Our Houses. Back to Our Houses
YOUR FAMILY’S INFORMATION

How we safeguard data

Your family’s records deserve care. Here are the safeguards built into Our Houses, what they protect, and where your own choices matter.

Last updated 6 September 2026

Sign-in and family access

Email sign-in uses an expiring, single-use code for an eligible member or invitation. Attempts are limited. A successful sign-in establishes a protected session; the site checks family membership and permissions when reading or changing records.

Knowing a house, task or file link is not enough to open it without the required family access. Family administration and site administration have separate permissions. Sensitive account changes use additional verification and an administration record.

Encrypted connections and storage

The live site uses HTTPS to encrypt the connection between your browser and Our Houses. Cloudflare documents encryption at rest for both the D1 database and R2 file storage, with encryption keys managed by Cloudflare. See D1 data security and R2 data security.

This protects storage and transmission, but it does not make the records unreadable to every operator. The application must read information to show it to your family or process a requested feature.

Protected photos, documents and sessions

Photo and document requests check that the signed-in person belongs to the right family. Private file responses tell shared caches not to retain them and restrict how the browser handles the returned content. Uploads have file-type and size checks.

Sign-in cookies are marked Secure, HttpOnly and SameSite=Strict. These browser protections help reduce exposure of the login session. The database stores verification hashes for sign-in codes and session tokens. Ordinary email sign-in is not multi-factor authentication: access to your email inbox is central to protecting your account.

A calendar subscription is a deliberate exception to interactive sign-in: its private link grants read access to the events selected for that subscription. Treat it like a key and revoke it if shared unintentionally.

Recovery after mistakes or failures

Family administrators can preview restore points before applying them. The app checks for intervening edits and captures an undo point before restoring family records, helping avoid silently replacing another person’s new work.

Downloaded family backup archives are encrypted in your browser with a password you choose. That password is not sent to the server. Keep it separately from the archive; losing it can make the download unreadable.

A separate recovery process copies database records and referenced files to another storage bucket, encrypting them before they are written. Its encryption key is kept separately from that bucket. File checks help detect missing or altered copies, and the site administration screen shows backup and recovery-verification status.

These copies help with recovery; they are not a guarantee that the newest change is always backed up or that service can never be interrupted. The backup storage also uses Cloudflare, so it is not independent of a Cloudflare-wide outage. See the retention and deletion explanation for what can remain in a backup.

You review external actions

Bob can advise, research and prepare drafts. Sending a provider email requires a family member to review and choose Send email. Replies are attached to the service conversation. Recording a payment or appointment in the app does not move money or book a provider.

When you choose AI research or document review, the relevant content is processed by OpenAI. A private family workspace does not mean that information stays exclusively inside Our Houses. Read what Bob receives before including sensitive material.

A few ways you can help

  • Protect your email account, preferably with multi-factor authentication, and never share an Our Houses sign-in code.
  • Sign out when using a shared device. Tell a family administrator promptly if a person should no longer have access.
  • Check email recipients and selected attachments before sending. Treat provider attachments as external files.
  • Keep downloaded records, calendar links and backup passwords private. Remove unnecessary personal information from documents before uploading or asking Bob to read them.
  • If you suspect an account or file has been exposed, contact the site operator promptly. Describe what happened without emailing passwords, sign-in codes or recovery keys.

What these safeguards do not promise

No online service can guarantee that information will never be lost, misused or accessed without permission. Our Houses is not end-to-end encrypted, and backups do not make a delivered email or a downloaded file retractable.

Keep passwords, sign-in codes and full bank or payment-card credentials out of house notes, uploads and messages. Keep those in your password manager or the relevant bank or provider service.

Read the privacy policy

Report a privacy or security concern

Email privacy@ourhouses.app to reach the current active site administrators. You can use this address even if you cannot sign in. Describe what happened without sending passwords, sign-in codes or backup keys.

These messages go to administrators’ current account inboxes and are kept separate from your family’s shared conversations. Read the privacy contact details for more information.