Privacy Policy
DomusXP is a gamified household chores app for families. We take privacy seriously — children's privacy above all.
What data we collect
From the parent or guardian: name, e-mail (required — it is how you sign in) and password, stored only as a hash.
From each child: name, date of birth (optional), avatar and, if the guardian wants one, a 4-digit PIN — also stored as a hash. Children provide no e-mail and no phone number.
From using the app: chores completed and approved, rewards, quests, penalties, reputation, schedule and notifications.
From the device: a notification identifier (push token), only if notifications are on, and the time zone, so that “today” is calculated correctly for routines.
We do not collect location, photos, contacts, microphone or advertising identifiers.
Children
Children's data is entered and controlled by the guardian, who confirms parental consent when creating each profile. Children need no e-mail; they sign in with a profile and a PIN on the family device. A child makes no purchases: any payment is made by the guardian, on screens the child cannot reach.
How we use it
Only to run the app (gamification, notifications between family members). We do not sell data, we do not use it for advertising, and there are no ads in the app.
Who we share it with
We neither sell nor hand data to third parties. We use only the service providers below, which process data on our behalf and to the minimum necessary:
- Google (Firebase Cloud Messaging) — receives the device notification identifier, to deliver the app's alerts.
- Amazon Web Services (SES) — receives the guardian's e-mail to send transactional messages (welcome, password recovery, therapist invitation).
- RevenueCat — when there is a subscription, receives a random identifier for the family and the purchase event. That identifier cannot be traced back to you.
- Google Play — processes the subscription payment. DomusXP neither receives nor stores your card details.
Subscription
DomusXP is paid through a family subscription, charged by the app store. Cancelling is done in the store itself. If the subscription ends, nothing is deleted: the family keeps seeing history and balances, and only stops creating and approving. Exporting and deleting your data stays available, with or without a subscription.
Security
Passwords and PINs are stored hashed and never in readable form. All traffic between the app and the server is encrypted (HTTPS). Access is isolated per family: one family never reaches another family's data.
If you turn on biometric unlock, the biometric data never leaves your device and never reaches us — the app only receives confirmation from the system that authentication happened.
Retention
We keep data for as long as the account exists. Notifications older than 90 days, sign-in attempt records, and expired invitations and recovery links are deleted automatically. You can export or delete your data at any time in the family settings.
Your rights (LGPD/GDPR)
Access, correction, export and deletion of data. Use “Download my data” and “Delete account and data” in the family settings. Deletion is permanent and cascading: it erases the family, the profiles and the whole history — it is not a deactivation.
Step by step for deletion, including for those who lost access to the app: Delete account and data.
Contact
Questions about privacy? Talk to us at contato@atenza.com.br.