Trust Document

A family's data is the family's data.

Not marketing. The specific guarantees we make, the posture of the platform, and the paperwork a security-minded reader clicks on. Printable, readable, honest.

Last revised 10 October 2026security@stresfri.com

§ 1. Guarantees

Six promises enforced by the database.

  1. 01

    Row-level security on every table.

    Every one of the 70+ Postgres tables ships with RLS enabled and explicit policies. A visiting user sees their household's rows; nothing more. The database refuses even if the application layer forgets to filter. Admin bypass exists only through a security-definer function whose use is logged.

  2. 02

    Health data lives in its own schema.

    Stresfri Health's tables (profiles, workouts, measurements, medications, daily check-ins) sit in a separate Postgres schema with per-user policies. A Calendar admin cannot see Health data by mistake. The policy stops them, not an if-statement.

  3. 03

    Short-lived, scoped tokens.

    Session tokens are issued by Supabase Auth with short TTLs and refreshed in the background. Service-role keys live only as encrypted Cloudflare Worker secrets. They never ship to a browser bundle. Publishable keys that do are, as the name suggests, publishable.

  4. 04

    GDPR export and erasure, both self-serve.

    A household owner can download every row we hold on them across Calendar and Health as a single JSON file from Settings. A second button in the same place requests deletion; erasure completes within thirty days per the regulation, with a hard-delete receipt by email.

  5. 05

    Live, honest status.

    A public status page probes the Worker, Supabase and push every minute. Incidents post within minutes of detection; resolution notes within a working day. The probe runs against real production endpoints, not a mock.

  6. 06

    A Data Processing Agreement, on request.

    A standard DPA is available for employer sponsors, co parenting arrangements with legal boundaries, or any household whose employer requires one.


§ 2. Operational practice

Day-one answers to the questions on your runbook.

  • Daily Postgres backups with point-in-time recovery.
  • TLS 1.2 or newer enforced on every custom domain; HSTS set.
  • CSP, X-Frame-Options and Referrer-Policy set globally on marketing and app.
  • Secrets stored as encrypted Cloudflare Worker secrets, write-only via wrangler.
  • Rate limiting on every public hook endpoint, per IP and per household.
  • Audit log on admin impersonation: who, whom, when, for how long.
  • No ads, no third-party trackers, no analytics beacons in the app surface.

§ 3. Your right to leave

Download everything. Erase everything.

In Settings → Export my data, your household owner can download every row across Calendar and Health as a single JSON file. In Settings → Close my household, that same person can request erasure; we deactivate immediately and schedule deletion within thirty days, with a hard-delete receipt emailed on completion.

Download, JSON, your rows only· Erase, 30 day window, receipt by email

§ 4. The paperwork

Four pages a lawyer actually wants.


§ 5. Found something?

Responsible disclosure is welcome.

Email the security team at security@stresfri.com. You'll hear back within one business day. Please don't publish anything publicly before we've had a chance to fix it.