
Privacy · approved for web
Home Cadence Privacy Policy
Home Cadence privacy policy approved for the public website — form and app data, providers, retention and user rights.
1. Controller and contact
The controller of personal data related to Home Cadence is Brillnet Piotr Adamski, ul. Sienkiewicza 73/6, 90-057 Lodz, Poland, Tax ID PL7321779060.
For support and data-subject rights, email hello@brillnet-app.com. Report vulnerabilities and security incidents to security@brillnet-app.com.
2. Scope and service stage
This policy covers the public Home Cadence website, its pilot-interest form and the app being prepared. Publication of the website at home-cadence.com is approved; the app has not been publicly released or published on Google Play.
The text distinguishes the active website, the locally prepared app, components checked in a test environment, the unconfirmed distribution version of the app and planned features. Website availability is not proof that the app is available to users.
3. Google account and identifiers
Sign-in uses Google Credential Manager, not Firebase Authentication. With the user's permission, Google supplies a credential containing a stable account identifier and may provide an email address, name and profile image. The current Home Cadence system uses the Google identifier to derive a Home Cadence user identifier and does not store the email, name or profile image in the account record.
The app and providers may process a Home Cadence user ID, device ID, session and request IDs, IP address, and technical app, operating-system and device information for sign-in, sync, security and diagnostics.
4. Household data and encryption
On the device, the app processes tracker, task, shopping, bill, budget, project, plan, document, photo, gallery, activity, search and export content. This remains user data even where it leaves the device only as ciphertext.
Content is stored in an encrypted local database and encrypted from device to device before synchronisation. Cloudflare services are intended to process ciphertext and the technical metadata needed to provide the service. Encryption does not mean that data is not collected.
5. Firebase Cloud Messaging
Firebase is configured only as an FCM channel. The planned SYNC_REQUIRED message contains no titles, amounts, content or domain identifiers.
After FCM activation, Google processes a Firebase installation ID (FID), the app version and technical device and software-tool information needed to deliver the signal. Automatic initialisation is currently disabled. Tests with synthetic data confirmed masked server-side FID registration and invalidation. We still lack confirmation on a real device running the app version intended for distribution that FCM unregistration and Firebase Installation identifier deletion work correctly.
6. Purposes and legal bases
- account and household creation, sync, export and app functionality — Art. 6(1)(b) GDPR or steps requested before entering into a contract;
- security, abuse prevention, basic logs and defence of claims — Art. 6(1)(f) GDPR;
- support and complaint handling — Art. 6(1)(b) or (f) GDPR, depending on the matter;
- contact and recruitment for the pilot after a voluntary form submission — Art. 6(1)(a) GDPR; consent can be withdrawn by emailing hello@brillnet-app.com;
- legal obligations — Art. 6(1)(c) GDPR;
- optional product research, only after a separate activation — Art. 6(1)(a) GDPR. Research analytics is not currently confirmed as active in production.
7. Recipients and transfers
Cloudflare serves the website and form and processes infrastructure data, ordinary request metadata and security signals. EmailLabs / Vercom S.A. processes the submitted form fields to deliver one transactional notification to the approved Brillnet contact; the form does not write a contact list or subscriber database. Google processes sign-in data through Credential Manager and, after app activation, FCM/FID technical data. The mailbox provider handles messages sent to support. Each provider's processing role, terms and applicable transfer mechanisms apply.
We do not claim EU-only processing. Data Safety and encryption are not evidence of data location.
8. Retention, export and deletion
The locally prepared app provides a seven-day export window after household separation begins, followed by thirty days of archive and deletion with a minimal record confirming deletion. Tests with synthetic data in a test environment confirmed the automated full account-deletion process. We have not confirmed that process on a real device running the app version intended for distribution, so we do not promise that it operates in an app available to users.
Pilot-form data is retained until recruitment closes or consent is withdrawn and is then deleted without undue delay, except for minimal records needed for legal claims or security. Retention periods for Cloudflare logs, backups, support data and the app's minimal deletion record are not yet approved. The app is designed to unregister FCM and delete the Firebase Installation identifier separately, but both operations still require confirmation on a real device running the app version intended for distribution. A readable or encrypted export is a deliberate local user action.
9. Your rights
Subject to the GDPR, you may request access, rectification, erasure, restriction and portability, object to processing, and withdraw consent without affecting earlier lawful processing. Send requests to hello@brillnet-app.com.
You may lodge a complaint with the President of the Polish Data Protection Office. Statutory response periods apply; acknowledgement targets do not shorten or replace them.
10. Website data and document changes
The Home Cadence website uses no cookies, marketing analytics, advertising pixels, third-party client scripts or external fonts. Ordinary browsing does not submit form data. When a person deliberately submits the form by POST, Cloudflare passes the supplied fields to EmailLabs / Vercom S.A. to deliver one notification for the stated purpose; Cloudflare also processes ordinary request metadata and security signals.
Owner approval and legal review of the public home-cadence.com website and form are complete. The public website is deployed, and every change is subject to automated testing after publication. Before the app is made available to users, the policy also requires a fresh comparison with the app's actual behaviour, the Google Play Data safety declaration and active service providers.