Privacy Policy
Last updated: July 10, 2026
This Privacy Policy describes how Choresome("we", "us", or "our") collects, uses, and shares information about you when you use our household chore management application. Choresome is built to be privacy-first: the text you write in the app is end-to-end encrypted so that only the members of your household - not even we - can read it. See Section 2 for details.
1. Information We Collect
We collect the following information when you use Choresome:
- Account information: Your email address, collected when you sign up via magic link or Google Sign-In.
- Profile information: A display nickname and a color preference you optionally set within the app. Your nickname is end-to-end encrypted (see Section 2).
- Chore and activity data: Chore assignments, completion records, tick scores and household activity history generated through your use of the app. The free-text you write - chore names, chore descriptions, tick notes and nicknames - is end-to-end encrypted before it leaves your device. Numeric scores, timestamps and the links between records - which accounts (identified only by an internal ID and email address) belong to a household, and which account a completion is attributed to - are stored as regular data so the app can function.
- Authentication data: Session tokens and login timestamps used to keep you signed in securely.
If you sign in with Google, we receive your email address and basic profile information (such as your name) as provided by Google. We do not receive your Google password.
2. End-to-End Encryption
When your household turns on encryption, all of the human-readable text you write is encrypted on your own device before it is sent to our servers. This covers chore names and descriptions, your nickname, and the notes you attach when logging ticks - and because your History and Hall of Fame pages are built from that text, they are protected too.
- We only ever store ciphertext.We do not hold the key to your household's encrypted content and cannot read it, recover it, or produce it in readable form - even if we were legally compelled to try.
- Your recovery code stays with you. During setup your household receives a recovery code that unlocks the encryption. We never see or store this code. If every member of a household loses their recovery code, the encrypted content cannot be recovered by anyone, including us.
- What is not end-to-end encrypted:email addresses, which accounts belong to a household and whether each is an owner or an invited member, numeric tick scores, and timestamps. These are needed to run the service and are protected in transit and at rest by the measures described in Section 9, but they are not encrypted with your household's key.
3. How We Use Your Information
We use the information we collect to:
- Create and manage your account and household.
- Authenticate your identity and keep your account secure.
- Display your activity, scores and history within your household.
Why we ask for your email.We use your email address for two purposes only: to sign you in (we email you a magic login link, or you sign in with Google), and to send and accept household invitations. We do not use your email for marketing, newsletters or advertising. To minimise what is shared, other household members only see the part of your email address before the "@" as a fallback display name when you have not set a nickname.
We do not use your data for advertising or sell it to third parties.
4. How We Share Your Information
We do not sell, rent, or share your personal information with third parties except in the following cases:
- Within your household: Your nickname, chore activity, tick notes and activity history are visible to other members of your household - they hold the encryption key, so their devices can decrypt this content. Your email address is also visible to members of your household so invitations can be managed.
- Infrastructure providers: Your data is stored and processed on servers located in the EU. We use trusted third-party infrastructure providers who act as data processors on our behalf and are contractually prohibited from using your data for their own purposes. For your encrypted content, these providers only ever handle ciphertext.
- Legal requirements: We may disclose your information if required by law or to protect the rights and safety of our users or others. We cannot disclose the contents of your end-to-end encrypted data because we are unable to read it.
5. Third-Party Services
Choresome integrates with the following third-party services, each with their own privacy practices:
- Google Sign-In (Google LLC): Used as an optional authentication method. Governed by Google's Privacy Policy.
- Cloudflare Turnstile: Used to protect our login form against automated abuse. Cloudflare may process technical signals from your browser to verify you are human. Governed by Cloudflare's Privacy Policy.
6. Data Retention
We retain your personal data for as long as your account is active. If you request account deletion, your data is permanently removed from our systems. Household activity history associated with your account is also deleted upon account removal. Because your content is end-to-end encrypted, deleted ciphertext cannot be read again once the associated keys are gone.
7. Your Rights
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate data (e.g. update your nickname or email).
- Delete your account and all associated data at any time using the in-app account deletion feature.
- Object to or restrict certain processing of your data.
- Data portability: Request a copy of your data in a structured format.
8. Cookies
We use cookies solely for authentication session management. We do not use tracking or advertising cookies.
9. Security
We use encrypted connections (HTTPS) and secure authentication flows to protect your data in transit, and access controls to protect it at rest. In addition, the text you write in the app is end-to-end encrypted (Section 2): it is encrypted on your device with a key we never hold, so we cannot read it. Your recovery code is the only way to unlock this content, and it is not stored on our servers and cannot be recovered by us if it is lost.
10. GDPR - EU Residents
If you are located in the European Union, the General Data Protection Regulation (GDPR) applies to our processing of your personal data. The legal basis for processing your data is:
- Contract performance: Processing your email address and account data is necessary to provide the Choresome service.
- Legitimate interests: Protecting the service from abuse (e.g. CAPTCHA verification).
In addition to the rights listed in Section 7, EU residents also have the right to:
- Lodge a complaint with your local data protection authority (DPA).
- Withdraw consent at any time where processing is based on consent.
Your data is stored on servers located within the EU and is not transferred outside the EU.
11. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will update the "last updated" date at the top of this page. Continued use of Choresome after changes constitutes your acceptance of the revised policy.