Privacy Policy
Last updated: August 21, 2026
1. Introduction
ChoreKeep ("we," "our," or "us") operates this website and the ChoreKeep mobile application for Android and iOS. Public availability may vary by platform during rollout. The website is located at https://chorekeepapp.com (collectively, the "Service"). ChoreKeep is operated by an individual developer based in the United States.
This Privacy Policy explains what information we collect, how we use and share it, and the choices you have. By using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
This Privacy Policy is designed to comply with the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), the California Online Privacy Protection Act (CalOPPA), and, where applicable, the General Data Protection Regulation (GDPR).
2. Information We Collect
2.1 Information You Provide Directly
- Account information — first name, last name, and email address when you sign up with email, or the account details you authorize when you use Google Sign-In or Sign in with Apple. Apple may provide a private relay email address if you choose to hide your email.
- Sign in with Apple authorization — when you use Sign in with Apple, we retain an encrypted refresh token solely so we can revoke Apple's authorization if you delete your ChoreKeep account. The token is not available to other users or used for advertising.
- Password — if you register with email and password. Your password is cryptographically hashed by our backend provider (Supabase) using bcrypt and is never stored in plain text. We cannot read your password.
- Profile photo — if you choose to upload a profile picture. Images are resized and compressed on your device before upload. Alternatively, a randomly generated avatar is used (no photo required).
- Household data — household name, optional description, and optional household photo.
- Chore data — chore titles, descriptions, effort levels, due dates and times, recurrence rules, assignments, completion status, and completion notes.
- Feedback & bug reports — if you voluntarily submit feedback through the app, we include your account name, email address, and internal user ID with the message. Bug reports may also include the affected screen, a description, and steps to reproduce the issue.
- Safety reports and blocking — report categories, optional report details, the authenticated reporter ID, household context, target type and ID, a server-generated snapshot of the reported member or content, report status and review timestamps, and household-scoped member-block relationships with their timestamps.
Public media URLs: Profile photos and household photos are currently stored in public media buckets. The app limits who may upload, replace, or delete these files, but the image itself can be viewed by anyone who has its URL. These URLs are difficult to guess but should be treated as bearer links; they may continue to work after someone leaves a household until the image is replaced or deleted.
2.2 Information Collected Automatically
- Device identifiers — device ID, device unique ID, device name, and platform (iOS or Android) are collected when you grant permission for push notifications.
- Push notification tokens — an Expo push token is generated and stored to deliver push notifications to your device.
- Notification preferences — your in-app choices for assignment notifications and reminder notifications.
- Diagnostics and performance data — error stack traces, device type, OS version, and sampled app performance timings may be sent to Sentry. Where diagnostic session replay is enabled in development or preview builds, all text, images, and vector content are masked. We configure Sentry not to send your name, email, or chore content.
- Product analytics data — we use PostHog, a product analytics service, to understand how users interact with the app. This includes screen views, feature usage events (such as creating chores, joining households, or managing subscriptions), and device environment information. The Internet Protocol (IP) address associated with an analytics request is used by PostHog to infer approximate geographic information, such as country, region, city, postal area, time zone, and approximate latitude and longitude. We use this information to understand regional usage and improve ChoreKeep. We do not request device location permissions or collect precise GPS location. When you are signed in, this data is associated with your internal user ID. Chore content, invite codes, email address, and display name are not intentionally sent to PostHog. You can opt out of analytics tracking at any time from Settings → Analytics in the app.
2.3 Information Stored Only on Your Device
Certain preferences — such as your chosen theme (light, dark, or system), week start day, chore feed layout, and filter settings — are stored locally on your device using MMKV-backed device storage and are not transmitted to our servers.
3. Information We Do Not Collect
We want to be transparent about the data we do not collect:
- Precise GPS location or location obtained through device location permissions
- Contacts or phonebook data
- Phone number or user-provided mailing address
- Call logs or SMS messages
- Browsing history outside of ChoreKeep
- Data shared with advertising networks or data brokers (we do not share data for targeted advertising)
- Payment-card or bank-account details. Purchases are processed by Apple or Google; we receive subscription and entitlement status through RevenueCat but do not receive your full payment credentials.
The mobile app does not use cookies. The website (chorekeepapp.com) may use essential, strictly-necessary cookies for site functionality but does not use tracking or advertising cookies.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and operate the Service — create and manage your account, synchronize chore and household data between household members, and display your content in the app.
- Send push notifications — deliver chore assignment alerts and reminder notifications you have configured.
- Send transactional emails — email confirmation upon sign-up, password reset emails, and other necessary account or service messages. We do not send marketing or promotional emails.
- Process feedback — if you submit a bug report or feedback, we use the information to investigate and improve the Service.
- Review safety reports — investigate reports, preserve the minimum content snapshot needed for a fair review, and apply content, member, household, or account restrictions when appropriate.
- Monitor errors and improve stability — anonymous crash and error data helps us identify and fix bugs.
- Maintain security — detect and prevent fraud, abuse, or unauthorized access to accounts.
- Analyze feature usage — understand which features are most useful so we can improve the Service and prioritize new development.
- Comply with legal obligations — respond to lawful requests and enforce our Terms of Service.
5. How We Share Your Information
We do not sell, rent, or trade your personal information to third parties. We do not share your personal information for cross-context behavioral advertising. We share data only with the following categories of service providers, solely as necessary to operate the Service:
| Provider | Purpose | Data Shared |
|---|---|---|
| Apple | Apple Sign-In and App Store billing | Authentication tokens and account details you authorize; purchase and subscription transactions processed by Apple |
| Supabase | Database, authentication, file storage, server-side functions | Account data, profile data, household and chore data, avatar/photo files, and an encrypted Apple revocation token when Sign in with Apple is used |
| RevenueCat | Subscription and entitlement management | Internal user ID, app-store purchase records, subscription status, and entitlement status |
| Sentry | Error monitoring and sampled performance diagnostics | Error stack traces, device and OS information, sampled performance timings, and masked diagnostic replay data where enabled. Default PII collection is disabled. |
| Google Sign-In and Google Play billing | OAuth tokens, name, and email address when you choose Google Sign-In; purchase and subscription transactions processed by Google Play | |
| Expo (EAS) | Push notification delivery | Expo push tokens and device identifiers |
| Resend | Transactional email delivery | Account name, email address, internal user ID, feedback or bug-report content, affected screen, reproduction steps, and safety-report category, details, target metadata, and content snapshot |
| PostHog | Product analytics | Screen views, allowlisted navigation properties, feature usage events, internal user ID, and app/device environment. PostHog also uses the IP address associated with an analytics request to derive approximate geographic information. You can opt out in Settings. |
We may also disclose your information if required to do so by law, or in the good-faith belief that such action is necessary to comply with a court order, subpoena, or legal process; to protect and defend our rights or property; or to prevent fraud or abuse of the Service.
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service. When you delete your account (available in Settings → Account Settings → Delete Account within the app), we permanently delete:
- Your profile and authentication records
- Household memberships and associated role data
- Households where you are the only active member, including their chores, instances, reminders, and notification records
- Reminders and notification preferences
- Push notification tokens and device registration data
- Your avatar files and photos belonging to sole-member households from our cloud storage
If other active members remain in a household, its chore and completion history is retained for those members. References identifying you as a chore creator or completer are removed or set to a non-identifying deleted-member state. A sole administrator must transfer administrator access before account deletion can proceed.
We retain a limited deletion-job record so failed or partial backend cleanup can be retried and audited. Safety reports, block records, support emails, and other records required for security, fraud prevention, legal compliance, or dispute resolution may also be retained only as long as reasonably necessary for those purposes.
Anonymized error logs in Sentry may persist for up to 90 days after account deletion as part of Sentry's standard retention cycle, but these logs contain no personally identifiable information.
Analytics data sent to PostHog is retained according to PostHog's standard data retention policies while your account is active. If you opt out of analytics, no new events will be captured, but previously collected events remain subject to PostHog's retention schedule. When you delete your account, our backend requests deletion of the PostHog person record and identified events associated with your internal user ID. PostHog processes this request asynchronously, so those records may remain briefly while the request is being completed. Aggregated or anonymized results, and operational records that no longer identify you, may remain.
App-store transaction records and subscription information may remain with Apple, Google, and RevenueCat according to their legal obligations and retention policies. Deleting your ChoreKeep account does not cancel an active app-store subscription; cancellation must be completed through the applicable store.
7. Data Security
We implement appropriate technical and organizational measures to protect your personal information, including:
- Encryption in transit — all communication between the app and our servers uses HTTPS/TLS encryption.
- Secure credential storage — authentication tokens are stored in your device's secure enclave (iOS Keychain / Android Keystore), not in plain storage.
- Password hashing — passwords are hashed using bcrypt via Supabase Auth.
- Row Level Security (RLS) — database-level access controls ensure users can only access their own data and data shared within their households.
- Image processing — photos are resized and compressed on your device before upload to minimize data exposure.
While we strive to protect your personal information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.
8. Your Rights and Choices
8.1 All Users
- Access and correct your data — you can view and update your profile information at any time in the app.
- Delete your account and data — you can permanently delete your account and personal data, subject to the shared-household and limited operational-retention rules described in Section 6, from Settings → Account Settings → Delete Account in the app.
- Data export — you may request an export of your personal data by emailing us at [email protected].
- Opt out of push notifications — you can disable push notifications through your device settings or the in-app notification preferences screen.
- Opt out of product analytics — you can disable analytics tracking at any time from Settings → Analytics in the app. When opted out, no usage events, screen views, or identifying information will be sent to our analytics provider (PostHog).
- Withdraw from households — you can leave a household, subject to any administrator-transfer requirement, which removes your access to that household's shared data.
8.2 California Residents — CCPA/CPRA Rights
If you are a California resident, you have the following rights under the California Consumer Privacy Act as amended by the California Privacy Rights Act (collectively, "CCPA"):
- Right to Know — you have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources from which information is collected, the business purpose for collecting the information, and the categories of third parties with which we share the information.
- Right to Delete — you have the right to request deletion of personal information we have collected from you, subject to certain exceptions.
- Right to Correct — you have the right to request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing — we do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. Therefore, there is no need to opt out, but you retain this right.
- Right to Limit Use of Sensitive Personal Information — we only use sensitive personal information (such as account login credentials) as necessary to provide the Service. We do not use sensitive personal information for any purpose other than providing the Service.
- Right to Non-Discrimination — we will not discriminate against you for exercising any of your CCPA rights.
Categories of personal information collected (as defined by the CCPA): Identifiers (name, email address, device identifiers); Internet or electronic network activity information (error logs); and other information that relates to or could reasonably be linked with you (chore data, household data, profile photos).
We have not sold or shared personal information of any consumer in the preceding 12 months.
To exercise your CCPA rights, please email us at [email protected] with "CCPA Request" in the subject line. We will verify your identity and respond within 45 days as required by law.
8.3 California Residents — CalOPPA Compliance
In accordance with the California Online Privacy Protection Act (CalOPPA):
- This Privacy Policy is conspicuously posted and accessible from our home page and within the mobile app under Settings → Privacy Policy.
- The "Last updated" date at the top of this page indicates when this policy was last modified.
- Users will be notified of material changes to this policy via an update to the "Last updated" date and, for significant changes, through in-app notifications or email.
- Do Not Track (DNT) Disclosure — ChoreKeep does not track users across third-party websites or services. We use first-party product analytics (PostHog) to understand app usage and improve the Service. This is not cross-site tracking and does not respond to Do Not Track browser signals. You can opt out of analytics tracking from Settings → Analytics in the app.
- Third parties cannot collect personally identifiable information about your online activities over time and across different websites or services when you use ChoreKeep.
- PostHog analytics data is not shared with third parties for their own purposes.
8.4 European Economic Area, United Kingdom & Switzerland — GDPR Rights
If you are located in the European Economic Area (EEA), United Kingdom, or Switzerland, the following additional provisions apply:
Data controller: ChoreKeep, operated by an individual developer. Contact: [email protected].
Lawful bases for processing:
- Performance of a contract — processing your account, profile, household, and chore data is necessary to provide the Service you signed up for.
- Legitimate interest — error monitoring, crash reporting, and product analytics help us maintain and improve the Service. You can opt out of product analytics at any time from Settings → Analytics in the app.
- Consent — push notifications are only sent after you grant notification permission. You can withdraw consent at any time.
Your rights under the GDPR:
- Right of access — request a copy of the personal data we hold about you.
- Right to rectification — request correction of inaccurate or incomplete data.
- Right to erasure ("right to be forgotten") — request deletion of your personal data.
- Right to data portability — receive your data in a structured, commonly used, machine-readable format.
- Right to restrict processing — request that we limit the processing of your data in certain circumstances.
- Right to object — object to processing based on legitimate interest.
- Right to withdraw consent — where processing is based on consent, you may withdraw at any time.
- Right to lodge a complaint — you have the right to lodge a complaint with your local data protection supervisory authority.
International data transfers: Your data is processed in the United States. By using the Service, you acknowledge the transfer of your data to the United States. We rely on our service providers' data processing agreements and Standard Contractual Clauses (where applicable) to ensure adequate data protection.
To exercise any of your GDPR rights, please email us at [email protected] with "GDPR Request" in the subject line. We will respond within 30 days.
9. Advertising
ChoreKeep does not display advertisements. We do not use remarketing, retargeting, or advertising services. We do not share data with ad networks. There are no advertising identifiers collected by the app.
10. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has provided us with personal information, please contact us at [email protected] and we will promptly delete such information.
If we become aware that we have collected personal information from a child under 13 without verification of parental consent, we will take steps to remove that information from our servers as soon as possible.
11. Device Permissions
The app may request the following device permissions. Each permission is optional and you can decline or revoke access at any time through your device settings:
- Photo Library — to upload a profile photo or household photo. Images are resized to 512 pixels wide and compressed before upload. The app does not use your device's camera.
- Push Notifications — to receive chore assignment alerts and scheduled reminders. You can opt out at any time.
The app does not request device location permissions or access to your precise GPS location, contacts, microphone, calendar, Bluetooth, or any other device sensors.
12. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we make changes, we will update the "Last updated" date at the top of this page. For material changes, we will provide notice through the app or by email to the address associated with your account. Your continued use of the Service after such changes constitutes your acceptance of the revised Privacy Policy. We encourage you to review this Privacy Policy periodically.
13. Contact Us
If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
- Email: [email protected]
- Website: https://chorekeepapp.com
For CCPA requests, include "CCPA Request" in the subject line. For GDPR requests, include "GDPR Request" in the subject line. We will respond to all requests within the timeframes required by applicable law.