Privacy policy

Last updated: July 2026

1. Data controller

The controller of the personal data described in this policy is Daniel Cimorra Tapia, an individual resident in Spain. As stated in the legal notice, full identification (national identity document) and the address for notices are not published on this page, but are available to the competent supervisory authority when legally required. For any privacy-related request, write to [email protected].

homeify.cc and hogarify.cc are the same service and a single processing operation, under the same controller. Whichever domain you signed up through, this policy and these rights apply to you.

2. Legal basis

We process your data on the following bases under Article 6 GDPR: performance of a contract (account, homes and all the content you need to use the service — without them there is no service); legitimate interest (security logs and abuse prevention, limited to what is necessary and balanced against your rights); and consent, where you have given it, for anything the above don't cover. We do not process special categories of data (Article 9 GDPR).

3. What data we process

Only what the service needs in order to work:

  • Account:your email address, your display name and your avatar colour. We don't store passwords because we don't use them: you sign in with a single-use link sent to your email.
  • Household content: chores, notes, calendar events, pantry items, shopping lists, expenses, settlements and subscriptions. It is visible to the other members of the home where you create it, and only to them.
  • Approximate location of the home(optional): the name of the town and its coordinates, if you choose to add them to see the weather. You can delete them whenever you like from the home's settings.
  • Billing data, only if you take out a paid plan: whatever the payment gateway requires to issue the invoice.
  • Technical data:IP address and user agent when signing in, and a record of emails sent, kept in a limited way for security and to be able to work out why a sign-in link didn't arrive.

4. Minors

homeifyis used, among other things, to run a household as a family, so we assume there may be minors among a home's members. Whoever creates the home and invites a minor acts as their parent or guardian and is the one authorising that processing; we do not verify anyone's age. A minor can be named on a chore without having their own account — if you prefer that, there is no need to give them an email address. If we detect a minor's account created without that authorisation, we will delete it.

5. Third-party data: letting homes

There is one case where the data stored belongs neither to the person entering it nor to anyone with an account: homes of the Lettingkind, where the landlord enters a contract with their tenant's name, email and payment history. It's worth being clear about who is responsible for what.

In respect of that data, the landlord is the data controller —they decide what is entered and what for— and we act as the processor: we host and process it following their instructions, we do not use it for any purpose of our own, we do not disclose it to anyone other than the providers in the next section, and we keep it for as long as the home exists or until we are asked to delete it. The full terms of that arrangement —security measures, sub-processors, deletion periods and breach notification— are in the data processing annex, which the landlord accepts when creating the home. Our staff do not access any home's content unless it is strictly necessary to resolve a specific incident, and in that case it is logged.

If you are a landlord, by entering that data you confirm that you have a lawful basis for processing it —normally the contractual relationship— and that you will inform your tenant that you use this tool. Store only what is needed: running a tenancy and its receipts doesn't require uploading an identity document or a payslip.

If you are a tenant and want to exercise your rights over that data, you can approach the landlord —who is the one deciding about it— or write to us at [email protected]: we will help you channel it. When the tenancy ends you lose access to the property inside the application, but the history of that relationship remains with the landlord, just like a paper file of receipts.

6. Who it is shared with

We do not sell data and we do not use it for advertising. Only the necessary providers are involved:

  • Outbound email provider: delivers sign-in links, invitations and any alerts you have turned on. It receives your address and the message content.
  • Open-Meteo:if you add the home's location, its coordinates are sent to look up the weather. No data of yours and no account identifier is sent.
  • Payment gateway (Lemon Squeezy), only if you take out a paid plan. Your card details are handled by the gateway; we neither see nor store them.
  • Analytics on the public pages: aggregated visit measurement. See the cookie policy.

Some providers may be outside the European Economic Area. Where that is the case, the transfer relies on the safeguards provided for by the applicable rules (for example, standard contractual clauses) to the extent that the agreement with that provider includes them.

7. How long

We keep your account and your content for as long as the account is active. When you delete it, we delete your personal data and the homes where you were the only person, except for anything the law requires us to keep (for example, billing records). A shared home's content doesn't disappear because you leave: it still belongs to the other members.

Security and email-sending logs are kept for a short period and rotated automatically. Sign-in links expire and are invalidated on first use.

8. Security

There are no passwords to steal: you sign in with a single-use link, with an expiry and atomic consumption. Sessions are server-side cookies, completely separate between the household panel and the platform administration. Third-party credentials we store (outbound email, payment gateway) are encrypted with AES-256-GCM. Each home is isolated by identifier in every database query. No system is perfectly secure and we cannot guarantee the absolute security of anything travelling over the internet.

9. Your rights

You can access your data, rectify it, erase it, restrict or object to its processing, and request a portable copy. Most of it you can exercise yourself from within the application: edit your profile, leave a home, delete content or delete your account. For anything else, write to the address in section 1. If you believe we haven't handled your request properly, you can complain to the Spanish Data Protection Agency (www.aepd.es) or, if you live in another EEA country, to your national authority.

10. Changes

We may update this policy as the service evolves. Material changes will be notified inside the application or by email. The date in the header reflects the last revision.