The Well is a private family app. Your calendar, meals, tasks, prayers, and photos belong to your family. We don't sell your data, we don't run ads, and we don't share it with third parties for marketing. Ever.
We use your data solely to make The Well work for your family: showing your calendar, generating your morning brief, delivering push notifications for reminders, and keeping your family's data in sync across devices. Nothing else.
We use a small number of trusted service providers to run the app. None of them are given data for their own marketing:
The Well is designed for families and is intended to be used by children under a parent's account and supervision. Children who use PIN sign-in do not have their own login credentials or email address associated with them — only a display name and avatar chosen by a parent-admin. We do not knowingly collect personal information directly from children under 13 outside of what a parent enters on their behalf. If you believe we have inadvertently collected such information, contact us and we will delete it promptly.
We keep your family's data as long as your account is active. If you delete your account, everything is purged within 30 days, except where we're legally required to keep records (e.g., billing/tax records — up to 7 years).
We take the security of your family's data seriously. Here is exactly what we do today, and what we are working toward.
In transit. Everything moves over HTTPS (TLS). Your phone or laptop and our servers never exchange data in the clear.
At rest — content encryption. The private content of your family's data — event titles, descriptions, notes, locations, journal narratives, prayer details, verses — is encrypted using AES symmetric encryption before it is written to our database. A stolen database backup or a rogue disk image reveals only ciphertext, not readable family calendars or prayers.
At rest — identifiers. Names, email addresses, and account metadata are stored in plaintext because they are required for login, invitations, and transactional email. PINs are stored as one-way bcrypt hashes — even we cannot recover them.
Administrator access. Because we hold the encryption key on our servers, Precipice Health (the company that runs The Well) has the technical ability to decrypt your family's content if compelled by legal process, if you request customer support that requires it, or in the course of investigating abuse. We do not access family content routinely, and we log every administrator access. This access model is comparable to that of Dropbox, Google Drive, and most family-scale SaaS. It is honest, it is auditable, and it is what allows us to help you recover accidentally-deleted data and to respond to lawful requests.
End-to-end encryption is on our roadmap. A future version of Precipice Health's shared identity service ("Aegis") will offer zero-knowledge encryption for families who want it — meaning we will structurally lose the ability to decrypt your content. When that ships, we will notify you and let you opt in. Until then, the encryption model above is what protects you.
If we materially change how we handle your data, we'll post the new policy here and notify you in the app before it takes effect. This page will always show the latest "Last updated" date at the top.
Questions, requests, or concerns:
privacy@precipice-health.com
Precipice Health, LLC