
Privacy in plain English
Shared home details are private. Here is what happens to the data.
A shopping list or bill amount can reveal more than it first appears. We therefore separate the content you read on the phone from its encrypted form and the technical data needed to keep the shared state current.
On the phone
Content is readable on an unlocked device because the app needs to display, edit and search it. Access to the phone and its screen lock still matter.
Before sending
Content is encrypted on the phone before it is sent. That includes shared entries such as shopping, bills, projects and plans.
On the server
The phone sends encrypted content to the server. The server stores encrypted data and the technical metadata needed to update the shared state.
When searching
Content search happens on the phone. Your search phrase is not used to build an external index of your shared home content.
In a notification
Notifications contain no titles, amounts or content. Google handles delivery and its delivery metadata. After you open the app, the phone retrieves the current shared state.
When adding a device
A new device should not receive access simply because someone knows the account address. The other person approves the device before shared content is made available.
What remains your responsibility
Encryption does not replace sensible phone security. Use a screen lock, do not share codes, and do not send readable exports to people you do not trust.
Read the privacy summaryQuestions about data
Does data leave the phone?
Yes. Content is encrypted before it is sent, and the server stores encrypted data and the necessary technical metadata.
Will a bill name appear in a notification?
No. Notifications contain no titles, amounts or content.
Does search run on the server?
No. Content search happens on the phone.