HomeAtlas: Privacy Policy
This Privacy Policy explains how OMNIA VINCULA PTY LTD ACN 700 615 498, trading as HomeAtlas (ABN 28 700 615 498) (“HomeAtlas”, “we”, “us” or “our”), collects, uses, shares, and protects your personal information when you use the HomeAtlas website, mobile applications, and related services (the “Service”).
We are committed to handling your personal information in line with the Australian Privacy Principles (APPs) under the Privacy Act 1988 (Cth), the EU/UK General Data Protection Regulation (GDPR), the New Zealand Privacy Act 2020, the U.S. California Consumer Privacy Act / CPRA, the Children's Online Privacy Protection Act (COPPA), and Canadian privacy law (PIPEDA), to the extent each of these applies to you.
1. Who we are and how to contact us
HomeAtlas is operated by OMNIA VINCULA PTY LTD ACN 700 615 498, an Australian proprietary limited company (ABN 28 700 615 498), trading as HomeAtlas. We are the data controller (and, in Australian terms, the “APP entity”) for the personal information described in this policy. information described in this policy.
Privacy contact: [email protected]
Postal address: Level 2, 58 Gawler Place, Adelaide SA 5000, Australia
Website: https://homeatlas.org
For users in the EU/EEA or UK who prefer to write in their own language, you can also contact us at the same email. We will respond in English.
2. Information we collect
2.1 Account and profile information
- Email address, password (stored hashed), display name, optional username, optional bio and phone number;
- Authentication identifiers from Google, Apple, Microsoft, or Facebook if you choose Sign in with that provider, typically your email and a stable user ID;
- Time zone, preferred currency, region, colour palette and other UI preferences;
- Subscription tier, Stripe customer/subscription ID, Apple/Google in-app purchase receipt identifiers, credit balance, top-up history.
2.2 Household and location information
- Home and garage names and postal addresses. We do not store map coordinates for them: an address is geocoded only to answer a question at the time you ask, and the coordinates are discarded;
- Garden, project, and event addresses, and a Google Place ID where you picked a place from the address suggestions;
- Household membership records, invite codes, roles (owner, co-parent, carer, viewer), and permissions you grant other members.
We do not collect continuous, background, or precise GPS location from your device. Location is only the address you type plus its geocoded coordinates.
2.3 Family and care records
- Child profiles you create: preferred name, date of birth, gender, height, weight, school name, allergies, medical conditions, health notes, emergency contact, and any AI-generated avatar (a stylised illustration, not a photo);
- Adult/household person profiles with similar fields, where you record them;
- Care plans: medications, dosages, schedules, dose logs (taken/skipped/notes), and care tasks;
- Documents you upload to the family paper inbox (school letters, consent forms, medical results, prescription labels) and the structured data we extract from them using AI vision;
- Family events and tasks (calendars, reminders, checklists);
- End-to-end encrypted family messages: we store ciphertext and metadata (participants, household, timestamps), but the content is decrypted only on your devices.
2.4 Kitchen, garage, garden, pets, and projects
- Recipes, meal plans, dietary preferences, palate questionnaire answers, shopping lists, and cocktail recipes;
- Pantry / fridge / freezer items, including barcode scans, expiry dates, brand and quantity, photos of groceries you upload;
- Garage projects with materials, tools, tasks, budgets, timelines, and any reference photos you upload;
- Garden, plant, lawn, and pet records, including pet vaccinations, parasite treatments, test results, and any photos or AI-generated avatars;
- Event project details (venue, theme, guests, menu) and any AI-generated invitation images.
2.5 Chat content
- Messages you send to the AI assistant (“Chat Atlas”) and the responses we generate, stored against the relevant project, recipe, or thread.
2.6 Calendar and tasks (when you connect them)
- If you connect Google Calendar, Google Tasks, or Microsoft Outlook, we receive, at your direction, calendar IDs, event titles, times, descriptions, attendees, and similar fields, plus a refresh token (encrypted at rest with a Fernet key) so we can keep your HomeAtlas calendar in sync. You can disconnect at any time.
2.7 Payment information
- For web subscriptions, Stripe processes your card directly. We never see or store your full card number; we receive metadata such as customer ID, plan, last four digits, country, and the result of the transaction.
- For mobile in-app purchases, Apple or Google tells us the product purchased, the transaction/receipt ID, and the subscription state. They do not share your card details with us.
2.8 Device and technical information
- IP address, user-agent, device type, OS version, app version, and timestamps for requests;
- Authentication tokens (JWT access/refresh), session cookies, and a CSRF token;
- Crash and error logs, basic performance metrics, push subscription identifiers (if you opt in to web/mobile push).
2.9 Information we do NOT collect
- We do not knowingly collect biometric data, government identifiers, sexual orientation, religion, political opinions, or trade union membership;
- We do not collect background or continuous device location;
- We do not collect data from your device's contacts, photo library, microphone, or health records unless you actively pick a file to upload.
3. How we use your information
We use the information described above to:
- Create and run your account, authenticate you, and keep your data in sync across devices;
- Operate and personalise the Service: for example, display your pantry, generate shopping lists, sync your calendar, and remember your preferences;
- Generate AI suggestions you ask for (recipes, project plans, care plan templates, images, document extraction);
- Process payments, manage subscriptions, allocate credits, and prevent fraud;
- Send transactional emails (verification, password reset, daily digests, billing receipts, household invites) and the in-app or push notifications you have enabled;
- Provide customer support and respond to your queries;
- Investigate misuse, enforce our Terms, and meet our legal obligations;
- Improve the Service, including using de-identified or aggregated usage data for product analytics. We do not train our own AI models on your content, and we do not allow our AI providers to use your content to train their general-purpose models, where that option is available to us.
3.1 Legal bases (EEA / UK)
If GDPR applies to you, we rely on the following legal bases under Article 6:
- Contract: to deliver the Service you signed up for (most processing).
- Legitimate interests: security, fraud prevention, service improvement, analytics. We balance these against your rights.
- Consent: for marketing emails (where applicable), optional features you turn on, sensitive AI features, and special-category data (such as health and child data: see below).
- Legal obligation: tax records, lawful requests from authorities.
For special-category data (Article 9 GDPR): such as health information you record in care plans, allergy notes, medication logs, or prescription label scans. We rely on your explicit consent, given when you choose to record that information. You can withdraw your consent at any time by deleting the data, or your account, in the app.
3.2 Sensitive information, health, medication and allergies
Some information you can choose to record is sensitive: medications and dosages, allergy lists, health notes, care plans, dose logs, and prescription-label or medical-result scans. We hold this to a higher standard:
- What we collect. Only what you choose to enter or upload, medication names and doses, schedules, dose logs, allergy and health notes, and the documents you scan into the family paper inbox.
- Why. So you can record and manage your family's care in one place, and so the AI features you actively ask for (for example reading a prescription label) can use that specific input to produce the result you wanted.
- Not used for anything else. Sensitive health information is never used for advertising, never sold, and never used to train AI models. It is shared only with the providers needed to deliver the feature you used, and only the minimum required (see sections 4 and 7). Where processing is based on consent, you can withdraw it at any time by deleting the data or your account in the app.
4. AI features and how data is sent to AI providers
HomeAtlas uses third-party AI providers to power features like the Chat Atlas, recipe suggestions, project planning, document extraction, and image generation (cocktail covers, event invites, child or pet avatars, DIY inspiration). When you use one of those features, the relevant input: for example your message, a project description, the photo you uploaded, or a child's profile fields needed for an avatar, is sent to our AI provider to produce the result.
How we limit what is shared:
- We only send the data needed for the specific feature you used (data minimisation).
- We use AI provider plans that, where offered, opt out of training the provider's general-purpose models on your content.
- Image-generation prompts about a child or pet use the profile fields you have recorded (name, age range, interests). We do not send a child's photo to image-generation models for avatar generation.
- Family E2E messages are never sent to AI providers, the plaintext exists only on your devices.
We engage third-party AI providers as sub-processors. We describe them here by category rather than by name:
- Large language model providers: used for the Chat Atlas assistant, recipe and meal suggestions, project and event planning, document extraction, homework hints, and pet, garden and DIY guidance.
- Image generation providers: used for avatars, invite cards, recipe and cocktail covers, and DIY inspiration.
We only send each AI provider the specific input needed for the feature you used, and we use plans that, where offered, opt out of the provider using your content to train its general-purpose models. You can email [email protected] at any time to ask which categories of provider we currently engage; we will answer in line with this policy and applicable law.
5. Children's data and family records
HomeAtlas is designed for adults to manage their household, including records about children in their care. We do not allow direct sign-up by children under 13.
Parent-managed child profiles. A parent or guardian (the household administrator) creates and manages each child profile. The administrator may optionally enable a “kid-mode” sub-profile for the child to use a restricted view of the Service. Kid-mode profiles are not separate accounts: the parent remains the account holder, has full control of the data, and can disable the sub-profile at any time. Kid-mode profiles cannot make purchases, change subscriptions, or access general AI chat.
What we collect about a child. Only what the parent or guardian enters: preferred name, date of birth, gender, height, weight, school, allergies, health notes, emergency contacts, calendar entries, tasks, school documents, and care plan items. AI avatars are stylised illustrations generated from those profile fields. We do not send photos of children to image models for avatars.
Verifiable parental consent. By creating a child profile or enabling kid-mode, the household administrator confirms they are the child's parent or legal guardian (or have the parent's authority) and consents on the child's behalf to the processing described in this policy. We accept the administrator's payment method and account verification (including email verification, and where applicable Stripe / Apple / Google identity checks) as the verifiable consent under COPPA / GDPR-K.
Withdrawing consent. A parent or guardian can review, edit, export, or delete a child's records at any time from the family settings, or by emailing [email protected]. Deleting a child profile removes the child's data on the same timeline described in section 13.
If you believe a child under 13 has registered an account directly: outside of a parent-managed profile. Please contact [email protected] and we will investigate and delete the account.
Child safety. Our Child Safety Standards describe how we prohibit and respond to child sexual abuse and exploitation, and how to report a safety concern from inside the app.
6. Sharing with household members
When you invite someone to your household, you choose what they can access: for example the family calendar, child records, the pantry, or shopping lists. Anything you grant access to becomes visible to that household member while their access is active. Household members may also create their own content (events, messages, dose logs) inside shared spaces. You are responsible for choosing who you invite. You can revoke access at any time from Profile → Settings → Home management.
Data about other people. You may add information about other people to your account: for example a partner, a child, a carer, or a pet. Those records belong to the people (or animals) they describe, and you should add them only with that person's consent or, for a child in your care, where you are entitled to as a parent or guardian (see section 5). If you delete your account, the records you created about other people are deleted on the same timeline as your own data (see section 13). If a person is also a household member with their own account, deleting your account does not delete their account or the data in it, but they will lose access to anything they could only reach through your account.
7. Service providers and data sharing
We share personal information only with service providers who process it on our behalf under written agreements that require confidentiality, security, and use restricted to our instructions. We do not sell personal information and we do not share it for cross-context behavioural advertising.
| Category | Providers (examples) | What is shared | Why |
|---|---|---|---|
| Cloud hosting & CDN | Amazon Web Services (Sydney region by default); Cloudflare | All Service traffic and stored data | Run the Service securely |
| Authentication / identity | Google, Apple, Microsoft, Facebook | Email and a stable user ID, where you choose social sign-in | Let you log in with an existing account |
| Payments: web | Stripe | Email, payment token, plan, country | Process card payments and subscriptions |
| In-app purchases: mobile | Apple App Store, Google Play | Receipt / transaction identifiers, subscription state | Process iOS and Android purchases |
| AI providers (large language models and image generation) | Engaged by category, not named in this policy: see section 4 | The specific input you submitted to that AI feature (text and / or image) | Generate the AI result you asked for |
| Maps & addresses | Google Maps Platform (Geocoding, Places) | Addresses you type, partial address text during autocomplete | Convert addresses to coordinates and show them on a map |
| Calendar sync (optional) | Google Calendar, Google Tasks, Microsoft Graph | Calendar events, task lists you choose to sync | Two-way sync with your existing calendar |
| Email delivery | Postmark (transactional email) | Email address, message contents (verification, digests, receipts) | Deliver transactional email |
| Product analytics | None: first-party and self-hosted on our own infrastructure | De-identified usage events (feature used, plan tier, app version), stored only on our own infrastructure and never sent to a third-party analytics provider; no message contents, health records, or other sensitive data | Understand how features are used so we can improve the Service |
| Error & performance monitoring | Sentry | Crash and error diagnostics (stack traces, app version, request path); personal identifiers are not sent by default | Detect, diagnose, and fix crashes and errors |
| Product lookups | Open Food Facts; USDA FoodData Central; the public product pages of hardware retailers we check prices on (currently Bunnings, AU/NZ) | The barcode you scanned, or the item name you are looking up | Identify a scanned product and estimate what an item costs |
| Shop links you open | Whichever shop you choose: supermarket, hardware, garden, pet or chemist | Nothing from us. Opening a shop link takes your own browser to that shop's search page, with your item in the search box. We do not send your list, your account, or anything else to the shop; from there its own privacy policy and cookies apply | Take you to the shop with your list |
| Push notifications | Web Push (VAPID), Apple Push Notification service, Firebase Cloud Messaging | Push subscription identifiers, notification content (no sensitive medical detail in the body) | Deliver notifications you opted in to |
| Customer support | Email: [email protected] | The contents of your support message and account context | Help you resolve issues |
We may also disclose information where required by a binding legal request, to enforce our Terms, or to protect the safety of users or the public, and, if HomeAtlas is sold, merged, or restructured, to a successor entity that takes on this policy's obligations.
8. International data transfers
By default we host your data in Australia (see section 9). Some service providers above are based in other countries (for example AI providers and payment processors in the United States or the European Union). When personal information is transferred outside of Australia or the EEA / UK, we rely on lawful transfer mechanisms, which may include the European Commission's Standard Contractual Clauses, the UK's International Data Transfer Addendum, equivalent provisions for Switzerland, or the recipient's adherence to a recognised certification (for example the EU-U.S. Data Privacy Framework, where applicable). For Australian users, we take reasonable steps to ensure overseas recipients handle your information consistently with the Australian Privacy Principles, as required by APP 8.
9. Where your data is stored and processed
Some processing of your personal information happens outside Australia. By category of provider and region, that processing is:
- Cloud hosting and storage: your primary data store is hosted in Australia (Sydney region). Backups, logs, and certain caches may be stored in additional regions managed by the same hosting provider.
- AI providers: the large-language-model and image-generation providers described in section 4 process the specific inputs you submit to a feature. These providers host and process data outside Australia, typically in the United States or the European Union.
- Payments: our web payment processor processes payment data outside Australia.
- Calendar and mapping: when you connect a calendar or use an address feature, that provider processes the relevant data in the regions it chooses for your account.
When personal information is transferred outside Australia or the EEA / UK, we rely on lawful transfer mechanisms as described in section 8.
10. Cookies and similar technologies
We use a small number of cookies and similar technologies on the website:
- Strictly necessary: session cookie, CSRF token, JWT refresh token, load-balancer cookies. Without these the site cannot work securely.
- Functional: UI preferences such as your colour palette, dismissed hints, and selected calendar.
- Referral attribution: if you arrive through a referral or influencer link, a first-party cookie remembers that code for up to 90 days so the referrer is credited when you sign up. It is not used for advertising.
- Analytics: aggregated, privacy-respecting product analytics, all first-party and stored on our own infrastructure. If you are not signed in, one first-party cookie holds a random identifier for up to 90 days so that ten pages read by one visitor are not counted as ten visitors. It contains no name, email address or anything else about you, it is never shared, and it is not used for advertising. We do not use third-party advertising or behavioural-tracking cookies.
You can manage cookies through your browser settings. Mobile apps do not use browser cookies but use the equivalent local storage and secure keychain entries to keep you logged in.
11. Marketing and notifications
We send transactional messages by default: for example email verification, password reset, billing receipts, household invites, and the daily/expiry digests you have configured.
Marketing consent is separate from accepting these terms: agreeing to the Terms of Service does not sign you up for marketing. We do not send promotional or newsletter emails unless you have opted in separately (for example by ticking a marketing box during sign-up or in Profile → Settings → Notifications). Every marketing message we send includes an unsubscribe link, and you can also unsubscribe at any time by emailing [email protected]. Withdrawing marketing consent does not stop transactional messages required to operate the Service.
Push notifications and in-app reminders are controlled per-device in your operating system settings and per-feature in Profile → Settings.
12. Security
We use a combination of technical and organisational safeguards, including:
- HTTPS for all traffic between your device and the Service;
- Hashing of passwords using industry-standard algorithms;
- Encryption at rest for sensitive tokens (for example calendar refresh tokens, encrypted with a Fernet key not exposed to the application);
- End-to-end encryption for family messaging, message content is encrypted on the sender's device and decrypted only on the recipient's device, so we never see the plaintext;
- Strict access controls inside HomeAtlas and with our service providers;
- Regular dependency updates, monitoring, and incident response procedures.
No internet service can be 100% secure. If we become aware of a personal-data breach that creates a likely risk of serious harm to you, we will notify you and the relevant regulator (for example the Office of the Australian Information Commissioner under the Notifiable Data Breaches scheme, your supervisory authority under GDPR, or the Office of the Privacy Commissioner of New Zealand) within the timeframes required by law.
13. Retention
We keep your personal information for only as long as we need it for the purposes described in this policy. In practice that means:
- Account and content data: kept while your account is active. When you delete your account, we delete or de-identify your personal data within 30 days, except for items in the next two bullets.
- Tax, billing, and fraud records: retained for the period required by law (typically up to 7 years in Australia under tax law).
- Backups and logs: backups rotate out on a fixed schedule (typically up to 35 days for daily backups). Application logs are kept for short windows for troubleshooting and security and then deleted or de-identified.
- Encrypted family messages: stored as ciphertext while the conversation is active. When you leave a household or delete your account, the encrypted record is removed on the same 30-day timeline.
- Short-lived caches: for example barcode lookups or one-off document-extraction evidence files are deleted within hours to days.
14. Your rights and choices
Subject to your country's law, you have the right to:
- Access the personal information we hold about you;
- Correct data that is inaccurate or incomplete;
- Delete your data (the “right to be forgotten” under GDPR, the right to erasure / opt-out of sale or sharing under the CCPA/CPRA, etc.);
- Export a portable copy of your data in a machine-readable format;
- Object to certain processing or restrict it;
- Withdraw consent at any time, where processing is based on consent (this does not affect the lawfulness of processing before withdrawal);
- Lodge a complaint with a privacy regulator (see section 18).
We do not sell your personal information and we do not use it for cross-context behavioural advertising. We do not subject you to decisions made solely by automated means that produce legal or similarly significant effects on you.
15. How to access, export, or delete your data
You can exercise the rights above as follows:
- In-app deletion: go to Profile → Settings → Delete account. You will be asked to confirm. We will delete or de-identify your data within 30 days, subject to the carve-outs in section 13.
- In-app export: go to Profile → Settings → Download my data to receive a JSON archive of your data within a reasonable timeframe.
- By email: write to [email protected] with the subject line “Privacy request”. We may need to verify your identity (for example by emailing your registered address). We will respond within the timeframes required by your law (within 30 days under GDPR / Australian Privacy Act, 45 days under the CCPA, extendable as permitted).
Requests are free, except where they are manifestly unfounded or excessive (for example repetitive), in which case we may charge a reasonable fee or refuse to act, as permitted by law.
16. Region-specific notices
16.1 EEA / UK (GDPR / UK GDPR)
We act as the data controller for personal data we collect through the Service. The legal bases we rely on are described in section 3.1. You have the rights listed in section 14. You can lodge a complaint with your local supervisory authority, for the UK, that is the Information Commissioner's Office (ICO) at ico.org.uk.
16.2 Australia (Privacy Act 1988)
We handle your personal information in line with the Australian Privacy Principles. You can ask us to access or correct your information at [email protected]. If you are unhappy with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.
16.3 New Zealand (Privacy Act 2020)
We comply with the Information Privacy Principles. You can complain to the Office of the Privacy Commissioner at privacy.org.nz.
16.4 California (CCPA / CPRA)
We do not sell your personal information and we do not share it for cross-context behavioural advertising. You have the right to know, delete, correct, and limit the use of sensitive personal information; we honour these rights without discrimination. You can designate an authorised agent to make a request on your behalf. We will require proof of authorisation. The categories of personal information we collect (mapped to CCPA categories) are: identifiers; commercial information; internet/network activity; geolocation (general); audio/visual content (the photos and documents you upload); inferences (preferences); and sensitive personal information including health information, account log-in credentials and information about a person under 16 collected with consent.
16.5 Children under 13 (United States, COPPA)
HomeAtlas does not allow children under 13 to register a HomeAtlas account directly. A parent or guardian may create a child profile inside their own account and optionally enable kid-mode (see section 5). The parent's identity-verified account, payment method (where used), and accepted invitation flow constitute verifiable parental consent. Parents can review, modify, or delete a child's data at any time, or revoke consent by deleting the child profile or contacting [email protected].
16.6 Canada (PIPEDA)
We comply with the Personal Information Protection and Electronic Documents Act and applicable provincial laws. You can contact our Privacy Officer at [email protected], or complain to the Office of the Privacy Commissioner of Canada at priv.gc.ca.
17. Changes to this policy
We may update this policy from time to time. If a change is material we will notify you by email and / or in-app at least 30 days before it takes effect (or the minimum period required by your local law, if longer). The “Last updated” date at the top of this policy tells you when we last revised it. Continuing to use the Service after the change means you accept the updated policy.
18. Complaints
If you have a privacy complaint, please email us first at [email protected]. We aim to respond within 30 days. If you are not satisfied with our response, you can refer the complaint to your local privacy regulator (see the relevant region-specific notice in section 16).