HouseHold - Privacy Policy
This Privacy Policy is applicable to the HouseHold app for mobile devices and web browsers, together with any related services operated by Tyde (collectively, the "Application"). Tyde is hereinafter referred to as the "Service Provider" or "Data Controller".
Data Controller Information
Tyde acts as the Data Controller responsible for the processing of your personal data.
- Name: Tyde
- Address: Strada Borșa 5, Bucharest - 077190, Romania (RO)
- Email: household@tydecode.com
For data protection inquiries and to exercise your GDPR rights, please contact the Data Controller using the contact information above.
EU Representative: Marian-George Alboaei
Data Protection Officer (DPO)
Marian-George Alboaei serves as the Data Protection Officer responsible for overseeing data protection practices and compliance.
- Email: household@tydecode.com
You may contact the DPO directly for any data protection inquiries, to exercise your privacy rights, or to raise concerns about how your personal data is processed.
Scope and Infrastructure
HouseHold is a house hold organization tool that helps users track house hold supplies, stock levels, low/out status, shopping/restock needs, and settings. The Application consists of a web and mobile user interface that communicates with our servers. Payment checkout, purchase processing, and subscription management are handled through our integrated payment infrastructure and third-party payment providers.
What information does the Application obtain and how is it used?
The Application processes the information you supply when you access, register for, or use the service:
1. Account and Authentication Information: The Application uses Clerk as our authentication provider. When you sign in or register, Clerk collects and processes personal data including your email address, first name, last name, username, user identifier, profile image (if provided), session data, and authentication log events. The Application receives access tokens and identifiers to connect your account securely to your data. 2. HouseHold Supply Information: The Application stores the details you enter and manage within the app, including:
- Rooms or categories (e.g., Kitchen, Bathroom, Cleaning, Laundry, Pets, and Baby)
- Supply item names and item types
- Tracking method (either by quantity or by days remaining)
- Current values and threshold values (used to calculate status)
- Default restock values
- Calculated stock status (such as OK, Low, or Out)
- Preferred brand, store links, and notes
- Stock history logs automatically generated when you perform actions (such as marking an item as used, restocking it, or manually marking it as low or out)
3. Settings and Preferences: The Application stores your configuration preferences, including:
- Your preference to enable or disable browser or device notifications
- Your preference to enable or disable email alerts
- Your preferred layout columns for the supply dashboard
- Your preferred sorting criteria (such as sorting by item name, stock level, status, or date created)
- Your choice on whether to display the welcome onboarding screen after logging in
4. Notifications: The Application displays local browser or device notifications when the backend returns a notification directive for a supply action and browser or device notification permission is granted. If email notifications are enabled, the backend sends automated low/out supply alerts to your Clerk-registered email address. 5. Backup Data: Premium users may export and import JSON backup files containing settings, categories, and item details. If you import a backup, the file contents are processed by the backend in a database transaction to restore your data. Uploaded backup files are processed in-memory and are not stored persistently on our servers after the import operation completes. Users are responsible for storing and securing their downloaded backup files. 6. Payment and Subscription Information: Checkout, subscription status, payment history, and billing notifications are managed through our servers and payment providers (such as Google Play billing for Android purchases, Apple App Store billing for iOS purchases, and Creem as the Merchant of Record for web checkout transactions). The Application does not store or process full payment card details directly; payment providers collect and process payment information under their own privacy policies.
What information does the Application collect automatically?
In addition, the Application and its service providers may collect certain technical information automatically, including, but not limited to:
- The type of mobile device or computer you use
- Your device's unique identifier or device ID
- The IP address of your device
- Your operating system and browser type
- App version, request metadata, diagnostic logs, and error details
- Authentication and session metadata
The frontend utilizes local storage or session storage for app experience state (such as onboarding status). Clerk may use cookies or similar browser storage to manage authentication sessions.
Legal basis for processing your personal data
Where the GDPR applies, the Service Provider relies on one or more lawful bases to process your personal data, including:
- Contract performance: processing necessary to provide the Application or fulfil a contract with you (specifically providing supply tracking, dashboard layouts, and settings configurations).
- Consent: where you have given explicit consent to processing, including for browser or device notifications, email notifications, or optional features. You may withdraw consent at any time without affecting processing that occurred before withdrawal.
- Legitimate interests: where processing is necessary for the Service Provider's specific legitimate interests, such as maintaining network and information security, preventing fraud and abuse, diagnosing bugs, or improving the Application's core functionality, provided those interests are not overridden by your data protection rights or fundamental freedoms.
- Legal obligation: to comply with laws, tax and accounting rules, or government requests.
Cookies and similar technologies
The Application or its third-party SDKs (such as Clerk for authentication) may use cookies, SDKs, and similar technologies to support authentication, session persistence, and secure functionality. Where required by law, the Service Provider will obtain your consent before using non-essential tracking technologies.
Automated decision-making and profiling
The Application does not use automated decision-making or profiling that produces legal effects concerning you or similarly significantly affects you.
Does the Application collect precise real time location information of the device?
This Application does not gather precise real-time location information of your mobile device or computer.
Does the Application use Artificial Intelligence (AI) technologies?
The Application does not use Artificial Intelligence (AI) technologies to process your data or provide features.
Do third parties see and/or have access to information obtained by the Application?
Only necessary data is transmitted to external services to aid the Service Provider in providing the Application. The Service Provider shares your information with third parties only in the ways described below:
- Clerk: For authentication, user profile management, and account/session validation.
- Hosting and Database Providers: For running the HouseHold backend and database infrastructure.
- Payment Providers: (e.g., Google Play Services for Android billing, Apple App Store for iOS billing, and web checkout providers) for managing purchases and payment status.
- Infrastructure & Diagnostics: Logging, monitoring, and security services.
Below are the links to the Privacy Policies of the main third-party service providers used by the Application:
The Service Provider may also disclose user data:
- as required by law, such as to comply with a subpoena or similar legal process;
- when they believe in good faith that disclosure is necessary to protect their rights, protect your safety or the safety of others, investigate fraud, or respond to a government request;
- with trusted service providers who work on their behalf, do not have an independent use of the information, and have agreed to adhere to the rules set forth in this privacy statement.
Where the GDPR applies, the Service Provider enters into Data Processing Agreements (DPAs) with third-party service providers that process personal data on its behalf, as required by Article 28 of the GDPR. These DPAs impose the same data protection obligations on those service providers as described in this Privacy Policy.
International Data Transfers
The Service Provider or its third-party service providers may transfer personal data outside the European Economic Area (EEA), including to hosting or infrastructure servers in other regions. Where such transfers occur, the Service Provider will use an appropriate transfer mechanism required by GDPR Chapter V, such as Standard Contractual Clauses (SCCs) approved by the European Commission, adequacy decisions, or other recognized safeguards.
Countries outside the EEA may not provide the same level of data protection as the EEA. Where required by law, the Service Provider will apply appropriate safeguards and obtain any consent required for the transfer.
What are my opt-out and management choices?
You can manage your information directly through the Application:
- Data Editing: You can create, rename, update, or delete categories and supply items at any time.
- Settings Preferences: You can toggle browser or device notifications, email notifications, dashboard columns, and sorting preferences in the Settings screen.
- Browser and Device Controls: You can disable notification permissions through your browser or operating system settings.
- Uninstall: You can stop further collection of information from your mobile device or computer by uninstalling the Application. Uninstalling will stop the Application from collecting data from your device, but it does not automatically delete information that has already been transmitted to the Service Provider or to third parties.
- Account Deletion (GDPR Right to Be Forgotten): You can request account deletion directly from the Application Settings screen. For step-by-step instructions, see the Account & Data Deletion page.
- Account Deletion Flow: When triggered, the Service Provider deletes your account information, including all stored categories, items, stock history, restock records, settings, and preferences from our database. Billing records are anonymized, active subscriptions are cancelled, and a deletion request is sent to our authentication provider (Clerk) to remove your login profile.
- Some records may be retained where required or permitted by law, such as payment, tax, transaction records, security, backup, or audit records.
What is the data retention policy?
The Service Provider retains personal data based on its necessity for the stated purposes:
- User Provided Data (Account, Settings, Backups): Retained for the duration of your use of the Application plus 12 months thereafter, unless you request deletion or longer retention is legally required.
- Automatically Collected and Technical Data: Retained for up to 24 months from collection, unless longer retention is required for legal compliance or security purposes.
- Aggregated and Anonymized Data: Retained indefinitely as it no longer identifies you.
- Data required for legal compliance (Tax, Payments, Audit): Retained as long as required by applicable law.
You have the right to request deletion of your personal data at any time, except where retention is required by law. If you would like the Service Provider to delete User Provided Data, please contact them at household@tydecode.com and they will respond within the time required by applicable law. Please note that some data may be required for the Application to function properly.
How does the Application address children's privacy?
The Application is not intended for children under 13 years of age, or where a higher age of digital consent is established under applicable law. The Service Provider does not knowingly solicit data from children or market the Application to them.
Where parental or guardian consent is required under applicable law, the Application is not intended for use without that consent. The Service Provider does not knowingly collect personally identifiable information from children under 13 years of age, or where a higher age of digital consent is established by applicable law, in violation of applicable law. In the event the Service Provider discovers that a child has provided personal information, the Service Provider will immediately delete this from their servers. If you are a parent or guardian and you are aware that your child has provided personal information, please contact the Service Provider (household@tydecode.com) so that they can take the necessary actions.
How is your information kept secure?
The Service Provider is committed to safeguarding the confidentiality of your information. The Service Provider implements physical, electronic, and procedural safeguards to protect information it processes and maintains, such as limiting access to authorized employees and contractors who need to know that information to operate, develop, or improve the Application, and encrypting data transmission via SSL/TLS. However, no security system can prevent all potential security breaches. Users are responsible for keeping their login credentials secure and protecting exported backup files.
Data Breach Notification
In the event of a personal data breach that poses a risk to your rights and freedoms, the Service Provider will notify the relevant supervisory authority within 72 hours of becoming aware of the breach, as required by applicable law. Where the breach is likely to result in a high risk to your rights and freedoms, the Service Provider will also notify you without undue delay, providing information about the nature of the breach, the categories of data affected, and the measures taken or proposed to address the breach.
How will you be informed of changes to this Privacy Policy?
The Service Provider may update this Privacy Policy from time to time. The Service Provider will notify you of material changes by posting the updated Privacy Policy with an effective date. Where required by law, the Service Provider will seek your consent to material changes before they take effect.
Previous versions of this Privacy Policy will be maintained and made available upon request by contacting the Service Provider at household@tydecode.com.
This Privacy Policy is effective as of 2026-06-01.
What are your GDPR data protection rights?
Under the GDPR, you have the following rights:
- Right of Access: You can request access to your personal data.
- Right to Rectification: You can request correction of inaccurate data.
- Right to Erasure: You can request deletion of your personal data (the "right to be forgotten").
- Right to Restrict Processing: You can request that the Data Controller limits how they use your data.
- Right to Data Portability: You can request a copy of your data in a structured, commonly used, machine-readable format.
- Right to Object: You can object to processing based on legitimate interests. You have an absolute right to object to processing for direct marketing purposes at any time.
- Right to Withdraw Consent: Where processing is based on your consent, you can withdraw it at any time. Withdrawal is as simple as toggling preferences in the Application's settings or contacting the Data Controller.
- Rights Regarding Automated Decision-Making: You have rights related to automated decisions that affect you.
If you believe your data protection rights have been violated, you have the right to lodge a complaint with your local Data Protection Authority. Contact details for each country's Data Protection Authority can be found at: https://edpb.ec.europa.eu/about-edpb/members_en
If you are located in the United Kingdom, you may contact the Information Commissioner's Office at https://ico.org.uk
What are your California privacy rights (CCPA/CPRA)?
If you are a resident of California, the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA) provide you with additional rights regarding your personal information:
- Right to Know: You have the right to request disclosure of the categories and specific pieces of personal information the Service Provider has collected about you. This includes the right to know whether your personal data is sold or shared, the categories of personal data sold or shared, and the categories of third parties to whom such personal data was sold or shared.
- Right to Delete: You can request deletion of personal information the Service Provider has collected from you, subject to certain exceptions.
- Right to Correct: You can request correction of inaccurate personal information.
- Right to Opt-Out: You have the right to opt-out of the sale or sharing of your personal information. This includes the right to opt-out of allowing the "sale" of your personal data to third parties, as well as the sharing of your personal data for cross-context behavioral advertising.
- Right to Limit Use of Sensitive Personal Information: You can limit the use of your sensitive personal information to essential purposes.
- Right to Non-Discrimination: The Service Provider will not discriminate against you for exercising any of your CCPA/CPRA rights.
The Service Provider does not sell or share your personal information as defined under the CCPA/CPRA. Because no sale or sharing of personal information occurs, no opt-out mechanism is currently required. If these practices ever change, a "Do Not Sell or Share My Personal Information" link will be made available in the Application and on the website, and you will be notified prior to any such change.
To exercise any of these rights, including opt-out rights, please contact the Service Provider at household@tydecode.com. The Service Provider will verify your request using the information you provide and respond within the timeframes required by law. You may designate an authorized agent to make a request on your behalf.
What are your rights under the LGPD (Brazil)?
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD, Law No. 13.709/2018) provides you with the following rights regarding your personal data:
- Right to Confirmation and Access: You can request confirmation of whether your personal data is being processed and access to that data.
- Right to Correction: You can request correction of incomplete, inaccurate, or outdated personal data.
- Right to Anonymization, Blocking, or Deletion: You can request anonymization, blocking, or deletion of unnecessary or excessive data, or data processed in violation of the LGPD.
- Right to Data Portability: You can request portability of your personal data to another service provider.
- Right to Deletion: You can request deletion of personal data processed with your consent.
- Right to Information: You can request information about public and private entities with which your data has been shared.
- Right to Revoke Consent: You can revoke your consent at any time.
- Right to Petition: You have the right to petition the Autoridade Nacional de Proteção de Dados (ANPD) regarding your data protection rights.
To exercise any of these rights, please contact the Service Provider at household@tydecode.com.
What are your rights under the VCDPA (Virginia)?
If you are a resident of Virginia, the Virginia Consumer Data Protection Act (VCDPA, Va. Code § 59.1-575 et seq.) provides you with the following rights:
- Right to Access: You can request confirmation of whether your personal data is being processed and access to that data.
- Right to Correction: You can request correction of inaccuracies in your personal data.
- Right to Deletion: You can request deletion of your personal data.
- Right to Data Portability: You can obtain a copy of your personal data in a portable, readily usable format.
- Right to Opt-Out: You can opt out of the processing of your personal data for purposes of targeted advertising, sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
The Service Provider does not sell your personal data, engage in targeted advertising, or use profiling that produces legal or similarly significant effects. Because no sale, targeted advertising, or profiling occurs, no opt-out mechanism is currently required. If these practices ever change, you will be notified and provided with an opt-out mechanism before any such processing begins. To exercise any of these rights or to inquire about your opt-out options, please contact the Service Provider at household@tydecode.com. The Service Provider will respond within 45 days of receiving your request.
How do you give your consent?
Where processing is based on consent, you provide that consent by affirmatively opting in to the relevant feature or action (such as enabling browser, device, or email notifications). You may withdraw consent at any time without affecting processing carried out before withdrawal. Processing based on other lawful bases, including contract performance, legitimate interests, or legal obligations, is carried out as described above.
How can you contact the Data Controller?
If you have any questions regarding privacy while using the Application, or have questions about the practices, please contact the Service Provider via email at household@tydecode.com.
To request deletion of your personal data or to exercise any of your rights, contact the Service Provider using the details provided above. The Service Provider will respond within one month of receiving your request, extendable by up to two months where necessary due to the complexity or volume of requests, as permitted by applicable law.