Privacy policy

How Chore Team handles your household information, device access, and support requests.

Last updated: 23 September 2026

The essentials

Chore Team is operated by Alexander Clausen. Contact: support@chore.team. This policy covers the iPhone app, its widgets, the household service, and this website.

You do not create an email-and-password account. The service still processes personal data: household profiles, tasks, contributions, and device access. A nickname is enough; please avoid sensitive information in names or task notes.

Chore Team has no advertising, advertising identifiers, tracking SDKs, or independent behavioural analytics. We do not sell your personal data.

What is processed

  • Household information: household name and time zone; profile names or nicknames, colours, and internal identifiers. A household member may enter your profile details before you join.
  • Household content: room names and icons; task titles, notes, assignments, dates, recurrence, and points; completion dates, points earned, and correction/activity history.
  • Access and synchronisation: device/session identifiers, device labels, creation times, protected invitation information, hashed device credentials, and operation identifiers/results to prevent duplicate submissions.
  • Connection information: your IP address and technical HTTP request information are processed to deliver the website/API and protect the service. Infrastructure can process operational and error logs. The application does not intentionally log invitation links, access credentials, or request bodies.
  • Support: your email address, message, and any diagnostics or screenshots you choose to send. Please redact other people’s personal information.
  • Privacy administration: a support reference made from household/profile identifiers, the household’s last authenticated activity (updated at most daily), and a minimal erasure/redaction record containing record identifiers, field locations and dates—not the erased text. A support reference cannot be used to sign in.

Why we use it

Household data and device credentials are needed to provide the shared planning service you request, including syncing, offline reconciliation, and scoreboards (Article 6(1)(b) GDPR). Without that data, the shared features cannot work. Optional task notes and support attachments are not required.

Where another member creates a profile for you, processing is based on the legitimate interests of organising the shared household and enabling your invitation (Article 6(1)(f) GDPR). Tell household members before adding their details.

Service security, preventing duplicate or abusive requests, diagnosing faults, and handling general enquiries rely on legitimate interests in operating a reliable service (Article 6(1)(f) GDPR). Support needed to provide the service also relies on Article 6(1)(b). Processing required by law relies on Article 6(1)(c).

Scores are calculated from completed tasks. We do not use them for automated decisions with legal or similarly significant effects, or for advertising profiles.

Handling statutory privacy requests and keeping the minimum records needed to honour them is based on Article 6(1)(c) GDPR. Restricting retained backup copies and preventing erased data from returning supports those obligations and service security.

Who can see your information

Everyone connected to a household can see its shared profiles, tasks, scores, and history. Members have equal management rights and can edit household information, correct completions, invite people, and revoke device access.

Anyone holding a current household invitation can select any profile, including one already used by another device. Names are not verified identities. Keep invitations private. Replacing a link prevents new joins with the old link; it does not remove existing devices. Use the access reset to revoke other devices.

The app service and database are hosted in Germany on Hetzner infrastructure through our hosting operator. Hosting and technical infrastructure providers process data needed to operate, back up and secure the service; email providers process support correspondence. Authorised operators can access records to maintain the service or handle a verified request. Information may also be disclosed where legally required. Provider categories are stated here; contact us for details of the recipients relevant to your request.

Apple handles App Store/TestFlight distribution separately under its own policies. Apple’s processing may take place outside Germany and the EEA; see the linked Apple information below. We do not send your household database to Apple for TestFlight feedback.

On your device and this website

The app and widgets keep a local household copy and a queue of pending completions. Device credentials are stored in the iOS Keychain. Language, appearance, accent colour, and reminder preferences are stored on your device. Widgets display household information on your Home Screen.

Daily reminders are optional local notifications scheduled on your iPhone. You can disable them in Chore Team or iOS Settings. The app does not request your contacts, photos, microphone, camera, or precise location. The household time zone is initialised from the creator’s device.

The website does not set analytics or advertising cookies, use tracking pixels, or load third-party fonts. Language is selected through the URL or your browser’s language preference. Household invitation secrets stay in the link fragment on the invitation page; joining in the app sends the secret to the service to authorise access.

Connections use HTTPS. Household content is not end-to-end encrypted: the service needs to process it to provide sharing and scores. Local data may also be included in backups made under your device’s settings.

Retention and deletion

Household records support shared planning and lifetime scores for as long as the household is used. A household is automatically removed after 24 months without authenticated app or widget activity, checked hourly. Existing households start this inactivity period when this rule is introduced on 23 September 2026. Viewing the public website does not reset it.

Disconnect this iPhone removes that device’s access and its app cache. Leave household archives the profile and contributions, unassigns tasks, revokes its devices and replaces the invitation. Delete my profile additionally clears the profile name, colour choice and relevant membership labels; recorded contributions and internal IDs remain and may still be identifiable. These actions are distinct from erasure.

In updated app versions, Erase profile and contributions removes the selected profile, its recorded completions and points, its device sessions and attributable request receipts. Tasks become unassigned; scores and due dates are recalculated. Related activity and correction metadata is removed. The invitation is replaced. If no active profile remains, the household is deleted. In older versions, contact support to request the same action.

Erasure does not automatically identify mentions in shared task notes, titles or other people’s text. Tell support which shared information also concerns you; we review and can redact specific fields without deleting unrelated household content. The last active member can also delete the whole household in Settings, removing its live database records, sessions and request receipts.

Server backups and basic infrastructure logs are enabled. Live database erasure does not instantly overwrite an existing backup. Backups must be kept out of normal use, expire under the hosting retention schedule, and have subsequent erasures reapplied before any restored database returns to service. Minimal erasure records are kept until backups that could contain the data have expired and restore checks are complete. We are confirming the hosting operator’s exact backup/log retention periods; contact support for the current details. We do not promise an unverified fixed expiry period.

Our support procedure is to delete routine correspondence and working exports within 12 months after a request is closed, and temporary database exports within 7 days. If a specific legal obligation or dispute requires longer retention, only the necessary information is retained for that purpose and we explain the applicable reason and period. These are operator procedures, not automatic deletion by your mail app.

Other devices may keep downloaded data while offline, and others may have made screenshots or copies. Current connected clients receive the changed household on their next successful refresh; revoked devices lose server access. We cannot remotely erase copies outside our control. Tell us if recipients need to be notified of an erasure request.

TestFlight and diagnostics

If you install through TestFlight, Apple collects beta-testing information such as installation and usage information, crashes, and feedback. Apple makes some of that information available to the developer. Information visible to us can depend on how you were invited and what feedback you submit. We use it to diagnose problems and improve the app.

A screenshot or feedback message can contain household information. Review it before sending. Chore Team does not need your Apple Account password.

Your rights

Depending on the circumstances, you have rights of access, correction, erasure, restriction, and data portability. You can object to processing based on legitimate interests for reasons relating to your situation. Where processing is based on consent, you can withdraw it for the future.

Email support@chore.team with your request. If you still have the app, Settings → Your data → Copy support reference gives a non-secret locator for your household/profile. Do not send your invitation link or device credential. The reference is not proof of identity or authority: profiles are shared and identities are not verified. We assess the scope and use proportionate verification before disclosure or destructive action. We do not routinely ask for an identity document.

If you have lost access, do not create a new profile just to submit a request. Describe the relevant records and any information that helps distinguish them. We will explain what additional information, if any, is necessary to locate the data and assess your request. If we cannot identify the records or establish entitlement, we explain the limitation and your options rather than deleting someone else’s data.

We respond without undue delay and normally within one month of receiving a rights request. Where legally permitted for a complex request, an extension of up to two further months may apply; we explain it within the first month. Requests are generally free. If a request is refused or limited, we explain the reasons and complaint options. Access/export responses are reviewed to protect other household members’ information.

You can lodge a complaint with a data protection supervisory authority, particularly in the EU country where you live, work, or believe an infringement occurred.

Changes to this policy

We update this page when the service or its data handling changes. The date above identifies the current version. For information about younger users and household access, see our age suitability page.

Contact

Operator and data controller: Alexander Clausen

For support or questions about your personal data, email:

support@chore.team