Trust Document
A family's data is the family's data.
Not marketing. The specific guarantees we make, the posture of the platform, and the paperwork a security-minded reader clicks on. Printable, readable, honest.
§ 1. Guarantees
Six promises enforced by the database.
- 01
Row-level security on every table.
Every one of the 70+ Postgres tables ships with RLS enabled and explicit policies. A visiting user sees their household's rows; nothing more. The database refuses even if the application layer forgets to filter. Admin bypass exists only through a security-definer function whose use is logged.
- 02
Health data lives in its own schema.
Stresfri Health's tables (profiles, workouts, measurements, medications, daily check-ins) sit in a separate Postgres schema with per-user policies. A Calendar admin cannot see Health data by mistake. The policy stops them, not an if-statement.
- 03
Short-lived, scoped tokens.
Session tokens are issued by Supabase Auth with short TTLs and refreshed in the background. Service-role keys live only as encrypted Cloudflare Worker secrets. They never ship to a browser bundle. Publishable keys that do are, as the name suggests, publishable.
- 04
GDPR export and erasure, both self-serve.
A household owner can download every row we hold on them across Calendar and Health as a single JSON file from Settings. A second button in the same place requests deletion; erasure completes within thirty days per the regulation, with a hard-delete receipt by email.
- 05
Live, honest status.
A public status page probes the Worker, Supabase and push every minute. Incidents post within minutes of detection; resolution notes within a working day. The probe runs against real production endpoints, not a mock.
- 06
A Data Processing Agreement, on request.
A standard DPA is available for employer sponsors, co parenting arrangements with legal boundaries, or any household whose employer requires one.
§ 2. Operational practice
Day-one answers to the questions on your runbook.
- Daily Postgres backups with point-in-time recovery.
- TLS 1.2 or newer enforced on every custom domain; HSTS set.
- CSP, X-Frame-Options and Referrer-Policy set globally on marketing and app.
- Secrets stored as encrypted Cloudflare Worker secrets, write-only via wrangler.
- Rate limiting on every public hook endpoint, per IP and per household.
- Audit log on admin impersonation: who, whom, when, for how long.
- No ads, no third-party trackers, no analytics beacons in the app surface.
§ 3. Your right to leave
Download everything. Erase everything.
In Settings → Export my data, your household owner can download every row across Calendar and Health as a single JSON file. In Settings → Close my household, that same person can request erasure; we deactivate immediately and schedule deletion within thirty days, with a hard-delete receipt emailed on completion.
§ 4. The paperwork
Four pages a lawyer actually wants.
§ 5. Found something?
Responsible disclosure is welcome.
Email the security team at security@stresfri.com. You'll hear back within one business day. Please don't publish anything publicly before we've had a chance to fix it.
