Security and trust
Built to respect the family information you share.
Reunion Portal combines private family spaces with controls for identity, family membership, content visibility, and subscriptions. Security is ongoing work, so we describe the safeguards the service actually uses and avoid promises no online service can make.
Family-scoped accessMembership, roles, permissions, and feature visibility decide who can open private family information.
Protected sign-inPasswords are stored as salted one-way hashes, sessions are validated server-side, and optional authenticator-based two-step verification is available.
Payment separationStripe handles full card details. Reunion Portal retains the billing identifiers and limited card summary needed to show and manage a subscription.
Purpose-limited operationsAdministrative and diagnostic records are limited to operating, supporting, securing, and auditing the service.
Account protection
Sign-in includes password verification, failed-attempt lockout, protected authentication cookies, expiring server-side sessions, and session revocation after security changes. People may add authenticator-app two-step verification and receive recovery codes. Sensitive account changes can require the current password or an additional verification code.
Family boundaries
A person must have an active membership to enter a private family space. Roles and permissions are assigned per family, so access in one family does not grant access in another. Ownership transfer uses a dedicated workflow, and a family must retain an owner while other account holders remain. A Super Admin role does not by itself grant private family-data access.
Content and messaging
Profile visibility, family membership, content-sharing selections, and feature permissions limit access to family profiles, events, media, recipes, updates, and messages. Messaging includes participant checks, reporting controls, attachment validation, and user data export. People should still avoid placing passwords, payment credentials, government identifiers, or unnecessary sensitive information in family content.
Infrastructure and providers
Production traffic uses encrypted HTTPS connections. SmarterASP hosts the web applications, database, and outgoing email; Cloudflare provides DNS, delivery, and security services; Stripe processes subscriptions and payments; and Google Maps supports optional map and address functions. Application secrets are supplied through protected deployment configuration rather than public source files.
Monitoring and response
We keep bounded authentication, authorization, delivery, administrative, and operational records to investigate failures and suspicious activity. We may revoke sessions, restrict an account, disable a feature, or preserve information when reasonably necessary to contain an incident, protect people, or comply with law.
What you can do
- Use a long password that you do not reuse on another service.
- Turn on two-step verification and store recovery codes somewhere safe.
- Review family roles, invitations, profile visibility, and message settings.
- Sign out on shared devices and report unexpected access promptly.
Report a security concern
Email [email protected] with a concise description, the affected page, and steps that reproduce the issue. Do not send passwords, authentication codes, card details, exploit payloads containing private family content, or other people’s personal information by email.
For information-handling details, read the Privacy Notice. No system can guarantee absolute security.