The short version
Household-only, by default
Access is checked in the database on every request, not just hidden in the interface. We are not certified against any security standard and we don’t claim end-to-end encryption — what we do and don’t do is set out in full below.
- Every adult has their own login and their own password. Nobody shares an account.
- Your school items, children and photos are visible only to the adults you have invited, and only for the children you shared with them.
- The wording of a school message — the title, your notes, your child’s name and year — is held in encrypted secure storage, separate from the ordinary tables. A copy of the database on its own shows dates and reminders, not what is happening or who it is for.
- Photos are stored privately, never on a public link. The app hands out a short-lived link only after checking you belong to that household.
- We don’t take payments, so we never hold card details. There is nothing to charge during the beta.
- There is no advertising, no data selling, and no third-party advertising or social tracking scripts in the app.
Accounts and sign-in
- Sign-in is handled by our managed authentication provider. Passwords are stored and checked by them — we never see or store your password.
- You can sign in with Google instead, in which case no password exists here at all.
- Signing up with an email address requires confirming that address before the account is usable.
- Password resets are single-use links sent to your address, and they expire.
- Adults in a family cannot see each other’s full email address: it is masked in the app.
Who can see your data
Access is enforced in the database, not just in the screens. Every table holding family information is protected by row-level rules keyed to your account, so a request for somebody else’s household returns nothing — even if it’s made directly to the API rather than through the app.
- A family holds at most six adults. Everyone else joins only via a private invite link you create, and each invite grants access to the specific children you choose — nothing else.
- The family owner controls access and can remove any other adult, or withdraw a single child from them, at any time.
- Invite links expire, can be revoked, and can be tied to a specific email address so only that person can accept.
- When someone leaves a household they stop seeing its items immediately, and their calendar link is revoked automatically.
- Sensitive tables — analytics, ingestion logs, calendar credentials, referrals — are not reachable from the browser at all. Only server code with verified identity can touch them.
- The same is now true of your school items themselves: the browser holds no access to those tables. Every read and edit goes through server code that checks which children you look after, then reassembles the wording from encrypted storage for you alone.
- Access changes leave a trail. Sharing a child, taking that access back, removing an adult and replacing a calendar link are all recorded — with who did it and when, and none of the school’s wording.
Photos of your children
Photos are entirely optional; initials work identically everywhere. When you do add one:
- It goes into private storage. There is no public URL, and we never generate one.
- The browser cannot reach photo storage directly at all. Only our server code can, and it checks you are a current member of that household before handing back a temporary link that expires within minutes.
- Every image is rebuilt as a small square before it is stored, and we strip camera metadata such as location on our side as well, so nothing about where a photo was taken is kept. We don’t keep the original file or its name.
- Your photos are never sent to the AI that reads school messages. No face detection, no face recognition, no inference of any kind.
- Photos never appear in analytics, calendar output, or anything shared outside your household.
- You can remove a photo at any time, and deleting a child deletes its photo.
School messages and the AI step
To turn a school message into a tidy list, the content you submit is sent to a third-party AI model through the Lovable AI gateway (currently Google’s Gemini models). We won’t pretend it never leaves our system, because it does.
- Uploaded screenshots and PDFs are processed in memory and discarded. We do not store the file.
- We don’t store the full text you sent, the prompt, or the raw AI response — only the validated items and a short quote showing where each came from.
- The item’s wording and that short quote are stored encrypted, under keys the app never hands to a browser. Ordinary tables keep only what the dates and reminders need — a date, a time, an amount, and a plain label such as “School trip”. They are put back together for you by server code once it has confirmed you look after that child.
- School content is treated as untrusted data: instructions hidden inside a message cannot make the app do anything.
- The short quote kept with each item is cleared by a nightly job, timed from the event rather than the upload: 30 days after the date it happened, or 90 days after it arrived if there is no date. A letter filed months early keeps its evidence until the day has passed. The item stays; the school’s wording does not.
- Details you add or we extract — the title, your notes and the child’s name as written — are cleared 90 days after a dated event, or 180 days after arrival if undated.
- The check that stops the same letter creating duplicates compares a keyed code, not the wording. The key is unique to your family and lives in a separate vault, so a stolen copy of the database cannot be reversed into your children’s school life.
- If your school messages are sensitive beyond ordinary school admin, please don’t send them.
Calendar links
A calendar subscription link is a capability: anyone holding it can read your approved school dates. We store only a hashed version of the secret, so we cannot reconstruct your link — and neither can anyone reading our database.
- You can revoke and replace a link at any time in Settings; the old one stops working immediately.
- Fetches are rate-limited to stop abuse, and only approved, dated items ever appear.
- New links hide the details by default: “School event” and a date, nothing more. Adding your child’s name, amounts and notes is a deliberate choice you make when you create the link, and you can change it afterwards.
- No entry ever carries a location, and none carries the school’s original wording.
- A one-off calendar download or “add to Google” always stays generic — “School event”, the date and time, and a note to open Musette. A downloaded file sits in your Downloads folder and a Google entry lives in someone else’s account, so we don’t put your child’s name or the details in either. The detail option applies only to a subscribed link, which you can withdraw.
What we deliberately haven’t built
Honesty is part of the security story, so here is the current state:
- Forwarding school emails to Musette is switched off. There is no live inbound address, so nothing is quietly receiving your mail.
- We are not certified against SOC 2, ISO 27001 or any similar standard, and we won’t claim to be.
- We have not yet published a formal subprocessor list or confirmed hosting regions. Ask us and we’ll tell you what we know.
- Account deletion is done by hand at this stage, after we confirm by email, rather than a one-tap button that could break a shared household.
- There are no push notifications or reminder emails, so nothing about your family is being pushed anywhere.
Found a problem? Tell us.
We’d genuinely rather hear it from you than find out later. If you spot something that looks wrong — data appearing where it shouldn’t, a link behaving oddly, anything at all — report it from inside the app: Settings → Feedback & requests, category Privacy question or request. A person reads every one.
Please don’t run automated scans, load tests or attacks against the service. Show us the issue and give us a reasonable chance to fix it; we won’t come after anyone who reports a genuine problem in good faith.
What we hold and for how long is set out on the privacy page.