Privacy Policy
1. Who we are
Vatriq ("Vatriq", "we", "us") is a family-coordination mobile app. A household ("family space") uses it to share schedules, meals, groceries, tasks, finances, wellness notes, and a family bulletin.
- Data controller: Optimum Software Development SRL, a company registered in Romania.
- Privacy contact:
privacy@vatriq.com - Lead supervisory authority: Autoritatea Națională de Supraveghere a Prelucrării Datelor cu Caracter Personal (ANSPDCP), Romania's data protection authority — www.dataprotection.ro.
- Data Protection Officer: not appointed. A formal DPO is assessed as not mandatory at launch scale (Art. 37); the named privacy contact above handles requests.
- EU representative (Art. 27): not required — the controller is established in the EU.
We do not show ads, do not sell your data, and do not share your data with third parties for their own marketing. Vatriq is funded by subscriptions only.
2. The data we process, and why
We only collect data needed to run features your household actually uses. There is no speculative collection, no advertising identifiers, and no device location/GPS (the only "location" is a free-text away-status you type yourself).
Lawful-basis legend (GDPR Art. 6 / Art. 9): 6(1)(b) = performance of our contract with you · 6(1)(f) = legitimate interests · 6(1)(c) = legal obligation · 9(2)(a) = your explicit consent (special-category data).
| What | Examples | Why | Lawful basis |
|---|---|---|---|
| Account identity | Email (your username), password hash, refresh token | Create and secure your account | 6(1)(b) |
| Member profile | Display name, optional phone, optional date of birth (age-gating), optional gender, language, avatar, role, colour/theme | Show family members; age-appropriate defaults | 6(1)(b); DOB also 6(1)(c)/(f) for child-protection |
| Phone number | Number + verification status | SMS one-time-code verification only (not marketing) | 6(1)(b) |
| Invitations | Invitee email, join-request name/email | Invite people to your family space | 6(1)(b) (pre-contract) / 6(1)(f) |
| Schedules & away status | Event title/description, free-text location, times, reminders, away dates/reason | Shared family calendar | 6(1)(b) |
| Meals, recipes, diet, allergens | Meal plans, ratings, diet preferences, allergens + severity | Meal planning and allergen warnings | 6(1)(b); allergens also 9(2)(a) (see §3) |
| Groceries & tasks | Grocery items, chores, points, optional photos | Shared lists and chores | 6(1)(b) |
| Household finance | Expenses, budgets, savings goals, shared costs, children's allowances, wishlists, financial plans, receipt images | Household bookkeeping (no bank linking, no card numbers) | 6(1)(b) |
| Wellness & cycle data | Mood + notes; menstrual/cycle dates, flow, symptoms; cycle settings | Optional mood & cycle tracking | 9(2)(a) explicit consent (see §3) + 6(1)(b) |
| Bulletin & notifications | Family messages, reactions, in-app/push notifications | Family message board and reminders | 6(1)(b) |
| Photos | Avatars, receipts, chore/meal/bulletin images | Feature content you upload | 6(1)(b) |
| Billing & entitlements | Store subscription identity keys, product/tier, trial ledger | Manage your subscription and prevent trial abuse | 6(1)(b); trial ledger 6(1)(f) |
| Security & diagnostics | Audit log (incl. IP address, user-agent), activity feed, PII-scrubbed error events | Security, accountability, keeping the app working | 6(1)(f) |
| AI suggestion metadata | Suggestion type, provider, token estimate, accept/feedback flag — no prompt/response text is stored | Improve and cost-monitor AI features | 6(1)(b) + 6(1)(f) |
3. Special-category (health) data — cycle, mood, and allergens
Menstrual/cycle data, mood entries, and allergen data are special-category data under GDPR Art. 9. We process them only with your explicit consent (Art. 9(2)(a)):
- Cycle and mood tracking are off by default and opt-in. Until you consent, the feature is inert (the app returns nothing for it).
- Your consent is recorded (policy version, timestamp) and is revocable at any time. On withdrawal, the relevant endpoints stop returning data and you are offered deletion of that data.
- Discreet by default: cycle data is visible only to you unless you explicitly choose to share a low-detail "low energy" status with your family. Lock-screen notifications use generic wording and never reveal health content. An optional biometric lock protects private data.
- Children under 13: cycle tracking is off and not visible to parents.
- Allergen safety carve-out: to protect life-threatening allergies, an in-family allergen warning always fires when a conflict is detected, but a non-consenting member's identity is hidden in that warning so their health status is not disclosed.
4. AI features and how we protect you
Some features (meal/task/schedule suggestions, grocery parsing, magic import, onboarding starter pack) use cloud AI models to generate suggestions.
- Names are removed before anything leaves our servers. Prompts are passed through a structural scrubbing boundary that strips member and child names (and addresses) — by design, a raw, unscrubbed string cannot reach a cloud AI provider.
- Health/cycle data never enters an AI prompt without your active consent (§3).
- We use Groq (primary) and Anthropic (fallback) for inference (see §7). We do not retain the prompt or response text (only anonymous usage metadata), and we do not permit these providers to use your data to train their models.
5. Children's data
Vatriq is an adults'/families' app; account holders are 16+/18+ (see the Terms). Children are profiles, not users:
- A child profile can be created only by an adult account holder in their own family space, who affirms parental authority when creating it (recorded).
- Child profiles have no email, no password, and no login — a child never signs in.
- Parental consent is therefore inherent: the parent enters and controls the child's data.
- High-privacy defaults: no AI suggestions are generated from a child's data unless a parent enables it; no behavioural profiling of children exists; child data is excluded from analytics by default; cycle tracking is off and parent-invisible for under-13 profiles; no geolocation is ever collected.
- COPPA (US): the parent-created-profile model keeps Vatriq within COPPA's parental-consent framework without a third-party age-verification vendor. No ads, no child profiling, no sale of child data.
6. Who your data is shared with
We share personal data only with the service providers (processors) that operate the app on our behalf, listed in §7. We do not sell data and do not share it for third-party marketing. Apple and Google act as independent controllers for your store purchase transactions (not our processors).
7. Subprocessors and international transfers
- Primary storage stays in the EU: Fly.io (Frankfurt) hosts the API and PostgreSQL; Upstash (EU) provides the cache; Tigris stores photos/receipts, pinned to an EU region.
- Some processors are US-based: Groq and Anthropic (AI inference — scrubbed prompts only), Twilio (SMS codes), Resend (transactional email), RevenueCat (subscription management), Sentry (PII-scrubbed error tracking), and Google/Apple (push delivery). PostHog (EU) is planned for post-launch, PII-free analytics only.
- Transfer safeguards: transfers outside the EU/EEA rely on each provider's Standard Contractual Clauses and/or EU-US Data Privacy Framework certification.
We publish subprocessor changes with a reasonable notice period.
8. How long we keep data
Most data is kept for the life of your account or family space and deleted when you delete it (§9). A small number of records are kept for a limited time for security and abuse-prevention purposes even after related data is deleted — for example phone-verification records, invite tokens, notifications, audit logs, away statuses, error-tracking events, post-erasure consent-proof records, and a minimal trial-abuse ledger (kept only to prevent repeated free-trial abuse). We do not retain AI prompt/response text.
9. Your rights
Under GDPR (and equivalent laws) you can:
- Access / export your data — in-app export provides a portable copy (Art. 15/20).
- Delete your account and data — in-app deletion (Art. 17) cascades to your family data where you are the sole owner, member profiles, health and financial records, uploaded files, cached AI suggestions, and tokens.
- Rectify data — everything is editable in the app (Art. 16).
- Restrict / object to processing, and withdraw consent for health features at any time (§3). To exercise restriction/objection, contact
privacy@vatriq.com. - Complain to your supervisory authority (§1).
Backups: deleted data may persist briefly in encrypted backups before older backups are rotated out.
10. Security
TLS 1.2+ in transit (with mobile certificate pinning); an encrypted on-device cache (AES-256); JWT access tokens with refresh-token rotation; strict per-family data isolation; secrets held outside the codebase; non-root containers; audit logging; PII-scrubbed error tracking; and a breach-response runbook (Art. 33/34; health/child-data breaches are treated as high-risk and trigger user notification). Data at rest is encrypted using our infrastructure providers' standard encryption.
11. Cookies & tracking
The mobile app uses no advertising SDKs, no cross-app/cross-company tracking, and no ad identifiers. No App Tracking Transparency prompt is required. Any future analytics (PostHog) will be first-party, PII-free, and re-disclosed here before it ships.
12. Changes to this policy
We will update this policy as the app evolves and post the new effective date. Material changes affecting how we use your data will be notified in-app or by email.
13. Contact
Privacy questions and rights requests: privacy@vatriq.com. Optimum Software Development SRL is registered in Romania; a full registered postal address is available on request.