Legal

How Tiptoe protects your data

Where information is stored, how it is separated, and how to report a vulnerability.

Storage and encryption

Tiptoe stores account and couple data in AWS in us-east-2, Ohio. The configured data stores use encryption at rest. Connections to Tiptoe use HTTPS and encryption in transit.

Encryption reduces risk, but no online service can promise perfect security. Tiptoe does not claim end-to-end encryption.

Partner-private data partitioning

Shared records use the couple's shared data partition. Partner-private records use a user-specific partition, and private API routes are scoped to the signed-in user. A partner cannot ask a shared route to include the other person's private data. Gift ideas, private topic drafts, private votes, and check-in answers before reveal follow those access rules.

Accounts and service providers

The web app keeps session tokens in Secure, HttpOnly, SameSite=Lax cookies. AWS Cognito handles authentication. Stripe handles web payment details, and Apple handles iPhone purchase details. Optional AI processing and Google Calendar access occur only for the connected or consented feature described in the Privacy Policy.

Report a vulnerability

Email [email protected] with the affected URL or feature, steps to reproduce, likely impact, and a safe proof of concept. Do not access another person's account, change or destroy data, degrade the service, or include sensitive user data in the report. We do not publish a bug-bounty promise on this page.