Legal
Privacy policy
Under legal review · version 21 August 2026
This is the complete current text and it describes what the product actually does today. It has been prepared in-house and sent to external counsel; it is not yet lawyer-approved and may change before public launch. Questions: privacy@visibleneeds.site.
1. Who we are
Visible Needs is a household planning and reflection service for adults. It helps the people in a household record needs, capacity, agreements, reflections and care-network context. The controller is Visible Needs; the privacy contact is privacy@visibleneeds.site.
2. What this policy covers
The Visible Needs mobile app, this website, and the waitlist, invitation, account-export and account-deletion flows, together with support, feedback and security-contact messages.
3. Data we process
- Account: email address, optional display name, authentication metadata.
- Household: household name, members, roles and invitations.
- Needs: titles, descriptions, categories, the six ratings, visibility settings and impact links.
- Capacity and agreements: check-ins, agreement titles and statuses, and the members they involve.
- Reflections: monthly counts, chosen focus, agreement outcomes.
- Care network: names, relationships and context for people a household records as support.
- Child and dependent profiles, managed by adults — display name, role and relevant care context.
- Consent records: optional SDK consent choices, policy version, timestamp and source.
- Security and audit data: action and entity identifiers, deliberately without need text.
- Waitlist: email address and consent metadata.
- Feedback reports: the message, its kind, optional diagnostics, an optional contact address, and triage status.
4. Sensitive family context
We never ask you to label anything as health, religion, sexuality or any other special category. But free text about a household can reveal sensitive information whether or not it is labelled, so we treat need text, capacity notes, relationship and co-parenting context, and child/dependent context as sensitive throughout — in what we store, who can read it, and what leaves the database.
5. Why we process it
To create and secure accounts; create, join and run households; record needs, check-ins, agreements and reflections; enforce the visibility rules; send invitations and waitlist confirmations; provide export and deletion; receive support, security and feedback messages; record consent decisions for optional crash reporting; and detect and investigate security problems.
6. Lawful bases
| Processing | Basis |
|---|---|
| Accounts, authentication, household features | Contract |
| Needs, capacity, agreements, reflections, care network | Contract, entered by your own explicit action |
| Waitlist emails | Consent |
| Crash reporting | Consent — off by default |
| Analytics | Not active. Consent required before it ever is |
| Security logs and abuse prevention | Legitimate interest |
| Consent records | Legal obligation / accountability |
| Billing | Planned. Contract and legal obligation |
7. Who can see household data
Access is enforced in the database itself, by row-level security, not by the app asking nicely. Every need carries one of four visibility levels:
- Private — only you.
- Partner-only — adult-equivalent household members.
- Family-visible — your household.
- Summary-only — others can see that a need exists and nothing else: not its title, not its ratings, not its priority.
Children and caregivers cannot see adult emotional or couple needs. Caregivers see only the agreements they are responsible for or supporting. These rules are covered by an automated test suite that runs on every change to the database.
8. Children and dependents
Children do not create accounts. A child profile with a login attached is rejected by a constraint on the table itself, so every route fails the same way rather than only the ones we remembered to check. A child or dependent profile is a household record managed by an adult. We deliberately have no field for a school name, a precise location, a photograph or a date of birth, and no way to message a child — though free-text notes can hold anything an adult types, which the children and dependents page explains in full.
9. Subprocessors and sharing
We do not sell personal data, and private need text is never used for advertising or tracking. The current providers are Supabase (authentication, database, storage), Vercel (website hosting), Resend (invitation and waitlist email) and Sentry (crash reports, only if you turn them on). Stripe or RevenueCat for billing, and any analytics provider, are planned and not active. See the subprocessor list.
10. Where data is held
Supabase is EU-hosted, Resend sends from the EU region, and Sentry is configured for EU ingest. Vercel delivers this website over a global edge network.
11. Cookies and optional SDKs
This website uses no analytics, advertising or marketing cookies. Crash reporting in the app is optional, off by default, and asked for once in plain words. The website runs server-side error monitoring, which records our own failures and sets nothing in your browser. Details: cookie policy.
12. How long we keep it
- Account data: for the life of the account, plus the deletion cycle.
- Deleted accounts: deleted or anonymised within 30 days where technically possible.
- Household content: yours until you delete it, the household is deleted, or account deletion applies.
- Unconfirmed waitlist entries: deleted after 30 days by a scheduled job.
- Confirmed waitlist entries: until you unsubscribe.
- Audit logs: deleted after 12 months by a scheduled job. They record actions and identifiers — never the text of a need — and deleting your account unlinks you from them immediately, before that.
- Backups: kept for the provider's backup window and reconciled through the deletion process.
13. Your rights
You can access and export your data, correct it, delete it, restrict or object to processing where that applies, and withdraw consent for anything optional. Export and deletion are self-service on the data management page; anything else goes to privacy@visibleneeds.site. During beta we aim to acknowledge within three business days and to complete within the applicable legal deadline.
14. Security
Row-level security in the database, least-privilege admin access with multi-factor authentication, TLS in transit, managed encryption at rest, audit logs that deliberately exclude need text, an automated test suite that would fail if the visibility rules regressed, and crash reporting that is both consent-gated and scrubbed of request bodies, query strings, headers and cookies.
15. Contact
Privacy: privacy@visibleneeds.site · Security: security@visibleneeds.site · Support: support@visibleneeds.site. An EU representative will be named before any EU launch.
Version 21 August 2026. Written against the running system rather than from a template — the categories above are the actual database columns, and the visibility rules are the ones the tests assert. If something here does not match what the product does, the page is wrong and we want to know: get in touch.