1. Scope
This Privacy Policy applies to:
- the domiya mobile application
- the domiya website
- backend APIs and account services
- communications related to the Service
1.1 Third-party services
This Privacy Policy does not apply to third-party services that are governed by their own privacy policies, including app stores, payment platforms, email providers, analytics providers, and push notification platforms.
2. Information We Collect
We collect information you provide directly, information created through your use of the Service, and information received from devices and service providers.
2.1 Account and profile information
When you register for or use domiya, we may collect:
- email address
- password hash
- display name
- avatar or profile image
- birth date, if you provide it
- time zone
- country code
- language or locale preferences
2.1.1 Password protection
We do not store your plain-text password.
2.2 Home and membership information
Because domiya is built around shared household collaboration, we may collect and store:
- home name
- home icon
- home location
- home membership data
- access role and household role
- invite history and invite state
2.3 User-generated content
We collect content you choose to create inside the Service, including:
- tasks and task descriptions
- shopping list items
- calendar events and important dates
- reminder-related content
- wishlist items, product notes, and saved store links
- meal plans, recipes, and ingredient lists
- financial goals, debt notes, expense records, and related notes
- profile images and other uploaded media
2.3.1 Content context
This content may include information about you, your household, or other people you choose to add to the Service.
2.4 Device session and authentication information
To provide secure login and account protection, we collect and store:
- access token and refresh token hashes
- device identifiers
- device name
- platform and platform version
- session issuance, rotation, and revocation metadata
- last seen timestamps
2.5 Notifications and reminder information
If you enable notifications, we may collect and process:
- push token or APNs token
- notification preferences as reflected by your device token state
- notification records
- reminder schedules and delivery state
2.5.1 Push delivery
We currently use Apple Push Notification service ("APNs") for iOS push delivery.
2.6 Subscription and billing information
For subscription features, we may collect and process:
- subscription plan and status
- subscription lifecycle metadata
- App Store transaction and product identifiers
- purchase restoration and reconciliation data
2.6.1 Payment card data
We do not directly store your full payment card details.
2.7 Support, email, and communications data
When you contact us or when we send service-related communications, we may process:
- your email address
- support messages
- email delivery metadata
- account confirmation and password reset flows
2.8 Technical, analytics, and operational data
We may automatically collect limited technical and operational information, such as:
- IP address
- user agent or device platform information
- request and API metadata
- timestamps
- application errors and exception context
- request profiling and performance data
- analytics events related to product usage
- security and abuse-prevention signals
3. How We Use Information
We use personal information to:
- create and manage your account
- authenticate users and secure sessions
- operate home, invite, task, shopping, calendar, reminder, wishlist, meal-planning, recipe, and finance features
- deliver notifications and reminders
- provide subscription functionality and restore purchases
- detect, prevent, and investigate fraud, abuse, misuse, and security incidents
- monitor performance, diagnose errors, and improve the Service
- communicate with you about your account, product updates, and support matters
- comply with legal obligations and enforce our Terms
4. Shared and Household Data
domiya is designed for shared household use.
When you join or create a home, certain information becomes visible to other members of that home as part of the product’s core functionality. Depending on the feature, this may include:
- display name
- avatar
- membership role
- tasks, shopping items, calendar items, wishlist items, meal plans, recipes, financial goals, and shared expense records created or assigned within the home
- invite and participation state where relevant to the feature
4.0.1 Feature-specific visibility
Some features may support narrower visibility for specific records. For example, certain finance entries may be visible only to the creator when the product marks them as private, while other household features are intentionally shared across current home members.
4.1 Shared content responsibility
You should only add people to a home or upload information to the Service when you have the right to do so.
5. Notifications and Reminders
If you enable push notifications:
- we may store your active device push token
- we may send account, home, task, shopping, calendar, reminder, wishlist, finances, meal-planning, recipe, or subscription-related notifications
5.1 Delivery limitations
If no active push token is available for your device, reminder or push delivery records may not be created or sent.
Push delivery is handled through Apple infrastructure for iOS devices.
6. Legal Bases for Processing
Where applicable, we process personal information on one or more of the following bases:
- performance of a contract with you
- our legitimate interests in operating, securing, and improving the Service
- your consent, where required
- compliance with legal obligations
7. How We Share Information
We do not sell your personal information.
We may share information with:
- service providers who help us host, operate, secure, analyze, and support the Service
- email and notification delivery providers
- analytics and monitoring providers
- subscription and app marketplace platforms, including Apple, where needed for purchases and restoration
- legal authorities or other parties when required by law or necessary to protect rights, safety, or the Service
- another entity in connection with a merger, acquisition, financing, reorganization, or sale of assets
7.1 Disclosure scope
We share only the information reasonably necessary for the relevant purpose.
7.2 External merchant and product links
Some features may let users save or open third-party merchant or product links. Those external websites are governed by their own terms and privacy practices, and we are not responsible for third-party content, pricing, availability, or policies.
8. International Transfers
Your information may be processed in countries other than the country where you live.
When required, we take appropriate steps intended to protect personal information transferred across borders.
9. Data Retention
We retain information for as long as reasonably necessary to provide the Service, maintain security and operational integrity, comply with legal obligations, resolve disputes, and enforce agreements.
Retention periods may vary depending on the data type.
Examples based on the current product architecture may include:
- account and home data retained while your account remains active
- device session records retained for active authentication and later cleared after expiration or revocation retention windows
- notifications retained for limited product windows
- reminder and sync-processing records retained for operational windows and later cleaned up
- invites, completed tasks, purchased shopping items, bought wishlist items, completed financial records, planned meals, and other feature records retained according to feature-specific lifecycle rules
- logs and profiling data retained for limited operational and security periods
9.1 Deletion and anonymization
We may delete or anonymize information when it is no longer needed.
10. Security
We use administrative, technical, and organizational measures intended to protect personal information, including measures related to:
- password hashing
- session management
- token rotation and revocation
- access controls
- logging and monitoring
- rate limiting and abuse prevention
- transport and infrastructure security
10.1 Security limitations
No system is completely secure, and we cannot guarantee absolute security.
11. Your Rights and Choices
Depending on where you live, you may have the right to:
- access personal information we hold about you
- correct or update your information
- delete your account or request deletion of your information
- object to or restrict certain processing
- request portability of your information
- withdraw consent where processing is based on consent
- lodge a complaint with a regulator or data protection authority
11.1 Additional choices
You may also:
- update profile information in the app
- revoke device sessions
- disable notifications at the device level
- contact us using the contact details below
11.2 Identity verification
We may need to verify your identity before acting on certain requests.
12. Account Deletion
You may request account deletion through the Service where available or by contacting us.
When you delete your account, we may delete or de-identify personal information, except where we need to retain certain records for legal, security, fraud-prevention, billing, operational, or dispute-resolution purposes.
Some shared household content may continue to exist in limited cases where necessary to preserve product integrity for other users, subject to applicable law and our internal retention rules.
12.1 Contact
For privacy-related questions or deletion requests, contact us at support@domiya.app.