Homie — Privacy Policy
Last updated: August 21, 2026
Homie is a household scheduling app for families. This policy
explains what data the app handles, where it goes, and what stays on your
device. The short version: your household’s data lives on your devices and
in a private synced copy only your household can read; nothing is sold,
shared for advertising, or used to train AI models; voice never leaves
your device as audio.
What the app stores
- Account data: an email address and password (password handled by our
authentication provider, Supabase — we never see it) for each adult or
invited member who signs in.
-
Household data you enter: family member names and roles, events and
schedules, routines, task lists, grocery lists, and saved places
(addresses and map coordinates). This is stored on your device and — if
you enable sync — in a Supabase-hosted database (Supabase Inc., cloud
infrastructure in the United States), where row-level security
restricts every record to signed-in members of your own household.
App developers do not read household content in the normal course of
operation; like any hosted database, it is technically accessible to
the database administrator and to Supabase as the infrastructure
provider.
- A notification token, if you turn nudges on. Turning on
leave-time nudges registers an anonymous push identifier for that
device, so other devices in your household can tell it that a plan
moved. It identifies a phone, not a person, and it is stored only while
nudges are switched on.
What leaves your device, and why
- Schedule text you type or dictate can be sent to Anthropic’s Claude
API to be turned into a structured draft event. It always passes through
our proxy service, which forwards it and stores only a count of
requests per account (for rate limiting) — never the text itself.
There is no setting for this and no key to enter; a device that is
signed out does the parsing on its own, on the phone. Anthropic
processes it under its API terms, which do not permit training on API
data. Parsing also works fully offline with reduced quality; an AI
failure never blocks the app.
- Voice capture is transcribed on your device by the operating
system’s speech recognition. Audio is never uploaded. Only the
resulting text is handled as above.
- Addresses you save are sent to a geocoding service (Geoapify) to
find map coordinates, and pairs of coordinates are sent to the same
service to estimate travel times. For driving plans, the same pair of
coordinates goes to a traffic service (TomTom) shortly before
departure, so the estimate reflects real conditions. These requests
contain no account identity — never who is going, never your schedule —
and results are cached on your device.
- Where you are, but only while you search for a place. When you look
up a place to put on a plan, the app can ask for your device’s location
and send it to Geoapify as the centre of the search, so the nearest
match ranks first. Permission is requested the first time a search needs
it — never when you open the app — and you may decline, in which case
your saved home address is used as the centre instead. On Android the
app asks for approximate location only. The position is used to order
that one list of results: it is not stored on our servers, not synced to
your household, and never attached to a plan.
- A “something changed” signal, if you turn nudges on. Our server
keeps a count of how many of these signals your account has sent in the
past hour, so a malfunctioning device cannot flood your family’s phones;
the count holds no schedule content and ages out. Nudges
themselves are worked out and scheduled entirely on your phone — the
times you see are never calculated on a server. What travels is only a
silent background message telling your other household devices that a
plan changed and which household it belongs to, so each phone can update
its own reminders. It carries no plan titles, no names, no addresses,
and nothing appears on screen when it arrives. Delivery goes through
Expo’s push service and then Apple’s or Google’s notification systems,
which see the device token and the message envelope.
- If the app crashes or hits an error, a diagnostic report (stack
trace, device model, OS version, app version) is sent to Sentry so we
can fix it. These reports are scrubbed of message text before sending
and never include household content or anything you captured.
What we do NOT do
- No advertising, no trackers, no analytics SDKs, no selling or
sharing of data with data brokers.
- No training of AI models on your data, by us or (per their API terms)
by Anthropic.
- No background location tracking, and no location access at all except
while you are actively searching for a place (see above). The app does
not follow you, does not log where you have been, and keeps no location
history.
Children
Homie is designed for families, including children. A child
cannot create an account on their own: child accounts can only join a
household through an invite code created by a signed-in adult of that
household — creating that invite is the parent’s or guardian’s consent
for the child’s use of the app. Invite codes for restricted (child)
accounts carry limited permissions set by the adult. Notifications are off
by default on every device, and the setting lives on a screen restricted
accounts cannot reach, so a child’s device does not register a
notification token. If you believe a
child’s account was created without parental consent, contact us and we
will delete it.
Your data, your control
- Access and deletion: household adults can edit or delete any
household record in the app. Removing a member (or a member leaving)
ends their access. You can delete your own account from inside the
app — Home tab → Delete account. If you are the last member of your
household, its synced data is erased along with your account. If others
remain, the shared schedule stays with them (it belongs to the
household, not to any one person) while your personal details — your
private task lists, your contact email, any invite codes you created —
are removed. You can also contact us at the address below.
- Turning nudges off deletes the token for that device, on our
servers as well as on the phone. Deleting your account deletes every
token registered to it.
- Local-only mode: the app works without sync; without it, household
data never leaves your devices except for the AI parsing and map
lookups described above.
- Backups you export are yours and are stored wherever you put them.
Service providers
| Provider |
Purpose |
What they receive |
| Supabase |
account auth + household sync |
email, password (hashed), synced household data |
| Anthropic (Claude API) |
turn captured text into draft events |
the text you capture, via our pass-through proxy |
| Resend |
password-reset emails |
your email address |
| Sentry |
crash + error diagnostics |
error reports: stack traces, device & OS version (NOT household content or captured text) |
| Geoapify |
address → coordinates + travel-time estimates + place search |
address text you save; pairs of map coordinates; while you search for a place, your device’s position as the search centre (NOT who is traveling or why) |
| TomTom |
live traffic drive times near departure |
pairs of map coordinates + a departure time (NOT who is driving, and only for driving plans) |
| Expo (Expo push service) |
delivering the silent “a plan changed” signal to your other devices |
your device’s notification token + a signal naming which household changed (NOT plan titles, names or addresses) |
| Apple (APNs) / Google (FCM) |
carrying that signal to the device |
your device’s notification token + the same signal |
Changes
We will update this page when the app’s data handling changes and adjust
the “last updated” date above. Material changes will be called out in the
app’s release notes.
Questions or data requests: homie.family@protonmail.com