Back to ChoreDen

ChoreDen Privacy Policy

Effective date: June 22, 2026 Last updated: June 22, 2026


1. Who we are

ChoreDen ("ChoreDen", "we", "us", "our") is a gamified household-chores application that lets a family or household manage chores, award points, and redeem rewards.

This Privacy Policy explains what personal data we collect, why we collect it, the legal bases on which we rely (where applicable), who we share it with, and the rights you have over it.

If you do not agree with this Policy, please do not create an account or use ChoreDen.


2. Scope

This Policy applies to the ChoreDen progressive web app (PWA) and related websites, emails, and push notifications operated by us (collectively, the "Service"). It does not apply to third-party services we integrate with, which have their own privacy policies (see Section 6).

ChoreDen is designed for use by households containing adults and, optionally, child sub-profiles created and managed by an adult. Please read Section 10 (Children's Privacy) carefully.


3. The data we collect and why

We collect the categories of data below. We have grouped them by how they enter the Service.

3.1 Account data (adults who register)

Data Purpose Source
Email address Create and secure your account; sign-in; account verification; password reset; transactional email You
Password Authenticate you. Passwords are handled and stored (hashed/salted) by our authentication provider, Supabase Auth; we do not store plaintext passwords. You
Authentication identifiers/tokens, email-confirmation status, sign-in timestamps, IP address and user-agent associated with auth events Account security, fraud/abuse prevention, session management Generated by the Service / Supabase Auth

Note on display names: when you register with email/password, the Service may automatically set your initial display name from the local part of your email address (the text before the "@"). You can change your display name at any time.

3.2 Profile data

Data Purpose Source
Display name Show who you are within your household and on leaderboards/activity feeds You
Avatar image (optional) Personalize your profile You (upload)
Time zone Schedule notifications and align chore deadlines to your local time You / device
Onboarding/preference flags Tailor your in-app experience Generated by the Service

Avatar storage. Avatar images are stored in a private storage bucket and served only through an authenticated proxy, so they are not publicly accessible by their URL. Images are re-encoded in your browser before upload, which removes embedded metadata (such as EXIF/GPS location), and the server enforces image content-type and size limits.

3.3 Household and activity data

When you use the Service, we process data about your household and what happens in it:

Purpose: to provide the core Service — running chores, awarding and tracking points, enabling rewards and redemptions, and showing households their activity.

Chore-photo storage. Chore-completion photos are stored in a private bucket and served only through an authenticated proxy that confirms you are a member of the relevant household; they are not publicly accessible by their URL. Photos are re-encoded on upload to strip metadata (e.g., EXIF/GPS), and the server enforces image content-type and size limits. Even so, please avoid uploading images that identify a child or reveal a sensitive location.

3.4 Notifications data

Data Purpose Source
Web Push subscription (endpoint URL and the p256dh and auth browser-generated keys) Deliver push notifications you enable (e.g., chore reminders, verification requests) Your browser/device
In-app notification records Show notifications inside the Service Generated by the Service

You can disable push notifications in your browser/device settings or within the app; stale subscriptions are automatically removed.

3.5 Invitations and emails we send

We send transactional/service emails as part of operating the Service. We do not send marketing emails.

3.6 Sign-in with Google (optional)

If you choose Sign in with Google, Google shares with us (via OAuth) a limited set of profile information (typically your name, email address, and a profile-picture URL) so we can create or access your account. Your use of Google sign-in is also subject to Google's privacy policy. We do not receive your Google password.

3.7 Cookies, local storage, and similar technologies

We use a small number of cookies and local-storage entries that are necessary to operate the Service:

Name / type Type Purpose Roughly how long
Supabase authentication cookies (session/refresh tokens) Strictly necessary Keep you signed in; secure your session Session / token lifetime
cd_locale Functional Remember your chosen language ~1 year
Active-household cookie Functional Remember which household you are viewing ~1 year
Theme preference (browser local storage, e.g. theme) Functional Remember light/dark/system appearance Until cleared

We use only strictly-necessary and functional cookies. We do not use third-party advertising cookies, and we do not set any non-essential cookies that would require consent.

3.8 Analytics

We do not use third-party product analytics or advertising trackers.

3.9 Technical and log data

Our hosting and infrastructure providers automatically process technical data needed to deliver and secure the Service, such as IP address, device/browser type, request metadata, and server logs. This is used for security, debugging, abuse prevention, and reliability.


4. Legal bases for processing (EEA/UK and similar regimes)

Where the UK GDPR or EU GDPR (or an equivalent law) applies, we rely on the following legal bases:

Children: processing relating to child sub-profiles relies on the consent/authorization of the holder of parental responsibility and on data-minimization principles. See Section 10.


5. How we use the data (summary of purposes)

We do not sell your personal data, and we do not use it for cross-context behavioral advertising.


6. Third-party processors and service providers

We share personal data with the following providers only as needed to operate the Service. Each acts as our processor/service provider (or, where noted, an independent controller) and is bound by appropriate contractual terms (e.g., a Data Processing Agreement).

Provider Role in the Service Data involved Privacy info
Supabase Database, authentication, file storage, realtime Account/auth data, profile data, household/activity data, uploaded images, push-subscription records https://supabase.com/privacy
Vercel Application hosting / serving Technical/log data, IP addresses, request metadata https://vercel.com/legal/privacy-policy
Resend Sending invitation and other transactional emails Recipient email addresses and email contents (e.g., household name, invite code) https://resend.com/legal/privacy-policy
Google (Google Sign-In / OAuth) Optional federated sign-in Email, name, profile-picture URL (received from Google with your authorization) https://policies.google.com/privacy
Web Push services (the push services operated by your browser/OS vendor, e.g. Google, Mozilla, Apple, Microsoft) Delivering push notifications you enable Push endpoint and message payloads routed to your device See your browser/OS vendor's privacy policy

We require providers to protect personal data and to use it only to provide services to us. We are not responsible for the independent practices of these providers; review their policies for details.


7. International data transfers

ChoreDen's providers may process data in countries outside your own, including the United States and other locations where our providers operate. Where we transfer personal data out of the UK or EEA, we rely on appropriate safeguards, such as the UK International Data Transfer Addendum and the EU Standard Contractual Clauses, adequacy decisions where available, and/or other lawful transfer mechanisms.


8. Data retention

We keep personal data only for as long as necessary for the purposes described in this Policy, unless a longer period is required or permitted by law.

Data Retention
Account and profile data While your account is active, then deleted/anonymized within 30 days of an account-deletion request
Household and activity data (chores, completions, points ledger, rewards) While the household exists; the points ledger is append-only and retained for the life of the household for integrity/audit; deleted/anonymized when the household is deleted, subject to legal holds
Uploaded images (avatars, chore photos) Until replaced or deleted by the relevant user, or within 30 days of account/household deletion
Push subscriptions Until you disable notifications, the subscription becomes invalid, or your account is deleted
Invitations Until accepted, revoked, or expired (invitations expire after 14 days), then retained for up to 30 days
Email logs (via Resend) and auth/security logs Up to 30 days (per provider defaults and our settings)

When data is deleted, residual copies may persist in encrypted backups for up to 30 days before being overwritten.


9. Your rights and how to exercise them

Depending on where you live, you may have some or all of the following rights:

How to exercise your rights:

Household admins and shared data: Because ChoreDen is a shared household app, some data you create (e.g., completions, activity-feed entries) is visible to other members of your household and may remain associated with the household even after you leave. Deleting your individual account does not necessarily delete the household or content created by others. We will explain any limits when you make a request.


10. Children's Privacy

ChoreDen handles children's data through a deliberately minimal, parent-controlled design. Because children's-data law (including the UK/EU GDPR age-of-consent rules and the U.S. COPPA) is strictly enforced and varies by jurisdiction, we encourage parents to read this section carefully.

No direct child accounts. ChoreDen does not allow children to register their own accounts. Only adults can create a ChoreDen account (with an email address and password, or via Google sign-in). Our Service is directed to adults managing a household.

Child sub-profiles. An adult household member may create child sub-profiles. By design, a child sub-profile:

Parental responsibility. The adult who creates a child sub-profile is responsible for:

Parental rights and controls. A managing adult can view and edit a child sub-profile in-app, and can request deletion of a child sub-profile and its associated data at any time by contacting privacy@choreden.com. We will honor verified parental requests to access or delete a child's information as required by law.

What we do not do. We do not use children's data for advertising or build advertising profiles of children. If you believe a child's personal data has been provided to us without proper authorization, contact us at privacy@choreden.com and we will take appropriate steps to investigate and, where required, delete it.


11. Security

We take reasonable technical and organizational measures to protect personal data, including:

No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.


12. Data breach notification

If we become aware of a personal-data breach that is likely to result in a risk to your rights and freedoms, we will notify the relevant supervisory authority and/or affected users as and when required by applicable law (for example, the UK/EU GDPR's 72-hour authority-notification timeline).


13. Automated decision-making

We do not use your personal data for solely automated decision-making that produces legal or similarly significant effects about you. Certain gameplay automations (such as auto-verification or auto-assignment of chores) are operational features and do not produce legal or similarly significant effects.


14. Changes to this Policy

We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date and, where appropriate, notify you (e.g., in-app or by email). Your continued use of the Service after an update means you accept the revised Policy, to the extent permitted by law.


15. Contact us