← The Well
Privacy Policy

A quiet word on how we handle your family's data.

Last updated: August 4, 2026 · The Well by Precipice Health, LLC

The plain-English version

The Well is a private family app. Your calendar, meals, tasks, prayers, and photos belong to your family. We don't sell your data, we don't run ads, and we don't share it with third parties for marketing. Ever.

What we collect

  • Account basics. Your name, email address, and profile picture (from Google sign-in). Children who sign in with a PIN have no email or picture — only a name and avatar you assign them.
  • Family content. Everything you and your family create inside the app: events, tasks, meals, grocery items, prayer requests, and location (for weather).
  • Payment info. Handled entirely by Stripe. We never see or store your card number.
  • Basic device info. IP address, browser type, and general error logs. We use these to keep the app running smoothly.
  • Voice input. If you use "The Whisperer" to add events by voice, your spoken words are transcribed and processed to understand your request. The audio is not retained.

How we use it

We use your data solely to make The Well work for your family: showing your calendar, generating your morning brief, delivering push notifications for reminders, and keeping your family's data in sync across devices. Nothing else.

Who else touches your data

We use a small number of trusted service providers to run the app. None of them are given data for their own marketing:

  • Google. Sign-in (via the Emergent Auth broker).
  • Stripe. Subscription billing.
  • Resend. Sending family-invite emails.
  • Anthropic & OpenAI. Language-processing for the morning brief, dinner ideas, and voice input. Requests are transactional — providers do not use your content to train their models under our contracts.
  • Weather providers. Anonymous location lookups for daily weather.

Children's privacy

The Well is designed for families and is intended to be used by children under a parent's account and supervision. Children who use PIN sign-in do not have their own login credentials or email address associated with them — only a display name and avatar chosen by a parent-admin. We do not knowingly collect personal information directly from children under 13 outside of what a parent enters on their behalf. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.

Your rights & controls

  • Export your family's data anytime. A single tap in Settings → Data & Privacy produces a plaintext JSON bundle of everything your family has stored — events, tasks, prayers, journal entries, verses, meals, chores, homework, contacts, rituals, handoff notes. Yours to keep, migrate, or archive.
  • Delete individual items (events, tasks, prayers, etc.) from within the app immediately.
  • Delete your entire account and all associated family data by emailing us. We will confirm deletion within 30 days.
  • Opt out of push notifications from your device settings.

How long we keep it

We keep your family's data as long as your account is active. If you delete your account, everything is purged within 30 days, except where we're legally required to keep records (e.g., billing/tax records — up to 7 years).

Security

We take the security of your family's data seriously. Here is exactly what we do today, and what we are working toward.

In transit. Everything moves over HTTPS (TLS). Your phone or laptop and our servers never exchange data in the clear.

At rest — content encryption. The private content of your family's data — event titles, descriptions, notes, locations, journal narratives, prayer details, verses — is encrypted using AES symmetric encryption before it is written to our database. A stolen database backup or a rogue disk image reveals only ciphertext, not readable family calendars or prayers.

At rest — identifiers. Names, email addresses, and account metadata are stored in plaintext because they are required for login, invitations, and transactional email. PINs are stored as one-way bcrypt hashes — even we cannot recover them.

Administrator access. Because we hold the encryption key on our servers, Precipice Health (the company that runs The Well) has the technical ability to decrypt your family's content if compelled by legal process, if you request customer support that requires it, or in the course of investigating abuse. We do not access family content routinely, and we log every administrator access. This access model is comparable to that of Dropbox, Google Drive, and most family-scale SaaS. It is honest, it is auditable, and it is what allows us to help you recover accidentally-deleted data and to respond to lawful requests.

End-to-end encryption is on our roadmap. A future version of Precipice Health's shared identity service ("Aegis") will offer zero-knowledge encryption for families who want it — meaning we will structurally lose the ability to decrypt your content. When that ships, we will notify you and let you opt in. Until then, the encryption model above is what protects you.

Changes to this policy

If we materially change how we handle your data, we'll post the new policy here and notify you in the app before it takes effect. This page will always show the latest "Last updated" date at the top.

Contact

Questions, requests, or concerns:

privacy@precipice-health.com
Precipice Health, LLC

The well-kept family is a wellkept.family.