Privacy Policy
Chorz · Effective 6 August 2026
Chorz is a household app for sharing expenses, chores, and shopping lists with the people you live with. It is operated by Franco Falaschi (the “data controller” under EU data protection law, GDPR). Contact: privacy@getchorz.com.
The short version: your data exists so the app works for your household. We don’t sell it, we don’t show ads, and we don’t use it for marketing.
What we collect
- Account data — your email address, a display name, an optional avatar photo, and your password (stored only as a cryptographic hash by our authentication provider).
- Household data — the expenses, splits, settlements, chores, and shopping lists you and your housemates create, visible only to members of your household.
- Receipt photos — if you use receipt scanning, the photo you take and the fields extracted from it (merchant, total, date).
- Invitation emails — the email address you invite a housemate with, kept until the invitation is accepted, revoked, or expires.
- Device data — a push-notification token if you enable notifications, and crash reports (device model, OS version, app state at the time of a crash) if the app crashes.
We do not collect your location, contacts, browsing history, or advertising identifiers, and we do not run behavioural analytics.
How we use it
- To run the app: sync your household’s data between members, calculate balances, deliver invitations and notifications.
- To read receipts: extract the merchant, total, and date from a photo you scan.
- To keep the service working: crash reports help us fix bugs. They are scrubbed of tokens and secrets before leaving your device.
- To secure accounts: sign-in emails, email confirmation, and optional two-factor authentication.
Legal bases under GDPR: performance of a contract (running the app you signed up for), legitimate interest (crash reporting, abuse prevention), and consent where required (notifications, receipt scanning — both optional).
Who processes it for us
| Provider | Purpose | Where |
|---|---|---|
| Supabase (on AWS) | Database, authentication, file storage — all app data | EU (Ireland, eu-west-1) |
| Anthropic | Receipt photos are sent to the Claude API to extract merchant/total/date when you scan | United States, under Anthropic’s commercial data-processing terms (API inputs are not used to train their models) |
| Resend (on AWS SES) | Sending sign-up confirmation and invitation emails | EU (Ireland, eu-west-1) |
| Sentry | Crash reports | EU (Germany) |
| Expo, Apple, Google | Delivering push notifications to your device (message content only; no household financial data in payloads beyond what the notification shows) | United States |
| Open Food Facts | Looking up a product name when you scan a barcode in the shopping list. Only the barcode itself is sent — no account, household, or other personal data. | Independent open database (openfoodfacts.org) |
Transfers outside the EU rely on the providers’ standard contractual clauses or an applicable adequacy decision. No provider may use your data for its own purposes.
How long we keep it
- Account and household data: for as long as your account exists.
- Invitation emails: until accepted, revoked, or expired.
- Crash reports: retained by Sentry on a rolling window (90 days).
- Deleting your account (Settings → Delete account) permanently removes your profile and personal data. Shared household records you contributed to (e.g. expenses you paid in a household that continues to exist) are settled or removed as part of the deletion flow.
Security
Data is encrypted in transit (TLS) and at rest. On your phone, the app’s local cache is encrypted with a key held in your device’s secure keychain, and you can additionally require Face ID / Touch ID to open the app. Access to household data is enforced per-household on the server, not just in the app.
Your rights
Under GDPR you can ask for access to, correction of, deletion of, or a copy (export) of your personal data, and you can object to or restrict processing. Deletion is available directly in the app; for anything else email privacy@getchorz.com and we’ll respond within a month. You also have the right to complain to your local data protection authority.
Children
Chorz is not directed at children under 16.
Changes
If this policy changes materially, the app will tell you before the change applies. The current version always lives at getchorz.com/privacy.