Privacy Policy — Warm Glow
Draft for legal review before public launch. Last updated October 3, 2026.
Warm Glow helps people who share a home organize it together. Your home is end-to-end encrypted: it's locked on your own devices before it's saved, so we can't read it. We collect only what the app needs, we don't sell anything, and we don't use it for advertising.
The short version
- End-to-end encrypted. Messages, notes, expenses, chores, calendar titles, house manual, lease, photos and files are encrypted on your device with keys only you and your housemates' approved devices hold. Our servers store scrambled data.
- Private means private. Your journal, private moods, private survey answers and gift ideas hidden from someone are encrypted with a key only your devices have — not even your housemates' devices can open them.
- We can't reset your keys. Keep your recovery kit safe. Lose every device and the kit, and the data can't be recovered — by anyone.
- Door codes and Wi-Fi stay hidden until you confirm it's you, and housemates are told when a code is viewed.
- Photos are resized and their hidden metadata (including GPS location) is removed on your device before upload.
- We never see your card number. Payments go through Stripe (web) or Apple / Google (in the app).
- No ads, no data sales, no tracking pixels, no third-party analytics, no external fonts.
- You can export or delete your data any time in Settings → Privacy & data.
What our servers can see
Encryption hides contents, but a few things have to stay readable for the app to work:
| Readable by our servers | Why |
|---|---|
| Your email, and your account and device identifiers | Signing in; delivering to the right devices |
| Which homes you belong to, and roughly when things change | Syncing |
| Your home's time zone and location rounded to about 1 km | Weather, street-sweeping and bin timing |
| Calendar event times (not titles, unless you choose to share a title with Google), and when reminders should fire | Delivering reminders on time, even if no phone has the app open |
| Notification settings (on/off, quiet hours) | Deciding whether to send a push |
| Plan and trial status; for business-run homes, which business | Billing |
| Smart-home webhook addresses you add, and their signing secrets (any member can see them in Settings) | Sending those events |
| Your private calendar-feed token (a random string) | Answering your calendar app's subscription |
| Feedback you send | Fixing bugs — we tell you it's readable |
Everything else — every title, note, message, amount, answer, file and photo — is ciphertext to us. The full list is in SECURITY.md.
Things that leave the encrypted zone only when you choose
| Feature | What's shared | With whom |
|---|---|---|
| Google Calendar (opt-in) | Event times and either a private title ("Warm Glow: chore") or the real title if you choose. Connecting asks Google for full access to your Google Calendar (see, add, change and delete events): Google offers no narrower permission that lets an app both show the calendars you pick and add house events to one of them. Warm Glow reads only the calendars you choose and changes only events it added | |
| House helper (Plus, off by default) | The question and the shared items you can see that are relevant — you see a preview first. Never private items or codes. | Anthropic (does not train on API data) |
| Notification previews (opt-in, per device) | Nothing leaves — the phone decrypts the text itself | — |
| Guest links (invites, guidebook) | Encrypted with a key inside the link; guests' RSVPs, photos and reactions are sealed to your home. An invite's cover photo or video is stripped of location and camera details on your device, then encrypted with the link's key | Whoever you give the link to |
| Invite link-preview title (only if you turn it on) | Stored unencrypted, so chat apps can show it before someone taps. Just the gathering's name, never the date, place, cover or guests. Off by default | Anyone the link is shared with, and their chat app |
| Voice assistants (opt-in) | The request (e.g. "oat milk") passes through our server for a moment before it's sealed to your home | Apple, Amazon/IFTTT or Home Assistant, as you set up |
| Repair requests in a business-run home (opt-in per request) | The request, sealed to the business's key. Your phone remembers that key the first time and refuses if it ever changes; the very first time, you're trusting our server to hand over the right one | Your property manager |
| Reports (Report a message or person) | Who you're reporting, your reason, and only the text you choose to include | Our team, to review |
| "Help improve" (off unless you turn it on) | Counts of which parts of the app were opened, how many people are in the home and how many shared things were added each week (counted, never read), under a random home number, and crash reports with only error names and code locations — sent without signing in, so they aren't tied to your account | Our team |
Who processes data for us
| Service | What for |
|---|---|
| Supabase | Database, sign-in, file storage, server functions — holds encrypted data |
| Vercel | Hosting the website (standard request logs) |
| Apple / Google push services | Delivering notifications (generic text unless your device decrypts a preview) |
| Apple, Google | Sign-in, if you choose Sign in with Apple or Google |
| Open-Meteo | Weather and air quality for a location rounded to about 1 km, and the city or ZIP you type when setting up a home (to find it) — no account information |
| Stripe, Apple, Google, RevenueCat | Subscriptions — payment details go only to them |
| Google, Anthropic | Only if you turn those features on (above) |
The beta waitlist (website)
If you join the waitlist on warmglowapp.com we keep your email, and if you give them, your city, household size and where you heard about us — only to invite you and tell you about the launch. Ask us to remove you any time (hello@warmglowapp.com).
How long we keep it
- While your account is active, so the app works.
- Deleted items are removed from everyone's devices, then purged within 30 days. Deleting a document also deletes its file.
- Delete my account (Settings → Privacy & data) removes your private items, your devices, keys, recovery backups and Google connection right away, and the homes you shared replace their keys. In shared homes your name becomes "Former housemate" so shared history still adds up; homes where you were the only person are deleted. Any web subscription is cancelled.
- Database backups roll off within 7 days (and contain only encrypted data).
Your rights
You can access, correct, export, or delete your data — most of it in the app; for anything else, email privacy@warmglowapp.com. Depending on where you live (for example California under the CCPA/CPRA, or the EU/UK under the GDPR), you have additional rights. We honor them for everyone.
Children
Warm Glow is for adults (18 and older), as the Terms and the sign-in screen say. We don't knowingly collect data from children under 13; if you believe a child has signed up, contact us and we'll delete it.
Security
End-to-end encryption with audited libraries, signed key sharing, safety codes, device approval, passkeys and two-step sign-in (enforced by the database), app lock, encrypted local storage, and a strict browser security policy — all described honestly, including what we can't protect against, in SECURITY.md. If we ever have a breach that affects you, we'll tell you promptly.
Changes
If we make a meaningful change, we'll tell you in the app before it takes effect.
Contact
Warm Glow — privacy@warmglowapp.com