Privacy Policy
PRIVACY POLICY
Last Updated: September 2026 (Version: v1.1-2026-09-08)
We are committed to protecting your privacy in compliance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs).
1. INFORMATION WE COLLECT
We collect the personal information necessary to run a shared household:
- Account Data: email address, display name, user ID, and your Terms agreement consent timestamp.
- Household Group Data: group names, members and roles, tasks, calendar events, meal plans, shopping and pantry lists.
- Household Chat: the messages you send in your household's group chat.
- Assistant Conversation: what you type or say to the in-app assistant, and its replies. This conversation is private to you — other members of your household cannot see it.
- Infant Health & Care Records: if you use the Baby Tracker, we collect what you record about a child in your care — feeds (including times, durations and volumes), sleeps, nappies, medicine doses, temperatures, baths, growth measurements, immunisation records and any notes you add. See section 4.
- User Photos: photographs you upload to your household's photo wall, a child's or member's display photo, and optional dish photos attached to public recipe reviews.
- Voice: if you use a voice assistant or a connected device, the text of what you asked and what was said back. See section 6.
- Technical Data: a push notification token per device, and counters recording how much of your weekly AI allowance you have used.
2. CLIENT-SIDE EXIF METADATA STRIPPING (PRIVACY BY DESIGN)
When you upload a dish photo from your camera or photo library, our mobile app automatically strips all embedded EXIF metadata (including GPS location coordinates, camera serial numbers, and device timestamps) in memory on your device BEFORE the image is transmitted. We do NOT collect or store household location metadata from your photos.
3. HOW WE USE YOUR DATA
We use your information solely to:
- Render your household's meal plans, calendar, tasks, chat, shopping lists and baby records for the people in that household;
- Answer what you ask the assistant, and carry out the actions you approve;
- Run automated safety and dish-relevance checks on uploaded dish photos;
- Display community reviews and photos in approved public galleries;
- Send you the notifications you have turned on.
We do not sell your personal information, and we do not use it for advertising.
4. CHILDREN'S AND INFANT HEALTH DATA
The Baby Tracker records health information about an infant, entered by an adult caring for them. We treat it as sensitive information under the Australian Privacy Principles.
- WHAT IS COLLECTED: what you choose to record — feed times, durations and volumes; sleeps; nappies; medicine name, dose and time; temperature; bath times; growth measurements; immunisation records; and free-text notes.
- WHY: solely to show it back to the adults in that household, so that two carers can hand over accurately, and to power reminders you have asked for.
- WHO CAN SEE IT: the active, approved members of that household, and nobody else. It is not shared with other households, is never part of any public gallery, and is not used to build a profile of a child.
- THE APP IS NOT A MEDICAL DEVICE. Nothing it records or shows is medical advice, and it does not diagnose. Consult a health professional for clinical concerns.
- CHILD ACCOUNTS. A person aged 13 to 17 may hold an account in a group, created by a parent or guardian who is an adult member of that group and who declares the child's age. A person younger than 13 is not an account holder at all; they are recorded the way a baby is, as the subject of an adult's own records. A child account has no assistant, no daily brief and no voice, and a child under 15 has their consents given by that parent or guardian; from 15 they may give some of their own, and from the month after their 16th birthday the account is an ordinary account. The guardian link to a dependant's account continues until the young person turns 18. What a child account holds, who can see it and what a parent can do is set out in plain words inside the app, on the child's own "What your parent can see" page. That child is also entitled to their own privacy policy, written for them: the Children's Privacy Policy, available in the app from the same place and published at this policy's own web address.
- WHAT A GUARDIAN CAN SEE AND DO FOR A DEPENDANT. As the parent or guardian who added a child to your group, you can see everything they do inside that group, the same as any other member — their tasks, their calendar, their chat messages, their photos and their game history. You cannot see the plan they keep for themselves; that is theirs alone, the same as anyone else's is theirs. You gave the consent that created their account, it lasts 12 months, we ask you again before it lapses, and you can withdraw it at any time; withdrawing does not remove their account by itself. Whether children may be members of your group at all is a decision you make together with any other owner or admin, and the whole group is told in the chat when it changes. The app does not tell you what your dependant looked at, or when.
5. ARTIFICIAL INTELLIGENCE
Some features send text to a third-party AI provider to produce an answer.
- WHAT IS SENT: what you type or say to the assistant, plus a short, relevant excerpt of household context needed to answer it — for example the names of members it may assign a task to, or a recent summary of a child's day if you have turned that on. Dish photos you upload are sent to an AI safety check before they are stored.
- WHAT IS NOT SENT: your household's chat messages, your photo wall, and any part of your records the feature does not need. Nothing is sent unless you have taken an action that asks for an answer.
- YOUR VOICE AUDIO IS NEVER SENT TO US. Speech is transcribed on your device where the platform supports it, and by the platform's own service where it does not. We receive text, never a recording, and we do not store audio.
- The provider processes the request to return an answer and does not use it to train models. We do not use your data to train models of our own.
- YOUR ASSISTANT CONVERSATION IS ENCRYPTED ON YOUR DEVICE, from September 2026 and from the point your device has done it. A message you type to the assistant is encrypted on your phone before it is saved, under a key held only by your own devices. Conversations from before that, and anything you asked a voice assistant for — those rows are written by our servers, which hold no such key — remain ordinary text until you run "Encrypt your past conversations" in the app's settings. Encrypting the record does not change what is sent to answer you: the text of your question still goes to the AI provider, as described above.
- HELPING US IMPROVE IT IS A SEPARATE, OPTIONAL CHOICE. A switch in the app's settings, off unless you turn it on, shares your assistant conversations with the tracing tool we use to work out why the assistant did something — the message, the recent turns sent with it, what it looked up in your group, and the replies. With it off, nothing is sent there. It applies to your own conversations only, we ask again every 12 months, and turning it off is one tap in the same place.
- A plain-language explanation of exactly what the assistant can and cannot see is available in the app, under the assistant and voice settings.
- AUTOMATED DECISIONS: a model makes three kinds of decision on its own. It may choose WHO should do a task or calendar item, from a list the app has already worked out, and any of you can change that assignment at any time. It checks whether a written recipe review or a dish photo meets our content rules before it is published or stored; if it does not pass, it is not published, you are told, and you can try again or write to us. And it may suggest a start time for a new event from your group's own past events, which you can change before saving. It never decides what needs doing, anything about a person's health or a child's wellbeing, or who is in your group. A plain-language explanation is available in the app, under the assistant settings.
6. VOICE ASSISTANTS AND CONNECTED DEVICES
If you connect a phone, watch or speaker, that device holds a narrow credential rather than your login. You can see and revoke every connected device in the app at any time. A spoken answer is heard by whoever is in the room, so the assistant will not read out a child's name or their records to a shared device unless you have allowed it.
7. DATA STORAGE, SECURITY & RETENTION
Data is stored in encrypted cloud database infrastructure, and access is enforced per household by Row Level Security policies rather than by application code alone. Photographs are stored in private buckets and are served through short-lived signed links.
- GROUP CHAT MESSAGES ARE ENCRYPTED ON THE SENDER'S DEVICE, from September 2026 and from the point a device in your group has done it. A message, and the quote a reply carries, are encrypted before they are sent, under a key held only by your group's own devices. Messages from before that remain ordinary text until somebody in the group runs "Encrypt older messages" from the chat, and until it finishes both kinds are there at once. A notification about a message therefore tells you who sent it and which group it was in, and does not carry the message, because we do not have it to send. If your group loses every device and its recovery phrase, the encrypted messages cannot be recovered — by you or by us.
RETENTION: we keep your information for as long as your account exists, because it is the record your household is using. Three things are kept to a fixed window instead:
- Assistant conversations — what you typed or said to the assistant, its replies, and the history of the action cards it raised — are deleted after 30 days. Anything you approved lives on in your household's tasks, calendar and records; only the conversation itself is discarded.
- Review moderation records — the text of a review our automated checker refused, held encrypted so that repeat abuse can be recognised — are deleted after 30 days.
- Diagnostic delivery records for notifications are removed when your account is.
When you delete your account (section 8) your data is removed from our live systems immediately.
CONSENT: we ask again every 12 months for anything you have switched on that shares information. When a year has passed we turn that setting off and tell you why on the screen it lives on, so nothing keeps running because nobody revisited it. We keep a record of each of these answers — what it was for, which wording you agreed to, when, and who gave it — and you can withdraw any of them at any time by turning the setting off.
BACKUPS AND RESTORES: our database is backed up on a rolling schedule by our hosting provider. Backups are not edited individually — nobody can reach into one to remove a single account, and a provider that offered to would be a worse custodian, not a better one. Instead they expire on that schedule, and if we ever have to restore one we re-apply every deletion recorded since the point we restored to, before the service is returned to use. We keep a separate, append-only record of which accounts have been deleted and when — held with a different provider, precisely so that restoring the database cannot erase the evidence that an erasure happened. That record contains an account identifier and a timestamp, and nothing describing the person: no name, no email, no household, no content.
8. YOUR RIGHTS (ACCESS, EXPORT, CORRECTION & ERASURE)
Under the APPs, you have the right to:
- Access the personal information we hold about you, and download a copy of it. "Download my data" in the app's settings produces a machine-readable archive of your account, your household records and a list of your photographs.
- Request correction of inaccurate data.
- Delete your account and your data. "Delete my account & data" in the app's settings removes your account, your assistant conversation, your display photo and your dish photos, and permanently deletes any household where you are the last remaining member — including its tasks, calendar, chat, baby records and photographs, files included. A household you share with other people is not deleted, because it is not yours alone to erase.
This is immediate and cannot be undone by us.
REQUESTS ABOUT A SPECIFIC ITEM, OR A COMPLAINT: you can also ask us to act on something more specific — a particular photo, message or record — or make a complaint about how we have handled your information. Write to privacy@brendanpatch.com. Anyone may make a complaint, including anonymously. A parent or guardian may make either kind of request on behalf of a person under 15. We acknowledge every request within a few business days and give you a written decision, including our reasons if we are unable to do what you asked, within 30 days. If you are not satisfied with our response, you may take the complaint to the Office of the Australian Information Commissioner (OAIC).
9. CONTACT US
For privacy inquiries or data requests, contact us at privacy@brendanpatch.com.