Legal

Privacy Policy

Homebro processes data to provide the application and this website. This policy details the data collected, their purposes, retention periods, recipients, transfers, and your rights.

Data controller

InformationDetails
EntityAMProd (represented by Axel Michel)
Address15 Rue du Mény, 44350 Guérande, France
Contact[email protected]
DPO (if applicable)Not appointed

Processed data & purposes

Data categoryExamplesPurposes
Account & authenticationFirst name, last name, email, username, hashed password, language, Apple/Google SSOAccount creation and management, secure login, household management
Optional profile dataBirthday, phone numberInternal social features (birthday reminders, contact sharing)
Household dataHousehold address, preferences (language, currency), membersMapping, organization, and sharing within the household
NotificationsPush token (APNs/FCM), notification preferencesService notifications, reminders, and alerts
Sensors & biometrics (device)Biometrics for local lock, gyroscope for animationsLocal security and UX improvements (not stored server-side)
User-generated content (UGC)Map points, recipes, contacts, access accounts, tasks, expenses, messages, stories, photos, documentsProviding core features within the household group
Internal mailboxAutomatically generated address, received messagesInternal sharing; members are responsible for received content
Subscriptions & billingSubscription identifiers, receipts, status (RevenueCat / App Store / Google Play)Premium management (monthly/yearly), access control, anti-fraud
Support & contactEmails, attachments, technical metadataResponding to requests and follow-up
Technical dataServer logs, IP addresses, device identifiers, error eventsSecurity, diagnostics, abuse prevention

Legal bases

  • Contract performance: providing the app and household-related features (Terms / Sales Conditions).
  • Legitimate interest: security, fraud prevention, service improvement, support.
  • Legal obligation: accounting and tax obligations.
  • Consent: optional data (e.g. birthday), non-essential trackers, notifications where required by the platform.

Retention periods

CategoryDuration
User accountUntil account deletion + backups (30–90 days).
Household dataLifetime of the household + 30–90 days (backups).
UGC (messages, files, stories…)Until deletion by members or household deletion.
Subscriptions & billing10 years (accounting obligations – FR).
SupportUp to 24 months after closure (unless dispute).
Logs & security3 to 12 months depending on purpose.
Push tokensUntil device unsubscribes or token is revoked.

Retention periods may vary depending on legal obligations and evidentiary needs in case of disputes.

Recipients / processors

We rely on service providers for hosting, media storage, subscriptions, and security.

ProviderServiceLocationSafeguards
OVH SASStrapi backend, database, business emailEU (France)EU processing, technical and organizational measures
Cloudinary LtdMedia storage (photos, videos, documents)USA/GlobalStandard Contractual Clauses (SCC), security
Cloudflare, Inc.Marketing site (Pages), CDN, security (Turnstile)EU/USASCC and technical safeguards
RevenueCatIn-app subscription management (Apple/Google)USA/GlobalSCC + contractual controls
Apple (Sign in / APNs)Apple SSO, iOS notificationsEU/USAApple rules + SCC where applicable
Google (Sign-In / FCM)Google SSO, Android notificationsEU/USASCC + Google controls

Transfers outside the EU

Some providers may process data outside the EU/EEA (e.g. USA): Cloudinary, Cloudflare, RevenueCat, Apple/Google. These transfers are governed by appropriate safeguards (Standard Contractual Clauses) and technical and organizational measures (encryption, access control).

Cookies & trackers

Security

We apply reasonable measures: encryption in transit (TLS), access control, logging, environment separation. Biometrics are handled locally on your device and are not transmitted to our servers. In case of a major incident, we will notify as required by law.

Your rights

  • Access, rectification, erasure
  • Objection and restriction
  • Data portability
  • Post-mortem directives (France)
  • Withdrawal of consent (non-essential trackers)

Exercise your rights: [email protected]

If you believe your rights are not respected, you may contact the competent authority (in France: CNIL).

Updates

We may update this policy due to legal or functional changes. In case of significant changes, appropriate notice will be provided (banner, email, etc.).