Handoff
Handoff support
Last updated 15 September 2026.
Handoff keeps one shared record between two co-parents: a message log neither of you can alter, the expenses between two households, and an export of the whole thing that either of you can produce.
Why you cannot edit or delete a message
Once a message is sent, neither party can change it or remove it, and that includes the person who wrote it. Each message also carries a cryptographic hash of the message before it, so altering, removing or reordering any message breaks every hash that follows.
A record only one person can revise is not a record. The composer says so above the box before you write rather than after you send, because people put things in anger they would not put in writing knowing a judge might read them.
Why an export cannot be filtered
An export covers every message between you both in the period, including your own, in the order things happened, with the expense record alongside it. There is no author filter and no keyword filter, and there will not be one. Exporting only the other parent's worst week is the most obvious way this app could be misused, so whoever exports also exports themselves.
What an export proves, and what it does not
Every export states this on its own first page, in full:
- It shows that messages were not altered after being sent. It says nothing about whether what they say is true.
- Timestamps come from the server's clock. This is not an independent timestamping authority.
- The chain alone cannot prove that messages after the last one shown were not left out, so the export prints the total message count and the final chain hash on its face, for the other party to check against their own copy.
Verification runs immediately before an export is built, and its result goes into the document whether it passed or failed. Either of you can also run "Check the record has not been altered" on the Account screen at any time, because the person receiving an export should be able to check it.
We are not a party to your matter and nothing here is legal advice.
How the balance is worked out
The Money tab shows one netted figure rather than two running totals, because the amount that has to be settled is one number. Only expenses you have both agreed count toward it: anything open or disputed is not a debt, and anything settled is already paid, so neither of you can inflate what you are owed by raising things the other never accepted. There are no read receipts anywhere.
The percentage on an expense is the share you are asking the other parent for. It defaults to half and is never assumed, because orders often specify something else.
Once the other parent has responded, an expense is fixed. A mistake is corrected by raising a new one, which leaves both versions visible.
Joining an arrangement
One of you creates the arrangement and generates an invite code on the Account screen. The code works once and lasts seven days. After the other parent joins, neither of you can remove the other, and there is no owner: an owner here would be a lever, because whoever signed up first could delete the shared record before a hearing. The name you set on Account is what the other parent sees beside your messages; your email address is never shown to them.
If you leave and delete your account
Deleting your account removes your own profile and ends your access to the arrangement. It does not erase the shared record. The other parent keeps the log and the expenses, and your messages stay in it under the name you had when you wrote them.
Your data
Signing in is a code sent to your email address; there is no password. Handoff holds the arrangement, the parties in it, the children it concerns, every message with the time it was sent, and every expense. It stores no location, no phone number, no court file and no card details, and nothing in your arrangement is sent to a language model. The full policy is at carrierpress.com/handoff/privacy.
Contact
One person reads that, so a reply may take a few days.
Handoff is published by Jeffrey L Carrier.