Privacy Policy

This English version is provided for convenience. In case of discrepancy, the French version available at https://kotidy.app/confidentialite prevails.

Last updated: 24 July 2026

1. Who are we?

The Kotidy service (kotidy.app website and mobile application) is published by Baptiste Levesque, sole trader, 49 rue de Bazeilles, 33400 Talence, France, SIREN 534 834 668, data controller for your personal data.

Contact for any question relating to your data: contact@kotidy.app.

Kotidy is an application for organising a household's everyday life (shopping, tasks, calendar), shared between its members. Our principle: we only collect what is necessary for the service to work, we do not sell any data, and we do not use any advertising trackers.

2. What data do we collect?

CategoryDataSource
AccountEmail address, display name, avatar (optional), preferences (theme, notifications), password (stored hashed, never readable), timestamp of acceptance of the Terms of UseProvided by you
Household contentShopping lists and items, tasks and projects, chores, calendar events, recipes, comments, tags, household activity log ("X ticked Milk")Provided by you and the members of your household
SubscriptionSubscription status, customer identifiers with our payment providers (Stripe, distribution platform), history of billing events. We never have access to your bank card number.Generated when you subscribe
TechnicalPush notification tokens (browser and/or mobile device), technical server logs (IP address, timestamp) for security purposesGenerated by use

We collect no geolocation data, no contacts from your phone, and no so-called "sensitive" data.

3. Why, and on what legal basis?

PurposeLegal basis (Art. 6 GDPR)
Creating and managing your account, providing the service (real-time synchronisation, offline mode)Performance of the contract (Terms of Use)
Sharing your household's content with its members, the very purpose of the service: what you add to a household is visible to the other members of that householdPerformance of the contract
Managing the Premium subscription, payment and invoicingPerformance of the contract + legal obligation (accounting)
Sending service emails (sign-in, invitations, confirmations)Performance of the contract
Sending push notifications (reminders, household activity)Consent: permission requested by your device, which can be turned off at any time (in the Settings of the service or of the device)
Ensuring the security of the service (logs, abuse prevention)Legitimate interest
Responding to requests to exercise rights and to legal obligationsLegal obligation

We carry out no profiling and no automated decision-making producing legal effects.

4. Who has access to your data?

4.1. The members of your household. By design, content added to a household (lists, tasks, events, activity) is visible to the other members of that household. Calendar events marked as "personal" are visible only to their creator. Your email address is not displayed to the other members; your display name and avatar are.

4.2. Our processors, strictly necessary for the service:

ProcessorRoleData location
OVHcloud (OVH SAS, France)Hosting of the service and the databaseFrance
Scaleway (Scaleway SAS, France)Sending of service emails (Transactional Email service)France
Stripe (Stripe Payments Europe Ltd / Stripe Inc.)Card payment (web)EU / United States*
Google Play (where applicable)Payment of subscriptions taken out in the Android applicationEU / United States*
RevenueCat Inc.Technical management of subscriptions taken out through the mobile applicationUnited States*
Expo (650 Industries, Inc.)Routing of mobile push notificationsUnited States*
Google (Firebase Cloud Messaging)Delivery of push notifications on AndroidEU / United States*

* Transfers outside the EU: where a processor processes data in the United States, the transfer is governed by the EU-US Data Privacy Framework for processors certified under it (Stripe, Google, Expo; status verifiable at dataprivacyframework.gov) and by the European Commission's standard contractual clauses for the others (RevenueCat). The data transferred is limited to what is strictly necessary for the function concerned (e.g. notification token, subscription identifier); your household's content, for its part, is hosted in France.

No data is sold, rented or passed on for advertising purposes. Audience measurement on our public pages is carried out by a tool that we host ourselves in France, without cookies and without any third party (see section 7).

5. How long do we keep your data?

DataRetention period
Account and household contentFor as long as the account (or the household) exists; permanently deleted when the account/household is deleted
Household activity log90 days (automatic purge)
Notification history90 days (automatic purge)
Past chore occurrences30 days (automatic purge)
Suggestions derived from shopping history6 months after last use (automatic purge)
Technical security logs12 months at most
Invoices and accounting records10 years (legal obligation)
Technical backupsBounded retention cycle: recent backups kept for a few weeks, encrypted monthly archives kept for up to 12 months; deleted data disappears from the backups at the end of the cycle (except accounting archives)

6. Your rights

In accordance with the GDPR and the French Data Protection Act (loi Informatique et Libertés), you have the rights of access, rectification, erasure, portability, restriction and objection, as well as the right to set out instructions regarding the fate of your data after your death.

  • By yourself, from the service: editing your profile and preferences in the Settings, exporting your data in JSON format (Settings → Account & data → Export my data) and deleting your account (Settings → Account & data → Delete my account, a permanent action). A dedicated page is available without installing the application: kotidy.app/compte/suppression.
  • By email: contact@kotidy.app. Any request (access, export, erasure, rectification, etc.) is handled within one month at most. Proportionate identity verification may be requested in case of doubt.

A specific feature of family sharing: deleting your account deletes your personal data; if you are the last member of your household, the household and its content are deleted together with the account. Otherwise, content that is useful to the rest of the household (e.g. items on a shared list) may be kept within the household but is dissociated from your identity.

You may lodge a complaint with the CNIL (French data protection authority, cnil.fr, 3 place de Fontenoy, TSA 80715, 75334 Paris Cedex 07).

7. Cookies and trackers

The website and the application only use cookies and local storage that are strictly necessary: keeping your sign-in session, display preferences (theme), offline operation. These trackers are exempt from consent (Article 82 of the French Data Protection Act, CNIL decisions): this is why no consent banner is displayed.

No advertising cookies, no third-party trackers. We set no audience measurement cookies.

Audience measurement on public pages

The public presentation pages (outside the application) use Umami, an audience measurement tool that we host on our own servers in France. No data is passed on to any third party, and no cookie is set.

The following is measured, in aggregate form: the page viewed, the page the visit came from, the approximate country, and the type of device and browser. Your IP address is never stored in a form that would allow you to be identified, no individual profile is built, and no cross-site tracking is carried out.

This measurement is strictly limited to producing anonymous statistics on the traffic to our pages, without cross-referencing with other processing and without being passed on to anyone. As such it is exempt from consent within the meaning of Article 82 of the French Data Protection Act and the CNIL's recommendations on audience measurement: this is why no banner is displayed.

The application itself, once you are signed in, is not subject to any audience measurement.

Should a tool that does not meet these conditions ever be added, this policy would be updated and your consent obtained as required by law.

8. Security

Main measures: encryption of communications (TLS), strict segregation of data by household enforced at database level (row level security), hashed passwords, mobile session stored encrypted on the device, encrypted backups, restricted and logged administrator access. In the event of a data breach likely to result in a high risk to your rights, you will be informed in accordance with Articles 33 and 34 of the GDPR.

9. Minors

The service is reserved for persons aged 15 and over (the age of digital consent in France). Minors aged 15 to 18 must have the consent of their legal guardians.

10. Changes

Any substantial change to this policy is notified by email or within the service at least 15 days before it takes effect. Previous versions are available on request.