TwoRoofs Privacy Policy
Effective Date: April 10, 2026 Last Updated: August 31, 2026
This Privacy Policy describes how PRICEBENCHMARKING.AI LLC ("PriceBenchmarKing.AI," "we," "us," or "our") collects, uses, discloses, and protects information in connection with the TwoRoofs mobile and web application and related services (the "App" or "Service"). This Privacy Policy applies only to TwoRoofs.
By creating an account or using TwoRoofs, you acknowledge that you have read and understood this Privacy Policy.
---
1. Who We Are and How to Contact Us
TwoRoofs is owned and operated by PriceBenchmarKing.AI LLC, a U.S. limited liability company. For privacy questions, requests, or complaints, contact us at:
Email: support@tworoofs.us
---
2. Eligibility and Intended Users
TwoRoofs is intended solely for adults (18 years or older) who are co-parenting minor children. The Service is not directed to children, and we do not knowingly allow children to create accounts. Information about children is provided by parents, never collected from children. Parents enter each child's first name and date of birth for scheduling. Parents may also upload custody agreements, court orders and similar legal records (see Section 3.1), and those documents may contain further information about their children, in whatever form the issuing court or the parents' own agreement recorded it. We do not collect any information from or about children other than what a parent enters or uploads. See Section 10 (Children's Privacy).
---
3. Information We Collect
3.1 Information You Provide
- Account information: email address, display name, password (stored only as a salted bcrypt hash), or Apple Sign-In identifier.
- Household and family information: co-parent identifiers, and the first name and date of birth of each child in your household, used solely for custody scheduling.
- Co-parenting content: messages (original and AI-rewritten versions), custody schedules and change requests, expense records, receipt photos, notes, and concierge negotiation history.
- Custody period plans: plans covering roughly six months of the children's time, made in the App and agreed between you and your co-parent. A plan records the handovers themselves, the assumptions each handover rests on (for example a school date that nobody has confirmed yet), and any reason a parent writes in their own words — an explanation of the life event that prompted a new plan, or a reason for turning one down. Once both parents have agreed to a plan, it is kept as an unchangeable snapshot of what was agreed, and, like the rest of your household's content, it is visible to your co-parent (see Section 5).
- Legal and custody records: custody agreements, court orders, parenting plans, stipulations and similar documents that you choose to upload; the text transcribed from them; and the document date you supply for each. These documents are stored and retained so that their exact wording can be quoted back to you and your co-parent. They frequently contain information beyond what TwoRoofs would otherwise hold — including your children's full names, dates of birth, addresses, schools, and medical or care arrangements, and sometimes details of other people named in the document. You decide which documents to upload; upload only what you need the App to be able to quote.
- Optional content you choose to upload: photos, receipts, documents, voice recordings you make when you choose to speak instead of type (see Section 6), and (if you opt in) calendar entries or contacts used to invite a co-parent.
- Communications with us: support requests, feedback, and survey responses.
3.2 Information Collected Automatically
- Device and technical data: device type, operating system, app version, language, timezone, crash logs, and diagnostic data.
- Crash and error reports: when the App encounters an error, we automatically collect exception messages, stack traces, device type, operating system version, app version, and related component context to diagnose and fix bugs. Crash reports are processed by our error-monitoring provider (Sentry) and are linked to your account to help us investigate issues you report.
- Product analytics: we collect feature usage events (such as message sent, expense submitted, schedule event created, onboarding completed, and screen views) to understand how the Service is used and to improve it. These events are processed by our analytics provider (PostHog) and are linked to your account via your user ID and email address.
- Session replay (iOS only): on iOS devices, we record screen interaction replays to help diagnose usability issues and bugs. All text input fields and images are automatically masked in these recordings so that message content, receipt photos, and other sensitive visuals are not captured. Session replay is not active on Android, web, or during development. Replays are processed by PostHog and are linked to your account.
- Usage data: feature interactions, session timing, and error events used to operate and improve the Service.
- Identifiers: session tokens (expire after 30 days of inactivity) and push notification tokens.
3.3 Information We Do Not Collect
- We do not collect precise geolocation.
- We do not use third-party advertising trackers or sell data to advertisers.
- We do not access your contacts, photos, camera, or calendar without your explicit, OS-level permission.
---
4. How We Use Information
We use the information described above to:
- Provide, maintain, and secure the Service (messaging, scheduling, expenses, records);
- Deliver AI-assisted features including tone checking, message rewriting, the AI Concierge, and receipt parsing (see Section 6);
- Locate and display verbatim passages from legal records you have uploaded, when a parent asks the App a question in a shared conversation, and record which passages were shown. The App reproduces your document's own words and identifies where they came from. It does not interpret them, does not tell you what your agreement means, and does not answer whether either parent may do something (see Section 15);
- Turn a voice recording into text when you choose to speak instead of type, so you can read and correct the words before you send them (see Section 6);
- Send transactional push notifications and respect your quiet-hours preferences;
- Authenticate users, prevent fraud and abuse, and enforce our Terms of Service;
- Diagnose bugs, monitor performance, and improve the Service;
- Comply with legal obligations and respond to lawful requests.
We rely on your consent (for optional features and device permissions), performance of our contract with you (to deliver the Service), and our legitimate interests (security, abuse prevention, product improvement) as the bases for processing.
---
5. How Information Is Shared Within Your Household
TwoRoofs is fundamentally a shared communication platform. All messages, schedules, custody period plans, expenses, children's information, negotiation records, and legal records you upload are visible to the other parent(s) in your household. Once content is sent or shared in the household, it becomes part of the co-parenting record and cannot be unilaterally deleted by you, because the record is designed to be reliable for both parents and for potential legal use. This applies to documents you upload and to passages quoted from them: either parent can remove a document going forward, but passages already quoted into a conversation remain part of that conversation (see Section 8). Please consider this carefully before sharing anything in the App.
---
6. Artificial Intelligence Features
TwoRoofs uses third-party AI services — currently Google Gemini for working with text, and Amazon Transcribe for turning speech into text — to power the following features:
- Tone analysis of draft messages;
- AI message rewriting into a neutral tone (originals are always preserved);
- AI Concierge that helps draft and negotiate proposals between co-parents;
- Receipt parsing to extract expense details from photos.
- Document transcription — reading the text of a legal record you upload, including photographs of paper documents, so that its wording can be stored and quoted;
- Passage selection — identifying which passages of your uploaded documents bear on a question asked in a shared conversation;
- Voice input — turning something you say into text, on the screens where you can speak instead of typing.
When you use these features, the relevant content is transmitted to the AI provider for processing. We have configured these integrations so that, to our knowledge and per our agreements with the providers, your content is not used to train the providers' general AI models. AI processing logs may be retained by us for debugging, abuse prevention, and quality improvement.
For passage selection, the AI service is given the passages of your documents and returns only identifiers naming which passages to show. The words shown to you are read from our own stored copy of your document, never generated by the AI service. Transcription is different: the AI service produces the text, which is why the other parent in your household is asked to review and accept a document before it is treated as verified, and why passages from a document that has not yet been reviewed are labelled as such wherever they appear.
Voice input, and what happens to the recording. On some screens you can answer by speaking instead of typing. The recording is uploaded to our file storage (Amazon Web Services (S3), Section 7) and transcribed by Amazon Transcribe, and the text is placed in the field so that you can read it and correct it before you send anything. What happens to the recording afterwards depends on why you made it. Where the recording is the thing you are sending — a voice message to your co-parent — the audio is kept alongside that message, in the same way the message itself is kept. Where the recording was only a way of typing — answering a question while planning a custody period — we do not intend to keep it: the App asks the storage service to delete the recording as soon as transcription finishes, whether the transcription succeeded or not. We describe that as our intention rather than as a guarantee, because the deletion is attempted once and is not retried; if the storage service is unavailable at that moment, the recording can remain in our storage. In either case the recording stays in our own storage and with the transcription service described in Section 7 — it is not sent anywhere else, and it is never sent to Google Gemini. Voice answers while planning a custody period are not switched on today, and neither are the AI features that help draft such a plan (reading what a parent types into the planning screens, and looking up a school district's published calendar dates); they are described here so that this Policy is accurate before they are enabled, not because they are processing your information now.
Important AI disclaimers:
- AI output may be inaccurate, incomplete, or inappropriate. You are responsible for reviewing any AI-generated content before relying on or sending it.
- AI-generated content is not legal, financial, medical, or psychological advice.
- The AI Concierge facilitates discussion only and does not make decisions, render judgments, or represent either parent.
- We do not guarantee any particular outcome from use of AI features.
---
7. How We Share Information With Third Parties
We do not sell or rent your personal information, and we do not share it for cross-context behavioral advertising. We share information only as follows:
- With your co-parent / household members, as described in Section 5.
- With service providers that operate the Service under contractual confidentiality and security obligations:
- Google (Gemini API) — AI processing
- Supabase — database and authentication hosting
- Fly.io — application hosting
- Amazon Web Services (S3) — file storage in the United States for receipt photos, images you attach to messages, and the original files of legal records you upload. Files are stored under access-controlled keys and are served only through short-lived links to members of your own household.
- Amazon Web Services (Amazon Transcribe) — turning voice recordings into text. Receives the audio recording you made and returns the transcribed words.
- Sentry — crash and error monitoring (receives error reports, device context, and account identifiers)
- PostHog — product analytics and session replay (receives usage events, device context, account identifiers, and masked session recordings on iOS)
- Apple Push Notification Service / Firebase Cloud Messaging — notification delivery
- Expo (EAS) — app builds and over-the-air updates
- Apple — Apple Sign-In authentication
- For legal and safety reasons: to comply with applicable law, lawful requests by public authorities (including subpoenas and court orders), enforce our Terms, protect the rights, property, or safety of our users or others, or investigate fraud or abuse.
- In a business transfer: in connection with a merger, acquisition, financing, or sale of assets, subject to standard confidentiality protections.
---
8. Data Retention
Because TwoRoofs is designed to produce a court-ready co-parenting record, we retain household content (messages, schedules, expenses, negotiations) for the life of the household account. Specifically:
- Account data: retained while your account is active.
- Household content: retained for as long as the household exists, even if one parent deletes their individual account, because the content also belongs to the other parent's record.
- Legal records you upload: retained for as long as the household exists. Either parent can remove a document at any time. Removing a document stops it being used or quoted going forward, notifies the other parent, and is recorded in the household's audit record — but it is not deletion. The document and the text transcribed from it are retained as part of the household record, and, importantly, any passage already quoted into a conversation stays readable in that conversation after removal. A passage is copied into the message at the moment it is shared, so removing the document later does not take back what has already been shared, in the same way that a message you have already sent cannot be unsent. Uploading a corrected version of a document supersedes the earlier version rather than erasing it.
- Voice recordings: a recording that is itself a message you sent is retained with that message, for as long as the household content it belongs to. A recording made only to be turned into text is not meant to be kept — deletion is requested as soon as transcription finishes — but, as explained in Section 6, that request is attempted once and is not retried, so a recording can remain in our storage if the request fails.
- Custody period plans: a plan both parents have agreed to is retained as an unchangeable snapshot for as long as the household exists, including the assumptions it rested on and any reason a parent wrote in their own words. A later plan supersedes an earlier one rather than erasing it, in the same way a corrected document supersedes the version before it.
- Backups: retained for a limited period after deletion in accordance with our backup rotation schedule.
- Session tokens: expire after 30 days of inactivity.
- Diagnostic and AI logs: retained for a limited period for debugging and abuse prevention.
We may retain information longer where required by law or to resolve disputes.
---
9. Your Privacy Rights and Choices
9.1 In-App Controls
- Access: view your messages, schedules, and expenses at any time within the App.
- Account deletion: Settings → Delete Account permanently deletes your individual account credentials and removes you from your household. As noted above, content you contributed to a shared household record may persist in the other parent's record.
- Notifications and quiet hours: manage in App settings; manage OS-level permissions in your device settings.
- Permissions: revoke camera, contacts, photos, or calendar access in your device settings at any time.
9.2 U.S. State Privacy Rights
Depending on your state of residence (including California, Colorado, Connecticut, Virginia, Utah, Texas, and other states with comprehensive privacy laws), you may have rights to:
- Know/access the personal information we hold about you;
- Correct inaccurate personal information;
- Delete your personal information (subject to the household-record limitations described above);
- Opt out of "sale" or "sharing" for cross-context behavioral advertising — we do not engage in either;
- Be free from discrimination for exercising your rights.
To exercise these rights, email support@tworoofs.us from the email address on your account. We will verify your request and respond within the timeframes required by applicable law. You may also designate an authorized agent. If we deny your request, you may appeal by replying to our response.
California "Shine the Light": We do not share personal information with third parties for their direct marketing purposes.
9.3 Global Privacy Control
We honor recognized opt-out preference signals where required by law.
---
10. Children's Privacy (COPPA)
TwoRoofs is not directed to children under 13 and we do not knowingly collect personal information directly from children under 13 in violation of the Children's Online Privacy Protection Act ("COPPA"). Information about children reaches the Service in three ways, all of them from a parent: the first name and date of birth a parent enters for scheduling; whatever a parent's uploaded legal records happen to contain (see Sections 3.1 and 8); and, where a parent chooses to speak instead of type, whatever a voice recording happens to capture, which can include a child's own voice or speech in the background. Recording happens only while a parent has explicitly started a recording and stops when they stop it — the App never listens continuously (see Section 6). We do not knowingly collect information about children from any other source. If you are a parent or guardian and believe a child has provided personal information directly to us, please contact support@tworoofs.us and we will promptly delete it.
---
11. Security
We use commercially reasonable technical, administrative, and organizational safeguards to protect your information, including:
- Passwords hashed with bcrypt;
- TLS/HTTPS encryption in transit;
- Apple Sign-In tokens verified server-side via Apple's JWKS;
- Session tokens stored in iOS Secure Keychain via expo-secure-store;
- Access controls on our infrastructure.
No system is perfectly secure. We cannot guarantee absolute security, and you use the Service at your own risk. You are responsible for keeping your account credentials confidential and for all activity under your account. Notify us immediately at support@tworoofs.us if you suspect unauthorized access.
---
12. International Users
TwoRoofs is operated from the United States. If you access the Service from outside the U.S., you understand that your information will be transferred to, stored in, and processed in the United States, which may have data protection laws different from those of your country. By using the Service, you consent to such transfer and processing.
---
13. Apple App Store Disclosures
Consistent with Apple's App Store requirements, the categories of data we collect and link to your identity include: contact info (email), user content (messages, photos, legal records you upload, voice recordings, other), identifiers, usage data, diagnostics, and analytics data. Usage data and diagnostics are collected for the purposes of analytics (understanding feature usage via PostHog) and app functionality (diagnosing errors via Sentry), and are linked to your identity. On iOS, masked session replays are collected for analytics and product improvement; all text inputs and images are masked in these recordings. We do not use data for tracking across apps and websites owned by other companies, and we do not collect the Identifier for Advertisers (IDFA). Full details are provided in our App Store privacy label and in this Policy.
---
14. Third-Party Links and Services
The Service may link to third-party websites or services. We are not responsible for the privacy practices of those third parties. Review their privacy policies before providing information.
---
15. Disclaimers and Limitation of Liability
TwoRoofs is a communication and record-keeping tool. We are not a law firm, mediator, mental health provider, or financial advisor, and we do not provide legal, mediation, counseling, or financial advice. Any reliance on the Service, including AI-generated content and stored records, is at your own risk. Admissibility, weight, and use of any record produced by the Service in legal proceedings is determined solely by the relevant court or tribunal, and we make no representation or warranty regarding such use. Your use of the Service is also subject to the disclaimers and limitations of liability in our Terms of Service.
---
16. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you in-app, by email, or by updating the "Last Updated" date above. Your continued use of the Service after changes become effective constitutes acceptance of the revised Policy.
---
17. Contact Us
Questions, requests, or complaints regarding this Privacy Policy or TwoRoofs' privacy practices:
PriceBenchmarKing.AI LLC Attn: TwoRoofs Privacy Email: support@tworoofs.us