Your data
Privacy Notice
This notice explains what Chorus handles, why it is needed, where it goes, and the controls available to each household.
Effective 16 August 2026 · Version 2026-08-16
What Chorus collects
Chorus stores the name and email returned by your sign-in provider, household membership and role, lists, chores, inventory balances and expiry dates, meal plans, recipes, optional dietary profiles, budgets, practical home-asset and maintenance details, private calendar-feed metadata, decisions, notification preferences, and activity needed to keep shared work understandable. It stores bill images and extracted bill details only when a household admin deliberately uploads them. The optional Medicines workspace stores only the cabinet names, label strengths, quantities, units, locations, batches, expiry dates, privacy choices, and stock changes that an adult member deliberately enters after a separate notice.
How it is used
The data is used to authenticate you, isolate each household, synchronise household work, produce requested notifications, extract uploaded bills, and draft recipes you request. Chorus does not sell household data, run behavioural advertising, or use uploaded bills as identity documents.
AI processing
When an admin chooses to scan a bill, the selected stored image is sent to OpenAI to extract visible merchant, total, tax, reference, and line-item details. When a member asks for a recipe, the relevant meal, serving, ingredient, inventory, confirmed food expiry, category, and active household dietary-profile context is sent to OpenAI. AI results can be wrong and must be reviewed; dietary handling is not a medical or allergen-safety guarantee. Medicine records are not sent to Luna or any AI prompt. Provider-side model-training storage is disabled by the application configuration.
Storage and service providers
Structured household data and uploaded originals are stored on persistent Railway storage, with access restricted by household and member. Google supplies sign-in. Railway hosts this application; OpenAI provides requested AI processing. When you choose barcode lookup, only the entered EAN or UPC number is sent to Open Food Facts; you review its returned product data before anything is saved. These providers process data only as needed to deliver their services and under their own applicable terms.
Retention and deletion
Household data remains until an authorised user removes individual records or a household super admin permanently deletes the household. Household deletion removes structured records, sessions, consent records, bill metadata, and tenant-prefixed originals. Short-lived security and infrastructure logs may remain for the period required to protect the service or meet legal obligations.
Medicine privacy
Private medicine records are visible only to the member to whom they are assigned; household admins cannot read them. Shared cabinet records are visible to non-guest household members. Medicine data is never placed in the offline snapshot, service-worker cache, external calendar feeds, general household export, or activity descriptions. Each member has a separate personal medicine export and can revoke access, which deletes their private medicine records.
Your controls
Household admins can download a complete archive containing non-medical structured household data and available original bills. Members can edit inventory dates and rules, dietary-profile entries they control, and revoke calendar feeds they created. The Medicines workspace provides a separate member-scoped export. A household super admin can permanently delete the household from More → App & data. Members can ask their household super admin to correct or remove membership details. These self-service controls are the primary route for access, portability, correction, and erasure requests.
Children and changes
Chorus private beta accounts are for people aged 18 or older. The version and effective date above change whenever this notice changes materially; Chorus will ask members to acknowledge the new version before continuing.