Game of Chores

Privacy Policy

Effective date: 11 August 2026 Last updated: 13 August 2026

This Privacy Policy explains how Game of Chores (“the App,” “we,” “us”) collects, uses, shares, and protects personal data when you use the App, our website at gameofchores.me, or any related service.

We are committed to processing your data lawfully, transparently, and only for the purposes described below.

1. Who we are

The data controller for Game of Chores is:

Umut Aktaş (natural person, sole controller)
Utrecht, the Netherlands
Contact: privacy@gameofchores.me

The App is distributed via the Apple App Store and Google Play Store under developer accounts registered in Turkey. The data controller is Umut Aktaş personally; the store accounts are distribution channels and do not create a separate legal controller.

If you are a user in the European Economic Area, your rights under the GDPR apply. If you are a user in Turkey, additional rights under the KVKK apply — see Section 13.

2. What we collect

We collect only what is needed to operate the App. Categories below map to GDPR Article 13/14 transparency requirements.

2.1 Account and session data

Game of Chores runs on a household model. When you first open the App you get an anonymous session (an anonymous authentication identifier) so the App works without you handing over any personal identifier.

  • Adults can upgrade a session to a durable account using the platform sign-in offered on your device: Sign in with Apple on iOS, Sign in with Google on Android. You can also skip this and keep the anonymous session. From Apple we receive your email address (or Apple’s private relay address, if you choose to hide it), a display name, and a unique account identifier. From Google we receive your email address, your display name, a unique Google account identifier, and (if available) your profile image.
  • Kids never get their own account. A kid seat is a profile inside a parent’s household; the child’s device holds an anonymous session whose identifier is linked to the seat (linkedUid). No email, no external identity provider, no photo.

2.2 Profile and account data

Your users/{uid} record holds the following, depending on how you use the App:

  • Identity: display name, username, and — for a signed-in adult — the email from your Apple or Google sign-in.
  • Avatar: for kids, an emoji only — no child photo is ever stored. For adults, an emoji, a curated in-app avatar tile (avatarId), or an optional profile photo you upload.
  • Role within the household: owner, adult, or kid.
  • Account timestamps: when the account/profile was created and last updated, and onboarding completion.
  • Notification data: your notification preferences and per-beat settings, a primer prompt timestamp/outcome, and — if you enable push — your device push token (see §2.8).
  • Preferences: a tone preference and a visibility setting controlling what other household members see.
  • Streak data derived from your activity: current streak (streak), best streak (bestStreak), and the day-key of your last completed chore (lastDoneDayKey).
  • Household link: the householdId that binds you to your household.

The V1 “play-style label,” XP, levels, badges, rank, and all battle/proof/taunt tallies are removed — V2 does not compute or store them.

2.3 User-generated content

  • Chores you create: title, score weight (1/3/5), recurrence, assignment, and — for custom chores in Manager mode — a how-to step list, pre-populated from our bundled on-device suggestion catalogue or entered directly by you.
  • Dones: a record that a chore was completed — which chore, which member, when, the day-key, and the score at completion.
  • After-photos (optional): a single in-app-camera photo attached to a done, only if the chore’s photo-proof toggle is on, which is off by default. Stored at households/{hid}/proofs/{doneId}.jpg, readable by household members only. Before storage we strip EXIF metadata (location, timestamp, device) from the photo.
  • Chore target photos (optional): a reference photo set by the chore’s creator, stored at households/{hid}/chores/{choreId}/target.jpg.

There are no battles, side-bets, taunts, rivalry records, or public arenas in V2, and none of that data is collected.

2.4 Household and membership data

  • Household: its mode (Manager / Couples / Solo), name, timezone, member cap, and a rotatable invite code used to add members.
  • Membership: which members belong to a household and their roles; for a linked kid device, the anonymous session identifier bound to the seat.

There is no social graph beyond your own household — no friends list, no cross-user rivalries, and no device-contacts access (the V1 “contacts friend finder” is not part of V2).

2.5 Device and technical data

  • Device model, OS version, app version.
  • We do not collect the Android Advertising ID (AD_ID) — it is explicitly removed from the app manifest — or any cross-app tracking identifier. Your device is identified for session continuity by the Firebase Installation ID used internally by Firebase, and by your push notification token where you enable notifications (see §2.8).
  • IP address, used transiently for authentication and session security and retained in authentication logs (see §6).
  • Language and region settings.

2.6 Aggregate counts (non-personal)

The App keeps anonymous, aggregate completion counts per day (counts/{dayKey}): a global total and per-chore-type totals, incremented by a server trigger and surfaced only above a minimum threshold (hidden below n = 25). These aggregates carry no account identifier and are not personal data under GDPR Art. 4(1); they power the Solo-mode “crowd” figures.

2.7 Analytics, crash, and error data

  • Firebase Analytics is integrated and collects automatic events in release builds (for example screen views, session start, app and device metadata). We do not use it for advertising and it carries no advertising identifier.
  • Sentry is used for crash and error reporting. Data is sent to Sentry’s EU region (Germany); we do not attach screenshots, view hierarchies or session replay, and the SDK’s text and image masking options (maskAllText, maskAllImages) are enabled.
  • We use no advertising identifiers, no attribution SDKs, and show no ads.

2.8 Notifications data

All notifications in V2 are scheduled locally on your device and send nothing to our servers: an optional morning digest (all modes), an optional evening streak-risk ping (Solo), and the Sunday result card. These are computed on-device from your streak, last-done day-key, and your already-synced chore list. We do not operate any server-side push.

When you grant notification permission, the notification framework registers a Firebase Cloud Messaging (FCM) push token and we store it on your users/{uid} record. We do not use it to send you anything. If we ever add server-delivered notifications that would be a material change, notified under §11. You can turn notifications off at any time in settings.

2.9 AI processing data

V2 does not use AI. Nothing you type and no photo you take is sent to any AI provider, and no image is sent to any classifier. Verification of a completed chore is done by a person — the household owner can void any done. There is no automated “referee,” and we run no automated moderation over your chore titles, steps, or photos.

2.10 Share cards

When you share a result card or a streak milestone, the image is generated entirely on your device, handed to your OS share sheet, and not uploaded to or retained by us. A share image may contain your display name, avatar, the chore/result, your streak, and an invite footer. Your account identifier is not embedded.

2.11 Invite links

Joining a household uses a short invite code stored on the household record, and a gameofchores.me invite link generated on your device. We do not create a separate invite record: the code is a single field on the household, and nothing about who minted a link is stored alongside it. The code has no time-based expiry; it stops working when the household owner rotates it.

2.12 Report

If you report content or a member for a safety reason, we store a report record — your identifier, the household, and a timestamp. The record carries a category and target field, but the App always writes a fixed placeholder into both, so which member or item you reported is never recorded, and there is no free-text note. The record is readable by the household owner for review — that is another member of your own household, not a moderator working for us — and the reported member is not told who reported them. Report is a lightweight household-internal flag: there is no AI or automated-moderation pipeline behind it, and no review team. The household owner can void a done, remove content, or remove a member. V2 ships no per-user block tool.

A plain-language summary is in our Community Guidelines.

3. Why we collect it (purposes and legal bases)

The table below maps each processing purpose to the data categories used and to the GDPR Article 6 lawful basis we rely on. The “Why we are allowed to do it” column restates each legal basis in plain language, so the table is readable without legal training.

Purpose Data categories Why we are allowed to do it Legal basis
Create and operate your account/session Account, session, profile Because we need it to give you the App you signed up for. Contract — Art. 6(1)(b)
Run households, chores, dones, weekly cycles User-generated content, household/membership data Because we need it to give you the App you signed up for. Contract — Art. 6(1)(b)
Add members via invite code Invite/membership records Because we need it to give you the App you signed up for. Contract — Art. 6(1)(b)
Notifications Notification prefs; FCM push token Because you gave us permission. You can withdraw permission at any time. Consent — Art. 6(1)(a)
Analytics Automatic Firebase Analytics events, app/device metadata Because we have a legitimate reason (to fix bugs and improve the App) and weighed it against your rights. Legitimate interest — Art. 6(1)(f)
Crash + error reporting Sentry crash/error events (no screenshots; EU/Germany) Because we have a legitimate reason (to keep the App stable) and weighed it against your rights. Legitimate interest — Art. 6(1)(f)
Abuse prevention and security As needed Because we have a legitimate reason (to keep the App and its infrastructure secure) and weighed it against your rights. Legitimate interest — Art. 6(1)(f)
Operate Report Report records Because we have a legitimate reason (community safety) and weighed it against your rights. Legitimate interest — Art. 6(1)(f)
Generate share cards locally User-generated content rendered on device only We do not process anything on our servers for this; the image is made on your phone. Not applicable — no controller processing

Legitimate interests assessment (GDPR Art. 6(1)(f) processing)

For each purpose relying on legitimate interest, we have considered (i) the interest itself, (ii) why processing is necessary to achieve it, and (iii) whether the user’s rights override it. Summary:

  • Analytics — interest: fixing bugs and improving the App. Necessity: aggregated event counts are the minimum needed to identify broken screens; we do not use advertising identifiers or attribution SDKs. Balance: data is minimized to event names + app version + device model, no identifier-level profiling for marketing; user rights are not overridden.
  • Crash + error reporting (Sentry) — interest: keeping the App stable. Necessity: stack traces and breadcrumbs are needed to diagnose the failure. Balance: no screenshot, view hierarchy or session replay is attached to these events, so no image of your screen leaves the device; the SDK’s text and image masking options are enabled regardless; data is stored in the EU (Frankfurt); user rights are not overridden.
  • Abuse prevention and security — interest: keeping the App and its infrastructure secure. Necessity: Firestore security rules, App Check, and server-side validation on Cloud Functions are the technical measures used to enforce it. Balance: this is security infrastructure, not behavioural profiling, and no operator reads user content as part of it; user rights are not overridden.
  • Report tool — interest: community safety. Necessity: the report record is the minimum needed to act on a report. Balance: the reviewer is the household owner, not a moderation operator, and there is no automated pipeline behind it; reporter identity is not surfaced to the reported user; user rights are not overridden.

Our legitimate-interests assessments are conducted in accordance with EDPB Guidelines 1/2024 on processing of personal data based on legitimate interests (adopted 8 October 2024), the WP29 Opinion 06/2014 it updates, and the Court of Justice ruling in Case C-621/22 confirming that commercial interests may qualify as legitimate where the three-step balancing test is satisfied.

You may object to any processing based on legitimate interest under GDPR Art. 21 by emailing privacy@gameofchores.me; we will stop processing unless we can demonstrate compelling legitimate grounds that override your interests, rights, and freedoms.

Consequences of refusing to provide data (GDPR Art. 13(2)(e))

Account/session data, profile data, and core user-generated content (chores, dones) are required to use the App. Optional items (notifications, and analytics where applicable) only disable the relevant feature and do not affect access to the App.

You may withdraw consent at any time for consent-based processing (notifications) via your device settings or in-App settings, without affecting the lawfulness of earlier processing.

4. Who we share data with (sub-processors)

We do not sell your personal data. We share data only with the service providers below.

  • Google LLC — authentication (Firebase Auth: anonymous, Sign in with Apple, Sign in with Google), database (Cloud Firestore, eur3), file storage (Cloud Storage, EU), serverless backend (Cloud Functions, europe-west1), push notifications (Firebase Cloud Messaging), product analytics (Firebase Analytics), integrity (Firebase App Check), and configuration (Remote Config). Google is certified under the EU-U.S. Data Privacy Framework, with Standard Contractual Clauses as a fallback transfer safeguard.
  • Apple — Sign in with Apple (authentication only). For users in the European Economic Area and Switzerland, Apple’s controller is Apple Distribution International Ltd (Ireland); the onward transfer to Apple Inc. (United States) is governed by Standard Contractual Clauses.
  • Google LLC (Gmail SMTP) — your data-export email from the exportUserData function (which contains your own data) is delivered via Gmail SMTP using nodemailer, in the europe-west1 region; the SMTP credentials are held in Google Secret Manager. This is the same Google sub-processor listed above — no additional third party receives the export email.

Other members of your household can see what you make visible in the App: your display name, avatar, and your dones/chores within the household. We may disclose data to law enforcement or competent authorities where required by applicable law, court order, or to protect the rights, safety, or property of users or the public.

Online-platform status under the Digital Services Act. Game of Chores is an online platform under EU Regulation 2022/2065 (the Digital Services Act) and qualifies as a micro/small enterprise, exempt from most platform-specific obligations under DSA Article 19, but keeps baseline duties: a single point of contact for authorities (privacy@gameofchores.me); a notice-and-action mechanism for illegal content (the in-App Report tool); a statement-of-reasons obligation for content-moderation decisions; and the prohibition on targeted advertising to minors (the App shows no advertising, targeted or otherwise).

We publish material sub-processor changes here before they take effect (see §11).

5. International data transfers

Your primary data is stored and processed on Google Cloud infrastructure in the European Economic Area:

  • Cloud Firestore: eur3 multi-region (Belgium and the Netherlands)
  • Cloud Storage: EU multi-region
  • Cloud Functions: europe-west1 (Belgium)
  • Sentry error reporting: EU data residency (Frankfurt, Germany)

Out-of-EEA processing that survives in V2: Apple Sign in (United States, onward transfer under Standard Contractual Clauses, for Sign in with Apple). As the user base grows, we expect to add a United States storage region for users outside Europe, with notice published under §11 before it takes effect.

6. How long we keep it

  • Active account and household data: retained while the account/household exists.
  • Dones and after-photos: retained while your account exists. On account deletion your after-photos are hard-deleted; the done records persist for the household with your identity anonymized (see below).
  • Invite code: a single rotatable code on the household record; no separate invite record is kept.
  • Sign-in logs (IP, device metadata, sign-in events): retained per the authentication provider’s (Firebase Auth / Google Cloud) published platform default; this is not app-configurable.
  • Account-deletion audit records: retained for 90 days, enforced by a time-to-live on the deletion-audit ledger.
  • Aggregate counts: anonymous; retained indefinitely.
  • Other security/fraud logs: as needed, typically ≤ 90 days.

Cached results from earlier versions. Version 1.x used AI services to generate chore suggestions and how-to step lists. A small number of those generated results are still stored on our servers. We use them for nothing else and we never share them. Game of Chores 2.0 and later send nothing to any AI service. We delete the remaining cached results within 30 days of version 1.x’s retirement.

Account / member deletion:

  • A member deletes themselves: their personal data (member doc, prefs, after-photos, push token if any) is purged; their done records stay in the household, re-attributed to a “left” member so the household’s history and cycle results remain intact.
  • The household owner deletes themselves: ownership transfers to the next adult (oldest-joined); if no adult remains, the household is archived. The owner’s personal data purges and their dones anonymize to “left”; the household/members/chores/cycles persist.
  • Kid / PIN profiles have no account and cannot self-delete; the owner removes them (the delete-account row is hidden on kid seats).

How to delete: in the App, via Settings → Delete account, with a multi-step confirmation. Deletion runs through the deleteAccount function.

7. Your rights under GDPR

If GDPR applies to you, you have the rights to: access (Art. 15), rectification (Art. 16), erasure (Art. 17 — also in-App via account deletion), restriction (Art. 18), data portability (Art. 20), objection to legitimate-interest processing (Art. 21), withdrawal of consent (Art. 7(3)), and to lodge a complaint (Art. 77).

Data export scope: a data-export request returns only the requesting person’s own personal data — their member doc, their dones, their preferences, and their after-photos — and never another member’s data, even for the household owner. An owner cannot export the whole household, because that would leak other members’ (including kids’) data.

Automated decision-making (Art. 22). V2 makes no solely-automated decision that produces legal or similarly significant effects. Chore completion is confirmed by people (the owner can void a done). (The V1 “AI Referee” that auto-judged proof photos has been removed.)

To make a request: email privacy@gameofchores.me with the email you signed up with and the right you’re exercising. We respond within 30 days (extendable by 60 for complex requests, with notice) and may ask you to verify your identity.

8. Supervisory authority

The lead supervisory authority for the controller is:

Autoriteit Persoonsgegevens (Dutch Data Protection Authority)
Postbus 93374, 2509 AJ Den Haag, Netherlands
autoriteitpersoonsgegevens.nl

You may also complain to the authority in your country of residence. The Autoriteit Persoonsgegevens coordinates with other EU and EEA authorities via the one-stop-shop mechanism set out in GDPR Articles 56 and 60.

9. Children

Game of Chores treats children two different ways depending on who is using the App.

Kids in a household (parent-managed). In Manager mode a parent (the household owner, who holds parental responsibility) creates emoji-only kid profiles. Children do not create accounts, do not provide an email or any external identity, do not upload photos, and receive no marketing. A kid’s device holds only an anonymous session linked to the seat. The parent can remove a kid profile and its data at any time, and a kid seat cannot delete itself.

Adults creating their own account. Game of Chores 2.0 and later do not ask for, collect, or store a date of birth. Our earlier release, version 1.x — which some people still have installed — asks for a birth month and year to run its own age check, and stores that value on the account. If your account has been used with version 1.x, it currently holds a birth month and year. We use it for nothing else and we never share it. We are retiring version 1.x, and we will delete all remaining birth month and year values within 30 days of that retirement completing. You can ask us to delete yours sooner at privacy@gameofchores.me.

During setup in 2.0 the account holder is asked once to state their age band. The answer is not stored, not transmitted to us, and not used to configure anything. Choosing the under-13 option ends setup and returns you to the welcome screen. The App shows no ads to anyone.

We do not knowingly collect personal data from a child under 13 outside a parent-managed profile; contact privacy@gameofchores.me and we will delete it.

10. Security

We protect data with measures appropriate to the risk (GDPR Art. 32): TLS 1.2+ in transit; provider-managed encryption at rest (Firestore, Cloud Storage); Firestore security rules enforcing that members read/write only what they’re authorized to (rules tested before each release); server-side validation on Cloud Functions before privileged writes; least-privilege service accounts with secrets in Secret Manager; multi-zone replication with point-in-time recovery; and breach notification to the Autoriteit Persoonsgegevens within 72 hours (Art. 33), notifying affected users where Art. 34 applies. No system is perfectly secure; we keep hardening as the App scales.

11. Changes to this policy

We may update this policy. When we make a material change — a new sub-processor, a new data category, a change of controller, or a material retention change — we publish the updated policy here with a future effective date, update the “Last updated” date at the top of this page, and describe the change in the App’s store release notes for the release in which it takes effect. Minor changes update the date only.

If you object to a material change before it takes effect, you can delete your account.

The disclosures here are kept consistent with the Apple App Store privacy label and the Google Play Data Safety section.

12. Contact

For privacy questions, requests, or complaints:

privacy@gameofchores.me

13. Additional information for users in Turkey (KVKK)

If you are located in Turkey, the Personal Data Protection Law (Kişisel Verilerin Korunması Kanunu — Law No. 6698, “KVKK”) applies to our processing of your data, in addition to GDPR. This Section discharges our transparency obligation under KVKK Art. 10 (Aydınlatma Yükümlülüğü).

Data controller (Veri Sorumlusu): Umut Aktaş, Utrecht, the Netherlands. Contact: privacy@gameofchores.me.

Lawful grounds (KVKK Art. 5 and Art. 6): we process personal data of Turkish users on the same grounds as set out in Section 3 for GDPR, mapped to KVKK equivalents — contract necessity (Art. 5(2)(c)), legitimate interests (Art. 5(2)(f)), legal obligation (Art. 5(2)(ç)), and explicit consent (Art. 5(1)) for notifications. Special-category data (Art. 6) is not knowingly processed; if an after-photo incidentally contains such content it is processed only for the App’s core function on the basis of your voluntary upload.

Your KVKK rights (Art. 11) mirror your GDPR rights above.

Supervisory authority: Kişisel Verilerin Korunması Kurulu (KVKK Kurulu), Ankara, Turkey — kvkk.gov.tr.

Cross-border transfers: the transfers in §5 (Google/Firebase in the EEA; Apple US under Standard Contractual Clauses) rely on the same Standard Contractual Clauses used for GDPR; incidental transfers may rely on explicit consent (Art. 9(6)).

Veri Sorumlusu Temsilcisi (Turkish controller representative) and VERBİS registration. The controller is below the VERBİS registration thresholds published by the Turkish Personal Data Protection Authority based on annual employee count and turnover. We re-evaluate this status at the close of each financial year and will appoint a Turkish data controller representative and complete VERBİS registration before exceeding the thresholds. Until then, KVKK rights and contact requests can be exercised directly via privacy@gameofchores.me.


This Privacy Policy is governed by the laws of the Netherlands. Any disputes are subject to the exclusive jurisdiction of the courts of Utrecht, the Netherlands, without prejudice to (a) mandatory provisions of Turkish law for users resident in Turkey, and (b) mandatory consumer-protection law in your country of residence that grants you the right to bring proceedings in your local courts.