Data We Collect
Account and identity data: name, email address, phone number where supplied in the mobile registration flow, password hash, account id, verification status, verification tokens, accepted terms/GDPR timestamps, profile picture URL, home name, membership/status labels and account role.
Login and security data: access tokens, session state, remember-me cookies, login history, password reset or change events, email verification events, API request metadata, IP address where logged for security or notify forms, device and browser details where supplied in support or IT workflows.
Household and preference data: home name, location label, weather location, latitude and longitude when device location is enabled, temperature/currency/measurement units, week-start preference, calendar visibility, theme, appearance mode, app icon, accessibility settings, onboarding progress, dashboard widgets and notification channel preferences.
Planning and daily-life data: calendar events, shifts, roles, locations, rates and overtime rates, tasks, reminders, notes, shopping lists, meal plans, ingredients, recipe links, vehicles, registration numbers, MOT/tax/insurance dates and household utility meter readings or reminders.
Butler assistant data: Butler briefings, messages, prompts, replies, action history, completed actions, speech/audio requests, transcriptions and cached speech output. Butler may use your account, home, calendar, task, shopping, meal, weather, news, smart-home, vehicle and health context to answer requests and carry out supported actions.
Health data: if enabled, daily health summaries from Apple Health or Health Connect, including date, steps, distance, active energy, sleep minutes, workouts, exercise minutes, stand hours, heart-rate summary, source provider and update time. We treat health data as sensitive and use it only for app features you enable.
Notification and device data: installation id, push token, push provider, device name, platform, app version, enabled status, notification outbox events, delivery status and notification categories such as shifts, calendar events, tasks, shopping, meals, meter readings and Butler briefings.
Smart-home, security and integration data: rooms, devices, scenes, device names, device types, provider ids, supplier device ids, local discovery data, capabilities, online/offline state, last-seen time, power/brightness/temperature/lock state, favourite state, camera locations, doorbell status, motion timestamps, privacy-mode status and whether recording remains active. Optional provider tokens may be stored encrypted server-side for connected suppliers such as Tuya/Smart Life, Home Assistant, Ring, Imou, Google Home or music providers.
Support, operations and admin data: customer portal requests, support messages, email replies, data export/deletion requests, subscription/order/download/security records, internal notifications, audit logs and operational metrics. Admin and employee tools may process work email, job title, department, manager, employment status, leave, payroll-change, document, training, IT ticket, device, audit and Google Workspace data for authorised staff workflows.
Hiring data: candidate name, email, application details, right-to-work confirmation, consent records, documents selected or signed, vacancy stage history, interview or offer actions, manager notes, provisioning plans and onboarding details where a candidate progresses through Concierge Hire.
Payments and finance data: plan, subscription, order, refund and payment status data. Payment card processing is handled by payment providers such as Stripe; we should not store full card numbers. Internal finance tools may process business banking or transaction data where a business account is connected.
Website and marketing data: notify-list email addresses, form submissions, social-post planning data, campaign records and basic analytics or communication preferences where enabled.