice)
  • Optional avatar (child photo)
  • Journal notes — observations, moments and events you share with the other parent
  • Photos uploaded to the journal (of what happens in the child’s life)
  • The child’s routine, if you fill it in — wake, nap and bedtime, meal habits, foods to avoid, free-text notes
  • The child’s wishes, if you record them — a title, an optional note and who bought the item
  • The recorded residence — which parent it is registered with, and since when. When there are two parents in the family, changing it requires the other parent’s agreement.

2.3 The child’s health record (special category, Art. 9 GDPR)

This is sensitive data. The health record is optional — the app works fully without it. You fill it in yourself, as a parent, and only if you want the other parent (or someone you granted viewer access) to have it at hand while the child is with them. By filling it in you give your explicit consent to processing this data within the meaning of Art. 9(2)(a) GDPR. You can withdraw it at any time by deleting the contents of the record or your account.

  • Blood type
  • Allergies
  • Chronic conditions
  • Current medication
  • The doctor’s name and phone number
  • An emergency contact
  • Free-text notes about the child’s health

The health record is never sent to analytics services and is not part of the events in section 2.6. We do not use it for profiling, advertising or automated decisions.

2.4 Data about custody coordination

  • The custody schedule (the days the child is with each parent)
  • Swap requests between parents
  • Expenses + photo receipts + settlements
  • Child support, if you set it up — the payer, the recipient, the amount, the currency, the day of the month, and the payments you record as made
  • The conversation in the shared space — messages and the files attached to them: photos and documents (PDF, Word, Excel, text)

2.5 Automatic technical data

  • IP address (partially anonymised) — for security
  • App version + operating system
  • Errors and crash reports (anonymous)

2.6 Usage analytics (optional, off by default)

If you turn it on, the mobile app sends seven events that record ONLY that a step happened — never what it contained. This is not automatic collection: nothing is sent until you explicitly opt in. The full list of events, the identifiers involved and what is never sent are in section 4.4.

3. Why we collect this data (purpose and legal basis)

We process your data for the following purposes, based on the GDPR legal bases:

  • Providing the service (Art. 6(1)(b) GDPR — performance of a contract): schedule coordination, custody swaps, expenses, journal — everything that makes Coparenta work for you
  • Authentication and security (Art. 6(1)(f) GDPR — legitimate interest): the sign-in code, sessions, abuse prevention
  • Push notifications (Art. 6(1)(a) GDPR — explicit consent): only if you grant the notification permission on your device
  • Data about children (Art. 8 GDPR + Art. 6(1)(b)): with implicit parental consent through acceptance of the Coparenta terms. You, as a parent, hold legal responsibility for the data you enter about your child
  • The child’s health record (Art. 9(2)(a) GDPR — explicit consent, on top of the Art. 6 basis): this is special-category data. We do not ask for it and do not assume it — we process it only if you choose to fill the record in, and for a single purpose: making it available to the other parent or to the person you granted access. Deleting the contents of the record withdraws that consent
  • Settlement details (Art. 6(1)(b) GDPR — performance of a contract): your IBAN, account holder name or Revolut username, if you fill them in, so the other parent can send the money. We do not pass them to any payment processor; they do not leave your family
  • Product improvements (Art. 6(1)(f) GDPR — legitimate interest): anonymous crash reports to fix bugs
  • Product usage analytics (Art. 6(1)(a) GDPR — explicit consent): the seven events described in section 4.4, only if you turn the feature on. You can withdraw consent at any time, as easily as you gave it.

4. Who we share data with

Your data stays within Coparenta. We share it ONLY with:

4.1 The other parent in your family (within Coparenta)

Data about the schedule, swaps, expenses and child journal is shared AUTOMATICALLY with the other parent you share a family with in Coparenta — this is the purpose of the app.

4.2 Technical providers (sub-processors)

  • Supabase Inc. (USA, with EU servers in Frankfurt, Germany) — database and authentication. Data stored in the EU.
  • Vercel Inc. (USA) — hosting for the coparenta.ro website
  • Resend Inc. (USA) — sending transactional emails (the sign-in code)
  • Google Firebase Cloud Messaging (USA) — delivering push notifications on Android
  • Apple Push Notification Service (USA) — delivering push notifications on iOS
  • Expo Inc. (USA) — mobile app build infrastructure
  • Functional Software, Inc. (Sentry) (USA, with EU servers in Germany) — the error and crash reports mentioned in 2.4. Configured with no default personal data and no session tracking.

All non-EU sub-processors are contractually bound by Standard Contractual Clauses (SCC) approved by the European Commission.

4.3 AI processors (Anthropic, Google)

Coparenta offers two AI-based features: Weekly AI Summary (summarises the child’s journal notes) and Rewrite with AI (rephrases a message before you send it). Both send text to an external AI processor, ONLY to generate the summary or the rewrite — for no other purpose.

  • Processors: Anthropic and Google (Gemini API). Each feature has a primary processor and a backup, used automatically if the primary fails to process the request (technical error, unavailability, or an invalid response) — so content may reach either one, regardless of the exact reason for the failure.
  • Weekly AI Summary sends ONLY journal notes marked as shared AND for which you gave explicit consent — by default from Settings → AI Summary, or chosen individually per note. It sends the note’s text, the child’s name and age, and the note’s category (e.g. “school”, “activities”). Private notes never leave. Photos never leave.
  • Notes in the “Health” category NEVER enter the AI Summary, regardless of consent — they are technically excluded before reaching any processor. They remain normally visible to the other parent, as a regular journal note.
  • Rewrite with AI sends the message text ONLY when you explicitly choose to use the feature, at that moment — nothing is sent automatically.
  • You can change your preference for the AI Summary anytime from Settings → AI Summary.

Neither of these processors uses the content Coparenta sends to train their models — Anthropic does not train on data from its commercial API; Google does not train on data from the Gemini API for users in the European Economic Area (including Romania). The transfer to these processors (USA) is covered by the same Standard Contractual Clauses (SCC) mentioned above.

4.4 Product usage analytics (PostHog)

To see where people get stuck in the app, we can send a small number of events to PostHog. The feature is off by default: until you switch it on yourself, the app does not even start the analytics component and sends nothing at all.

  • Processor: PostHog, Inc. (USA), running on PostHog Cloud EU — servers in Frankfurt, Germany (the AWS eu-central-1 region). The events stay stored in the European Union; our relationship with PostHog, Inc. is covered by the same Standard Contractual Clauses (SCC).
  • Purpose: measuring the journey through the app and nothing else — how many people finish a step and where they stop. Not for advertising, commercial profiling or targeting.
  • The seven events, and no others: onboarding completed · family invitation sent · family invitation accepted · expense created · Expenses screen opened · Coordination guidelines screen opened · Resources for parents screen opened. Each one records only THAT the action happened.
  • What travels with an event: your internal account identifier and, where one exists, the family identifier — two system-generated codes (UUIDs), with no name, email or other profile field. We do not call them anonymous: on our side they remain linkable to your account, which is why we treat them as personal data and ask for your consent. Beyond that, only technical fields belonging to the analytics library travel along — its name and version, our public PostHog project key, and two internal processing flags.

What never leaves, even with analytics on: message content · journal note text · health notes and medical records · expense amounts, descriptions and receipts · photos · your name, email or any other profile field · addresses and location data. This is not a promise on trust: the app passes every event through a filter that keeps only the fields listed above and discards everything else before sending.

We have explicitly disabled, at configuration level: session replay · automatic error and exception capture · deriving location from the IP address (GeoIP) · automatic device and app properties (model, operating system, version) · automatic app lifecycle events · push-notification events · in-app surveys · feature flags.

How to give and withdraw consent: in the app, under Settings → Usage analytics. This consent is separate from the one for the AI Summary and the one for notifications — none of them inherits from another. You can turn the switch off at any time, in a single tap: from that moment the app sends no further events and shuts the analytics component down. Declining or withdrawing changes nothing about how the app works. If you want the events already sent deleted, write to us at contact@coparenta.ro.

4.5 Legal authorities

Only where we are required to by a valid court order in Romania or the EU.

We do NOT sell your data. We do NOT use it for advertising. We do NOT share it with data brokers.

This stays true after the introduction of usage analytics (section 4.4): those events serve only to understand how the app is used. Coparenta contains no advertising pixel, no ad network and no marketing attribution tool.

5. Where data is stored

Your data is stored on Supabase servers in Frankfurt, Germany (the AWS eu-central-1 region) — within the European Union.

Usage analytics events, if you have turned the feature on, are stored separately on PostHog Cloud EU — also in Frankfurt, Germany (AWS eu-central-1). Error reports go to Sentry’s EU region, in Germany.

International transfers (to the USA for email, push and hosting) are made ONLY with GDPR safeguards (Standard Contractual Clauses). Supabase, PostHog and Sentry are US companies that keep Coparenta’s data on EU servers — our relationship with each is governed by those same clauses.

6. How long we keep data

  • Active account — for as long as you use Coparenta
  • After account deletion Your account, email, profile, IBAN, and notification tokens are deleted. Notifications from Coparenta stop. Journal notes marked private are deleted. Files are deleted in a separate step: we try, but if we can't, a file can remain on the server. This can't be undone. Database backups are kept for 7 days, then they expire. They hold only the database, not the photos or documents.
  • What stays in the shared space: the schedule, holidays, vacations, handoffs, expenses, shared journal, wishes, health record, the child's routine, events, child support, the conversation (with the photos and documents sent in it), and the reminders you shared. Your days, shared notes, expenses, and events stay under your first name. Some open requests can stay open for the other parent. If you're the last remaining member, the shared space is deleted too.
  • Audit log (actions)The action log stays as long as the shared space exists and is deleted together with it. We don't delete it after a fixed number of days.
  • Usage analytics events — stop the moment you withdraw consent. Those already sent stay with PostHog; you can ask us to delete them by writing to contact@coparenta.ro.
  • Legal documents (settled expenses, custody decisions) — may be kept for up to 5 years in accordance with Romanian tax legislation, to allow export where needed

7. Security

  • HTTPS / TLS 1.3 connection for all data in transit
  • Supabase database with Row Level Security (RLS) — each family sees ONLY its own data
  • Children’s avatars — signed URLs expiring in 15 minutes (private bucket)
  • Passwordless authentication — a one-time code sent by email, valid for 10 minutes (security through possession of the email address)
  • Immutable audit log for critical actions
  • For security bugs, contact us at contact@coparenta.ro

8. Your rights (GDPR)

You have the right to:

  • Access — to receive a copy of your data
  • Rectification — to correct inaccurate data
  • Erasure (“the right to be forgotten”) — to delete your account and the associated data
  • Portability — to receive your data in a structured format (JSON / CSV)
  • Objection — to object to processing based on legitimate interest
  • Restriction — to temporarily restrict processing
  • Withdrawal of consent — for push notifications, for the AI Summary and for usage analytics. Each has its own switch in Settings and is independent of the others. Withdrawing is as easy as consenting, and does not affect the lawfulness of processing carried out beforehand.
  • Complaint to the National Supervisory Authority for Personal Data Processing (ANSPDCP): dataprotection.ro

To exercise any of these rights, write to contact@coparenta.ro. We respond within a maximum of 30 days.

9. Cookies

The coparenta.ro website uses ONLY strictly necessary cookies (Vercel hosting session). There are no tracking, analytics or advertising cookies on the website — no analytics code runs in these pages. The usage analytics described in 4.4 exist only in the mobile app.

The mobile app does NOT use cookies (data is stored locally on the device). If you turn usage analytics on, the app keeps a local technical identifier for that feature. It never leaves the device except alongside the seven events, and it stops being used the moment you withdraw consent.

10. Children under 16

Coparenta is NOT intended for children. The minimum age to be a user (parent) is 18.

Data about children is entered by parents, as legal representatives. Under Art. 8 GDPR, parental consent is required for children under 16 — this is implicit through the fact that you, as a parent, are the one who decides what data you enter about your child.

If you are the other parent and believe the shared child’s data is being processed without your consent, contact us at contact@coparenta.ro and we will resolve the situation within a maximum of 7 days.

11. Changes to this policy

We will announce significant changes by email and via in-app notification. The current version is marked with the date above.

Version history: 28 May 2026 — first public version (beta) · July 20, 2026 — added disclosure for AI processors (Anthropic, Google) used by the Weekly AI Summary and Rewrite with AI, with the exact data sent and guarantees on model training (no-training) and SCC · August 25, 2026 — added disclosure for usage analytics in the mobile app (PostHog Cloud EU): the analytics events, the identifiers involved, the list of what is never sent, the legal basis (explicit consent) and how to withdraw it; added Sentry to the sub-processor list, for the error reports already mentioned in 2.4; clarified that each consent (push, AI Summary, analytics) is withdrawn separately · September 2, 2026 — analytics event list aligned with the app registry (seven, without a check-in event); account-deletion policy aligned with the tombstone (what stays in the shared space, under the first name); removed the mention of a custody-papers feature the app does not provide; APNs is no longer marked as forthcoming · September 8, 2026 — declared the categories of data the app actually stores that were missing from “what we collect”: the child’s health record, in a section of its own (2.3), because it is special-category data within the meaning of Art. 9 GDPR; the routine, the wishes and the recorded residence; child support; the IBAN and settlement details. Added the missing legal bases — Art. 9(2)(a) for the health record and Art. 6(1)(b) for the settlement details · September 18, 2026 — the data controller becomes COPARENTA S.R.L. (formerly PACSUNA CARTIE S.R.L.), replacing the app's founder; the company's identification details are in section 1.

12. Contact

Questions, GDPR requests, suggestions?

contact@coparenta.ro

We respond in Romanian or English, within a maximum of 7 business days.