Trust

Security at Pipa

🔒 Read-only inbox access
🇬🇧 UK/EU data residency
📧 hello@pipa-assist.co.uk

Pipa reads school emails, so we hold ourselves to the standard you'd expect of something that touches your family's inbox. This page explains, in plain English, how the service is secured. For what data we collect and why, see the privacy notice.

1 Why Security Matters Here

Pipa processes school communications that mention children's names, classes and school events. We treat every part of that as sensitive: we collect the minimum needed to send the right reminder to the right parent, and we design the service so the impact of anything going wrong is as small as possible.

2 Email Account Access

  • Read-only, always. If you connect Gmail or Outlook, Pipa requests read-only access. We cannot send, delete or modify anything in your inbox.
  • Google-verified. Our Gmail integration goes through Google's verification process for restricted scopes, including an annual independent CASA security assessment by an authorised lab.
  • Limited Use. Use of Google data follows the Google API Services User Data Policy, including the Limited Use requirements: never used for advertising, never sold, never used to train generalised AI models.
  • Forwarding works too. If you'd rather not connect an inbox at all, you can simply forward school emails to your personal Pipa address — access on your terms.
  • Revoke any time. You can disconnect a linked inbox from your Google or Microsoft account settings at any moment, and access stops immediately.

3 Infrastructure & Encryption

  • Encryption in transit. All traffic uses HTTPS/TLS, enforced with HTTP Strict Transport Security. A strict Content Security Policy protects the public site against script injection.
  • UK/EU data residency. Your data is stored and processed only within the UK and EU, with trusted providers named in our privacy notice (hosting with DigitalOcean, transactional email with Postmark).
  • Restricted access. Production systems are password-protected with access limited to authorised Pipa team members, and administrative actions are captured in audit logs.
  • Encrypted backups. Nightly encrypted backups with restricted access, so your reminders survive a bad day without widening exposure.

4 Data Retention & Deletion

  • Forwarded emails are deleted after processing, or within 60 days at most.
  • Message history is kept for 12 months.
  • Audit logs are retained for a minimum of 12 months.
  • When you close your account, your personal data is deleted in line with the retention periods in the privacy notice.

5 Payments

Card payments are handled by Stripe, a PCI-DSS Level 1 certified payment processor. Your card details go directly to Stripe and never touch Pipa's servers.

6 Reporting a Concern

If you believe you've found a security vulnerability in Pipa, please tell us — we'd genuinely rather know.

🛡️

Security reports: hello@pipa-assist.co.uk
Data & privacy enquiries: privacy@pipa-assist.co.uk

Please include enough detail to reproduce the issue. We ask that you don't access other people's data or disrupt the service while investigating, and we won't take action against good-faith research.