Security

How we protect your center’s data

You are trusting us with records about children and families. This page explains, plainly, where that data lives, how it is protected, and who else processes it.

Last verified September 22, 2026

Childcarious runs on Microsoft Azure in the United States. Data is encrypted in transit and at rest, production databases keep 30 days of point-in-time backups, photos and documents are held in private storage and shared only through links that expire, and every request is limited to what the signed-in person is allowed to see.

Where your data lives

All production data — databases, the activity and messaging store, photos and documents — is hosted on Microsoft Azure in the West US 2 region, in the United States.

Encryption

  • In transit: every connection to our website, web app and mobile APIs uses HTTPS, served through Cloudflare. Plain HTTP requests are redirected to HTTPS.
  • Storage accounts accept HTTPS connections only, with TLS 1.2 as the minimum.
  • At rest: Transparent Data Encryption is enabled on our production databases. Azure Storage and Azure Cosmos DB encrypt all stored data at rest.

Backups

Production databases keep 30 days of point-in-time restore, so data can be recovered to any moment within the last month.

Photos and documents

  • Stored in private containers. Public access is disabled at the storage-account level, so no file can be made publicly readable.
  • Shared only through signed links that expire — between 15 minutes and an hour, depending on the file type.

Who can see what

  • Every request is scoped to your facility. No center can see another center’s data.
  • Within your facility, access follows granular role-based permissions, including custom roles you define — so a teacher can see their classroom without reaching billing or staff records.
  • Parents see only their own children.
  • Children do not have accounts. Child records are entered by your staff and by parents.

Sign-in, secrets and payments

  • Sign in with Google, Apple or Microsoft, or with email. Registration is protected by Google reCAPTCHA Enterprise against automated sign-ups.
  • Application secrets and connection credentials are held in Azure Key Vault, not in code.
  • Payments are taken on Stripe’s hosted checkout. Card numbers never pass through or rest on our servers.

AI search

When you ask AI search a question, the question and the records it matched are sent to Microsoft’s Azure OpenAI Service to compose the answer. Only records the signed-in person is already permitted to see are included.

Microsoft states that prompts and responses are not available to OpenAI and are not used to train or improve models. Microsoft may retain flagged content for abuse monitoring under its own terms. See Microsoft’s data, privacy and security documentation.

Subprocessors

These companies process data on our behalf to run the service:

ProviderPurpose
Microsoft AzureHosting, databases, file storage and AI search (United States)
CloudflareNetwork edge: HTTPS, performance and protection against attacks
StripeSubscription and tuition payments
MailgunTransactional email such as verification codes and receipts
Google reCAPTCHA EnterpriseBot protection during registration
ExpoDelivering push notifications to the mobile apps

Google Analytics is used on this marketing website only. It is not used inside the Childcarious app.

Your data, your control

You can request an export or deletion of your data at any time. See our Privacy Policy for your rights, or request account deletion.

What we have not done yet

We have not completed a third-party security audit such as SOC 2. We would rather tell you that than imply otherwise. If your organization requires one, let us know.

Reporting a security issue

If you believe you have found a vulnerability, email [email protected] with the subject “Security”. Please give us a reasonable chance to fix it before disclosing it publicly.

Frequently asked questions

Where is our data stored?
In Microsoft Azure data centers in the western United States (the West US 2 region). That covers our databases, file storage and document store.
Is our data used to train AI models?
No. AI search runs on Microsoft’s Azure OpenAI Service. Microsoft states that prompts and responses are not made available to OpenAI and are not used to train or improve models.
Can other centers see our data?
No. Every request is scoped to your facility, and within it to the permissions of the person signed in. Parents see only their own children.
Do you store credit card numbers?
No. Subscription and tuition payments are handled on Stripe’s hosted checkout. Card numbers never pass through or rest on Childcarious servers.
Do you have a SOC 2 report?
Not yet. We have not completed a third-party audit such as SOC 2. If your organization requires one, tell us — it helps us prioritize it.