Privacy

Privacy Policy

This Privacy Policy explains how domiya ("we", "us", or "our") collects, uses, stores, shares, and protects personal information when you use our website, mobile application, and related services (the "Service").

Last updated: June 14, 2026

Effective date: June 14, 2026. Contact email: support@domiya.app. Website: https://domiya.app. domiya is a home and family organization product with accounts, homes and memberships, invites, notifications, tasks, shopping lists, calendars, reminders, wishlist items, household finances, meal planning, recipes, subscriptions, and support-related communications.

1. Scope

This Privacy Policy applies to:

  • the domiya mobile application
  • the domiya website
  • backend APIs and account services
  • communications related to the Service

1.1 Third-party services

This Privacy Policy does not apply to third-party services that are governed by their own privacy policies, including app stores, payment platforms, email providers, analytics providers, and push notification platforms.

2. Information We Collect

We collect information you provide directly, information created through your use of the Service, and information received from devices and service providers.

2.1 Account and profile information

When you register for or use domiya, we may collect:

  • email address
  • password hash
  • display name
  • avatar or profile image
  • birth date, if you provide it
  • time zone
  • country code
  • language or locale preferences

2.1.1 Password protection

We do not store your plain-text password.

2.2 Home and membership information

Because domiya is built around shared household collaboration, we may collect and store:

  • home name
  • home icon
  • home location
  • home membership data
  • access role and household role
  • invite history and invite state

2.3 User-generated content

We collect content you choose to create inside the Service, including:

  • tasks and task descriptions
  • shopping list items
  • calendar events and important dates
  • reminder-related content
  • wishlist items, product notes, and saved store links
  • meal plans, recipes, and ingredient lists
  • financial goals, debt notes, expense records, and related notes
  • profile images and other uploaded media

2.3.1 Content context

This content may include information about you, your household, or other people you choose to add to the Service.

2.4 Device session and authentication information

To provide secure login and account protection, we collect and store:

  • access token and refresh token hashes
  • device identifiers
  • device name
  • platform and platform version
  • session issuance, rotation, and revocation metadata
  • last seen timestamps

2.5 Notifications and reminder information

If you enable notifications, we may collect and process:

  • push token or APNs token
  • notification preferences as reflected by your device token state
  • notification records
  • reminder schedules and delivery state

2.5.1 Push delivery

We currently use Apple Push Notification service ("APNs") for iOS push delivery.

2.6 Subscription and billing information

For subscription features, we may collect and process:

  • subscription plan and status
  • subscription lifecycle metadata
  • App Store transaction and product identifiers
  • purchase restoration and reconciliation data

2.6.1 Payment card data

We do not directly store your full payment card details.

2.7 Support, email, and communications data

When you contact us or when we send service-related communications, we may process:

  • your email address
  • support messages
  • email delivery metadata
  • account confirmation and password reset flows

2.8 Technical, analytics, and operational data

We may automatically collect limited technical and operational information, such as:

  • IP address
  • user agent or device platform information
  • request and API metadata
  • timestamps
  • application errors and exception context
  • request profiling and performance data
  • analytics events related to product usage
  • security and abuse-prevention signals

3. How We Use Information

We use personal information to:

  • create and manage your account
  • authenticate users and secure sessions
  • operate home, invite, task, shopping, calendar, reminder, wishlist, meal-planning, recipe, and finance features
  • deliver notifications and reminders
  • provide subscription functionality and restore purchases
  • detect, prevent, and investigate fraud, abuse, misuse, and security incidents
  • monitor performance, diagnose errors, and improve the Service
  • communicate with you about your account, product updates, and support matters
  • comply with legal obligations and enforce our Terms

4. Shared and Household Data

domiya is designed for shared household use.

When you join or create a home, certain information becomes visible to other members of that home as part of the product’s core functionality. Depending on the feature, this may include:

  • display name
  • avatar
  • membership role
  • tasks, shopping items, calendar items, wishlist items, meal plans, recipes, financial goals, and shared expense records created or assigned within the home
  • invite and participation state where relevant to the feature

4.0.1 Feature-specific visibility

Some features may support narrower visibility for specific records. For example, certain finance entries may be visible only to the creator when the product marks them as private, while other household features are intentionally shared across current home members.

4.1 Shared content responsibility

You should only add people to a home or upload information to the Service when you have the right to do so.

5. Notifications and Reminders

If you enable push notifications:

  • we may store your active device push token
  • we may send account, home, task, shopping, calendar, reminder, wishlist, finances, meal-planning, recipe, or subscription-related notifications

5.1 Delivery limitations

If no active push token is available for your device, reminder or push delivery records may not be created or sent.

Push delivery is handled through Apple infrastructure for iOS devices.

6. Legal Bases for Processing

Where applicable, we process personal information on one or more of the following bases:

  • performance of a contract with you
  • our legitimate interests in operating, securing, and improving the Service
  • your consent, where required
  • compliance with legal obligations

7. How We Share Information

We do not sell your personal information.

We may share information with:

  • service providers who help us host, operate, secure, analyze, and support the Service
  • email and notification delivery providers
  • analytics and monitoring providers
  • subscription and app marketplace platforms, including Apple, where needed for purchases and restoration
  • legal authorities or other parties when required by law or necessary to protect rights, safety, or the Service
  • another entity in connection with a merger, acquisition, financing, reorganization, or sale of assets

7.1 Disclosure scope

We share only the information reasonably necessary for the relevant purpose.

7.2 External merchant and product links

Some features may let users save or open third-party merchant or product links. Those external websites are governed by their own terms and privacy practices, and we are not responsible for third-party content, pricing, availability, or policies.

8. International Transfers

Your information may be processed in countries other than the country where you live.

When required, we take appropriate steps intended to protect personal information transferred across borders.

9. Data Retention

We retain information for as long as reasonably necessary to provide the Service, maintain security and operational integrity, comply with legal obligations, resolve disputes, and enforce agreements.

Retention periods may vary depending on the data type.

Examples based on the current product architecture may include:

  • account and home data retained while your account remains active
  • device session records retained for active authentication and later cleared after expiration or revocation retention windows
  • notifications retained for limited product windows
  • reminder and sync-processing records retained for operational windows and later cleaned up
  • invites, completed tasks, purchased shopping items, bought wishlist items, completed financial records, planned meals, and other feature records retained according to feature-specific lifecycle rules
  • logs and profiling data retained for limited operational and security periods

9.1 Deletion and anonymization

We may delete or anonymize information when it is no longer needed.

10. Security

We use administrative, technical, and organizational measures intended to protect personal information, including measures related to:

  • password hashing
  • session management
  • token rotation and revocation
  • access controls
  • logging and monitoring
  • rate limiting and abuse prevention
  • transport and infrastructure security

10.1 Security limitations

No system is completely secure, and we cannot guarantee absolute security.

11. Your Rights and Choices

Depending on where you live, you may have the right to:

  • access personal information we hold about you
  • correct or update your information
  • delete your account or request deletion of your information
  • object to or restrict certain processing
  • request portability of your information
  • withdraw consent where processing is based on consent
  • lodge a complaint with a regulator or data protection authority

11.1 Additional choices

You may also:

  • update profile information in the app
  • revoke device sessions
  • disable notifications at the device level
  • contact us using the contact details below

11.2 Identity verification

We may need to verify your identity before acting on certain requests.

12. Account Deletion

You may request account deletion through the Service where available or by contacting us.

When you delete your account, we may delete or de-identify personal information, except where we need to retain certain records for legal, security, fraud-prevention, billing, operational, or dispute-resolution purposes.

Some shared household content may continue to exist in limited cases where necessary to preserve product integrity for other users, subject to applicable law and our internal retention rules.

12.1 Contact

For privacy-related questions or deletion requests, contact us at support@domiya.app.