Privacy Policy

Last updated: August 17, 2026

This Privacy Policy describes how Choresome ("we", "us", or "our") collects, uses, and shares information about you when you use our household chore management application. Choresome is built to be privacy-first: the text you write in the app is end-to-end encrypted so that only the members of your household - not even we - can read it. See Section 2 for details.

1. Information We Collect

We collect the following information when you use Choresome:

  • Account information: Your email address, collected when you sign up via magic link or Google Sign-In.
  • Profile information: A display nickname and a color preference you optionally set within the app. Your nickname is end-to-end encrypted (see Section 2).
  • Chore and activity data: Completion records, tick scores and household activity history generated through your use of the app. The free-text you write - chore names, chore descriptions, tick notes and nicknames - is end-to-end encrypted before it leaves your device. Numeric scores, timestamps and the links between records - which accounts (identified only by an internal ID and email address) belong to a household, and which account a completion is attributed to - are stored as regular data so the app can function.
  • To-do lists and reminders: To-do items, the list they belong to, who completed them and when, and the schedule of any repeat or reminder you set - including the time zone it should fire in. List names, item names and reminder text are end-to-end encrypted (see Section 2); schedules and timestamps are not.
  • Members without an account: A household owner can add members who do not sign in themselves. For these members we store only a nickname and a color chosen by the owner. The nickname is end-to-end encrypted.
  • Notification devices: If you turn on reminders, we store what is needed to deliver a notification to that device: a push address issued by your browser vendor, the keys used to encrypt the message to it, a short description of the browser and device type, and the date it was last active. You can view and remove your registered devices in the app.
  • Billing information: If your household subscribes to Choresome Pro or leaves a tip, our payment provider collects your payment details, billing address and, where you choose to give one, a VAT ID. We never see or store your card details. On our side we keep only your subscription status, renewal date, a customer reference from the payment provider and which account purchased the plan.
  • Feedback you send us: If you use the in-app feedback form, we store your message together with your account so we can read and act on it. Unlike the other text you write in the app, feedback is not end-to-end encrypted.
  • Authentication data: Session tokens and login timestamps used to keep you signed in securely.
  • Technical logs: Our infrastructure providers keep request and sign-in logs containing standard technical connection details, and our own error logs reference internal account identifiers. These are used only to keep the service running securely and to diagnose faults.

If you sign in with Google, we receive your email address and basic profile information (such as your name) as provided by Google. We do not receive your Google password.

2. End-to-End Encryption

When your household turns on encryption, all of the human-readable text you write is encrypted on your own device before it is sent to our servers. This covers chore names and descriptions, your to-do lists and the tasks on them, the text of your reminders, your nickname, and the notes you attach when logging ticks - and because your History and Hall of Fame pages are built from that text, they are protected too.

  • We only ever store ciphertext. We do not hold the key to your household's encrypted content and cannot read it, recover it, or produce it in readable form - even if we were legally compelled to try.
  • Your recovery code stays with you. During setup your household receives a recovery code that unlocks the encryption. We never see or store this code. If every member of a household loses their recovery code, the encrypted content cannot be recovered by anyone, including us.
  • Reminders stay encrypted on the way to your device. The text of a reminder notification travels as ciphertext and is decrypted on your device. Neither we nor the service that delivers the notification can read it.
  • Your own to-do lists are private by access control. Lists you keep to yourself are not shown to other members of your household, but they are encrypted with the same household key - so that separation is enforced by our access rules rather than by encryption.
  • What is not end-to-end encrypted: email addresses, which accounts belong to a household and whether each is an owner or an invited member, numeric tick scores, timestamps, reminder schedules and time zones, billing information, and the feedback you send us. These are needed to run the service and are protected in transit and at rest by the measures described in Section 9, but they are not encrypted with your household's key.

3. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and household.
  • Authenticate your identity and keep your account secure.
  • Display your activity, scores and history within your household.
  • Deliver the reminders and notifications you choose to set up.
  • Process subscription payments and tips, and manage your plan.

Why we ask for your email. We use your email address for two purposes only: to sign you in (we email you a magic login link, or you sign in with Google), and to send and accept household invitations. We do not use your email for marketing, newsletters or advertising. To minimise what is shared, your full email address is only ever sent to the household owner, who needs it to manage invitations. Other members receive just the part before the "@", used as a fallback display name when you have not set a nickname.

We do not use your data for advertising or sell it to third parties.

4. How We Share Your Information

We do not sell, rent, or share your personal information with third parties except in the following cases:

  • Within your household: Your nickname, chore activity, tick notes and activity history are visible to other members of your household - they hold the encryption key, so their devices can decrypt this content. Your full email address is visible only to the household owner, who manages invitations; other members never receive it.
  • Infrastructure providers: Your data is stored and processed on servers located in the EU. We use trusted third-party infrastructure providers who act as data processors on our behalf and are contractually prohibited from using your data for their own purposes. For your encrypted content, these providers only ever handle ciphertext.
  • Payment provider: If you subscribe or leave a tip, we share what is needed to take the payment with our payment provider, who handles it on our behalf and acts as the controller of your payment details.
  • Notification delivery: To deliver a reminder we pass the encrypted message and your device's push address to the push service run by your browser vendor. They deliver the notification but cannot read its contents.
  • Legal requirements: We may disclose your information if required by law or to protect the rights and safety of our users or others. We cannot disclose the contents of your end-to-end encrypted data because we are unable to read it.

5. Third-Party Services

Choresome integrates with the following third-party services, each with their own privacy practices:

  • Google Sign-In (Google LLC): Used as an optional authentication method. Governed by Google's Privacy Policy.
  • Cloudflare Turnstile: Used to protect our login form against automated abuse. Cloudflare may process technical signals from your browser to verify you are human. Governed by Cloudflare's Privacy Policy.
  • Stripe (Stripe, Inc.): Used to process subscription payments and tips, including billing address and tax details. Card details are entered with Stripe and never reach our servers. Governed by Stripe's Privacy Policy.
  • Browser push services: If you enable reminders, the notification is delivered by the push service of your browser or device vendor (such as Apple, Google or Mozilla). They receive your device's push address and the encrypted message, and are governed by their own privacy policies.
  • Vercel Web Analytics (Vercel Inc.): Used for cookieless, aggregate visitor statistics on our public pages only - never inside the signed-in app. See Section 8. Governed by Vercel's Privacy Policy.

6. Data Retention

We retain your personal data for as long as your account is active. If you request account deletion, your data is permanently removed from our systems. Household activity history associated with your account is also deleted upon account removal. Because your content is end-to-end encrypted, deleted ciphertext cannot be read again once the associated keys are gone.

A registered notification device is removed when you remove it or when it stops being valid.

7. Your Rights

You have the right to:

  • Access the personal data we hold about you.
  • Correct inaccurate data (e.g. update your nickname or email).
  • Delete your account and all associated data at any time using the in-app account deletion feature.
  • Object to or restrict certain processing of your data.
  • Receive a copy of your data in a structured, portable format.

To exercise any of these rights, contact us using the details in Section 12. We will respond within one month.

8. Cookies and Analytics

We use cookies solely for authentication session management. We do not use tracking or advertising cookies.

Storage on your device. So the app can work offline and stay unlocked, it keeps some data in your browser's own storage, including your display preferences and a copy of your household's encrypted content. This stays on your device and is never used for tracking. You can remove it using the option in the app to forget this device, or by clearing your browser data.

Analytics. On our public pages only - never inside the signed-in app - we use Vercel Web Analytics to count visits and a few anonymous interactions, such as which button was clicked or whether a login link was requested. It sets no cookies, stores nothing on your device and cannot identify you or recognise you across visits. It never includes your email, your account or anything you write, and we use it only to improve those pages.

9. Security

We use encrypted connections (HTTPS) and secure authentication flows to protect your data in transit, and access controls to protect it at rest. In addition, the text you write in the app is end-to-end encrypted (Section 2): it is encrypted on your device with a key we never hold, so we cannot read it. Your recovery code is the only way to unlock this content, and it is not stored on our servers and cannot be recovered by us if it is lost.

10. GDPR - EU Residents

If you are located in the European Union, the General Data Protection Regulation (GDPR) applies to our processing of your personal data. The legal basis for processing your data is:

  • Contract performance: Processing your email address and account data is necessary to provide the Choresome service, and processing your subscription status and payment reference is necessary to provide a paid plan you have purchased.
  • Legitimate interests: Protecting the service from abuse (e.g. CAPTCHA verification), and measuring aggregate use of our public pages so we can improve them (Section 8).

In addition to the rights listed in Section 7, EU residents also have the right to:

  • Lodge a complaint with your local data protection authority (DPA).
  • Withdraw consent at any time where processing is based on consent.

Your account and household data - including all end-to-end encrypted content - is stored on servers located within the EU. A small number of processors operate outside the EU: the anonymous page statistics described in Section 8 (Vercel Inc.), payment processing (Stripe, Inc.), and the push service that delivers reminder notifications to your device, which receives only encrypted content. These transfers take place under the European Commission's Standard Contractual Clauses or an equivalent safeguard.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. Continued use of Choresome after changes constitutes your acceptance of the revised policy.

12. Who We Are and How to Contact Us

Choresome is operated by Santeri Kangas, who is the data controller responsible for the personal data described in this policy.

For any privacy question, or to exercise the rights in Section 7, email support@choresome.app. If you are signed in, you can also reach us with the feedback form in the app. We answer privacy requests within one month, and you do not need an account to contact us.