Privacy Policy
Zeno Home and Zeno Kitchen are published by Zeno One LLC. Last updated: 2026-09-07.
Who this applies to
Zeno Home is a household management tool; Zeno Kitchen is its meal, recipe, and grocery companion and can also be used as a standalone app. This policy explains what both account-backed apps collect, how data is stored, and what control you have over it.
What data we collect
- Household setup and planning data: member names (first name, nickname, or initials), roles, emoji, color choices, optional birthday month and day (without a birth year), optional bedtime, home and place names, optional addresses you type, activities, schedules, transportation assignments, responsibilities, private My Day blocks, screen-time agreements, reminders, the setup path you picked, and feature toggles.
- Household activity and user content: tasks and steps, adult tasks, notes and praise, calendar items, task completions, approvals, points earned or spent, rewards and reward proposals, redemptions, meal ratings, and Home Check-in answers and history.
- Kitchen and food-profile data: grocery items and quantities, store names and shopping order, staples, meals, recipes and ingredients, ratings, food preferences, and optional diets, allergies, or ingredients to avoid. These preferences help organize and filter meal suggestions; Zeno does not diagnose or treat a health condition.
- Photo proof (optional): camera images a member attaches to a task when an authorized adult chooses to use that workflow. Stored in Firebase Storage for your household.
- Recovery, invite, or feedback contact details: if an adult protects a household with email recovery, requests an invite, or sends feedback, we use that email only for the requested account/reply workflow.
- Zeno account identity: an adult owner or standalone Kitchen shopper signs in with secure email, Google, or Apple. Firebase Authentication stores the internal account identifier plus the email, display name, and linked methods returned by the chosen provider. An Apple private-relay address is treated as an ordinary account email. For native Sign in with Apple, a one-time authorization code is exchanged on Zeno's server and the resulting refresh token is kept only so Apple authorization can be revoked during account deletion; neither value is stored in household data.
- Subscription information: RevenueCat and its payment processor or the app store process purchase and renewal events. Zeno stores the product, entitlement, status, and relevant period timestamps needed to grant or end access. Zeno does not receive a payment-card number.
- Device and usage data: registered notification tokens and security identifiers, plus basic counters such as setup completion, task completion, approvals, and metered-feature use so we can operate the service, enforce limits, and fix problems.
- Error reports: when an app error occurs, Zeno automatically records a bounded, scrubbed technical report in the household's private data. It can include browser type, app build, message, stack and context, and up to 10 recent action breadcrumbs. The household buffer keeps only the 50 most recent family error reports; household-code, email, and invite-code patterns are redacted before storage. External diagnostics contain only the error class, app release, screen category and code locations described under Sentry below.
What we do NOT collect
- We do not collect real names beyond what you type in (we recommend first names, nicknames, or initials).
- We do not collect a birth year or full date of birth, phone number, or device geolocation. A household may optionally type a home, activity, pickup, or drop-off address into its private plan; Zeno does not require one or infer one from the device.
- We never receive your Google or Apple password. Google account sign-in requests identity scopes only; optional Google Calendar access is a separate connection described below.
- We do not sell household data or share it for advertising. We use service providers listed below to run the app.
- We do not use your data for advertising, targeting, or training any model.
Where data lives
Service providers used to run Zeno Home and Zeno Kitchen:
- Firebase / Google Cloud: shared Zeno account authentication, Zeno Home authentication, Firestore sync, and optional Storage photos.
- Apple: optional Sign in with Apple identity and authorization revocation.
- Netlify: web hosting, serverless functions, feedback logs, and invite request handling.
- Resend: account, invite, and feedback email delivery when enabled. A report includes the note, app/screen/build context, and screenshot you explicitly choose to send after preview. Screenshot reports are delivered as private email attachments, not uploaded to a public image store or saved to household records. Support mailbox copies remain until the support issue and any applicable retention obligations are resolved; contact us to request deletion.
- Sentry: error class, app release, screen category and code locations to investigate failures. This integration excludes error messages, household identifiers, names, form content, request bodies and screenshots.
- PostHog: optional usage counts for app opens, screen categories, save failures and successful reports. Enable or disable this on your device in Settings - Safety & data. A random identifier lasts for the current page session only; no person profile, household identifiers, text, screen recording or advertising data is sent. Do Not Track is respected.
- RevenueCat, its payment processor, and the app stores: subscription purchase, restore, renewal, and entitlement processing.
- Anthropic: only after a paid plan's first charge and only when an optional AI action is used, Zeno sends the minimum input for that request: a task or chore title and age band for a checklist; recipe page text, pasted text, or recipe photos for ingredient extraction; recent meal titles for meal ideas; or bounded task, approval, schedule, and Home Check-in metrics for a household summary. Free and trial access make no generative model calls. These requests exclude passwords, authentication tokens, household codes, and account or member identifiers. Recipe text and photos can contain information the adult chose to submit.
- Kroger: optional product search and cart handoff after an adult connects a Kroger-family account.
Your controls
- Export: Settings - Your data downloads a JSON copy of your household.
- Delete in-app: Settings - Your data - "Delete household data" permanently removes the household record, proof photos, recovery pointer, and device data, no email required.
- Delete a linked Zeno account: the separate in-app account option confirms a recent sign-in, revokes Apple authorization when linked, removes the exact Zeno billing customer record, then deletes the Zeno Home and shared Zeno account identities. For the household owner, this also deletes the household. For a protected non-owner adult or guardian, it removes that person's household membership and associated profile, grant, recovery, and private integration records while leaving the household in place. Because the shared account can be used by other Zeno apps, deleting it signs that identity out across those apps. It does not delete your Google Account or Apple Account. Removing the billing customer immediately cancels any Plus subscription purchased through Zeno's website. It does not turn off App Store or Google Play auto-renewal. Manage subscription opens the RevenueCat customer portal for a web purchase or the app store for a mobile purchase; cancel a mobile-store subscription there before deletion if you do not want another charge.
- Delete by email: you can also follow our public data-deletion instructions to request deletion when you cannot access the app.
- Use nicknames: member names are whatever the household owner chooses to type.
Optional connections
- Zeno account sign-in: secure email, Google, and Apple are alternative ways to authenticate the same shared Zeno account. Provider tokens are used only to complete or confirm that account operation. Google sign-in does not grant Calendar, Drive, or Gmail access. A native Apple refresh token is held server-side only for required deletion-time revocation; after confirmed revocation it is replaced by bounded one-way receipt proofs.
- Google Calendar: when an adult connects Google Calendar, Zeno uses the Google account email to label the connection, reads the account's calendar list so the adult can choose calendars, and reads events only from the calendars they select. Those selected events are displayed to the household. Zeno can create a dedicated "Zeno Home" calendar and write, update, or delete only the Zeno events on that app-created calendar; it does not change events on the account's other calendars. A server-side refresh token keeps the connection working without another sign-in and is never sent to household devices. Disconnecting Google Calendar deletes the stored link and refresh token and stops this access; it does not delete calendars or events from Google.
- Google Account permission: Google grants access to the Zeno Home Google project, not to just one household screen. Removing Zeno Home from your Google Account's third-party connections may also stop other Zeno Home calendar links that use the same Google Account. If you only want to remove one household's link, disconnect that household inside Zeno first.
- Apple Calendar on iPhone or iPad: if you grant calendar access, Zeno reads and displays events only from the device calendars you choose. EventKit event data and Zeno's calendar cache stay on that device and are not uploaded to Zeno's servers. You can change or revoke this permission in iOS Settings.
- Public calendar feeds (ICS): separately, if you paste a public or subscription calendar address from iCloud, Google, Outlook, or another provider into Settings, Zeno's server fetches that feed to display its events to your household. The address is stored with your household data and used only for that feed. This is separate from native Apple Calendar access on an iPhone or iPad.
- Kroger-family account: if an adult explicitly connects this optional retailer account, Zeno stores that adult's server-side refresh token in a private Firestore record that household devices cannot read. When the adult chooses to fill a Kroger-family cart, Zeno sends the selected grocery item names and quantities to Kroger's product-search and cart APIs. Kroger returns product matches and fills its cart; store choice and checkout remain at Kroger.
- Lampway: if you link a Lampway family code, the app reads reading-streak data from your Lampway account to display it. This is read-only and can be disconnected at any time in Settings.
Children and COPPA
Households do not need to include children. When a household does include a child, Zeno Home is set up and controlled by an adult parent or legal guardian. Children use only the household experience that adult provides; they do not create direct accounts or provide an email address. The adult controls the household, its member data, and deletion. If you are under 13 and using this app without a parent or guardian's permission, please stop using it and ask that adult for help.
Retention
Daily task completions accumulate over time for streaks, rewards, and Home Check-in. Optional proof photos remain until removed by product cleanup or deletion request. Zeno account identity remains while that account is active. Confirmed deletion removes household content from active systems; cloud-provider backups may retain deleted data for a limited period as part of standard disaster recovery. To prevent reuse of a deleted household code and block late writes, Zeno permanently retains a minimal deleted-household tombstone containing the random deletion capability, a one-way owner proof, and cleanup timestamps, but no household content, name, or member identifiers. During a protected non-owner adult or guardian's account deletion, a server-only pending cleanup record temporarily holds the household code, member identifier, and up to 20 bound authentication identifiers solely to find and delete that person's device-token records. Scheduled cleanup retries until no matching device records remain; account deletion stays blocked, and the raw cleanup fields have no fixed expiry while cleanup is incomplete. They are removed as soon as cleanup is confirmed. A confirmed Apple revocation removes its stored token immediately. An in-progress, server-only Apple revocation credential is retained for no more than 24 hours while scheduled recovery retries; if Apple confirmation remains unavailable, the credential is removed without authorizing account deletion. The separate one-way Apple and account-operation receipt proofs used for response-loss recovery expire within 30 days.
Contact
Questions, concerns, or data requests: reach out through the feedback link in the app, or email msiljander@zenoone.com. The controller of record for this service is Zeno One LLC.
Delete your data · Back to Zeno