Trust

Security

This page is maintained by PocketGrow to explain the security controls currently in place. It is not an independent certification or audit report. Customise with your security lead before publishing.

Accounts & access

  • Parent and carer accounts use email + password authentication.
  • Child and teen profiles are created and managed by the parent account.
  • Administrative tools live behind a separate, parent-only login.
  • Two-factor authentication and social login are on the roadmap — not enabled yet.

Data in transit & at rest

All connections to PocketGrow use HTTPS. Data is stored by our managed backend provider (Lovable Cloud) using their platform-level encryption at rest. You can read more about their infrastructure and security practices on their site.

Placeholder — confirm the provider name and link to their security page before publishing.

Children's data

We minimise what we collect from child profiles and never share them with advertising networks. Parents can delete a child profile at any time from the parent dashboard.

Subprocessors

PocketGrow uses a small set of third-party services to run the app, send emails, process payments and understand usage. Our current subprocessors include:

  • Hosting & database: Lovable Cloud / Supabase (backend, authentication, database).
  • Email: Resend or SendGrid (transactional email, parent invites).
  • Payments: Stripe (one-off purchases and subscription billing).
  • Analytics: PostHog or Plausible (product analytics, no advertising data).

Placeholder — confirm the exact services and contract details before publishing, and review the list quarterly.

Report a vulnerability

If you believe you've found a security issue in PocketGrow, please email us with details and steps to reproduce. We aim to acknowledge reports within two business days. Please don't access data that isn't yours, and give us a reasonable window to fix issues before public disclosure.

Contact the team