TheParentDashboard reads the mail in the account you connect and sends you back a weekly summary of what it is actually asking of you — the permission slip, the early dismissal, the fee that is due. It can also put what it finds where you will actually see it: as entries on your calendar, as items on your task list, or in an email you ask it to send. Doing any of that means reading your mail, so this policy is specific about what is read, what is kept, where it goes, and how to end it.
This policy covers the website at theparentdashboard.com, the application, and the summary emails. In it, “we” means TheParentDashboard, and “you” means the person who connected an account.
Google is the only account you can connect today, and the Google-specific section below is written for that. We expect to support other providers — Apple, Microsoft 365, Yahoo and others — and everything in this policy is meant to apply to each of them as it arrives. Whichever provider it is, the permissions we hold are the ones you granted on that provider’s own consent screen, and you can withdraw them there.
| Scope | What it gives us | Why we need it |
|---|---|---|
openid, email, profile |
Your Google account ID, email address, name and profile picture. | To sign you in, to know which account a summary belongs to, and to have somewhere to send it. |
gmail.readonly |
Read-only access to the messages in your mailbox. | The product is a summary of your mail. Without reading it there is nothing to summarise. |
calendar.events |
Permission to read and change the events on your calendar. | So dates found in your mail can be put on the calendar you already use, rather than on a separate one you would have to switch on in every app. This permission does reach the events you created yourself; we only ever change or remove entries we added, which we recognise by a marker we attach to each one, and we check that marker on the entry itself before touching it. Optional — see below. |
tasks |
Read and write access to your Google Tasks lists. | So things you have to do can appear on a task list we create. Google offers no narrower permission for tasks, so we do not ask for this at sign-in at all — only if you switch task lists on, at which point Google asks you separately. Optional. |
This table is what we may request. The first three are asked for when you sign in; the fourth only if you switch task lists on. Other features described in this policy — sending a summary from your own address, for one — each need a permission beyond these. We request a permission when the feature that needs it ships, never before, and you will see Google’s consent screen naming it at that point. Nothing here grants itself quietly: a permission you have not agreed to is one we do not hold.
Today, mail access is read-only. We cannot send, change, label or delete anything in your mailbox, and that is a limit Google enforces rather than a promise we are asking you to take on trust. If we later ask to send mail from your account, it will be for something you asked us to send — a summary to yourself, or to someone you name — and it will be a separate permission you can decline while keeping everything else.
Each permission is separable. You can untick one on Google’s consent screen and the rest of the product still works, and anyone who signed in before a permission existed simply does not have it. We ask whether a sign-in carries a permission rather than assuming it.
Calendar entries and task list items are switched off until you turn them on. Task list items go into a list we create. Calendar entries go onto the calendar you already use, so that they appear where you actually look — which means we hold a permission that reaches the events you made yourself. We attach a marker to every entry we add, and we read that marker off the entry before changing or removing anything, so an event of yours is never touched even if our own records are wrong about it. Everything we create is recorded, which is what lets us update the right entry later, stop touching one you have edited, and remove all of it in one action if you ask. If you edit or delete one of our entries, we leave it alone from then on. At the time of writing, no mail has been sent from anyone’s account.
You can also publish your family’s dates as a calendar feed you subscribe to from any calendar app. That feed has a private address, and anyone holding that address can read what is in it — it carries no password, because no calendar app has anywhere to put one. You can change the address at any time in settings, which stops every copy of the old one working.
When a summary runs — on one of your schedules, or when you press the button — the assistant searches your mailbox using queries it chooses from what you have told it to care about, opens the messages that look relevant, and writes the summary. It reads only what it opens; it does not bulk-download or index your mailbox.
The optional setup interview does the same thing for a different purpose: it searches your mail while it asks you questions, so that it can ask about your actual school and your actual children rather than presenting you with a blank form.
Google API Services Limited Use disclosure. TheParentDashboard’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Concretely, that means we use Google user data only to provide and improve the features you can see in the product; we do not transfer it to others except as needed to provide those features, for security, or to comply with law; we do not use it for advertising; we do not sell it; and no human reads it except with your explicit permission, where it is necessary for security or to comply with law, or in aggregated and anonymised form.
A summary you have to act on is only half the job, so the product can put what it finds where you will meet it again: an entry on your calendar, an item on your task list, or an email you asked us to send. Each of these is optional, each needs its own permission, and none of them happens until you turn it on.
Two rules govern everything we write, on every provider:
Everything we write is drawn from what your summaries already found in your mail and from the material you wrote yourself. We do not add anything you could not already see in the product, and each entry records where it came from.
Mail we send from your account is sent because you asked for it — a summary to yourself, or to a person you named — and it contains the same information the product already shows you. We do not send mail as you for our own purposes, and we do not contact anyone in your address book.
We deliberately do not keep a copy of your mailbox. What we keep is what a summary is made of, plus enough of a trail that you can check any line in it against the message it came from.
| What | Detail |
|---|---|
| Account | Your Google account ID, email address, name, profile picture URL, time zone, and your schedule. |
| What you write | Your instruction — what you want summarised, in your own words — and anything you write about the people in your family: names, nicknames, ages, grades, schools, and free-text notes. |
| Family members’ email addresses | If you give us the email address of someone in your family, such as a partner or a caregiver, we keep it so that, if you switch invitations on for that person, we can add them as a guest on the calendar entries that concern them. Before they are first invited, we send them one short email from us saying who added them, with a link to stop the invitations; if they use it, we keep a note that they did, so they are not invited again. That link works for a year, and after that the page it opens offers to email a new one to the same address. Stopping cannot be undone from the link; if they change their mind, they can write to us and we will reverse it. The address is kept until you remove that person or delete your account. |
| Reference material | Text you paste and links you add, such as a school calendar feed, plus the content fetched from those links. That content is replaced each time the link is fetched again, and kept until you remove the link. |
| Items found | Events, tasks and notices the assistant identified: titles, dates, locations, amounts and links. Each one records where it came from — the Gmail message and thread ID, sender, subject, date, and a short excerpt of up to 500 characters. The sender, subject and excerpt are deleted 30 days after the item is over — its last date has passed, or, for an item with no date, it has not been seen for 30 days. When the assistant thinks an item may already be done, the note it keeps on why, which can quote the message, is also deleted 30 days after the item is over. The message and thread ID, date and link are kept, so you can still find the original in your mailbox. Clearing them here does not change entries we already put on your calendar or task list. |
| What we created | A record of every calendar entry, task and sent message we made on your behalf, and which item it came from. This is what lets us update the right entry later, leave your own edits alone, and remove everything we created if you ask. |
| Summaries | Each summary as sent, and a record of every search the assistant ran and every URL it fetched, so you can see what it looked at. The summary’s subject and text and that record are deleted 30 days after it was written. We keep that a summary ran, when, and counts such as how many messages it read. |
| Web addresses fetched | Separately, a record of each web address a summary tried to open, and whether we let it through. Only the site and the path are kept, not the query string or anything after a “#”, which is where a link in your mail usually carries details about you. A record of an address we opened is deleted 30 days after the attempt. A record of one we refused is kept for 180 days, because it is the evidence that something tried to reach a place it should not. |
| Setup interviews | The transcript of a setup conversation. This one includes the full text of the messages the interview read, because it is what lets the conversation continue across turns. It is never sent to your browser. The transcript, the list of searches, and the senders, subjects and notes recorded as evidence for what the interview saved are deleted 30 days after the conversation was last used, whether or not you finished it. What it saved to your Family and Resources pages stays until you change it. |
| Sign-in | Your Google refresh token, encrypted. We use it to get a short-lived access token each time we need to reach your Google account, and do not store the access token. Sessions are stored only as a hash, so a copy of our database cannot be replayed as a login. Each session also records when it signed in, when it was last used, and a rough name for the device, such as “Chrome on Android”, so Settings can show you where you are signed in. We do not keep your browser’s full identifying string or your IP address with it. |
| Waitlist | If you ask to be let in while signups are closed, the email address you give us, when you asked, and whether we have sent you an invitation. An entry is deleted 12 months after you asked if we never sent you an invitation. If we did, it is kept while the invitation is, and deleted 12 months after the later of the two dates once the invitation is gone. Deleting your account deletes it straight away. |
| Invitations | Each invitation link we make: the name we gave it, which for a link sent to one person is their email address, when it stops working, who made it, and which accounts it was used to create. A link nobody used is deleted 90 days after it expired or was withdrawn, whichever came first. A link that was used to create an account is kept, including after that account is deleted. |
| Administrative actions | A record of each change our operators make, such as switching a feature off for an account or sending an invitation: who did it, when, which account it was about, and what changed. These records can include your email address. Each is deleted 2 years after it was made, and is kept until then even if the account it is about is deleted. |
| Operational logs | Identifiers, timings, counts and errors, and for each web request the page asked for and the IP address it came from. The private part of unsubscribe, invitation and calendar-feed addresses is removed before a request is logged. When a summary finds something, the log also records the item’s title, the file name of the attachment it came from, and any web address it was found at, so those can come from your mail. The logs do not hold the text of your messages. They are deleted 30 days after they are written. |
Message bodies are held in memory for the length of a run and are not written to our database, with the single exception of the setup transcript noted above, which is kept for at most 30 days after the conversation.
We use a small number of service providers. They process data on our instructions and for no purpose of their own.
| Provider | What it handles |
|---|---|
| Anthropic (Claude API) | The assistant that reads and writes. The contents of the messages it opens, the material you have written, and your reference material are sent to Anthropic’s API to produce your summary. Under Anthropic’s commercial terms, this data is not used to train their models. |
| Amazon Web Services | Hosting, the database, the logs, and delivery of your summary emails and of the notices to family members described above, in the US East (N. Virginia) region. |
| Sign-in, the mailbox your data comes from, and — where you have granted it — the calendar and task list we write to. Other providers you connect in future will appear here and handle the same things for their own accounts. |
We also fetch the links you add as reference material — a school calendar, a team page — directly from those sites. Those sites are third parties with their own privacy practices, and this policy does not cover them.
We do not sell your personal information, and we do not share it for advertising or cross-context behavioural advertising. We may disclose information if the law requires it, or where it is necessary to investigate abuse or protect the security of the service, and if TheParentDashboard is ever acquired or transferred, your data would move with it under this same policy.
Our infrastructure is in the United States. If you use the service from elsewhere, your data is processed there.
This is a product about family logistics, so the material you write will often be about children: names, ages, schools, and what is going on in their week.
That information is provided by you, the parent or guardian, from your own account. The service is intended for adults; it is not directed to children, we do not offer accounts to children, and we do not knowingly collect information directly from them. Information about a child is used only to produce your own summaries and is never used to build a profile, to target advertising, or for any purpose beyond the features you can see. Deleting your account deletes it along with everything else.
Every cookie we set is our own, and each one is there to make signing in work.
All of them are HttpOnly, so the page’s own scripts cannot read
them, SameSite=Lax, and sent only over HTTPS.
When the app sends you to sign in again, it also notes the time in your browser’s session storage, for that tab only, so that it cannot get stuck sending you round in a loop. There are no analytics cookies, no advertising cookies, and no third-party trackers anywhere in the product.
No system is perfectly secure, and we would rather say that plainly than imply otherwise. If you believe you have found a vulnerability, please write to contact@theparentdashboard.com. The same address is published at /.well-known/security.txt for tools that look for it there, and our security policy says more about how we handle a report.
We keep your data for as long as your account exists, because the product is cumulative: an item found in March is what lets the assistant recognise the same thing in May. Sessions that have ended, by age or by going unused, are swept automatically.
Depending on where you live, you may have rights to access, correct, export, or delete your personal information, and to object to or restrict its processing. Write to us at the address above and we will honour those requests. We will not treat you differently for exercising them.
If we change what we collect, who we send it to, or how long we keep it, we will update this page and change the effective date at the top. If the change is significant, we will email you before it takes effect.
TheParentDashboard — contact@theparentdashboard.com