This policy explains what TritonChores does with personal data. It covers the mobile app for iOS and Android and this website at tritonapps.com/tritonchores.
1. Who we are
TritonChores is published by TritonApps, Republic of Ireland. TritonApps is the data controller for the personal data described here. For privacy matters, email privacy@tritonapps.com.
2. What we process, and why
TritonChores is a shared app: a household is a group of people looking at one list, so some of your data is visible to the other members of your household by design. That is the point of it, and it is worth knowing before you join one.
| Data | Why | Who can see it |
|---|---|---|
| Email address and display name | To create and sign in to your account, and to show who a chore belongs to | You, and the other members of any household you join |
| Password | Authentication. It is salted and hashed by Supabase Auth; we never see or store the plaintext | Nobody |
| Optional profile image | Only if you choose one, to tell members apart at a glance | You, and your household |
| Households, chores, assignments, due dates, recurrence and templates | The core function of the app | You, and your household |
| Completion history, points, streaks, levels, achievements and leaderboard position | To show progress and how the work is split | You, and your household |
| Push notification token | Only if you enable reminders, so a notification can reach your device | Nobody but us and the push service |
| Notification preferences | To respect when, and whether, you want to be reminded | You |
| Usage events (for example that the app was opened, or a chore completed) and last-sign-in time | To understand which features are used and to detect misuse of an account | Nobody but us |
Our lawful bases are contract (we cannot run a shared household list without an account and the chores in it) and legitimate interests (keeping the service secure, and understanding in aggregate which features are worth keeping).
What we do not do. There is no advertising SDK in the app, no third-party analytics SDK, and no profiling or automated decision-making. We do not sell personal data, and we do not share it with anyone for their own marketing. The app does not request location, contacts or microphone access.
3. Sub-processors
- Supabase — authentication, the database that holds households and chores, and the edge function that deletes an account.
- Expo push service — delivery of push notifications, and only if you have enabled them. It receives the device token and the notification content, not your chore history.
- Apple and Google — distribution of the app, and the platform notification services a push travels over.
Usage analytics are stored in our own Supabase project rather than sent to a third-party analytics provider.
4. How long data is kept
Account and household data is kept while your account exists. Delete your account and the account record, your profile, your notification tokens and your personal completion history are removed.
Chores you created in a shared household may remain visible to that household after you leave or delete your account, with your name detached from them — otherwise deleting one member would silently rewrite the household’s shared record. Usage events are retained in aggregate.
Backups are retained on a rolling basis by Supabase and are overwritten in the ordinary course.
5. Your rights
Under the GDPR you have the right to access your data, correct it, erase it, restrict or object to processing, and to data portability. You may also lodge a complaint with the Irish Data Protection Commission.
6. How to exercise your rights
Two of them are in the app and need no request: Settings → Export Data gives you a copy of your data, and Settings → Delete Account erases it.
For anything else, email privacy@tritonapps.com from the address on your account. We respond within 30 days, in line with GDPR Article 12, and may need to verify your identity first.
7. Children’s data
TritonChores is a household app and is plainly usable by families, but it is not directed to children under 13 (or 16 where GDPR Article 8 sets that threshold), and an account is required to use it. We do not knowingly collect personal data from children below the applicable age.
A parent setting up a household for their family should create the accounts themselves. If you believe a child has created an account independently, email privacy@tritonapps.com and we will delete it.
8. International transfers
Supabase and the Expo push service may process data outside the European Economic Area. Where they do, transfers rely on the European Commission’s Standard Contractual Clauses or an equivalent mechanism, and your data keeps the protection the GDPR requires.
9. Security
Traffic between the app and Supabase is encrypted in transit. Access to household data is enforced by row-level security in the database, so one household cannot read another’s. Your session token is held in the device keystore rather than in ordinary app storage.
No system is perfectly secure. If a breach affects your rights and freedoms we will notify you and the Data Protection Commission as the GDPR requires.
10. Changes to this policy
If this policy changes materially we will update the effective date above and, where the change affects how your data is used, tell you in the app before it takes effect.
11. Contact
TritonApps, Republic of Ireland — privacy@tritonapps.com.