Privacy Policy

v0.4 · Effective 27 July 2026 · pending one professional review pass

The short version

We are House Brownie, a household-inventory app. Here is the whole privacy story in a box; the detail is below.

  • We do not sell your data, and we do not show ads. No ad pixels, no trackers, no data brokers.
  • Analytics are strictly opt-in. Nothing is measured until you say yes. If you never opt in, no analytics ever run — the switch to turn them on lives on your device, and until you flip it, no analytics network call is made at all.
  • Your household inventory is yours. It is isolated from every other household at the database level (row-level security keyed to your household). We do not read it to train anything.
  • Voice is powered by AI (OpenAI). If you use voice or the AI assists, your audio is sent to OpenAI to turn into text and is then discarded. Voice transcripts auto-delete after 90 days. If you never turn on AI, no audio and no AI processing happens.
  • You can export everything and delete everything, yourself, at any time, from Settings.
  • We are a US-registered company operated from Portugal — EU data-protection law applies to us directly, and we use trusted US and EU vendors to run the service. We list every one of them below.

If you only read one thing: we collect what we need to run a household-inventory app you asked us to run, we keep it only as long as we need it, we never sell it, and you can take it or delete it whenever you want.

1. Who we are (the controller)

House Brownie is operated by Fresh Eyes Studio LLC, a Wyoming limited liability company ("House Brownie", "we", "us").

For personal data we handle about you as a House Brownie user, we are the data controller — we decide why and how it is processed. (Your payment is handled by Paddle as the seller of record; for the payment transaction itself, Paddle is the controller — see §4/§6 and the Terms of Service.)

Where we are established: House Brownie is operated from Portugal, where its sole operator permanently resides — for GDPR purposes we are an EU-established controller, and our lead supervisory authority is the Portuguese Comissão Nacional de Proteção de Dados (CNPD, cnpd.pt). Our Portuguese legal notice (imprint), including registration details, is published at /imprint. (Because we are EU-established, no EU Article 27 representative is required.)

United Kingdom — not offered at launch

House Brownie is currently offered to residents of the United States and the European Union only. We do not offer or market the Service in the United Kingdom, and no UK representative is appointed.

2. What we collect, why, and our legal basis

We collect only what the app needs. We do not ask for your date of birth, and House Brownie is a general-audience product not directed to children (see §11).

WhatExamplesWhy (purpose)Legal basis (GDPR Art 6)
Account identityYour email, name, and login, managed through our auth provider ClerkCreate and secure your account; sign you in; send account emailContract (Art 6(1)(b)) — we can't give you an account without it
Household data you enterYour inventory items, locations/rooms, shopping lists, tasks, store names, notesThis is the product — it answers "what do we have / where / what to buy / what to do"Contract (Art 6(1)(b))
Membership & rolesWho is in your household, owner vs. memberRun a shared household; enforce isolation between householdsContract (Art 6(1)(b))
Voice & AI content (only if you use AI)Audio you record, the text it becomes, the structured actions parsed from it, translationsTurn speech into inventory actions; translate notes; estimate item freshnessContract (Art 6(1)(b)) for the feature you invoked
Billing metadataPlan, credit balance, renewal/refund status — not your card numberGive you the plan/credits you paid for; honor refundsContract (Art 6(1)(b)) + legal obligation (tax/records)
Your own AI key (BYOK) (optional)An OpenAI API key you choose to storeLet you run AI on your own key at no platform costContract / consent — you opt in by entering it
Product analytics (opt-in only)Feature-usage events via PostHogUnderstand which features are used, to improve the appConsent (Art 6(1)(a)) — off until you say yes; withdraw anytime
Security & operational logsError reports (secret-scrubbed), rate-limit counters, audit of admin actions, cost/usage meteringKeep the service secure, working, and abuse-free; bill AI usage accuratelyLegitimate interests (Art 6(1)(f)) — running a secure, reliable service

Card data: we never see or store your full payment-card details. Checkout is handled by Paddle (our merchant of record); your card data goes to Paddle and its payment processors, not to us.

No special-category data, no profiling. We do not intentionally collect sensitive data (health, religion, etc.), and we do not do automated decision-making that produces legal or similarly significant effects about you (Art 22). Voice-to-action is a convenience feature that structures what you dictated; it is not emotion recognition or biometric categorization.

Do you have to provide it? The account and household data are required to use the app — without them there is no service. Voice/AI, BYOK, and analytics are all optional; declining them just means those features are off.

3. AI features and OpenAI (plain disclosure)

House Brownie's voice capture, translation, and the "freshness" estimate are AI-powered, using OpenAI. Here is exactly what happens:

If you use BYOK (your own OpenAI key), we encrypt it at rest with AWS KMS envelope encryption, bind it cryptographically to your household, and never log it. See §7.

4. Who we share it with (processors / sub-processors)

We do not sell your personal data and we do not share it for cross-context behavioral advertising. We use the following vendors to run the service. Each processes data only on our instructions under a data-processing agreement, and only for the purpose listed.

Sub-processorRoleWhat it processesLocation
ClerkAuthentication & household/organization managementAccount identity, membershipUS
NeonManaged Postgres databaseAll household data, at rest (row-level isolated per household)US (AWS us-east-1)
VercelApplication hosting / serverless computeData in transit while serving requestsUS / global edge
OpenAIVoice transcription, parsing, translation, freshness (AI features only)Audio (transient), text you submit to AIUS
PaddleMerchant of record / billingPurchase, billing, and refund data; card data (we don't see it)UK/EU + US
AWS (KMS)Encryption-key management for BYOK secretsEncrypted key material / key operationsUS (us-east-1)
PostHogProduct analytics and error trackingOpt-in usage events; secret-scrubbed error reportsUS (us.i.posthog.com)
UpstashRate limiting (Redis)Ephemeral rate-limit counters keyed to request identityUS / [region]
ResendTransactional emailYour email address + the message (receipts, resets, notices)US
CloudflareDNS, edge/CDN, bot protection (Turnstile)Network-level request dataUS / global edge

This is our current sub-processor list as of 2026-07-20. We keep it accurate; when it changes we update this notice. (We do not use Sentry, and we do not store your photos or files in object storage — there is no such feature.)

We may also disclose data if legally required (valid legal process), or to protect the rights, safety, or security of House Brownie, our users, or the public. If we are ever party to a merger or acquisition, we will require the successor to honor this policy and will notify you.

4.1 Our data promise — and its canary

Beyond the legal minimum, this is the promise the product is built on. Your data is yours. Your usage is yours. Concretely, as of the affirmation date below:

The canary: we re-affirm all four statements, with a fresh date, in every revision of this policy. Last affirmed: 26 July 2026. If this section is ever removed, or its date is left to go stale while the rest of the policy keeps updating, treat that as the warning it is.

5. International data transfers

We are an EU-established controller (Portugal). Several of our sub-processors (§4) are based in the United States, so personal data we control is transferred to the US — these are restricted transfers under GDPR Chapter V, and for each one we rely on:

We keep the signed DPAs / SCCs and a short transfer-impact assessment on file. You can ask us which mechanism applies to a given sub-processor (§8).

6. How long we keep it (retention)

DataRetention
Account & household dataFor as long as your household exists. Deleted when you delete the household (§8).
Voice transcripts (text)Auto-deleted after 90 days by a nightly job. Structured actions derived from them are kept as inventory history.
Voice audioNot retained — sent to OpenAI to transcribe, then discarded.
Operational/audit logsAdmin-action and security audit logs are kept ~90 days; activity logs are slimmed/aged over 12–24 months.
Analytics events (if opted in)Retained by PostHog per our configured retention; deleted/stopped when you opt out.
Billing recordsHeld by Paddle and by us for the period required by tax/accounting law.

When your household is deleted, we purge the data we control across our tables. Some records that we are legally required to retain (e.g. transaction/tax records held by Paddle) persist for their statutory period.

7. How we protect it

No system is perfectly secure, but we design for isolation-by-default and keep the attack surface small (for example, we don't retain audio and don't run third-party trackers).

8. Your rights and how to use them

Wherever you live, you can:

If you are in the EU (or another region granting these rights), you also have the rights to: access your data, rectify inaccurate data, erase it, restrict or object to processing, data portability, and to withdraw consent at any time (for anything based on consent, e.g. analytics or BYOK) without affecting prior processing.

How to exercise them: most are self-service (above). For anything else, contact us at hello@housebrownie.com. We respond to requests within one month (extendable by two further months for complex or numerous requests — we'll tell you within the first month if we need the extension and why). We don't charge for this unless a request is manifestly unfounded or excessive.

Right to complain: if you think we've mishandled your data, you can lodge a complaint with a data protection supervisory authority. Our lead supervisory authority is Portugal's CNPD (Comissão Nacional de Proteção de Dados, cnpd.pt); in the EU you may equally complain to the authority in your own country of residence or work. We'd appreciate the chance to fix it first, but it's your right either way.

9. Cookies and similar technologies

House Brownie is deliberately light here:

10. Changes to this policy

We'll update this notice when our practices or sub-processors change. When we make a material change, we'll update the version and effective date at the top and, where appropriate, notify you (e.g. by email or in-app). Continued use after an update means the current version applies.

11. Children

House Brownie is a general-audience product not directed to children under 13 (or the equivalent age in your country). We don't knowingly collect data from children, and we don't ask for age or birthdate. If you believe a child has given us personal data, contact us and we will delete it.

Attribution & sources

This policy was hand-drafted to House Brownie's actual practices. External policies were used for structure and coverage checklists only — no third-party wording was copied — so no share-alike or other license obligation attaches to this document. Sources consulted:

Every factual claim here was checked against the House Brownie codebase on 2026-07-20 (export route, app.purge_org/Danger Zone, 90-day transcript TTL cron, opt-in PostHog consent gate, AWS-KMS BYOK envelope, the AI-cost firewall). If the code changes, this notice must change with it.

← housebrownie.com