Trust & privacy
Security and privacy
This page answers the common security and privacy questions about the app. It describes controls that exist today, not a third-party certification or independent audit.
What is protected, and how
Who can see your data
Every household is isolated. Bills, expenses, chores, groceries, notes, maintenance, vault documents, rewards and guest visits are readable only by the people you invited to that household.
Access is enforced in the database itself, not just in the UI. Removing a member revokes their access on the next request.
Account access
Sign-in runs through a managed identity provider and we never store your password. You can end a session at any time by signing out.
Household invites are single use, expire after 7 days, and require a signed-in account to accept.
Hosting and storage
Data lives in a managed database with encryption in transit and at rest, and files are kept in private buckets served through short-lived signed links.
What we collect
Only what you enter for the home: household records, an email address for sign-in, and your display and language preferences.
We do not sell your data and we do not pass it to third-party advertising models.
Vault documents
The vault stores files in a private bucket. Access follows household membership and each document's visibility rule, so a private file is readable only by its owner, the primary tenant, or explicitly granted members.
Retention and deletion
You can delete any record from inside the app. Deleting your account removes your profile and revokes your access to every household you belong to.
Active controls
Household isolation
Row-level security policies in the database prevent access to another household's data, even when a request is sent straight to the server.
Managed authentication
Sign-in is handled by a managed identity provider. We do not store passwords.
Single-use invites
An invite link is valid for a limited time, can be used once, and requires a verified account to accept.
Encrypted vault
Vault documents live in a private bucket, with client-side encryption and per-document visibility rules.
Action history
Meaningful changes are written to an audit log, so it is always clear who did what and when.
Rate limiting and abuse protection
Sensitive actions are rate limited, and registering a duplicate apartment by city, street, floor and apartment is blocked.
Security scans
We run security scans over the database and dependencies on an ongoing basis and address findings before a release goes out. We do not publish open findings on a public page, so that nothing useful to an attacker is exposed.
- Access policies are reviewed for every new table.
- Dependencies are updated when a known vulnerability appears.
- Functions with elevated privileges verify household membership themselves.
Data retention policy
- Content you enter is kept as long as the household exists, and any record can be deleted from inside the app.
- An account deletion request enters a 30-day waiting period, during which it can be cancelled.
- After deletion your profile is removed and your access to every household is revoked.
- Audit logs are kept for integrity tracking and are removed together with the household.
- We do not sell data and we do not pass it to advertising.
Your rights
You can export your data, request deletion, and update your details from the app settings at any time.
Reporting a suspected vulnerability
Write to us and we will get back to you. A good-faith report is always welcome.
If you believe you found a vulnerability, write to us through the contact page. We respond to credible reports quickly and will not pursue good-faith researchers.
This page is maintained by the iZoku team and describes controls that exist in the app. It is not a certification, an external audit or a legal commitment.