Privacy policy
Updated 6 September 2026
In short
Kotityöt is an app built for one family's internal use. It collects no usage data, contains no advertising and does no tracking, and includes no third-party components whatsoever. All data lives in the family's own database and is never shared with anyone.
The app does not ask for an email address and creates no user account. The family shares one password and pairs devices with a join code.
What data is processed
Everything below is content entered by the family itself.
| Data | What it is | Why |
|---|---|---|
| Family members' first names | Names chosen by the family, e.g. “Matti”. No surnames, no contact details. | A completion has to belong to someone. |
| Chores | Name, category, allowed weekdays and star value. | The contents of the week grid. |
| Completions | Which chore, which day, under whose name, how many stars and from which device. | The app's core function. |
| Rewards and redemptions | Reward name, star price and the moment of redemption. | Spending stars. |
| Achievements, streaks and goals | Values derived from completions. | Gamification. |
| Device identifier | The name given when pairing and a SHA-256 hash of the token. The token itself is never stored on the server. | Identifying and revoking a device. |
What is not processed
- No email addresses, phone numbers, postal addresses or surnames.
- No location, contacts, photos, health data or payment data.
- No usage analytics, crash reporting or advertising identifiers.
- No tracking cookies. The website's only cookie is the sign-in session.
Where the data is
- Database: PostgreSQL (Neon), region eu-central-1, Frankfurt, Germany.
- Application server: Vercel, region fra1, Frankfurt, Germany.
- Data does not leave the EU and is not disclosed to third parties.
Both are the family's own installations. The author of the app does not operate a central service that would accumulate families' data.
What stays on the device
| Item | Location | Note |
|---|---|---|
| Device token | iOS Keychain | Not UserDefaults: that is readable in plain text from a backup. |
| Server address and selected member | UserDefaults | No secrets. |
| Week cache and unsent completions | The app's caches directory | Cleared when the device is unpaired from the family. |
Who can access the data
- Website: the whole interface is behind the family's shared password. The session is a signed cookie valid for 30 days. Changing the password signs out every device immediately.
- iOS app: a device is paired with the family's join code and receives its own token. Only a hash of the token is stored on the server, so a leaked database grants no access.
- Administrative actions (editing chores and rewards, approving redemptions, recording a past day) require a separate administrator password.
Children's data
The app is intended for use within a family, and the data partly concerns children. It is entered by the family itself, is limited to first names and chore completions, and lives in the family's own database. The app is not published in the App Store Kids category and contains no advertising, purchases or external links.
Retention and deletion
Data is retained for as long as the family keeps it in its own database. The family can delete chores, members, completions and rewards from the app, and the entire database can be deleted at once. Unpairing a device revokes its token and clears the cache left on that device.
Controller and contact
Because each family maintains its own installation, the family itself is the controller of its data. Questions about the app: tietosuoja@chores.fi.