Privacy Policy
This Privacy Policy explains how ParentLedger (“ParentLedger,” “we,” “us”) processes personal data in the mobile apps, attorney web portal, and related services. Capitalized terms not defined here have the meaning in our Terms of Service.
Related notices: AI processing · Payments · Subprocessors · Privacy center
A. Controller identity
The controller of ParentLedger personal data is Kenneth William Momsen III, trading as ParentLedger (Google Play developer of record).
- Privacy contact: support@parentledger.org
- Developer / ops contact: kmomsen@gmail.com
- Postal address: 323 Washington Ave, Sellersville, PA 18960, USA
- EU/EEA Art. 27 representative: Not yet appointed. If counsel determines one is required for our offering, we will name them here and in-app.
B. What ParentLedger does
ParentLedger is a co-parenting and family-law records product. Features may include shared schedules, expenses, messaging, documents, exchange check-ins, exports, optional AI assistance (Ryno / related tools), subscriptions, and an attorney workspace. ParentLedger is software — not a law firm and not legal advice.
C. Categories of personal data
Depending on how you use the service, we may process:
- Account & authentication: phone number, email, sign-in provider identifiers (e.g. Apple, Google), authentication tokens.
- Profile & workspace: name, role (parent or counsel), firm or household details you enter, matter/case identifiers.
- Children-related metadata: names, ages/DOB, or schedule details that adults enter about children in a matter (processed as part of the adult user’s records; the app is not for children to use on their own).
- User content: messages, timeline entries, calendar items, expenses, receipts, documents, photos, and similar uploads.
- Location (if you use exchange / check-in features): approximate or precise location you choose to submit for an exchange event.
- Device & technical: device type, OS, app version, IP address, security and reliability logs.
- Diagnostics: crash reports and, only when enabled for your region/build, analytics events.
- Purchases: subscription status and entitlements via Apple, Google Play, and/or RevenueCat.
- Payments (Connect): limited payment-account metadata (e.g. Connect status, last4) when you use reimbursement features; Stripe processes KYC.
- AI prompts & outputs: case-derived text sent to the model provider when you use AI features (see AI notice).
- Communications: support emails; transactional email/SMS where configured (not attorney marketing CRM).
D. Purposes and legal bases (EEA/UK overview)
Where the GDPR / UK GDPR applies, we rely on the bases below. Mandatory consumer and privacy rights in your country still apply.
- Contract (Art. 6(1)(b)): create and secure your account; operate messaging, schedules, expenses, documents, attorney workspace, exports; process store subscriptions and Connect reimbursements you request.
- Legitimate interests (Art. 6(1)(f)): security, fraud/abuse prevention, service reliability, product improvement that does not override your rights. You may object where applicable.
- Consent (Art. 6(1)(a)): optional analytics/Crashlytics where gated on; optional marketing communications if ever offered (marketing SMS is not used in the current product); certain device permissions (notifications, precise location) at the OS level.
- Legal obligation (Art. 6(1)(c)): respond to lawful requests and keep records where required.
Special-category data (e.g. health) is not sought as a product category. If users paste sensitive content into messages or AI prompts, engineering minimization may strip some medical patterns from AI packs when those controls are on — that does not mean the service is designed for health records.
E. Sharing
- Service providers / subprocessors: cloud hosting, auth, storage, functions, email, SMS, payments, maps, AI, stores — see Subprocessors.
- Co-parents & counsel: content in a shared matter is visible to participants invited under product permissions.
- Legal: if required by law, legal process, or to protect rights, safety, or security.
We do not sell personal information for money as a business model. We do not run cross-context behavioral advertising in the current product.
F. International transfers
Primary application backends run on Google Firebase / GCP with Cloud Functions in us-central1. AI inference may use Google Generative AI with region configuration that is not EU-only today. Stripe, Twilio, SendGrid, RevenueCat, Apple, and Google may process data in the United States or other countries where they operate.
Where required, we rely on appropriate transfer tools (for example, the vendor’s Data Processing Addendum and Standard Contractual Clauses, and/or EU–US Data Privacy Framework participation where a vendor self-certifies). Execution status of each vendor DPA is tracked internally until counsel confirms the packet is complete.
G. Retention
We keep personal data while your account is active and as needed to provide the service, resolve disputes, enforce agreements, and meet legal duties. Backups may retain copies for a limited period after deletion. Shared matter records may persist for other participants after you leave or delete your account — see our account deletion page and in-app EU Data Rights Center.
H. Security
We use industry-standard measures appropriate to the service (encrypted transit, access controls, authenticated APIs). No method of transmission or storage is 100% secure. Protect your device and credentials.
I. Children / age
ParentLedger is for adults managing co-parenting or counsel workflows. It is not directed to children using the app on their own. Our current self-declaration age gate uses a provisional threshold of 16 pending final counsel confirmation of Art. 8 / national ages for markets we enable. Do not create an account for a child to use independently.
J. AI features
AI features (including Ryno) are enabled for EEA/UK users when you choose to use them. Prompts may include minimized case-derived text sent to Google Generative AI (Gemini). See the AI processing notice for details, minimization, and how to stop using AI. Analytics for EEA users remain off by default until consent copy is approved.
K. Your rights (EEA / UK / similar)
Subject to applicable law, you may have rights to:
- access and portability;
- rectification;
- erasure;
- restriction;
- object to certain processing (including legitimate interests);
- withdraw consent where processing is consent-based;
- lodge a complaint with your supervisory authority.
In-app: Privacy & security → EU Data Rights Center. Email: support@parentledger.org. We may need to verify your identity. Some shared-matter content cannot be fully erased without affecting other users’ lawful records.
L. California (CCPA/CPRA) — summary
We collect the categories in Section C for the purposes in Section D. Retention follows Section G. You may have rights to know, delete, and correct personal information. We do not “sell” or “share” personal information for cross-context behavioral advertising in the current product.
M. Account deletion
Request deletion from in-app settings or by emailing the privacy contact. See account deletion for process and limits.
N. Changes
We may update this Policy by posting a new version here and in the app. Material changes may require renewed in-app acceptance (consent document version). The document version at the top is authoritative.
O. Contact
Privacy questions and rights requests: support@parentledger.org.