Privacy Policy

Last updated: September 19, 2026

The operator is a sole proprietor doing business as Domi Ops (no limited liability company).

Who is responsible

Domi Ops Cloud (domi-ops.com, app.domi-ops.com, demo.domi-ops.com): the sole proprietor doing business as Domi Ops is the data controller for accounts and household data stored on hosted infrastructure.

Self-hosted instances: the person or household who operates that server is the controller. Domi Ops (the project) does not operate a central database for self-hosted deployments and does not see that data.

Information stored

  • Account identifiers (email, username, display name, profile photo)
  • Household content you create (calendar events, shopping and chores, notes, expenses, school work, Drive files, optional health records)
  • Session and authentication cookies (HTTP-only on the app domain)
  • Optional Web Push subscription endpoints if you enable notifications

Data protection mechanisms for sensitive data

Security procedures are in place to protect the confidentiality of your data. We use encryption to protect your information when it is stored or sent over the network.

  • In transit: Domi Ops Cloud serves the app and API over HTTPS (TLS). Browsers and our servers negotiate encrypted connections for sign-in, household data, and Google OAuth flows.
  • At rest (OAuth): Google OAuth access and refresh tokens stored on your instance are encrypted at rest using the instance ENCRYPTION_KEY before they are written to the database.
  • At rest (health): When the health module is enabled, sensitive health fields (for example titles, notes, medication names, dosage, instructions, and comparable vitals or log values) are encrypted at rest with the same ENCRYPTION_KEY. Dates, member assignment, and schedule times stay queryable without storing those values in plaintext.
  • Access controls: Household members see only content their role and per-module permissions allow. Private notes, Drive objects, and health records are further limited by per-record visibility and segment ACLs — there is no operator back door to read private health data on Cloud.
  • We do not sell your data to advertisers, data brokers, or other third parties.
  • Revoking Google access: Disconnect Google Calendar or Docs in household settings, or remove Domi Ops from your Google Account under Third-party access. That stops Domi Ops from accessing Google on your behalf.

Self-hosted: the person who operates the server is responsible for HTTPS, backups, and protecting ENCRYPTION_KEY — the same encryption behavior applies when the key is configured.

Google account data

If you choose Google sign-in or connect Google services, Domi Ops accesses only the Google user data needed for the features you enable:

  • Sign-in — basic profile (name, email, profile photo) via OpenID Connect scopes used for authentication.
  • Calendar — when you connect Calendar sync, calendars and events you select so Domi Ops can display and sync household events.
  • Drive — when you enable Docs or Drive features, only files you create or open through Domi Ops (Google drive.file scope and the Google Picker), not your entire Drive.

We use this Google user data only to provide those features — for example signing you in, showing synced events, or exporting reports you request. We do not use it for advertising, and we do not use it to train general-purpose artificial intelligence or machine learning models.

We do not sell or transfer Google user data to third parties except service providers that help us run Domi Ops Cloud (for example hosting and email), and only as needed to operate the service. Our use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

Processors (when enabled)

  • Google — optional sign-in, Calendar sync, and Drive drive.file (Docs/Picker). See Google's Privacy Policy. OAuth tokens are encrypted at rest on the instance.
  • Object storage — S3-compatible storage (MinIO or a cloud bucket) for uploads.
  • Email — SMTP you or the hosted operator configure (verification and transactional mail).
  • Weather — Open-Meteo using coordinates you provide; no weather account is required.
  • Web Push — browser vendors deliver notifications; subscription keys stay on the instance.
  • Stripe — billing, trials, and invoices when hosted checkout is live. Card details are handled by Stripe, not stored in Domi Ops.

Health module

Optional. Sensitive fields (titles, notes, medication names, dosage, instructions) are encrypted at rest with the instance ENCRYPTION_KEY. Dates, member assignment, and schedule times remain queryable. Access follows per-record visibility and segment ACL — there is no admin override of private health data. Domi Ops is not a healthcare provider and is not HIPAA-compliant.

School module

Homeschool and family coursework only. Domi Ops is not a school of record, not an accredited institution, and does not issue official transcripts to third parties.

Children and household accounts

Households may provision child or student accounts (including username-only members). A parent or guardian who owns or administers the household is responsible for those accounts and for deciding what data is stored.

Sharing inside a household

Members see household-visible content per module permissions. Private notes, Drive objects, and health records are limited to owners and people you explicitly share with (or grant ACL access).

Optional anonymized metrics

Off by default on every household, self-hosted or Cloud. An owner or admin can turn it on in Settings → Privacy. When on, we collect:

  • Technical health — page load speed, JavaScript errors, API response times
  • Feature usage — which modules and actions get used (e.g. "a chore was completed"), never the content of what you created

These events carry a randomly generated id stored in your browser — not your account, household, name, or email — and nothing in our metrics storage links back to household data. Turning it off stops collection immediately; turning it on later starts a new random id, not a resumed history. We do not sell this data, or any data, to anyone, ever — it is used only to find bugs and decide what to build next.

Separately, anyone can send a bug report or feedback from their Profile page at any time, regardless of this setting — that message (and an optional reply email, if you choose to leave one) is sent because you chose to send it, not collected passively.

Retention and deletion

Cloud: email privacy@domi-ops.com to update profile data, revoke Google connections, or request account and household deletion. You may request deletion of your Cloud account and associated household data by emailing that address; we will delete or anonymize hosted records within 30 days of verifying your request, unless we must retain specific records for legal, security, or billing disputes (for example open invoices).

Self-host: the instance operator exports or deletes data by managing PostgreSQL and object storage directly.

Your choices

You can disconnect Google Calendar or Docs in household settings, revoke Domi Ops in your Google Account, disable Web Push, turn off optional modules (within what the instance enables), and turn anonymized metrics on or off. See also the Terms of Service.

Contact

Cloud privacy questions: privacy@domi-ops.com. For a self-hosted instance, contact the person who administers that server.