Security & Compliance
PersonVersion is a personal app. The information you put in it is yours, and keeping it safe is something we take seriously. This page explains, in plain language, how your data is protected and who has access to what.
Your data is encrypted, always
Every connection to PersonVersion uses HTTPS, which means your information travels between your device and our servers in an encrypted tunnel that nobody else can read. Your data is also encrypted at rest inside our database using AES-256, the same standard used by banks and governments worldwide. In plain terms: even if someone somehow got access to the physical storage, they would see nothing but scrambled noise.
Built on infrastructure you can trust
PersonVersion runs on Railway, which is built on top of Google Cloud Platform. Railway holds SOC 2 Type II certification and ISO 27001 compliance. Google Cloud holds over 40 security certifications including FedRAMP, PCI DSS, and HIPAA. Our database is never exposed to the public internet, all services run in isolated containers, and daily automated backups mean your data can be recovered even in worst-case scenarios.
Passwords are never stored in plain text
When you create a password, we immediately run it through a process called bcrypt hashing before storing anything. This means your actual password never touches our database. What we store is a mathematical fingerprint that can verify your password at login but cannot be reversed to reveal it. Even the people who built PersonVersion cannot see your password. Password reset links expire within one hour and can only be used once.
Email handled by Resend
We send emails (like password resets and your birthday changelog) through Resend, a provider that is SOC 2 Type II certified and runs on AWS. We only share your name and email address with Resend, nothing else. Your goals, chores, family data, and any other personal content stay entirely within PersonVersion's own infrastructure.
Payments handled by Stripe
The optional Superuser upgrade is processed by Stripe, which is certified at PCI DSS Level 1, the highest level of payment security certification available. Your card details are entered directly into Stripe's secure interface and never pass through PersonVersion's servers at any point. We simply receive a confirmation that the payment was successful.
Location sharing is one-time, not live tracking
When you share your location with someone, we use your device's built-in location capability to get your current coordinates at that moment, send them an email with a Google Maps link, and then discard the coordinates immediately. We do not store your location on our servers. There is no persistent location tracking of any kind.
Protection against common attacks
PersonVersion includes protection against cross-site request forgery (CSRF), which prevents malicious websites from performing actions on your behalf without your knowledge. Sessions use cryptographically signed, HTTP-only cookies that expire after 7 days. Our infrastructure benefits from DDoS protection at the network edge, which shields the service during large-scale automated attacks.
Delete your account, delete your data
If you decide to leave, you can delete your account from the Settings page at any time. When you do, every piece of data associated with your account, including your profile, goals, chores, achievements, shopping lists, tracker history, family connections, and all other records, is permanently and irreversibly deleted from our database. There are no hidden backups retained after deletion.
GDPR and privacy compliance
PersonVersion is designed with privacy as a default, not an afterthought. We collect only the information needed to run the service: your first name, birthday, and email address. No advertising networks, no third-party analytics, no selling of personal data. If you are based in the European Union, your data is handled in accordance with the General Data Protection Regulation (GDPR).
Infrastructure partners
PersonVersion uses the following certified third-party providers. We do not manage physical servers ourselves.
Railway
Hosting & database
SOC 2 Type II, ISO 27001
Stripe
Payments
PCI DSS Level 1
Resend
Email delivery
SOC 2 Type II
Questions or concerns?
If you have a question about how your data is handled, or if you believe you have found a security issue, please reach out directly at personversion@gmail.com. We will respond as quickly as possible.