Privacy in plain English

Shared home details are private. Here is what happens to the data.

A shopping list or bill amount can reveal more than it first appears. We therefore separate the content you read on the phone from its encrypted form and the technical data needed to keep the shared state current.

01

On the phone

Content is readable on an unlocked device because the app needs to display, edit and search it. Access to the phone and its screen lock still matter.

02

Before sending

Content is encrypted on the phone before it is sent. That includes shared entries such as shopping, bills, projects and plans.

03

On the server

The phone sends encrypted content to the server. The server stores encrypted data and the technical metadata needed to update the shared state.

04

When searching

Content search happens on the phone. Your search phrase is not used to build an external index of your shared home content.

05

In a notification

Notifications contain no titles, amounts or content. Google handles delivery and its delivery metadata. After you open the app, the phone retrieves the current shared state.

06

When adding a device

A new device should not receive access simply because someone knows the account address. The other person approves the device before shared content is made available.

07

What remains your responsibility

Encryption does not replace sensible phone security. Use a screen lock, do not share codes, and do not send readable exports to people you do not trust.

Read the privacy summary

Questions about data

Does data leave the phone?

Yes. Content is encrypted before it is sent, and the server stores encrypted data and the necessary technical metadata.

Will a bill name appear in a notification?

No. Notifications contain no titles, amounts or content.

Does search run on the server?

No. Content search happens on the phone.