Privacy Policy
Last updated: 19/07/2026
1. Who we are
All in Hand is an ultra-secure digital household handbook for the UK. It helps a household record the practical information a family relies on — bills, children’s health and school details, emergency contacts, home practicalities and more — and share precisely scoped parts of it with the people they choose.
For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), the data controller is [Company details to be confirmed]. Our company registration number and registered office are placeholders pending confirmation. If you have any questions about this notice or how we handle your data, contact us at privacy@allinhand.com.
2. The data we collect
We collect and process the following categories of personal data.
- Account and identity data — your name, email address, authentication credentials (via our sign-in provider), and records of the devices and sessions you use to sign in.
- Handbook content — the structured answers, notes, documents and photographs you add to your household handbook. This tier is encrypted, and our staff cannot read it in the normal course of operating the service.
- Secrets Vault data — the most sensitive credentials you choose to store are held in a zero-knowledge vault. We store this data only as ciphertext (encrypted on your device) together with technical metadata such as item counts, timestamps and access logs. We cannot read your vault contents — it is cryptographically impossible for us to do so — and we cannot recover them if you lose your keys (see sections 7 and 8).
- Payment data — subscriptions are handled by Stripe. Card details are entered directly with Stripe and are never seen by or stored on our servers; we hold only your subscription state and the tokens Stripe returns.
- Usage, security and audit data — technical logs, security events and an append-only audit trail of security-relevant actions (such as sign-ins, sharing changes and vault access). These are designed to minimise personal data and never contain your handbook or vault content.
3. Special-category data (including children’s health)
Some handbook sections are designed to hold health information — for example a child’s allergies, medications, conditions or vaccination history. This is special-category data under Article 9 of the UK GDPR, and much of it is about children.
Where you enter this information we rely on your explicit consent (Article 9(2)(a)), captured with a clear, separate, affirmative step the first time a health section is used, recorded per person. A parent or guardian provides consent for their child. You can withdraw consent in your settings; withdrawal is as easy to give as to withdraw and triggers deletion or de-specialisation of the affected fields. We do not rely on any health or social-care condition — we are not a care provider.
4. People other than our users
Your handbook may contain details of other people — a cleaner, a GP, a neighbour who holds a spare key, an emergency contact. When you record this information for your own household purposes, a personal or household-activity exemption applies to you. It does not apply to us: we process those third parties’ personal data as a controller.
If you are someone whose details have been recorded in an All in Hand household and you want to exercise your rights, contact us at privacy@allinhand.com and we will handle your request as described in section 9. We ask our users to record other people’s data responsibly, and our Terms of Service require this.
5. How and why we use your data
We use your personal data to:
- create and secure your account, and manage your devices and sessions;
- store and serve your handbook so you and the people you choose can rely on it;
- provide features you configure — smart reminders and notifications, sharing, and the optional AI assistant, which answers your natural-language questions only from your own stored handbook data (it never accesses your vault), processed in the UK region via AWS Bedrock;
- take payment and manage your subscription through Stripe;
- keep the service secure — detecting and preventing abuse, and maintaining audit and security logs;
- meet our legal obligations and respond to your data-protection requests.
We do not sell your data, we do not advertise against it, and we do not use it to train machine-learning models. Our AI provider processes your data in-region with zero data retention and does not train on it.
6. Lawful bases
Depending on the activity, we rely on the following lawful bases under Article 6:
- Contract — to create your account and deliver the handbook, sharing, reminders, AI assistant and billing you sign up for.
- Legitimate interests — for security, fraud/abuse prevention, minimal product analytics, and for processing the details of third parties recorded by our users. Where we rely on legitimate interests we balance them against your rights.
- Legal obligation — for example keeping billing and tax records, and handling data-protection requests.
- Consent — for special-category (health) data (see section 3) and for marketing email (see section 12).
7. Security and the two encryption tiers
Security is central to the design of All in Hand. If our servers were stolen, an attacker would obtain only encrypted data. We use two deliberately different tiers:
- The handbook tier is encrypted using server-side envelope encryption. This lets us provide search, reminders and the AI assistant. Our staff cannot read your content in normal operation; any exceptional access is tightly controlled, dual-authorised, audited, and notified to you.
- The Secrets Vault is end-to-end, zero-knowledge encrypted. All vault encryption happens on your device. We only ever hold ciphertext, public keys and metadata. We cannot read vault contents, we cannot include them in search, notifications, exports or AI answers, and we cannot decrypt them for anyone — including law enforcement, to whom we could only ever hand over ciphertext and metadata.
8. Where your data is stored and international transfers
We host and process personal data in the United Kingdom (AWS London region, eu-west-2), including AI inference and document text-extraction. Our aim is to keep plaintext in-region.
Where a limited transfer outside the UK is unavoidable (for example certain onward transfers by our payment provider, or a support tool), we rely on an approved transfer mechanism — UK adequacy where it applies, or the ICO’s International Data Transfer Agreement or the EU Standard Contractual Clauses with the UK Addendum — with a transfer risk assessment on file.
9. Who we share your data with
We share personal data only in these ways:
- People you choose — the household members, trustees and guests you invite see exactly the parts of your handbook you share with them, and no more.
- Our service providers (sub-processors), acting on our instructions, by category: cloud hosting, storage, key management, email delivery, document text-extraction and AI inference (Amazon Web Services, UK region); payments (Stripe); error monitoring (EU-hosted, with personal data scrubbed); and mobile push delivery (Apple and Google — notification bodies never contain vault or health content). We publish and keep our sub-processor list current.
- Authorities — where we are legally required to. We would challenge over-broad orders and notify you unless legally barred. We could never disclose vault plaintext, because we do not hold the keys.
10. How long we keep it, and erasure
We keep your data for as long as your household subscription is active, followed by a short read-only grace period during which you can export it, after which handbook and vault data are erased. Account records are removed shortly after account closure. Some records are kept longer where the law requires — for example billing and tax records.
We erase encrypted data by crypto-shredding: destroying the encryption keys renders the corresponding data permanently unreadable everywhere it exists, including in backups, which then expire on their own schedule. Specific retention periods are being finalised and will be confirmed before launch.
11. Your rights
Under UK data protection law you have the right to:
- access the personal data we hold about you;
- have inaccurate data corrected;
- have your data erased in certain circumstances;
- receive a copy of certain data in a portable, machine-readable format;
- object to, or restrict, certain processing; and
- withdraw any consent you have given, at any time.
You can make a data-subject access request (DSAR) by contacting privacy@allinhand.com; we will verify your identity and respond within one calendar month. Because household members may record information about one another, a request about you covers data about you wherever it was entered, while protecting other people’s information in the same records. For the vault we can only ever return ciphertext, metadata and access logs, because we cannot decrypt the contents.
12. Cookies and marketing
Our public marketing pages use privacy-friendly, cookieless analytics that fall within the “strictly necessary” exemption; we do not use advertising trackers. Any conversion or marketing tags are gated behind your consent, in line with PECR. The authenticated app is never indexed and carries no advertising cookies.
We send marketing email only if you have opted in, and we keep it separate from essential service messages (such as billing and security alerts). Every marketing email includes a one-click unsubscribe that we honour immediately.
13. Children
The service is used by adults to manage their household. Children do not have their own logins; where a child’s information is recorded, it is managed by a responsible adult under the explicit-consent arrangements in section 3. A child of sufficient maturity may exercise their own rights over data recorded about them — contact us and we will handle the request sensitively.
14. Contact and complaints
- Data protection: privacy@allinhand.com
- Security: security@allinhand.com
If you are unhappy with how we have handled your data, you have the right to complain to the Information Commissioner’s Office (ICO), the UK supervisory authority, at ico.org.uk. We would appreciate the chance to resolve your concern first.
15. Changes to this policy
We may update this policy from time to time. When we make material changes we will update the “last updated” date above and, where appropriate, tell you directly. This policy was last updated on 19/07/2026.