Privacy Policy

Last updated: 2026-09-20

co-life is a household organizer for events, expenses, notes, and the everyday logistics of your household's members — kids and pets included. This policy explains, in plain language, what data the app stores and why. The short version: your household's data is yours, it's stored in the EU, we run no advertising and sell nothing to anyone.

On this page

Who we are

The data controller for co-life is RMATAKOV, vl. Robert Mataković (OIB 16585545644), Borongaj aerodrom 5, 10000 Zagreb, Croatia. For anything related to your data, write to privacy@co-life.online.

What data we store

We store only what you (or a member of your household) enter into the app:

  • Account and profile — your name, email address, password (stored as a hash by our authentication provider), interface language, theme, notification preferences, and, if you enable two-factor authentication, your enrolled factors.
  • Household — household name, timezone, and optionally an address.
  • Events — titles, dates, times, locations, notes, categories, and who they're assigned to.
  • Expenses — amounts, dates, categories, who paid, and optional notes; budgets and recurring templates.
  • Notes — their content, tags, checklists, due dates, and assignees.
  • Members (kids and pets) — names, colors, birthdates, and, for kids only, optionally an OIB (see the next section). Members do not have accounts. You can also add your own free-text detail rows to a member's card (for example allergies, a vet's name, or a school) — these are entirely optional and may contain health information if you choose to record it.
  • Google Calendar sync — only if you connect it: your Google account identifier, calendar tokens, and the synced events.
  • Push notifications — only if you enable them: a per-device subscription token.
  • Receipt scanning — if you photograph a receipt, the image is sent for one-time text extraction and immediately discarded; we never store the photo.

Children's data and OIB

Members in co-life — kids and pets — are entries created and controlled by a parent; they cannot register or sign in themselves. Pets are not people, so nothing here about a pet's entry is personal data about anyone. Everything about a child is entered voluntarily by you, and the OIB (Croatian personal identification number) is entirely optional and never collected for pets. We treat OIBs with national-ID-level care: they are never written to logs, never included in search, and excluded from data exports by default. Any free-text detail row you add to a member's card is also entirely optional, is never included in search, and may contain health information (for example an allergy or a doctor's or vet's name) only if you choose to record it there. You can remove a child's OIB, edit or delete any detail row, or remove the whole member entry, at any time in Settings.

Why we process your data

  • To provide the service (contract) — everything in "What data we store" exists solely so your household can use the app.
  • To improve the product (legitimate interest) — we record a small number of usage events (for example "an event was created"). These events are not linked to your account: they carry no names, titles, amounts, or identifiers — only counts and true/false flags — and are processed on our servers without any tracking cookies. You can turn this off at any time in Settings → Profile.
  • With your consent — optional integrations you explicitly connect, such as Google Calendar sync and push notifications. Disconnecting them stops the processing.

Who processes data for us

We use a small number of service providers (processors) to run co-life:

  • Supabase — database and authentication; all data is stored in the EU (Ireland).
  • Vercel — application hosting and serving.
  • Cloudflare — domain/DNS and the sign-in captcha (Turnstile).
  • Resend — sends transactional email (confirmation links, invitations, reminders).
  • Google — only if you connect Google sign-in or Calendar sync; receives/returns your calendar events.
  • Anthropic — only when you use receipt scanning; receives the receipt photo for one-time text extraction. Not used for AI training.
  • PostHog (EU) — product analytics as described above; hosted in the EU.
  • Sentry (EU) — error monitoring; hosted in the EU (Germany). Receives technical error reports from the live app only: the error message, the stack trace, and the address of the page where it happened. We deliberately do not attach your identity to these reports, and we collect no performance traces and no session recordings. OIB numbers are stripped automatically before a report leaves our servers, and calendar-feed tokens are removed from any address it records. Sentry also receives browser security (Content-Security-Policy) violation reports.

We do not sell data, run no advertising, and share data with no one beyond this list.

Each member's card can hold a link to wherever that member's documents are kept — a folder in your own cloud storage, for example. co-life stores only the link you typed. It never receives, stores, or transmits the documents themselves, and it does not open the link on your behalf: following it happens in your browser, under your own account with whichever service hosts it.

Links are included in your data export, and are deleted when you delete the member or your household. Removing a link in co-life deletes nothing at the destination — those files remain yours and are governed by your agreement with whoever stores them.

International transfers

Your household's data is stored in the EU. A few of our providers are based in, or process limited data in, the United States: Anthropic receives only the receipt photo you choose to scan, and Vercel, Resend, and Cloudflare are US-headquartered companies. Sentry stores our error reports in the EU but is likewise a US-headquartered company. Where personal data leaves the European Economic Area, it is protected by the safeguards the GDPR requires — Standard Contractual Clauses and/or the EU–US Data Privacy Framework.

How we protect your data

We apply technical and organizational measures appropriate to the sensitivity of the data we hold:

  • Encryption in transit and at rest. All traffic between you and co-life travels over HTTPS/TLS, and your data is encrypted at rest in our EU database.
  • Strict household isolation. Every record is scoped to your household and enforced by database-level row security, so one household can never read another's data. Access to production systems is limited to the data controller named above.
  • Extra care for sensitive data. The sensitive identifiers and free-text details you may record about members — a child's OIB, or any health information you choose to add — are never written to logs, never included in search, and excluded from data exports by default.
  • Account protection. Sign-in is guarded by a captcha, and you can turn on two-factor authentication (2FA) for your account at any time.
  • Passwords are never stored in readable form — our authentication provider keeps only a salted hash.

Google user data and Limited Use

co-life's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. If you connect Google Calendar, we use that data solely to provide two-way calendar sync inside your household; we do not transfer or sell it, and we never use it for advertising.

We do not use Google user data — including your Google Calendar data, whether raw or derived — to develop, train, or improve any generalized or foundational artificial-intelligence or machine-learning models. co-life's only AI-assisted feature, receipt scanning, processes exclusively the receipt photos you upload; it never receives any Google user data.

Cookies

co-life sets no advertising cookies, no analytics cookies, and nothing that can follow you to another website. Everything we store on your device is strictly necessary — it exists only to make the app do what you asked it to — which is why you are never asked to accept cookies when you arrive.

Cookies we set:

  • sb-…-auth-token — keeps you signed in. Created when you sign in, removed when you sign out or when the session expires.
  • NEXT_LOCALE — remembers whether you chose English or Croatian. Kept for one year.
  • colife-tz — your household's timezone, so dates and times show correctly. Kept for one year.
  • g-oauth-state — set only while you connect Google Calendar, it holds a single-use security token that prevents someone else's request from being passed off as yours. Kept for ten minutes, then deleted.

Stored by your browser rather than as cookies, under the same rules:

  • colife-theme — whether you chose the light or dark appearance.
  • colife.sidebar.collapsed — whether you collapsed the sidebar.

These two never leave your device and are never sent to us; they stay until you clear your browser data.

Our sign-in, registration, and password-reset forms are protected by Cloudflare Turnstile, a captcha that may store data on your device in order to tell a person from a bot. It runs only on those forms, it is a security measure on a form you chose to submit, it is never used for advertising, and it does not track you across websites.

Why there is no cookie banner: consent is required for storage that is not strictly necessary — advertising, tracking, and in-browser analytics. We use none of those, so there is nothing to ask you to accept. Our product analytics run on our own servers and never in your browser, carry no identifiers, and can be switched off in Settings → Profile (see "Why we process your data"). If we ever add anything that is not strictly necessary, we will ask for your consent first, and you will be able to refuse without losing access to the app.

You can delete cookies and stored data at any time in your browser settings. Removing the sign-in cookie signs you out; removing the others simply resets those preferences.

How long we keep your data

Your data lives as long as your household exists. Deleting your household (Settings → Household → Delete household) permanently erases all of its data — events, expenses, notes, members, profiles, and accounts — immediately.

Our current hosting plan does not include automatic database backups. We take occasional manual backups so the service can be recovered after a failure; these are encrypted before they are stored off-site. If you delete your household, a copy of its data may remain in the most recent such backup until that backup is superseded or deleted.

Your rights

Under the GDPR you can ask us, at any time, to access, correct, export, or erase your personal data, or to object to processing. Most of this you can do directly in the app: editing and deletion are self-service, and you can download a full copy of your household's data at any time via Settings → Household → Download my data. For anything else, email privacy@co-life.online. You also have the right to lodge a complaint with the Croatian data protection authority (AZOP, azop.hr) or your local supervisory authority.

Changes to this policy

If we materially change this policy, we'll announce it in the app or by email before the change takes effect, and update the date at the top. Continued use after the change means the new version applies.

Back to top