Names stay hidden from the AI
Before anything is sent to a model, every name and detail is swapped for a neutral tag. The AI works on “Child A”, never your daughter.
Homedays holds where your children are, when, and with whom. That deserves more than a reassuring sentence in a policy. Here is precisely how we protect it, in plain English.
Before anything is sent to a model, every name and detail is swapped for a neutral tag. The AI works on “Child A”, never your daughter.
Your core data is encrypted, so the raw storage holds nothing anyone can read. Not an intruder, and not us.
A grandparent doing Wednesday pickups sees only those days. Adding a new child never quietly opens things up for anyone.
Download everything in one tap, whenever you like. We want to keep you because Homedays is good, not because leaving is hard.
A photo of a newsletter mentioning “Ada, Year 3, trip on 14 March”.
Ada becomes Child A. Names, schools and detail are swapped for neutral tokens on our servers, before anything leaves.
The model extracts “Child A · event · 14 March”. It never receives, and cannot learn, who Child A is.
Homedays maps the tokens back to Ada on our side and shows you the draft event to approve before it saves.
The mapping between real names and tokens never leaves Homedays. The AI provider sees pseudonyms and dates, nothing that identifies a child.
Your core family data is protected with envelope encryption. Each piece of data is locked with its own key, and those keys are themselves locked by a master key held in a managed key vault, separate from the database. If someone walked off with the raw storage, they would hold ciphertext and nothing else.
This is deliberately stronger than “we can see it but promise not to look”. For core data, Homedays staff cannot read your records straight out of storage either. Access is mediated, minimal, and logged.
The caregiver network is powerful because it’s precise. When you invite someone, you choose what they see:
Swaps, approvals and schedule changes are recorded, so there’s a shared, factual history rather than competing memories. Where records must be retained for a legitimate window, they’re kept securely, and an account deletion still removes your personal data. Portability and deletion are treated as rights, not favours.
A single tap produces a complete export of your data, a proper GDPR download. No support ticket, no retention gauntlet. We’d rather earn the next month than trap you in it.
Homedays is early, and we’ll keep this page current as we publish formal policies and, in time, independent assessments. If a security question isn’t answered here, ask us directly at security@oiko.app, a straight question deserves a straight answer.
No. Before a school letter or message reaches a model, a pseudonymisation firewall replaces every name with a placeholder such as “child 1”. The model works on tokens; the real names are restored inside Homedays afterwards, and you confirm anything it drafts.
Not straight out of storage. Core family data is protected with envelope encryption: each item is locked with its own key, and those keys are locked by a master key in a managed key vault separate from the database. Access is mediated, minimal and logged.
You choose per person. A co-parent shares the full picture; a scoped caregiver such as a grandparent doing Wednesday pickups sees only the days and details they need. Adding a new child never automatically widens anyone’s access.
Yes. One tap produces a complete GDPR export, with no support ticket. Account deletion removes your personal data; where records must be kept for a legitimate window they are held securely.
Because a child should not need to manage an app to be looked after by one. Homedays is for the adults around a child; the child is the subject of the calendar, never a user of it.