Effective date: August 11, 2026 · Version 2026-08-11
Privacy Policy
ChoreClub helps shared households plan chores, split work fairly, and keep a household history. This policy explains what information is processed when you use the ChoreClub app or website, why it is processed, who receives it, how long it is kept, and the rights available to you.
Short version: ChoreClub uses your information to provide and secure the household service, deliver features you request and, only if you opt in, understand limited product usage or diagnose errors. ChoreClub does not sell personal information, show ads, use session replay, or use your data for cross-app tracking.
Who is responsible for your data
The data controller is the operator of ChoreClub:
Jan SustrIm Mainfeld 7
60528 Frankfurt am Main
Germany
Full provider details are in the Impressum. For privacy questions or requests, email privacy@choreclubapp.com.
Information processed
| Category | Examples | How it is obtained |
|---|---|---|
| Account and profile | Email address, display name, profile color, optional avatar, authentication provider and internal user ID | From you or, when you choose social sign-in, from Google or Apple |
| Household and invitations | Household name, member roles, invite codes and placeholder member names. Invitations use a shared code, so ChoreClub does not collect the email addresses of people you invite. | Entered by you or another household administrator |
| Household content | Chores, categories, assignments, completion history, reviews, reactions, comments, availability and problem reports | Entered or generated through household activity |
| Safety and moderation reports | Reporter identity, reported account or content, reason, optional note, a limited content snapshot, review status and moderation outcome | Submitted by a household member and generated during ChoreClub's review |
| Device and notification data | Push token, device name, app version and notification preferences | From your device when notifications are enabled |
| Optional analytics and diagnostics | Pseudonymous user and household IDs, event names, limited event properties, platform, OS, app version, exception type and app code frames | Generated only after you separately enable usage analytics or anonymous crash reports |
| Terms acceptance | The accepted Terms of Use version and the acceptance timestamp, kept both on your profile and as a dated entry in an acceptance log | Recorded when you accept the Terms on the consent screen shown after sign-in; the version and timestamp are set by ChoreClub's server, not by your device |
| Support and deletion requests | Email address, request details and correspondence | From you when you contact ChoreClub or use the deletion-request form |
| Launch waitlist | Email address, selected mobile platform and a keyed hash of the connection address used for short-lived abuse prevention | From you when you ask to be notified about the ChoreClub launch, and generated when the protected form is submitted |
| Technical connection data | IP address, request time and user-agent or similar network metadata | Automatically received by hosting and service providers when a request is made |
Availability reasons and other free-text fields are optional. Please do not include health information or other sensitive personal information unless it is genuinely necessary for your household. When you add a placeholder member, use a nickname or first name rather than a full legal name, and do not enter sensitive information about another person.
Purposes and legal bases
| Purpose | Legal basis under the GDPR |
|---|---|
| Provide accounts, household synchronization, chores, roles, history and fairness features | Performance of the service requested by you (Article 6(1)(b)) |
| Provide Google or Apple sign-in and notifications you choose to enable | Performance of the requested service (Article 6(1)(b)); device permissions remain under your control |
| Process limited information about placeholder household members that another member enters about them | Legitimate interests in enabling shared-household coordination, preventing abuse and maintaining household records (Article 6(1)(f)). A placeholder member is not a party to the member's contract, so this processing does not rely on Article 6(1)(b). |
| Record which version of the Terms of Use you accepted and when | Document contract formation, and establish or defend legal claims (Articles 6(1)(b) and 6(1)(f)) |
| Keep shared household records after a member deletes their account, so remaining members retain a functional history | Performance of the remaining members' contracts (Article 6(1)(b)) and legitimate interests in preserving a functional shared record (Article 6(1)(f)); records are minimized and deleted when no longer needed |
| Secure accounts, prevent abuse and maintain basic service reliability | Legitimate interests in operating a secure and reliable service (Article 6(1)(f)) |
| Receive and review safety reports, preserve evidence, prevent reporting abuse and enforce the Terms of Use | Legitimate interests in protecting users, enforcing service rules and operating a safe service (Article 6(1)(f)); legal obligations where applicable (Article 6(1)(c)) |
| Receive optional anonymous crash reports and diagnose app failures | Your consent (Article 6(1)(a)); you can disable crash reports at any time |
| Measure limited product usage and understand which features are useful | Your consent (Article 6(1)(a)); you can disable usage analytics at any time |
| Remember an email address only on your device when you select that option | Your choice and consent (Article 6(1)(a)); you can disable it at any time |
| Answer support, privacy and deletion requests | Performance of the service, legal obligations and legitimate interests (Articles 6(1)(b), 6(1)(c) and 6(1)(f), as applicable) |
| Send the one-time launch notification you request | Your consent (Article 6(1)(a)); you may withdraw it at any time by email |
| Comply with law and establish or defend legal claims | Legal obligations and legitimate interests (Articles 6(1)(c) and 6(1)(f)) |
Information about placeholder members
ChoreClub invitations work by sharing a short invite code — ChoreClub does not ask for, store or email the addresses of people you invite. A member can, however, create a placeholder member for someone who has not joined yet. Information about that person — the placeholder name, and any assignments, reviews, comments and availability recorded against it — is entered by another household member rather than by the person themselves.
ChoreClub processes this limited information on the basis of legitimate interests (Article 6(1)(f) GDPR) in enabling shared-household coordination, preventing abuse and maintaining household records.
Because a placeholder is created by someone else, ChoreClub has no contact details for that person and cannot send them this notice directly. Publishing this policy therefore does not by itself discharge ChoreClub's obligation under Article 14 GDPR; ChoreClub relies on the member who created the placeholder to tell that person their information is recorded in ChoreClub, and asks members to use a nickname or first name rather than a full legal name and not to enter sensitive information about anyone else. If you learn that a placeholder about you exists, this policy sets out the categories of data, purposes, legal basis, recipients, retention criteria and your rights — including the right to object to processing based on legitimate interests. Emailprivacy@choreclubapp.com and ChoreClub will tell you what is held, correct it, or delete it.
Who receives information
- Other members of your household receive the names, assignments, reviews, problem reports and activity needed for shared household features.
- Reported users are not shown the reporter's identity. ChoreClub may give them limited information about an outcome when appropriate without identifying the reporter.
- Supabase provides authentication, database, storage and backend infrastructure. ChoreClub's production project is hosted in Ireland (
eu-west-1). - Cloudflare provides website hosting, DNS, CDN, Turnstile abuse prevention and email routing for ChoreClub's domain.
- Resend delivers authentication and transactional emails, such as confirmation and password-reset codes.
- PostHog provides product analytics and error diagnostics through its EU ingestion endpoint.
- Google processes authentication information when you choose Continue with Google, and processes push-notification tokens to deliver notifications to Android devices.
- Apple processes authentication information when you choose Continue with Apple, and processes push-notification tokens to deliver notifications to Apple devices.
- ChoreClub's email provider receives and stores messages you send to contact@choreclubapp.com or privacy@choreclubapp.com, so ChoreClub can answer support, privacy and deletion requests.
- Authorities or professional advisers may receive information when disclosure is legally required or reasonably necessary to protect users, the service or legal rights.
ChoreClub does not sell personal information and does not share it for advertising or cross-app tracking. Supabase and PostHog are configured for EU-hosted project data. Some providers, including Google, Apple, Cloudflare and Resend, may process information outside the EEA. Where required, transfers rely on an adequacy decision, Standard Contractual Clauses, or another safeguard made available by the provider. You may request more information by email.
Analytics and diagnostics
Both Send anonymous crash reports and Share usage analytics are off by default. You can enable them separately under More > Privacy & diagnostics. Consent also covers the access to or storage of information on your device needed for the selected feature where applicable. You can withdraw either consent in the same place at any time; this stops new collection without affecting earlier lawful processing.
If you enable usage analytics, product events sent to PostHog use ChoreClub's internal user ID as a pseudonymous person identifier and the internal household ID for grouped analysis. Events describe actions such as completing onboarding or creating and completing chores, together with low-cardinality properties such as a role, rating, recurring flag or assignment mode. Chore titles, display names, emails and invite codes are not intentionally included. If you enable crash reports, error events are limited to exception type, app code frames, app version, platform and OS. Error messages, raw stack traces, chore content and other user-entered values are not intentionally included. PostHog and its network providers also receive ordinary connection metadata such as an IP address; ChoreClub instructs PostHog to anonymize IP addresses.
ChoreClub disables advertising, session replay, automatic screen capture and cross-app tracking.
Retention
| Information | Retention criterion |
|---|---|
| Account, profile, device tokens and availability reasons | Kept while the account is active and removed when account deletion completes, except where law requires limited continued retention |
| Household content and history | Kept while the household uses the service or remaining members reasonably need the shared record; deleted when the household is deleted |
| Safety and moderation reports | Kept while a report is reviewed and afterwards only as long as reasonably needed to document the decision, prevent abuse, protect users or handle legal claims; identifiers may remain pseudonymous after account deletion |
| Invitations | Kept while needed to administer membership, prevent invite abuse and maintain the household |
| Notifications | Kept while needed to provide the in-app notification history and operate the household |
| Terms acceptance | Kept while the account is active, and deleted together with the account — the acceptance log is removed when your account is deleted, so no acceptance record is retained after erasure |
| Optional analytics and diagnostics | Kept for no more than 12 months in PostHog, then deleted automatically |
| Support and deletion requests | Kept until the request is resolved and afterwards only as needed to document compliance, prevent abuse or handle legal claims |
| Deletion-form abuse prevention | A derived network identifier and request timestamp are kept until they are more than 24 hours old and the deletion form next receives a request; the raw IP address is not stored in this database table |
| Launch waitlist | Kept until the selected app launches and the requested notification is sent, or until you ask ChoreClub to remove it |
| Waitlist abuse prevention | A keyed hash of the connection address and request timestamp are kept for no more than 24 hours and removed by a scheduled database cleanup; the raw address is not stored in the waitlist rate-limit table |
Security
ChoreClub uses encrypted network connections, authenticated access, role-based database controls and service-provider access controls. No internet service can guarantee absolute security. If you believe your account or household data is at risk, contact ChoreClub promptly.
Account deletion
You can permanently delete your account from More > Profile > Delete account, or use the account-deletion page if you cannot access the app. In-app deletion removes the authentication identity, profile, device data and personal availability reasons. Your account link and direct identifiers are removed. Some shared household records may remain associated with a generic “Former member” label so that remaining members keep a functional history. Depending on the context, remaining members of a small household may still be able to infer who performed a past action, so these records may remain personal data even after this pseudonymization. ChoreClub keeps them on the basis of the remaining members' contracts (Article 6(1)(b)) and its legitimate interests in preserving a functional shared record (Article 6(1)(f)), and deletes them when they are no longer needed. If no real member remains, the household and its content are deleted. If deletion cannot complete, the app reports an error instead of presenting the request as successful. Safety reports and their audit history may be retained for the limited period described above; account identifiers in those records no longer provide access to a deleted account. ChoreClub also deletes the PostHog person associated with your internal user ID and its linked events. Anonymous crash reports that cannot be linked back to your account expire under the 12-month retention limit.
Your privacy rights
Depending on where you live and the applicable law, you may have the right to:
- access a copy of your personal information;
- correct inaccurate or incomplete information;
- request deletion or restriction of processing;
- receive information you supplied in a portable format;
- object to processing based on legitimate interests;
- withdraw consent at any time where processing is based on consent, without affecting earlier processing; and
- lodge a complaint with a data-protection supervisory authority.
Email privacy@choreclubapp.com to exercise a right. ChoreClub may ask for information needed to verify your identity and normally responds within one month. EU and EEA supervisory authorities are listed by the European Data Protection Board.
Children
ChoreClub is intended for adults. You must be at least 18 to create an account, as stated in theTerms of Use, and people under 18 must not create an account. If you believe someone under 18 has created an account or provided personal information, email ChoreClub so the account and associated personal information can be investigated and deleted. Adults who create placeholder household members should avoid entering a child's full name or other identifying information.
Changes to this policy
ChoreClub may update this policy when the service or legal requirements change. Material changes will be highlighted in the app or on the website where practical. The effective date and version at the top identify the current notice.
Contact
Jan Sustr, Germany
Email: privacy@choreclubapp.com