Security

Security Policy

Privacy Policy

TheParentDashboard reads mail from a connected Google account, and for some users it can write to a calendar or a task list too. If you find a way to make it do something it shouldn't — read, change or expose data that isn't yours, bypass a permission check, or anything in that family — we want to hear about it before anyone else does.

Reporting a vulnerability

Email contact@theparentdashboard.com with what you found, the steps to reproduce it, and its impact. The same address is published at /.well-known/security.txt in the machine-readable format described by RFC 9116, for anyone whose tooling looks for it there rather than here.

Please report by email rather than anywhere public. The source code is not public, and we handle every report privately, by email, between you and us until a fix has shipped.

What to expect

This is a small, actively developed project, not a company with a security team on call. We read every report that comes in and take real issues seriously. Once we have confirmed a report, we aim to ship a fix within these times, by severity:

If a fix will take longer, we'll tell you why. We can't yet commit to a fixed acknowledgement window, and we'd rather say that plainly than promise a number we can't back up.

Scope

In scope: the web application at theparentdashboard.com, its API, and the Android app that wraps it. Out of scope: the third-party services it depends on (Google, Anthropic, AWS) — please report issues in those directly to their own security teams.

We ask that you avoid accessing, modifying or deleting data that isn't yours, and that you give us a reasonable chance to fix an issue before disclosing it publicly.