Denly · Version 1.3 · Effective September 3, 2026
Denly Privacy Policy
How GuildStack Labs collects, uses, and protects your family's data in the Denly app — and the privacy philosophy behind it.
Version 1.3 · Effective: September 3, 2026
This Privacy Policy describes how GuildStack Labs LLC (“we,” “us,” “our”) collects, uses, and discloses your personal information when you use our mobile application, Denly (the “Service”).
Denly is a co-parenting coordination app designed to help separated parents manage shared expenses, calendars, and documents. We believe your family’s data belongs to you, not us.
Where Denly is offered. Denly is currently available only to residents of the United States, and your data is stored and processed in the United States. Denly is not directed to, or intended for, users in the European Union, the European Economic Area, the United Kingdom, Canada, or other jurisdictions. If we expand Denly to other regions, we will update this policy — including the additional rights and cross-border transfer protections that apply there — before doing so.
1. Our Privacy Philosophy
- You own your data. We don’t sell it. We don’t mine it for advertising.
- Privacy by design. We collect only what is necessary to provide the service.
- Transparency. We tell you exactly what we collect and why.
- Security. We use industry-standard encryption to protect your family’s sensitive information.
2. Information We Collect
A. Information You Provide
When you create an account or use Denly, you provide us with:
-
Account Information: Email address and display name. You sign in with Sign in with Apple or Sign in with Google (OAuth) — Denly does not create or store a password for you, so there is no password for us to lose.
-
Profile Information: Your name and avatar image.
-
Den Data:
- Children’s profiles: Names, birthdates, and other details you choose to add.
- Calendar events: Titles, dates, times, locations, and descriptions.
- Expenses: Amounts, categories, descriptions, receipts (images/PDFs), and settlement status.
- Documents: Files you upload to the shared vault, including any you save to a child’s Medical folder (see “Health information” below).
- Messages: The message thread between Den members. Messages are permanent by design — once sent, a message cannot be edited or deleted, and it remains part of the Den’s record until the Den is deleted (see Section 7). Health information. Denly has no dedicated health fields. The one place designed to hold health information is a child’s Medical folder in the vault (records, prescriptions, insurance cards). Saving documents there is optional and turned off until you give explicit, opt-in consent, separate from your acceptance of these terms; each parent confirms for their own account. You can withdraw that consent at any time in Settings > Privacy — withdrawal stops new saves and edits in the Medical folder but does not delete what is already stored; to remove existing documents, delete them from the folder. Health details can also appear in free-text you write elsewhere — a calendar event, an expense description, a message. That content is not scanned and is not gated by the health consent; it is handled like any other Den data.
-
Payment Information: We do not store credit card details. Subscriptions are purchased through Apple’s App Store (In-App Purchase), using the Apple ID signed in on your device. Apple receives the purchase and a randomly generated identifier for your Den — not your name or email. We receive back transaction identifiers, the product purchased, purchase and renewal dates, price, and the App Store storefront. We never receive your card details, name, or email through this flow. See Apple’s privacy policy at https://www.apple.com/legal/privacy/ for how Apple handles payment data.
B. Information Collected Automatically
- Device Information: Device model, operating system version, and unique device identifiers (for push notifications).
- Log Data: IP address, access times, and app crashes (for debugging and security).
- Usage Data: Analytics are off by default. Only if you turn them on (Settings > Privacy > Analytics; see Section 12) do we collect anonymous statistics about how you use the app (e.g., “created an event”) to help us improve features.
C. Hardship Exemption Requests
If you request a hardship exemption through the form on our Transparency page, we collect the email address you provide and the short description of your situation you choose to share. We use this only to review and administer your waiver and to contact you about it (including renewal). We do not require or ask for income documentation or other proof, and we do not use this information for any other purpose. We retain hardship requests for as long as a related waiver is active and for up to 24 months after it lapses so we can administer renewals, after which they are deleted.
3. How We Use Your Information
We use your information solely to:
- Provide, operate, and maintain the Service
- Facilitate coordination between co-parents (sharing events, expenses, etc.)
- Send you technical notices, updates, and security alerts
- Respond to your comments and customer support requests
- Detect, prevent, and address technical issues and fraud
We do NOT use your data for:
- Targeted advertising
- Training artificial intelligence models
- Selling to data brokers
4. How We Share Your Information
With Your Co-Parent and Den Members
When you join a Den, data is shared with other Den members based on their role. You control who joins your Den through invite codes.
| Role | What they can see |
|---|---|
| Co-parents | Everything — calendar events, expenses, settlements, documents (including the Medical folder), children’s profiles |
| Guests (grandparents, nannies) | Calendar events, plus children’s names and birthdays so the schedule makes sense. Guests cannot see messages, expenses, settlements, or documents (including the Medical folder) |
| Counsel (attorneys, mediators, therapists) | Read-only access to everything. Counsel cannot create or change anything |
All Den members can see each other’s display name, email address, and avatar. These role limits are enforced by our servers — not just by the app’s interface — so they hold even outside the app.
Legal Process and Government Requests
Because Denly is used to coordinate co-parenting — and sometimes to keep records that end up in family-law disputes — we may receive subpoenas, court orders, or other legal demands for user data. How we handle them:
- We require valid legal process. We disclose personal data to law enforcement, courts, or other parties only when we are compelled by a subpoena, warrant, court order, or other legal process that we reasonably believe to be valid, or where disclosure is otherwise permitted or required by law (for example, to address an imminent risk of serious harm).
- We tell you where we can. Where we are legally permitted to do so, we will make reasonable efforts to notify the affected user before disclosing their data, so they have an opportunity to object — unless a law or court order prohibits notice, or we believe notice would create a risk of harm.
- What we can and cannot produce. We can only produce data we actually hold, in the form we hold it. Some records are stored in ways that limit what we can retrieve — for example, we never hold your Apple or Google sign-in credentials (authentication is handled by them, not us), and content that has passed our retention and deletion periods (Section 7) no longer exists to produce. We do not decrypt, reconstruct, or fabricate data we do not have.
- We do not volunteer your data. We do not proactively share user data with government agencies, and we do not sell data to anyone.
If you are involved in a legal matter and need your own records, you can export them yourself from within the app (Section 8) — you do not need a subpoena to obtain your own data.
5. Third-Party Service Providers
We use a small number of infrastructure providers to operate Denly. Each is bound by data processing agreements and receives only the data necessary for their function.
| Provider | Purpose | Data They Receive |
|---|---|---|
| Supabase (Supabase Inc.) | Database, authentication, file storage, serverless functions — hosted in the United States | All application data, encrypted at rest (AES-256) and in transit (TLS) |
| Apple (App Store) | Subscription purchases, via In-App Purchase | The purchase and a randomly generated identifier for your Den (not your name or email). We receive back transaction identifiers, the product purchased, dates, price, and storefront from Apple; we never receive your card details |
| PostHog (PostHog Inc.) | Product analytics, only when you have enabled analytics (see Section 12) | Anonymous product-usage and subscription-funnel events tied to a pseudonymous identifier. We do not put your name, email, children’s data, or other personal content in analytics events |
| Apple / Google (OAuth sign-in) | “Sign in with Apple” and “Sign in with Google” — authentication | Confirms your identity and returns your email and name. Because sign-in is OAuth-only, we never receive or store a password |
| Apple (APNs) / Google Firebase (FCM) | iOS and Android push notifications | Device tokens and notification content (which may include event or expense titles) |
| Timestamping authorities (e.g., FreeTSA, DigiCert) | Independent, once-daily timestamping of record integrity | Only a cryptographic hash — a one-way fingerprint of record history. They never receive your content, personal information, or any data that can be turned back into your records |
| Expo (650 Industries, Inc.) | App updates — each time the app launches, it checks Expo’s update service for a newer version of our app code | The app’s project identifier, version information, and platform. Expo’s servers see your device’s IP address as part of serving the request. No account data or content is sent, and these requests are not linked to your identity |
| GitHub (GitHub, Inc.) | Encrypted database backups for disaster recovery | A periodic backup of our database, encrypted before upload with a key only we hold. GitHub stores the encrypted file for up to 90 days and cannot read its contents |
Note: Fonts are self-hosted within the app. No requests are made to external servers for font loading.
Supabase uses sub-processors including Amazon Web Services (AWS) and Google Cloud Platform. Their data handling is governed by Supabase’s Data Processing Agreement.
We do not share your data with any other third parties.
6. Where Your Data Is Stored
Your data is stored on Supabase infrastructure in the United States, and Denly is offered only to residents of the United States. Supabase maintains SOC 2 Type II compliance, and our infrastructure providers are bound by data processing agreements.
Because we offer Denly only in the United States, we do not currently transfer your data to the EU/EEA, UK, or Canada, and we do not rely on international transfer mechanisms such as Standard Contractual Clauses. If we expand Denly to other regions, we will update this policy to describe the applicable cross-border transfer protections before doing so.
7. Data Retention
- Active accounts: Your data is retained for as long as your account is active.
- Den closure: When a Den is closed, all data scoped to that Den — calendar events, expenses and settlements, uploaded documents and files, and logs scoped to that Den — enters a 30-day grace period and is then permanently and irreversibly deleted. If you need your records, export them (Section 8) before closing the Den.
- Account deletion: When you delete your account, your profile is soft-deleted and your personal references on shared data (expenses, events, documents) are anonymized (set to NULL). After a 30-day grace period, your profile is permanently and irreversibly deleted.
- Shared Den data: Events, expenses, documents, and messages you contributed to a Den remain for other members after you leave or delete your account, but your name is removed (anonymized). Children’s profiles remain with the other co-parent as well — they are shared Den records about the children, not either parent’s personal profile. This is because your co-parent’s records belong to them too.
- Messages: The message log is immutable by design. Individual messages cannot be edited or deleted, and they are retained until the Den is deleted. Hiding a message from your own view does not remove it from the Den’s record or from data exports.
- Confirmed settlements: Settlement records that have been confirmed by both parties are immutable by design. They cannot be modified or deleted and are retained until the Den is deleted.
- Audit logs: Retained for security and accountability. The Den reference is removed when a Den is deleted, but the log entries are preserved.
- Soft-deleted data: A weekly automated process permanently deletes soft-deleted records (Dens, profiles, events) after 30 days.
- Encrypted backups: We keep encrypted backups of our database for up to 90 days for disaster recovery (see Section 5). Data deleted from our live systems may persist inside these encrypted backups until they age out, after which it is gone from backups too. Backups are used only to recover from system failure — we do not restore them to resurrect individually deleted data.
8. Your Rights
All Users
You can exercise these rights directly within the app, no email required:
- Access your data: Settings > Privacy > Download My Data (exports a ZIP containing your data as JSON records, your uploaded files exactly as you uploaded them — including any metadata embedded in photos, such as location (EXIF) data — and the integrity-verification materials for your Den’s records)
- Correct your data: Settings > Personal Info (edit your name and profile)
- Delete your account: Settings > Privacy > Delete My Account (requires re-confirming your identity through Sign in with Apple or Google). If you can no longer access the app, you can also request deletion by emailing [email protected].
- Control analytics: Settings > Privacy > Analytics toggle (off by default for new accounts)
Where you have contributed data to a shared Den, or to a settlement both parties have confirmed, deleting your account removes your personal references but does not erase the underlying shared record — those records are anonymized rather than deleted, as described in Section 7 (Data Retention).
California Residents (CCPA/CPRA)
- Right to know what personal information we collect, use, and disclose
- Right to delete your personal information
- Right to correct inaccurate personal information
- Right to opt-out of the sale of personal information — We do NOT sell or share personal information for cross-context behavioral advertising, so there is nothing to opt out of.
- Right to non-discrimination — We will not treat you differently for exercising your privacy rights.
Nebraska Residents (Nebraska Data Privacy Act)
- Right to access — Confirm whether we process your personal data and request a copy
- Right to correct inaccurate personal data
- Right to delete personal data you have provided or that we have collected about you
- Right to data portability — Receive your data in a portable format
- Right to opt-out of the sale of personal data — We do not sell personal data, so there is nothing to opt out of
- Sensitive data consent — We store documents in a child’s Medical folder only with your explicit consent, which you may withdraw at any time (see Section 2, “Health information”)
To exercise these rights, use the in-app tools in Settings > Privacy or email [email protected].
Appealing Our Decision
If we’re unable to fulfill a privacy request, we’ll explain why in writing. You can appeal our decision by emailing [email protected] with the subject line “Privacy Appeal.” We’ll respond within 30 days. If you’re still not satisfied after our appeal response, you may contact the Nebraska Attorney General’s office or your own state’s attorney general.
9. Consumer Health Data (Washington, Nevada & Similar State Laws)
If you are a resident of Washington, Nevada, or another state with a consumer health data law, this section serves as our Consumer Health Data Privacy Policy and applies to “consumer health data” as those laws define it.
Categories of consumer health data we collect. Documents you choose to save to a child’s Medical folder in the Info vault — such as medical records, prescriptions, and insurance cards. Denly has no structured health fields. Health-related details may also appear incidentally in free-text you write elsewhere (calendar events, expense descriptions, messages); that content is not scanned, is not separately gated, and is handled like any other Den data.
How we collect it. We collect this data only when you, the account holder, enter or upload it. We do not buy it and we do not collect it from outside sources.
Why we collect it and how we use it. Solely to provide the Denly co-parenting service, so that you and the people you authorize can coordinate your children’s care. We do not use it for advertising and we do not use it to train AI models.
How it is shared. Consumer health data is shared only with the Den members you authorize, according to their role (see Section 4), and with the infrastructure providers that store and process it on our behalf (see Section 5). We do not sell consumer health data, and we do not share it for targeted advertising.
Consent. The Medical folder stays closed until you give affirmative, opt-in consent that is separate from your acceptance of our Terms; each parent consents for their own account. We share this data only as needed to provide the service at your direction. You can withdraw consent at any time in Settings > Privacy. Withdrawal stops new saves and edits to the Medical folder; it does not delete documents already stored (delete those from the folder) and does not affect processing that already took place.
Your rights. You may (1) confirm whether we collect, share, or sell your consumer health data and access that data; (2) withdraw your consent; and (3) have your consumer health data deleted. To exercise these rights, use the in-app tools or email [email protected]. We will respond within 45 days (extendable once where the law allows), and you may appeal a denial as described under “Appealing Our Decision” above. Because some shared and confirmed-settlement records are anonymized rather than erased (see Section 7), a deletion request removes your personal health data and your personal references, but anonymized records may remain.
No sale. We do not sell consumer health data and do not seek authorization to do so.
10. Children’s Privacy
Denly is for adults only. You must be at least 18 years old to create an account.
Children do not create accounts, do not interact with the service, and do not provide their own personal information. All data about children is entered by their parents or legal guardians who are the account holders.
We do NOT knowingly collect personal information from children under 13 (or under 16 in jurisdictions where applicable). Parents control all children’s data within the app and can modify or delete it at any time.
If you believe a child under 13 has created a Denly account without parental consent, please contact us immediately at [email protected] and we will delete the account.
11. Security
We take the security of your family’s data seriously. Here’s how we protect it:
- Encryption in transit: All data is transmitted over TLS (HTTPS)
- Encryption at rest: All stored data is encrypted using AES-256 via Supabase
- Row Level Security (RLS): Database-level policies ensure complete data isolation between Dens — one family cannot access another family’s data
- Audit logging: Significant actions within a Den are logged for accountability
- Rate limiting: Authentication attempts and invite code entries are rate-limited to prevent brute-force attacks
- File validation: Uploaded files are validated using magic-byte signature checking to prevent malicious uploads
- Incident response: We maintain a documented incident response procedure. In the event of a data breach affecting your personal information, we will notify affected users and, where required, the appropriate regulators (such as state attorneys general) without unreasonable delay and within the timeframes required by applicable US federal and state breach-notification laws.
No system is 100% secure. If you discover a security vulnerability, please report it to [email protected].
12. Analytics
Analytics is off by default (opt-in). New accounts start with analytics disabled, and we collect no usage analytics unless you turn it on. Your analytics preference is stored in your profile and gates all collection, so you have control from day one. You can toggle it at any time: Settings > Privacy > Analytics.
Who processes it. When you enable analytics, we use PostHog (PostHog Inc.) to collect anonymous product-usage data and crash reports that help us improve the app. Events are tied to a pseudonymous identifier, not to your name or email.
What we collect. Two kinds of events, both gated on your consent:
- Product-usage events — anonymous signals about how the app is used (for example, “created an event” or “opened the calendar”), never the contents of what you created.
- Subscription-funnel events — anonymous signals about the subscription flow (for example, viewing a plan, starting a trial, or completing a purchase). Some of these, such as a purchase-completion event confirmed on our servers, are recorded server-side so our records of a subscription are accurate.
No personal content in analytics. We do not put your name, email address, children’s information, message contents, documents, or other personal content into analytics event properties. Analytics tells us that something happened, not what was in it.
We will update this policy before materially expanding what we collect or adding a new analytics processor.
13. Calendar Integration
Denly offers one optional calendar integration:
- Device calendar sync: You can sync Denly events to your device’s native calendar (iOS Calendar, Google Calendar). This requires explicit permission. Once synced, event data on your device is subject to your device’s own privacy settings.
Event data synced to your device’s calendar is subject to that calendar service’s own privacy policies.
14. Changes to This Policy
We may update this Privacy Policy from time to time. When we make material changes, we will notify you via in-app notice or email before the changes take effect. You consent to receive this policy and any privacy notices electronically, as described in the Terms of Service (Section 3, Electronic Communications and Notices).
Your continued use of Denly after the effective date of any changes constitutes your acceptance of the updated policy. If you disagree with the changes, you may delete your account.
Previous versions of this policy are available from GuildStack Labs on request.
15. Contact Us
For any questions about this Privacy Policy or your personal data:
Email: [email protected] Data controller: GuildStack Labs LLC
Version History
We keep a record of material changes to this Privacy Policy so you can see what changed and when. The current version and effective date are shown at the top of this page.
| Version | Effective | Summary of changes |
|---|---|---|
| 1.3 | September 3, 2026 | Payment processor update. Subscriptions are now purchased through Apple (App Store In-App Purchase) instead of a Stripe checkout — Apple receives the purchase and a randomly generated identifier for your Den, and we receive back transaction identifiers, product, dates, price, and storefront, never card details, name, or email. Replaces the Stripe row in the Section 5 processor table with Apple (App Store); Stripe no longer processes Denly payments. |
| 1.2 | August 27, 2026 | Health-data accuracy update. States the actual scope of the health consent: it gates saving documents to a child’s Medical folder, is opt-in and per-account, and withdrawal stops new saves and edits without deleting existing documents. Removes references to structured health fields (allergies, medications, provider contacts) that the app does not have. Discloses that health details may appear incidentally in free-text elsewhere (calendar events, expense descriptions, messages), which is not scanned or separately gated. Section 4 role table updated to match. |
| 1.1 | August 6, 2026 | Accuracy and disclosure update. Adds messages to the data inventory and retention sections (the message log is immutable by design; hiding a message does not remove it from the record or exports). Adds two processors to Section 5: Expo (app-update checks on launch — version metadata only, request IP visible to Expo, never linked to identity) and GitHub (encrypted database backups, unreadable by GitHub, kept up to 90 days) — with a matching Section 7 note that deleted data may persist in encrypted backups up to 90 days. Documents that data exports include uploaded files exactly as uploaded, with embedded photo metadata (EXIF) intact, plus integrity-verification materials. Clarifies that children’s profiles remain with the other co-parent after account deletion (they are shared Den records). Removes the ICS calendar-feed description (that feature does not exist; only device calendar sync is offered). Corrects the Section 4 role table to match server-enforced access: Guests see calendar events plus children’s names and birthdays only (not care or medical information, which the previous version overstated), Counsel is strictly read-only, and these limits are enforced server-side. |
| 1.0 | July 17, 2026 | First versioned edition. Clarifies OAuth-only sign-in (no passwords stored); adds Stripe, PostHog, and independent timestamping authorities to the list of processors (timestamping receives only a cryptographic hash, never content); adds a Legal Process and Government Requests section; documents hardship-request data and its retention; states the 30-day permanent-deletion policy for closed Dens covering files, records, and Den-scoped logs; and describes product-usage and subscription-funnel analytics events with no personal content in event properties. |