⌂TIDY 20
GuideTermsPrivacyRefundsAccessibilitySupport
PRIVACY POLICY

Your home data is private by design.

This policy explains what Tidy 20 collects, why it is needed, which service providers process it, and how to export or delete it.

Effective August 22, 2026 · Version 2026-08-22

1. Who controls the data

Krausenhouse LLC operates Tidy 20 and is responsible for the personal information covered by this policy. Questions and privacy requests can be sent to friends@tidy20.com.

2. Information you provide

  • Account information: email address, display name, household name, a securely derived password hash, household membership, and legal acceptance records.
  • Home content: room names, reset tasks, timing, completion history, friction notes, calibration findings, and preferences.
  • Optional photos and AI content: room images, prompts, generated goal images, and friction-coach conversation content when you actively use those features.
  • Billing information: subscription status, price or product identifier, customer, transaction, and subscription identifiers, store platform, expiration, and a one-way hash of the Google purchase token where applicable. Native purchases use a random Tidy 20 account identifier—not your email—to bind the store transaction to your account. Payment-card details are handled by Stripe, Apple, or Google and are not stored by Tidy 20.
  • Beta and support information: invitation status, feedback, rating, product context, platform, and messages you send us.

3. Information collected automatically

We collect limited operational information needed to authenticate sessions, prevent abuse, diagnose failures, meter feature allowances, and secure the service. This can include session identifiers, request time, IP-derived security signals, browser or app platform, model and token usage, and provider logs. Tidy 20 does not use third-party advertising trackers and does not sell personal information.

4. How information is used

We use information to provide and synchronize household features, authenticate accounts, process subscriptions, deliver password and invitation emails, analyze optional photos, generate requested images, provide friction coaching, enforce allowances, respond to feedback, prevent fraud, improve reliability, comply with law, and protect users and the service.

5. Room photos and AI processing

Original and generated room images are stored in private object storage and are not public. When you choose an AI feature, the necessary image and text are sent to OpenAI’s API for that request. OpenAI states that API inputs and outputs are not used to train its models by default unless the API customer opts in. OpenAI may retain API abuse-monitoring data for up to 30 days under its standard controls, subject to its policies and legal obligations.

Do not photograph people, sensitive documents, medications, financial information, access codes, or anything you do not want processed. You can use the Free plan without photos or AI.

6. Service providers and disclosures

We disclose only what is necessary to service providers acting for product operations: Railway for application hosting, database, and private object storage; OpenAI for requested AI analysis and image generation; Stripe for web billing; Resend for transactional account email; and Apple or Google for native distribution and in-app billing when those versions are offered. We may also disclose information when required by law, to protect rights and safety, during a business transaction with appropriate safeguards, or with your direction.

Group sprint participation

When you host or join a group sprint, we store the display name you enter, the sprint’s room labels, room selections, progress, timer state, and an access-token hash so participants can reconnect. The host’s account is linked to the sprint. Guests do not need an account or subscription. Anyone with the invitation code can join and see the sprint’s names, room labels, and progress. Sprint participation does not share private household photos, saved tasks, AI content, or subscription access.

Sprint access expires 24 hours after creation. Expired sprint records are removed when accessed or during cleanup when a new sprint is created; deletion may therefore occur after the access window. Leaving removes a guest from the active participant list. Deleting a host’s account removes the sprints they hosted. Database backups and operational records follow the retention controls described below.

Optional Observe & learn features

Additional disclosures for optional observations, contextual AI, and study check-ins are in the Observe & learn privacy supplement, version 2026-09-28. These features require separate opt-in and do not change the version of this core policy or the Terms.

7. Retention

Account and home content are kept while the account is active. Optional photos and generated images remain until you replace/remove them or delete the owning account or household. Confirmed removals are hidden from the app immediately. Private backup copies are removed on the next successful hourly deletion-sync run; a storage or service outage can delay that cleanup. Minimal opaque deletion records are retained to prevent removed content from being restored. Beta feedback remains while needed to evaluate and document the beta unless you delete your account or request earlier deletion. Subscription, security, and operational records may be retained as needed for fraud prevention, dispute resolution, accounting, or legal obligations. Service-provider logs follow the provider’s retention controls.

8. Your choices and rights

You can use manual Free features without submitting photos, export household data from account settings, correct profile information, revoke household members, cancel renewal, and delete your account. Depending on your location, you may also request access, correction, deletion, restriction, portability, or appeal a privacy decision. We do not discriminate for exercising privacy rights.

Use the in-product deletion control or follow the external instructions at tidy20.com/support#delete-account. We may verify that a request comes from the account owner.

9. Security

We use authenticated household separation, hashed passwords, revocable sessions, restricted private storage, signed billing webhooks, and server-side API credentials. No system is perfectly secure, so please use a unique password and report suspected access promptly.

10. Children and international processing

Tidy 20 is for adults and is not directed to children under 13. We do not knowingly create accounts for children. Information is primarily processed in the United States and may be processed where our providers operate, subject to applicable safeguards.

11. Changes

We will update the effective date and notify account holders when a material privacy change requires notice or consent. Contact friends@tidy20.com with a privacy question or request.

Tidy 20Operated by Krausenhouse LLCfriends@tidy20.com