PRIVACY POLICY
Privacy Policy
Last updated: July 26, 2026
This Policy explains what information Household Routine Tracker (the “Service”) handles and why.
1. Guest mode and local storage
In guest mode, the Service stores chore entries, categories, completion dates, recurrence intervals, history, deletion status, update times, queued offline sync data, and sync or migration status in your browser’s localStorage. This information normally stays on that device until you choose to sync by signing in with Google.
2. Google sign-in information
Google and Supabase Auth are used when you sign in. We may receive an account identifier, display name, email address, and profile image as part of the authentication response. The Service may show a display name or part of an email address so that you can recognize the signed-in account.
The Service does not create its own localStorage entries for your Google access token, password, or secret keys. Authentication sessions are managed by the official Supabase client library.
3. Cloud storage with Supabase
After sign-in, chore entries, completion dates, recurrence settings, history, deletion status, and update times are stored in Supabase so they can sync across devices. Browser code uses only the public anon key and assumes Row Level Security (RLS), so each signed-in user can access only their own record. A service-role key is never placed in browser code.
4. Google Analytics 4
We load Google Analytics 4 (GA4) on the official production domain only after you choose “Allow analytics.” If you decline, the Google Analytics tag is not loaded and no access information is sent to Google Analytics. We use Basic Consent Mode v2: advertising storage, user data, and personalization remain denied at all times.
Your analytics choice and consent-format version are stored in localStorage with the date and time of the update. You can change or withdraw your choice at any time by selecting “Analytics preferences” in the app footer. Withdrawing consent stops future analytics events and removes Google Analytics cookies where the browser permits; it does not delete your household records or sign-in data.
We do not send chore names, user-entered item names, completion dates, next dates, chore history, email addresses, Google account data, Supabase user IDs, backup contents, or free-form text to GA4. GA4 is not loaded on localhost, file URLs, or preview hosts.
Information processed by Google Analytics is also subject to Google’s terms and privacy policies.
5. Cookies and similar technologies
The Service may use cookies, localStorage, and similar technologies for authentication sessions, CSRF protection and rate limiting on the feedback form, and analytics. Blocking these technologies may prevent some features from working.
6. Why we use information
- to provide chore tracking, display, backup, and restore features;
- to provide Google sign-in and cross-device sync;
- to answer questions, investigate problems, and improve the Service;
- to detect abuse and operate the Service safely; and
- to understand aggregated, non-content usage trends.
7. Sharing and service providers
We do not sell personal information. We disclose it only with consent, when required by law, when necessary to protect a person or property, or to service providers needed to operate the Service. Google, Supabase, and Google Analytics may process information under their own terms and privacy policies.
8. Retention
Local data may remain until you clear browser storage or use the Service’s reset feature. Cloud data is kept while needed to provide the Service or until an account-deletion request is completed. Feedback and analytics data are retained only as long as reasonably needed for support, security, and statistics, subject to the configured retention periods of the relevant provider.
9. Logging out and deleting local data
Logging out may leave data in localStorage so that offline use and a later sign-in remain possible. To delete local data, open “Data,” choose “Delete all data,” and type “RESET” on the confirmation screen. Export a JSON backup first if you may need the data later.
10. Deleting your account and cloud data
Open the feedback page, choose “Other,” and write “Delete my account and cloud data.” If possible, enter the email address used for Google sign-in in the optional reply field. After verifying the request, the operator will delete the Supabase chore record and Auth account through an administrative or secure server-side process.
An account-deletion request does not automatically erase localStorage on your device. Use the reset steps above if you also want to remove the local copy. The Service does not expose a service-role key or direct administrator deletion privileges in the browser.
11. Security
We use reasonable safeguards such as encrypted transport, RLS, input validation, and separation of privileges. No internet transmission or storage system can be guaranteed completely secure.
12. Contact
Questions or requests about your information can be sent through the Household Routine Tracker feedback page.
13. Changes to this Policy
We may update this Policy when the Service, law, or third-party providers change. Material changes will be announced on this page or through the Service, and the updated Policy applies when posted.
This Policy reflects the current implementation, but the operator must confirm actual retention periods, vendors, and request-handling procedures and obtain a final legal review before release.