Privacy Policy
Effective August 12, 2026 · Bairat Labs, LLC · Applies to the OnePage app and tryonepage.com
1. Who we are
OnePage is made by Bairat Labs, LLC, a company organized under the laws of the State of Delaware, United States. Bairat Labs, LLC is the data controller (or "business", under CCPA/CPRA terminology) responsible for the personal information described in this policy. Throughout this policy, "OnePage," "we," "us," and "our" refer to Bairat Labs, LLC.
2. Scope of this policy
This policy covers two things: the OnePage mobile app (iOS and Android) and this website (tryonepage.com), including our blog, guides, comparison pages, and free tools (custody schedule generator, expense split calculator, and similar). Where a section applies only to the app or only to the website, we say so explicitly.
3. Information we collect and why
OnePage is built to collect only what it needs to run the app. Here is what each category of app data includes and why it exists:
| Category | What it includes | Why we need it |
|---|---|---|
| Account | Email address, display name, profile photo (optional), authentication tokens | To identify your account and let you sign in |
| Custody schedule | Rotation pattern, day-by-day overrides, handoff times and locations (free text, not GPS) | So both parents see the same calendar |
| Messages | Message text, timestamps, read receipts, edit history | To deliver messages and maintain a reliable, tamper-evident record |
| Expenses | Description, amount, date, payer, split ratio, approval status, optional receipt photo | To track the shared expense ledger and running balance |
| Children's info library | Name, birthdate, medical notes, allergies, medications, school and emergency contacts | So both parents have the same essential information about their kids |
| Photos and media | Files uploaded to the shared family album, with basic metadata | To power the shared media library |
| Legal documents | Custody orders or parenting plans you choose to upload, plus AI-extracted obligations and key dates | To help you track obligations from your own court order (see Section 6) |
| Decision proposals | Requests for a co-parent's decision (school, travel, medical, activities) and the decision history | To create a documented record of joint decisions |
| Subscription | Purchase token, subscription status, store identifier (App Store or Google Play) | To validate your OnePage Plus subscription |
| Website visitors | Standard web analytics and interaction events (pages viewed, referrer, device type, content engagement, tool use, and download or contact intent), if enabled, see Section 12 | To understand how tryonepage.com is used and improve it |
We do not collect device advertising identifiers, browsing history outside our own website, or GPS/location data. Handoff "location" fields are free-text entries you type (for example, "Front porch"), not coordinates captured from your device.
Some fields in the children's info library, allergies, medications, and medical notes, are health-related information about your child. In some jurisdictions this counts as a special, more sensitive category of data with additional legal requirements beyond ordinary personal information. See Section 11 for how we handle this specifically.
4. How we store your data
OnePage's app data is stored using Google Firebase, a cloud platform operated by Google LLC, specifically:
- Firebase Authentication: manages your account and sign-in (email/password, Sign in with Apple, Sign in with Google).
- Cloud Firestore: stores structured data: your schedule, messages, expenses, and info-library entries.
- Firebase Storage: stores files you upload: photos, videos, receipts, and legal documents.
- Cloud Functions: runs backend logic such as invite handling, push notifications, and the AI features described in Section 6.
Firebase data lives in Google-operated data centers and is encrypted in transit and at rest (see Section 14). Access to your family's data is restricted by Firebase Security Rules to the accounts that belong to your co-parenting group; other OnePage users cannot see your information.
5. Sign-in methods
You can create a OnePage account using:
- Email and password: stored and managed by Firebase Authentication.
- Sign in with Apple: we receive a unique Apple ID token and, if you choose, a private relay email address. Apple's practices are governed by Apple's Privacy Policy.
- Sign in with Google: we receive a Google ID token and your public Google profile name and photo, if provided. Google's practices are governed by Google's Privacy Policy.
We never receive your Apple or Google password. Authentication is handled entirely by Apple and Google via OAuth 2.0.
6. AI features
OnePage uses AI to power several optional features, all of them run through Amazon Bedrock, calling an Anthropic Claude model hosted on AWS infrastructure in the us-east-1 (N. Virginia) region. Bedrock is Amazon's own hosting of the model, not a direct call to Anthropic's consumer or API service, so the applicable data terms are AWS's Bedrock service terms, not Anthropic's own API or consumer terms. As a matter of AWS account configuration, we have Bedrock model invocation logging turned off, so AWS is not configured to retain a persistent log of request or response content for our model calls. Amazon's standard Bedrock terms state that customer content submitted through the API is not used to train Amazon's or the underlying model provider's models. We have not independently audited AWS's infrastructure, and this description reflects our account configuration and AWS's published terms as of the effective date above, not an independent guarantee about Amazon's internal systems.
What each AI feature actually sends
- Tone check (OnePage Plus): when you tap "Check tone," your draft message text is sent from your device to our Cloudflare Worker, which forwards it to Bedrock to analyze tone and suggest a calmer rewrite, then returns the result. Our Worker and backend code do not write the draft text to any log, and it is never stored against your account. Only the message you actually choose to send afterward is stored normally, as in Section 3. Cloudflare, as our proxy's hosting provider, may retain standard infrastructure-level request logs (timing, status codes) under its own privacy policy, separate from the message content itself.
- AI family assistant (OnePage Plus): when you ask a question, relevant snippets of your family's messages, expenses, custody schedule, info library, and media captions are retrieved and sent to Bedrock to generate an answer with citations back to the source records.
- Weekly AI summary (OnePage Plus): aggregated statistics about the week (message counts, expense totals, schedule changes) are sent to Bedrock to generate a plain-language narrative summary. Raw message text is not included, only the aggregated numbers.
- Legal document extraction: if you upload a custody order or parenting plan, its text is sent to Bedrock to extract obligations and key dates into your account. Extracted items may include short verbatim quotes from the document you uploaded, stored so you can trace each obligation back to its source.
Every AI feature is optional and only runs when you take an explicit action, opening the assistant, tapping "Check tone," requesting a summary, or uploading a document. Nothing is sent to an AI model automatically or in the background. AI-generated output can be wrong; see the Terms of Use for the full disclaimer on AI accuracy.
7. Subscriptions
OnePage Plus subscriptions are managed through RevenueCat, a subscription management platform. When you subscribe, RevenueCat receives your purchase token from the App Store or Google Play and validates your subscription status. RevenueCat stores your subscription state (active, expired, or cancelled) linked to your account, but never receives your payment card details, those are handled entirely by Apple or Google.
8. Transactional email
We send account-related email (email verification, password reset, weekly digests you've opted into) through Zoho ZeptoMail, a transactional email provider. Every digest email includes a one-click unsubscribe link. We do not use your email address for marketing without your consent, and we never sell or rent your email address to anyone.
9. Push notifications
If you enable notifications, OnePage sends push notifications through Apple Push Notification service (APNs) or Firebase Cloud Messaging (FCM), routed via the Expo push notification service. We store a device push token, not your notification content, on Apple's or Google's servers. You can disable notifications at any time in your device settings or in the app.
10. How we share your data
We share your information only in these specific circumstances:
- With your co-parent. Data you put into OnePage (schedule, messages, expenses, info library, shared photos) is shared with the other member(s) of your co-parenting group. That is the core function of the app.
- With our service providers, strictly to operate the app: Google/Firebase (Section 4), AWS/Anthropic (AI features, Section 6), RevenueCat (subscriptions, Section 7), Zoho ZeptoMail (email, Section 8), and Apple/Google (push notifications, Section 9, and app store billing).
- If required by law, such as in response to a valid subpoena, court order, or other legal process, or where necessary to protect the safety of a user or the public.
- In a business transfer, if Bairat Labs, LLC is involved in a merger, acquisition, or sale of assets, in which case we will notify you before your data becomes subject to a different privacy policy.
We do not sell personal information and we do not share it with advertisers, data brokers, or anyone for cross-context behavioral advertising, as those terms are defined under CCPA/CPRA and similar laws.
Here is the full list of service providers we share data with, what each one handles, and where to read more:
| Provider | Purpose | What they receive | Learn more |
|---|---|---|---|
| Google Firebase / Google Cloud | Authentication, database, file storage, backend functions | All account and family data described in Section 3 | Google Privacy Policy |
| Amazon Web Services (Bedrock) | AI features (Section 6) | Only the specific content each AI feature sends, per Section 6 | AWS Privacy Notice |
| RevenueCat | Subscription validation | Purchase token, subscription status | RevenueCat Privacy Policy |
| Zoho ZeptoMail | Transactional and digest email | Email address, email content | Zoho Privacy Policy |
| Expo (push notifications) | Routing push notifications | Device push token, not notification content | Expo Privacy Policy |
| Apple / Google | Sign-in, app store billing, push delivery | Auth tokens and purchase data described in Sections 5 and 7 | Apple / Google |
11. Children's information
OnePage is designed for use by adult parents and guardians, not by children. You must be at least 18 years old, or the age of majority in your jurisdiction, to create an OnePage account. We do not knowingly allow children to create accounts, and OnePage does not collect personal information directly from children; the app has no separate login or profile for a child.
The info-library feature lets a parent store information about their child (medical notes, school contacts, allergies) for coordination purposes between the two parent accounts. This is provided by the parent, about the parent's own child, and is visible only within that family's co-parenting group. We do not use children's information for advertising, profiling, or any purpose other than helping their parents coordinate care. If you believe a minor has created an account, or that a child's information was submitted in error, contact us at hello@tryonepage.com and we will remove it promptly.
A note on health information
Allergy, medication, and medical-note fields in the info library are health information about a child. Some laws treat health data as a special, more protected category, this includes GDPR/UK GDPR "special category data" rules for users in the EEA and UK, and it may implicate U.S. laws that reach health-adjacent apps outside the standard hospital/insurer context, such as the FTC's Health Breach Notification Rule. OnePage is not a healthcare provider and this info library is not a medical record, it is a convenience field for parents to share basic facts with each other. We are treating this as a heightened-sensitivity category internally and recommend any organization operating OnePage have counsel confirm the specific obligations that apply before relying on this policy as a complete statement of those obligations.
12. Website cookies and analytics
tryonepage.com may use privacy-respecting analytics tools, such as Google Analytics, Microsoft Clarity, or PostHog, to understand aggregate visitor behavior (pages viewed, referring site, device type, content engagement, tool use, search result counts, and download, app-store, source-link, or contact clicks). This website asks every visitor before loading these optional tools. If you decline, their scripts are not requested and OnePage's custom analytics events are not sent. You can change your choice through the Cookie settings link in the website footer. Website analytics are not tied to your OnePage app account, and the website does not use third-party advertising cookies. We do not send raw website search terms, calculator inputs, custody schedules, family names, dates, income, expense amounts, or parenting-plan text through website analytics events.
13. Your rights and choices
You can exercise the following rights at any time:
- Access: you can access and review much of your personal information directly within the app.
- Correction: edit your profile, schedule, and info-library entries directly in the app.
- Export: OnePage Plus subscribers can export a PDF summary of their data from within the app.
- Deletion: delete your account from Settings → Account → Delete Account. What happens next depends on your family. If you are the only member of your co-parenting group, your family's data is deleted from our live database and file storage immediately, along with your login credentials. If you share a family with a co-parent, your own account and login credentials are deleted immediately, but messages, expenses, and other records you authored remain part of the shared family history, marked as authored by a removed user. We retain those shared records because OnePage is designed as a tamper-evident, append-only record both co-parents rely on, and because unilaterally deleting one parent's side of a shared, court-relevant record could itself cause harm to the other parent. This is our product rationale, not a statement of which specific legal exception (for example, under GDPR Article 17 or CCPA/CPRA) applies in a given jurisdiction; that determination should be confirmed with counsel and may mean this practice needs adjustment for some jurisdictions or circumstances.
- Opt out of AI features: every AI feature (tone check, assistant, summaries, document extraction) is off unless you actively invoke it.
- Opt out of marketing email: use the unsubscribe link in any digest email; account-critical email (like password resets) cannot be turned off while your account is active.
If you are located in the European Economic Area, the United Kingdom, California, or another jurisdiction that grants additional rights under laws like the GDPR, UK GDPR, CCPA/CPRA, or a comparable state or national privacy law, see Section 15 for how those rights apply and how to exercise them. We respond to verified rights requests within 30 days, or sooner where local law requires.
14. Data retention
We retain your data for as long as your account is active. When you delete your account, Firestore records, Firebase Storage files, and your Firebase Authentication credentials are deleted immediately as part of that same request (subject to the shared-family exception described in Section 13), not on a delayed schedule. This does not cover routine, short-lived infrastructure backups our cloud providers may keep as part of their own disaster-recovery processes, those age out under our providers' standard backup cycles rather than being individually purged. RevenueCat retains purchase tokens and subscription status, no cardholder data, for as long as needed to meet standard financial record-keeping obligations under applicable law.
15. Security & encryption
We take the security of your family's data seriously:
- Encryption in transit. All data moving between the app, this website, and our backend is encrypted using TLS (HTTPS), including calls to Firebase, AWS Bedrock, RevenueCat, and ZeptoMail.
- Encryption at rest. Data stored in Firestore and Firebase Storage is encrypted at rest by Google using industry-standard AES-256 encryption; the same applies to data processed through AWS Bedrock.
- Tamper-evident records. Confirmed messages and expenses are cryptographically hashed and chained to their prior version, so any attempt to silently alter a historical record after the fact is detectable. This is an integrity mechanism, it makes tampering detectable, and is separate and different from encryption for confidentiality: it does not hide the content from OnePage's systems, it proves the content hasn't been secretly changed.
- Access control. Firebase Security Rules restrict read and write access to authenticated members of your specific co-parenting group. No other OnePage user can see your family's data.
No system is perfectly secure, and we cannot guarantee absolute security. If you believe you've found a security vulnerability in OnePage, please report it to hello@tryonepage.com.
16. International data transfers
OnePage is available globally, and our infrastructure providers (Google Cloud/Firebase, AWS) operate data centers in multiple countries, which may result in your data being processed outside your home country, including in the United States. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on appropriate safeguards, such as Standard Contractual Clauses or an equivalent legal mechanism, as required by GDPR and UK GDPR, through our infrastructure providers' own data processing agreements.
17. Legal compliance and applicable law
We design OnePage to comply with applicable privacy and data protection laws in the jurisdictions where we operate. Laws we specifically account for in how we've built and operate OnePage include:
- The General Data Protection Regulation (GDPR) and UK GDPR, for users in the European Economic Area and United Kingdom;
- The California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA), and comparable state privacy laws including but not limited to Virginia's VCDPA, Colorado's CPA, Connecticut's CTDPA, and Utah's UCPA, for users in those states;
- The Children's Online Privacy Protection Act (COPPA), reflected in Section 11;
- Canada's Personal Information Protection and Electronic Documents Act (PIPEDA);
- Australia's Privacy Act 1988 and the Australian Privacy Principles.
Data protection law continues to evolve, varies by jurisdiction, and can require specific formal steps beyond disclosure, for example, some laws require an in-region representative or a designated privacy contact for companies based elsewhere. Where a jurisdiction requires that kind of representative and we haven't yet named one here, that is a gap for us to close, not a suggestion that the requirement doesn't apply. Where the specific requirements of your local law grant you rights beyond what is described in this policy, that law governs, and you are welcome to contact us at hello@tryonepage.com to exercise those rights; we will work with you to honor them even where a formal process is not yet built into the app.
18. Changes to this policy
We may update this Privacy Policy from time to time as OnePage's features, or the law, change. If we make a material change, we will notify you within the app and update the effective date at the top of this page. This policy is a disclosure of our practices; our contractual terms with you are set out separately in our Terms of Use.
19. Contact us
Questions about this policy or your data? We're a small team and read every message.
Bairat Labs, LLC
Email: hello@tryonepage.com
Please include "Privacy" in your subject line for the fastest response.