Privacy Policy

Last updated: 4 September 2026

This mock notice explains how HomeKeeper handles data on the public website and in the authenticated application. These two surfaces use different storage and measurement tools.

Mock data controller

  • Controller: HomeKeeper sp. z o.o. (mock), registered in Poland.
  • Mock address: ul. Mockowa 1, 00-001 Warsaw, Poland.
  • Contact for support and privacy: gethomekeeper@outlook.com.

Public website

The marketing website does not create a language cookie. Your selected language is part of the page address.

  • Appearance preference: nuxt-color-mode in Local Storage, kept until you clear site data.
  • Install prompt: homekeeper-web-pwa-install-dismissed in Local Storage after you dismiss the prompt.
  • Offline support: the service worker may cache public pages, fonts and static assets in Cache Storage; the browser evicts these caches as needed.
  • On deployed pages, Vercel Web Analytics measures aggregate page visits without HomeKeeper cookies, and Speed Insights measures web performance.

Authenticated app

The app stores only the browser data needed for sign-in, preferences, installation and reliable operation.

  • Sign-in: Supabase stores access and refresh tokens in one or more sb-…-auth-token cookies. They are readable by the app so it can refresh your session, use SameSite=Lax and Secure in production, and are removed on sign-out.
  • Language: i18n_locale records the selected interface language. Appearance uses nuxt-color-mode in Local Storage.
  • Install prompt: homekeeper-pwa-install-dismissed is stored locally only after you dismiss the prompt.
  • Offline support: the service worker caches the app shell and static assets, but not Supabase API responses. A push subscription is created only after you enable notifications and allow browser permission.

Analytics and diagnostics

  • Product analytics in the app is off by default. If you opt in under Settings, HomeKeeper records only named product milestones in Supabase, without home names, addresses, task text, documents or other household content.
  • Sentry receives production error reports, technical logs and sampled performance traces so failures can be diagnosed. HomeKeeper does not enable Sentry Session Replay.
  • Public-site Vercel measurements are separate from the app's product-analytics preference and do not run inside the authenticated app.

Retention and control

  • Supabase authentication cookies use a long browser expiry so the cookie does not outlive or contradict the server session. Actual access is controlled by Supabase session validity, security events and sign-out.
  • Preferences and install-dismissal flags remain on the device until you change them or clear site data. Browser caches remain until updated, evicted or cleared.
  • You can withdraw product-analytics consent at any time in app Settings. Previously recorded aggregate events are not household content.

Your choices

  • Use browser controls to clear cookies, Local Storage and cached site data.
  • Sign out to remove the app's authentication cookies from that browser.
  • Enable or disable optional product analytics in app Settings and manage push permission in your browser or device settings.
  • You may request access, correction or deletion through the project's public support channel. Account deletion is also available inside the app.

Security

HomeKeeper limits browser storage and does not cache authenticated API responses. Because the app is client-rendered, authentication cookies cannot be HttpOnly; protecting the application from injected scripts and keeping dependencies current are therefore important safeguards.

Questions and requests

For this mock, HomeKeeper sp. z o.o. is the stated controller. Send privacy questions and requests to the address below; replace the mock operator details before launch.

gethomekeeper@outlook.com