Trust & Privacy

How iZoku protects your household

This page is maintained by the iZoku team to answer common security and privacy questions about the app. It describes app-visible controls and current practices; it is not a third-party certification or independent audit.

Who can see your data

Every household is isolated. Bills, expenses, chores, groceries, notes, maintenance requests, vault documents, rewards and guest visits are only readable by people you have invited as members of the same household.

Access is enforced server-side by row-level security policies on the database - not just in the UI. Removing a member revokes their access on the next request.

Account access

Sign-in is handled by our managed authentication provider. We do not store your password. Sessions live in your browser and can be ended by signing out.

Household invites are single-use, expire after 7 days, and require an authenticated account to accept.

Hosting & infrastructure

iZoku runs on Lovable Cloud, which provides managed application hosting, a managed PostgreSQL database, authentication and file storage. Traffic to the app is served over HTTPS.

Data we collect

We collect only what the app needs to function: your display name and (optionally) avatar, your household memberships, and the content you enter into the app (expenses, chores, notes, documents you upload to the vault, etc.).

We do not sell your data and we do not use it to train third-party advertising models.

Vault documents

The Vault stores files in a private bucket. Access is gated by household membership and per-document visibility rules - files marked private are only readable by their owner, the primary tenant, or explicitly granted members.

Retention & deletion

You can delete individual records at any time from inside the app. Deleting your account removes your profile and revokes your access to every household you belong to.

Reporting a security issue

If you believe you have found a vulnerability, please email the team using the contact channel in the app. We respond to credible reports as quickly as we can and we will not pursue good-faith researchers.