Security
Sign-in without passwords
You sign in with a passkey or a one-time link sent to your email. Sign-in links work once and expire after 15 minutes. Invite links work once, only for the invited email, and expire after 7 days. There are no passwords to leak or reuse.
Infrastructure
Casa Cadence runs on Cloudflare: Workers for the app, D1 for the database, R2 for files and Cloudflare Email for sign-in and notification emails. All traffic uses HTTPS.
Access is checked on the server
- Roles (owner, member, helper) are enforced on the server for every request. Helpers reach only the tasks assigned to them.
- Kids mode locks a device to the kids view. Leaving it takes a parent's passcode, with a lockout after repeated misses.
- Shared links use random tokens that we store only in hashed form. Every link expires within 90 days and can be turned off instantly. Shared pages never show notes, contacts, files, people or points, and are hidden from search engines.
Calendar credentials
Google and Microsoft access tokens and iCloud app-specific passwords are encrypted before they're stored. We request the narrowest calendar permissions that sync needs.
Reporting a problem
If you find a security issue, please email hello@casacadence.com with “Security” in the subject. We'll reply promptly and won't take action against good-faith research.
