Ahenora helps families run a household together. This policy explains what we collect, why, who processes it, and what you can ask us to do about it. It is written to be read, not to be survived.
Who is responsible for your data
Ahenora is built and operated by Dzoagbe Labs, established in France, which is the data controller for the purposes of the EU General Data Protection Regulation. Contact: privacy@ahenora.com.
There is no advertising network in Ahenora, no data broker, and no sale of personal data — not as a policy we might revise, but because the app has no mechanism to do it.
Information we collect
Account details from sign-in — your name and email address. Email and password accounts store the password only as a salted, irreversible hash; we never hold the password itself. Google sign-in additionally stores your Google account identifier and profile photo. Sign in with Apple stores your Apple account identifier and the email address Apple gives us, which may be a private relay address.
Household information — the members of your household, their roles, invitations, tasks, cards, chores, rewards, stars and PIN state, and your app preferences.
Ages, when a parent records one for a child or teen. An age is used to decide whether that person may hold their own account, and for nothing else.
Health details, only if you choose to record them for a family member — allergies, conditions, medicines and when to give them, vaccinations, blood group, doctor, dentist and emergency contacts, and optionally a medical or insurance number. None of it is required. It is there so the people caring for a child have it to hand.
Money you record — household spending by shop and receipt, amounts shared between parents, and children's pocket money.
Messages sent inside your household, including who sent each one and who has read it. Messages are visible to the people in that conversation and to nobody else.
Content you add — card titles, descriptions, due dates, vault document titles, categories and images, scanned images, and any calendar entries you choose to import.
Notification settings and device push tokens, when you turn reminders or alerts on.
Basic diagnostic information — app version, platform and error reports — used to find and fix faults, the date you last used the app, and daily totals of how features are used across Ahenora. Totals are counts, not content.
Why we use it, and on what legal basis
To create your account, keep your session secure, and show your household its own data — necessary to perform our contract with you.
To deliver messages, invitations, reminders and service notices you have asked for — performance of the contract, or your consent where you enabled the notification.
To decide who may hold an account, including refusing one to a child recorded as under 13 — compliance with our legal obligations and the protection of children.
To process a scan or an AI-assisted suggestion, at the moment you ask for one — performance of the contract at your request.
To store the health details you choose to record for a family member — your explicit consent, given by recording them. You withdraw it by deleting them, from the member's page, at any time.
To keep the service working and secure, to prevent abuse, and to fix faults — our legitimate interests in operating a reliable and safe app.
To handle paid plans bought through the App Store, Google Play or by card on the web — performance of the contract and our legal obligations.
Children and family data
Ahenora is for adults. It is not directed at children, and a person under 13 cannot hold an Ahenora account. Our server refuses to create one at every point an account can come into being — an invitation naming a child recorded as under 13 is rejected, an under-13 age cannot be recorded against someone who already holds an account, and joining a household refuses to turn an under-13 profile into an account holder. This is enforced by the service, not by asking politely on a form.
A young child appears in Ahenora only as a profile that a parent or guardian creates and controls: a name, optionally an age, a PIN, stars and rewards, and notes a parent writes for them. That information is provided by the parent, who consents on the child's behalf and can see, correct or delete all of it at any time from within the app.
A child's health details are visible to their parents. The details someone looking after the child needs — allergies, conditions, medicines, vaccinations, and doctor and emergency contacts — are also visible to a helper the parents have added, such as a grandparent or a nanny. A medical or insurance number is visible to the parents only.
Kid mode is a restricted view on a parent's own device. It shows a child their own chores, stars and notes. It cannot reach household data, cannot send messages, and cannot make any change that matters. A child never signs in.
A teenager aged 13 or over may be invited to hold their own account. A teen sees their own tasks and chores, the events the household has shared with everyone, and their conversation with their parents — and nothing else: not another member's private items, not expenses, not pocket money, not the vault. That boundary is enforced on the server for every request, and it is a promise we make to the teenager as much as to the parent.
We do not knowingly collect personal information from a child directly. If you believe a child has provided us information without a parent's involvement, email privacy@ahenora.com and we will delete it.
Messages inside your household
A conversation in Ahenora is defined by who is in it, and only those people can read or write it. A private one-to-one always includes a parent — Ahenora does not open a channel between two young members that no parent can see.
Messages are stored on our server so they reach the other person and are still there tomorrow. They are not scanned for advertising, not used to train any model, and not read by us except where we are compelled by law or must act on a safety report.
Calendar, documents and photos
Calendar sync is something you start, never something we do in the background. We read the events you import from Google Calendar or Microsoft Outlook — their titles, times, places, notes and who is invited — at your request, and imported entries become Ahenora cards. The names and email addresses of other people invited to those events are kept so the app can suggest inviting them; Ahenora never contacts them unless you send an invitation. Vault images and document records are stored so your household can view and manage them. You can delete any of it from inside the app.
AI-assisted features
When you ask Ahenora to read something or suggest something, the content of that request is sent to Google's Gemini API, which processes it and returns the result. That covers reading a scanned letter, card, receipt or shopping list; writing or suggesting a recipe or a week of meals; and writing the Sunday brief from the tasks you can see. It happens only at the moment you ask, and only that request's content is sent.
Suggesting who a new task is for does not use an AI provider. It is worked out on our own server, from the names already in the task.
AI output is a suggestion, not advice. Check anything that matters before relying on it.
Who else processes your data
We use service providers to run the app, and they process data on our instructions and for no purpose of their own: Railway (hosting), MongoDB Atlas (database), Resend (email), Google and Apple (sign-in), Expo, Apple and Google (notifications to phones, and your browser's own push service on the web), and Google (the AI provider named above). When you import a calendar, we read it from Google or Microsoft at your request. The ahenora.com website and the web app load their typefaces from Google Fonts, so your browser asks Google's servers for them, which shows Google your IP address; no account information is sent.
Paid plans are sold by Apple through the App Store, by Google through Google Play, or by Stripe for card payments on the web. RevenueCat tells us when a store subscription is active. We never see your card details.
Links you share outside your household show some information to whoever opens them. An invitation shows the invited email address, the inviter's name, the relationship they chose, the household being joined, the one task the invitation hands over, and counts — how many things are on this week, how many children, how many shopping items — never what they are. Once an invitation has been used or withdrawn, its link shows only the inviter's name and that it no longer stands. A gift pot link shows the pot's title and note, the organiser's name, the target and the total pledged. A Secret Santa link shows one person their own match, the budget and the date.
Someone who joins a gift pot through its link gives the name they choose and how much and how they will give, which the household then sees. A phone number or email you type for someone outside the household in a Secret Santa draw is shown to you so you can send them their link; Ahenora never contacts them.
Our providers may process data outside your country. Where data leaves the UK or the EEA, it is covered by the transfer safeguards those providers offer, such as standard contractual clauses.
Security and retention
All traffic is encrypted in transit. Passwords are stored as salted hashes and session tokens only as hashes, so a copy of our database does not hand anyone your password or your session. Tokens on your device are kept in the platform's secure storage where it is available.
We keep your data while your account and household are active. When you delete your account we delete your profile, sessions, push tokens and memberships, your private cards and private documents, and a household that no longer has anyone in it. If you were the last person in a household paying by card, the card subscription is cancelled first. Some records may persist briefly in routine backups, and we keep what the law requires us to keep — billing records, for example.
You can end sessions on devices you no longer hold from Settings, without changing your password.
Your rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict or object to how we use it, or to receive it in a portable form. Email privacy@ahenora.com and we will respond within one month.
Where we rely on your consent, you can withdraw it at any time — that does not undo what was done while it was given.
We do not sell personal information and we do not share it for cross-context behavioural advertising.
If you think we have got this wrong, you can complain to a data protection authority. Ours is the CNIL, the French Commission nationale de l'informatique et des libertés. If you live elsewhere in the EU or in the UK, you can complain to the authority in your own country instead.
Your controls in the app
Sign out, or sign out everywhere, from Settings.
Turn notification categories on or off in Settings.
Delete cards, vault documents, rewards, messages, invitations, member profiles and any health detail where the app offers the control.
Delete your account and your household data from the Account deletion screen, or by emailing us.
Changes and contact
We will announce material changes in the app before they take effect, and update the date at the top of this policy. For any privacy or deletion request, contact privacy@ahenora.com and include the email address your Ahenora account uses, so we can match the request to the right account.