FridgeDoor FridgeDoor

Privacy

What we do with your family's data

Last updated 14 September 2026

The short version

  • We store only what the app needs to work, on servers in the European Union.
  • Nobody gives us an email address or a phone number — there are no accounts at all.
  • No ads, no tracking of your family, and nothing sold or shared for marketing.
  • Delete your family and the data goes with it.

Who is responsible

FridgeDoor is made and run by Re-dizajn, Sebastijan Kolenko s.p., Ulica bratov Greifov 24, 2000 Maribor, a sole trader registered in Slovenia. For anything in this document, including any request about your data, write to app@fridgedoor.net. A real person reads that inbox.

What we collect

  • No accounts at allFridgeDoor has no sign-up, no username, no password and no email login — not for the grown-ups either. A family is identified by a six-character join code, and each device that has joined keeps an access key for that family in its own browser storage. That key is what lets the device read and write your family's data.
  • The parent PINIf you set a four-digit PIN to keep the settings out of small hands, we store only a salted, one-way hash of it on our servers, never the digits. It guards one screen inside the app; the join code is what actually protects your family’s data.
  • Family contentThe names and avatars you choose, your chores and their point values, rewards, family goals, points earned, streaks and badges, and the six-character join code.
  • Join-code attemptsWhen someone enters a six-character join code, we record that an attempt happened, whether it succeeded, and a one-way fingerprint of the network address it came from. The code itself is never stored in readable form, and the fingerprint cannot be turned back into an address. We keep these records for 30 days and use them for nothing but blocking someone guessing their way into a family; after that they are deleted automatically.
  • Photo proofsThe pictures your family takes to confirm a chore. They are stored in a private folder for your family in EU object storage, reachable only by a device that holds your family’s access key. Your most recent 100 photos are kept; older ones are deleted automatically. Each time a photo is shown, that device is given a temporary link to it that stops working within an hour; no permanent link to your photos is stored anywhere.
  • Technical basicsEssential server error and access logs needed to keep the service running and secure, and a copy of your family data cached in your browser’s local storage so the app keeps working when the connection drops. Clearing that browser storage also clears the access key, so keep your join code somewhere safe.
  • Launch-list emailIf you ask to hear when the iOS and Android apps arrive, we keep your address in a plain mailbox for that one announcement and delete it afterwards.

What we never do

There are no ads in FridgeDoor and no advertising or tracking code in the app or on this website. We do not sell, rent or share your family's data with anyone for marketing, and we do not build profiles of your children. The only counting we do is the anonymous statistics described below, which carry no names, chores or photos; the platform that hosts the app may also record basic, aggregated visit statistics such as page views.

There are no tracking cookies either, so there is no cookie banner to click away. Instead of cookies the app uses your browser's own local storage — your family's access key and an offline cache of your family data — plus one session flag remembering that the parent PIN was entered, and — only while anonymous statistics are on — a random device id. The key, the cache and the PIN flag are strictly necessary for the app to work; the device id disappears the moment you switch the statistics off. None of it is used for advertising and none of it is shared.

Anonymous statistics

We count how the app is used: that a chore was completed, that a reminder was allowed, that setup finished. Each count carries a family id, a random device id, whether the person was a grown-up or a child, the app version and the language. It never carries names, chore or reward names, notes or photos, and it is never shared with anyone or used for advertising. You can turn it off in Settings → App.

Where your data is stored

Your family data and uploaded photos are hosted on cloud infrastructure provided by Amazon Web Services in Frankfurt, Germany (EU region eu-central-1). Encrypted backups expire automatically within 30 days. Your device also keeps a local copy of your family data so the app works offline; the authoritative copy is the one in the cloud, and clearing your browser data removes the local copy only.

We use two kinds of service provider and no others: hosting and database — Lovable Cloud, running on Amazon Web Services in Frankfurt; and email — Resend, in its Ireland (EU) region, for the one launch announcement and for anything you write to us. No family data goes anywhere else.

Children

A family is always created by a parent or guardian, who decides who joins it and consents on the children's behalf. Children join with the six-character join code and pick an avatar. We ask them for nothing else: no email address, no phone number, no date of birth. The only data about a child in FridgeDoor is what the family itself puts there — the name you type, the avatar, the chores done and the photos taken. A parent can change or delete any of it at any time. Under Slovenian law a child under 15 cannot consent to this on their own, which is why the family is always set up by a parent or guardian.

Why we are allowed to process it

Under the GDPR we rely on three grounds: performing our agreement with you, so the app can do what you signed up for; the consent a parent gives for their children's data and the consent you give when you join the launch list; and our legitimate interest in keeping the service secure and working.

How long we keep it, and how to make it go away

We keep your family's data for as long as the family exists. Delete the family in the app and the data is deleted with it — chores, points, rewards, history and photos. Copies inside routine backups age out within 30 days. Photo proofs also roll off on their own once a family passes 100 photos. Launch-list addresses are deleted after the apps are released, or sooner if you ask. If a family is ever removed some other way — by us, at your request — a daily sweep deletes any photos left behind within three days.

Your rights

You can ask for a copy of your data, have it corrected, have it deleted, take it elsewhere, or object to how we use it. Because we hold no account and no email address for you, we can only find your family from its join code — include it in your message. Write to app@fridgedoor.net and we will answer within 30 days. If you think we have handled your data badly, you can complain to the Slovenian Information Commissioner (Informacijski pooblaščenec) or to the supervisory authority where you live.

How we keep it safe

Family data travels over encrypted connections and is stored on managed EU infrastructure, with access limited to the one person who runs FridgeDoor, using individual credentials. Photos sit in a private per-family folder that only a device holding your family's access key can reach, and backups are encrypted. If personal data is ever exposed, we notify the Slovenian Information Commissioner, and we tell you directly if the risk to your family is high.

No profiling, no automated decisions

Nothing in FridgeDoor profiles your family or makes automated decisions about anyone. Points, streaks and badges are simple arithmetic on what your family entered, and they have no effect outside the app.

Changes to this page

FridgeDoor is young and will change. When this document changes we update the date at the top, and if a change matters to you we will say so in the app rather than hope you re-read this page.