Privacy Policy
Last updated: 25 August 2026
This policy reflects HausKeep's actual current data practices, including on-device storage, Premium AI processing, and analytics. Passages marked [CONFIRM] need a founder-supplied fact before this page is final; passages marked [LEGAL] need review or drafting by a qualified data protection solicitor. This page has not yet been reviewed by a lawyer and should not be treated as finished or as legal advice until those items are resolved.
1. Who we are
HausKeep is operated by Tom Harrison, trading as HausKeep ("we", "us"), England and Wales, registered address Heathfield Road, Bembridge, PO35 5UW. [CONFIRM: operating as a sole trader, not a limited company — no company number exists. Revisit this section if that changes.] For the purposes of UK GDPR and EU GDPR, we are the data controller for the limited personal data described in this policy.
[LEGAL: if the app is offered on EU App Store storefronts and the entity has no EU establishment, assess whether an EU representative is required under Article 27 EU GDPR. Same question in reverse for a UK representative if the entity is non-UK.]
Contact for privacy matters: [CONFIRM: dedicated email, e.g. privacy@usehauskeep.com — must be live before publication]
2. This policy at a glance
- Your inventory data lives on your device. We do not run a server that stores your inventory.
- The free on-device AI features never send your photos anywhere.
- Premium AI features send the specific photo and a short prompt to our backend, which passes it to Anthropic for processing. This happens only when you actively trigger the feature.
- We don't sell your data. We don't use advertising or third-party analytics SDKs. We don't train AI models on your data.
- No account, login, or email is required to use HausKeep. [CONFIRM: still true at publication]
3. What we collect, where it lives, and why
3.1 Data stored on your device only
Your item photos, titles, Spaces and Containers, item values, Keep/Maybe/Donate/Sell decisions, and warranty/maintenance information are stored locally on your device using Apple's on-device storage (SwiftData). We cannot see or access this data. It is not transmitted to us.
Device backups: Your device data may be included in your own iCloud or local device backup, controlled by you and governed by Apple's terms and privacy policy — not by us. [CONFIRM: verify whether the app's SwiftData store is included in standard iOS backup, and whether any store is excluded via isExcludedFromBackup. State the answer plainly here once confirmed.]
3.2 On-device AI (free, all users)
Item title suggestions are generated on your device using Apple's Vision framework. Photos and suggestions never leave your device for this feature. No data is collected by us.
3.3 Premium AI features (only when you actively use them)
If you subscribe to Premium and choose to use an AI-powered feature — currently richer item-title suggestions and second-hand value estimates (the two request types our app sends) — the relevant photo and a short text prompt are sent to our backend and forwarded to Anthropic, PBC (provider of the Claude AI model) for processing.
- This happens only when you actively trigger the feature. Nothing is sent automatically or in the background.
- Our backend is a Cloudflare Worker that acts purely as a relay: it receives the photo and prompt, forwards them to Anthropic, and returns the result. It does not log, cache, or store the photo or the prompt text. The only thing our backend retains is a per-install usage counter — a randomly generated device token (a value we create on your device; it is not linked to your name, email, or Apple ID) together with the current calendar month and a running count — held in Cloudflare's key-value store solely to enforce a monthly usage cap. This counter is deleted automatically after approximately 40 days. Cloudflare's own infrastructure logging (Workers Logs) is enabled and records per-request operational metadata, which may include your device's IP address; these logs are retained for 3 days and then automatically deleted, and are not exported to any other system (Logpush is not configured). See section 5 for the full list of recipients and section 7 for retention periods.
- Anthropic retains this data for up to 30 days under its commercial API terms and may access it during that period for safety and security purposes. See section 6. [CONFIRM at publication and at every re-publication — provider terms change.]
3.4 A single, anonymous "you're using this" signal
Once, per household, when you reach a point where HausKeep judges you've genuinely started using it (cataloguing a handful of items, organising them into a couple of Spaces, making a first Keep/Maybe/Donate/Sell decision), the app sends a single anonymous signal to our backend marking that moment. This applies to every household, whether or not you're a Premium subscriber.
- What's sent: only the same anonymous, randomly generated device token described in 3.3 above — nothing else. No item data, no photos, no names, no location, no account information (there is none to send).
- Why: so we can tell whether HausKeep is actually useful to the people who install it, not just downloaded and abandoned. This is product-improvement measurement, not advertising, profiling, or tracking — it can't be tied back to you individually, and we never use it that way.
- Retention: recorded once per device token and never re-sent. This signal is retained for 24 months from the date it's recorded, after which it is automatically deleted. We chose this period because it's long enough to understand how households use HausKeep over a meaningful stretch of time, without holding data longer than that purpose requires.
3.5 Purchases and subscriptions
Premium subscriptions are processed by Apple through the App Store. We receive only the information Apple provides to developers (e.g. anonymised transaction/receipt validation data). We do not receive your name, payment card details, or billing address. [CONFIRM: describe exactly what, if anything, the backend receives for subscription entitlement checks.]
3.6 What we do not collect
- No account, login, email address, or phone number is required. [CONFIRM]
- No third-party advertising or analytics SDKs. The only first-party in-app event that leaves the device is the anonymous activation signal described in 3.4 above.
- No location data, contacts, health data, or browsing history.
- We do not sell or share your personal data for advertising, and we do not use your photos or data to train AI models. [CONFIRM as a firm commitment — this is a strong, enforceable claim in several jurisdictions.]
4. Legal bases for processing (UK GDPR / EU GDPR)
Where UK or EU data protection law applies, our legal bases are:
| Processing | Legal basis |
|---|---|
| Premium AI processing of photos/prompts you actively submit | Performance of a contract (Art. 6(1)(b)) — delivering the Premium feature you requested. [LEGAL: confirm contract vs. consent as the better basis; photos of a home interior can incidentally capture other people or sensitive items, which a lawyer should assess.] |
| Subscription entitlement validation | Performance of a contract (Art. 6(1)(b)) |
| Responding to privacy requests, legal obligations | Legal obligation (Art. 6(1)(c)) |
| Service security and abuse prevention (if backend logging exists) | Legitimate interests (Art. 6(1)(f)) [CONFIRM whether this processing exists at all — see 3.3] |
We do not rely on consent for core functionality, and we do not carry out automated decision-making with legal or similarly significant effects.
5. Who we share data with (processors and recipients)
We share personal data only with service providers who process it on our instructions:
| Recipient | Role | What they receive | Location |
|---|---|---|---|
| Anthropic, PBC | AI processing (Premium features only) | The photo and prompt you actively submit | United States |
| Cloudflare, Inc. (Workers) | Serverless relay for Premium AI requests; per-install usage-cap counter | Photo + prompt in transit only (not stored); a pseudonymous device token + month + call count stored ~40 days; operational request metadata (may include IP) in logs retained 3 days, not exported | Global edge network — no region pinning configured (Data Localization Suite not enabled) |
| Apple Inc. | App distribution, payments, OS-level backup | Purchase/subscription data; device backups under your control | Per Apple's terms |
We do not share data with advertisers, data brokers, or analytics companies. We may disclose data if required by law, but given the on-device architecture we hold very little that could be disclosed.
6. International transfers
When you use a Premium feature that relies on AI (such as generating an item title or estimating a value), the relevant photo or text is sent to Anthropic PBC, the maker of the Claude AI model we use (specifically, Claude Haiku 4.5), for processing. This means your data is transferred from the UK to the United States, where Anthropic processes it.
Anthropic retains this data for up to 30 days before deleting it, and does not use it to train its AI models. We have chosen Anthropic because of its stated data-handling practices, and we are reviewing the specific legal safeguards that govern this transfer as part of our ongoing compliance work.
Free-tier features that don't need server-side AI (such as on-device photo recognition) never leave your device.
Because our Cloudflare relay runs on a global edge network with no region pinning configured, requests may also be processed transiently at Cloudflare locations outside the UK/EEA.
7. How long data is kept
- On your device: until you delete it or delete the app. Deleting the app deletes local data (subject to your own backups).
- Anthropic (Premium AI only): inputs and outputs are deleted within 30 days under Anthropic's standard commercial API terms, except where retention is required to enforce their usage policy. We do not currently have a zero data retention arrangement. [CONFIRM at every publication — some newer Anthropic models mandate 30-day retention with no ZDR option, so this should be checked against the specific model used.]
- Our backend (Cloudflare Worker): No request content (photos or prompts) is retained. The per-install usage counter (device token + month + count) is deleted automatically after approximately 40 days. The one-time anonymous activation signal (device token + timestamp, see 3.4) is not on an automatic deletion schedule. [CONFIRM/founder decision: add an expiry, or state this indefinite retention as a deliberate choice — don't leave it unaddressed at publication.] Cloudflare operational logs (Workers Logs, 100% sampling) are retained for 3 days and then deleted; they are not exported (Logpush is not configured). No long-term or region-pinned log store exists (Data Localization Suite not enabled).
8. Security
Your inventory data — photos, titles, values, and decisions — is stored only on your device, protected by Apple's standard on-device data protection and whatever passcode or Face ID/Touch ID you have set. We hold no copy of it, so there is no server-side inventory database to secure or breach.
Premium AI requests are sent over TLS-encrypted connections. Our backend does not log, cache, or store the photo or prompt text it relays — see section 3.3. Access to that backend is currently controlled by a single shared application secret rather than a per-purchase or per-user check; this limits who can reach the endpoint but is not, on its own, proof of a genuine Premium subscription. We plan to strengthen this with server-side receipt validation. [LEGAL: final review of this section before publication.]
No system is perfectly secure. Because your inventory lives on your device, the security of your device (passcode, Face ID, OS updates, backup settings) matters more than anything on our side.
9. Your rights
9.1 UK, EU and EEA
You have the right to access, rectify, erase, restrict, object to processing of, and port your personal data, and the right not to be subject to solely automated decisions with legal effect. Because your inventory data is stored only on your device, you exercise most of these rights directly: viewing, editing, exporting [CONFIRM: does an export function exist?], and deleting data in the app.
For data we or our processors hold (Premium AI requests within the retention window), contact us at [CONFIRM email]. We will respond within one month.
You may complain to a supervisory authority. In the UK: the Information Commissioner's Office (ico.org.uk). In the EU/EEA: your national data protection authority. [LEGAL: review this whole section — statutory rights language must be precise.]
9.2 United States
We do not sell your personal information or share it for cross-context behavioural advertising, and we have not done so in the preceding 12 months. We do not use or disclose sensitive personal information for purposes requiring a right to limit.
[LEGAL: HausKeep likely falls below CCPA/CPRA applicability thresholds (annual revenue over $25M, or data on 100,000+ California consumers/households, or 50%+ revenue from selling/sharing personal information) and below most other US state law thresholds. Confirm, then decide whether to (a) state rights voluntarily as good practice, or (b) note the laws' applicability. Include a Do Not Sell/Share statement regardless — it is true and costs nothing.]
US residents may contact us at [CONFIRM email] to request access to or deletion of any personal data we hold. Given our on-device architecture, in most cases we hold none.
9.3 Australia, New Zealand, Singapore, Japan and other APAC regions
[LEGAL: jurisdiction-specific review needed if the app is distributed on these storefronts. Australia — Privacy Act 1988 small business exemption (under AUD 3M turnover) may currently apply but is under reform; APP 8 governs overseas disclosure (Anthropic/US). Singapore — PDPA applies without a size threshold; transfer limitation obligation applies to the US transfer. Japan — APPI applies without a size threshold; overseas transfer requires consent or equivalent safeguards and specific disclosure about the destination country's regime. New Zealand — Privacy Act 2020, IPP 12 on overseas disclosure. South Korea (PIPA) is notably strict — confirm whether the app ships on the Korean storefront before including or excluding it.]
Residents of these regions may contact us at [CONFIRM email] with any privacy request or question.
10. Children's privacy
HausKeep is not directed at children, and we do not knowingly collect personal data from children.
HausKeep does let a household add the names of family members to help organise who owns or is responsible for particular items. This is a household's own record, entered and controlled entirely by the household, and it is not currently shared with us or with anyone outside the household's own device — Family Sharing, which would let this information sync across a household's devices via Apple's iCloud, has not yet launched. Family members' names are not required, can be left blank, and can be edited or removed by the household at any time.
If a household chooses to enter a child's name in this field, that name is treated the same as any other on-device personal data: it stays on the household's own device today, and if Family Sharing launches in future, we will update this policy before that feature goes live to explain exactly how family data — including any names — is handled at that point.
11. Family Sharing (future feature — not yet available)
[PLACEHOLDER — complete before the feature ships, not after. It will involve Apple ID sign-in and iCloud/CloudKit syncing, which changes sections 1, 3, 5, 6, 9 and 10 of this policy and the App Store privacy label. Publishing a policy that does not cover a live feature is a compliance gap and an App Review risk.]
12. Changes to this policy
We will update this policy when HausKeep's features or data practices change, note the date at the top, and — for material changes — notify users in the app before the change takes effect. [LEGAL: confirm notification standard.]
13. Contact
[CONFIRM: privacy contact email; postal address of the legal entity (required in several jurisdictions); response-time commitment.]