HullStack House Privacy Policy
Document set: core · Type: privacy
Applies to: every HullStack fleet app that adopts this house policy,
together with that app's Per-App Addendum, which
together describe the complete privacy practices for that app.
0. How this document works; who "we" are; precedence
This House Privacy Policy describes practices shared across every app in the HullStack fleet. Each app additionally publishes a Per-App Addendum covering what personal information that specific app collects, why, and who it shares it with — this document intentionally does not enumerate app-specific data categories (e.g. calendar entries, chore lists, chat messages, pantry contents) so that a change to one app's data model does not require re-drafting a document every other app also relies on.
"We," "us," and "our" mean the entity identified in the applicable app's Terms of Service §3 — the same entity that is the data controller (and, under some laws, "business") for the information described here. Today, that entity is Field's Edge Software LLC, which operates both the Hundredfold Home OIDC identity provider and every current fleet app as a single controller for shared sign-in data. If a future fleet app is operated by a different legal entity, that app's Terms and Addendum identify the controller for that app's data — see Terms §6. Capitalized terms not defined here have the meanings given in the Terms.
Where this Policy and an app's Addendum conflict, the same order-of- precedence rule stated in Terms §0 applies (the Addendum controls for app-specific data-collection matters; the House documents control for core mechanisms).
1. Scope
This Policy covers information we collect through the Service, as defined in the applicable app's Terms of Service. It does not cover third-party sites or services you may access through the Service, which have their own privacy practices.
2. Information We Collect
The categories below reflect the shared account, consent, and identity infrastructure common to every fleet app. App-specific content categories are described in that app's Addendum, not here.
- Account and identity information: e.g. email address (for a Household Adult; a Child Account is provisioned without one), household membership, and role (adult/child). For authentication, we store credential material we cannot reverse — for a Household Adult, a password verifier (not the password itself); for a Child Account, only the one-way hash and short public prefix of the child's login code (a Child Account has no password). We do not store passwords or full login codes in readable form.
- Consent and acceptance records: which version of these house documents (and any app-specific Addendum) you accepted, when, how (e.g. scrollwrap vs. clickwrap), the button label shown, and — for a Household Adult accepting on behalf of a household — which Child Accounts were covered and the accepting adult's stated relationship to them, plus corroborating context (IP address, user agent, app build, platform, locale) captured at the moment of acceptance. These records are kept as an immutable, append-only log; see §6.
- Device and technical information: e.g. IP address, user agent, app build/platform, locale — collected primarily as part of the consent and security record described above, and for basic service operation, security, and abuse prevention.
- Communications metadata: to deliver messaging and shared-content features, we process information about communications and content — such as participants, timestamps, ordering, delivery/read state, and approximate sizes — even where the content itself is end-to-end encrypted and unreadable by us. See §12.
- Content you or your household create: described per-app in that app's Addendum, not here. For apps offering end-to-end encryption, we cannot read that content (§12); we store it only as ciphertext we do not hold the keys to.
3. Children's Privacy (COPPA)
The Service supports Child Accounts. Read this section together with House Terms §4.3, which describes the same practices from the contract side.
- A Child Account is provisioned by a Household Adult, not by the child directly signing up.
- We do not knowingly collect more personal information from a child than is reasonably necessary to participate in a Service activity.
- A Household Adult may review the personal information associated with a Child Account, request its correction, or request its deletion (subject to §7's limits on deleting append-only records) by contacting us as described in §13.
- We do not condition a child's participation in an activity on the child disclosing more personal information than is reasonably necessary.
- Household key recovery. A Child Account's private encryption key is escrowed to household administrators, so a household administrator can recover and decrypt that Child Account's end-to-end-encrypted content. This is a deliberate family-safety design and is described in §12 and House Terms §10.3.
- Verifiable parental consent (VPC). Consistent with House Terms §4.3, the verifiable-parental-consent requirement for collecting a Child Account's personal information is treated as separate from acceptance of the Terms of Service, even though both currently occur through the same Household Adult action. We presently rely on the Household Adult's attestation (the relationship affirmation in Terms §4.2) as that consent; the consent architecture supports requiring a stronger, pluggable verifiable-consent method for a specific feature in the future, but no such stronger method is presently in effect.
- Processors and children's data. Each app's Addendum §C lists the third-party processors that app uses and states whether any of them can receive information from a Child Account session. Where a processor can, we require a data processing agreement that accounts for children's data.
4. How We Use Information
We use the information in §2 to: operate, provide, and maintain the Service; authenticate you and secure your account; maintain the security and integrity of the consent ledger (§6) and prevent fraud and abuse; communicate with you, including the change-of-terms notices described in §9; provide customer support; and comply with legal obligations. An app may describe an additional, app-specific purpose in its Addendum. We do not use end-to-end-encrypted content we cannot technically access (§12), we do not use the information described here to build advertising profiles, and we do not sell or share your personal information for cross-context behavioral advertising as those terms are defined under the CCPA/CPRA (see §8).
5. Legal Bases for Processing (where applicable, e.g. EEA/UK users)
The Service is presently US-first. We do not target or offer the Service to users in the EEA/UK, and this Policy therefore does not set out a GDPR/UK GDPR legal-bases-per-purpose analysis. If the Service expands to EEA/UK users, we will update this section — and §8 and §10 — before doing so.
6. The Consent and Acceptance Record
Unlike most of the information described in §2, your acceptance of these documents is kept in a dedicated, append-only, immutable ledger: once you accept a specific version of a document, that acceptance record is never edited or deleted in the ordinary course — corrections, where needed, are made by adding a new record, not by altering the old one. We do this because the acceptance record is itself the evidence that you agreed to a specific, exact, content-hashed version of these documents at a specific time; silently editing history would defeat that purpose.
We retain a limited ability to purge or restrict records where required by law (for example, to honor a valid erasure or legal-hold obligation). Any such purge is a privileged, explicitly-invoked operation, distinct from ordinary application behavior, and does not change how the ledger behaves in normal use.
7. Data Retention
We retain personal information for as long as needed for the purposes described in this Policy, and then delete or de-identify it, except where a longer retention period is required or permitted by law. Specifically:
- Account data — retained while your account is active, and deleted or de-identified within 30 days of account deletion or termination (Terms §14), except for records covered below.
- Device and technical information — retained for up to 12 months, and then deleted or aggregated into non-identifying form.
- Support communications — retained for up to 24 months after the matter is closed.
- Content you or your household create — retained until you or your household delete it, or until account deletion, whichever is first; deleted content may persist briefly in backups.
- The consent and acceptance ledger (§6) — retained indefinitely as a legal record by design.
8. Your Rights
Depending on where you live, you may have rights over your personal information. A Household Adult may exercise applicable rights on behalf of a Child Account, consistent with §3.
- California (CCPA/CPRA). You have the right to know what personal information we collect and how we use it, to request its deletion, to request its correction, and to opt out of the "sale" or "sharing" of personal information. As stated in §4, we do not sell or share personal information as those terms are defined under the CCPA/CPRA, so there is no opt-out to exercise. We will not discriminate against you for exercising any of these rights. To submit a request, contact us as described in §13; we will verify your request through your account (for example, by confirming control of the email address or household account the request concerns) before acting on it.
- Other US state privacy laws. Where another US state privacy law applies to you, you have the equivalent rights that law provides — typically access, correction, deletion, portability, and an appeal of a denied request — and you may exercise them the same way.
To exercise a right, contact us as described in §13. Note that some records (e.g. the append-only consent ledger, §6) are subject to the legal-retention limits described in §6 and §7.
9. Changes to This Policy
We may revise this Policy from time to time. This Policy uses the same change process, and the same material vs. non-material distinction and re-acceptance mechanism, described in House Terms of Service §20 and §21 (no retroactive application) — we do not duplicate that mechanism's description here to avoid the two documents drifting apart; if you are reviewing one, review both.
10. International Data Transfers
Not presently applicable. The Service is US-first and presently operates single-region infrastructure serving US users; there is no international transfer mechanism to disclose. If that changes, we will state the applicable transfer mechanism here before it does.
11. Security
We use technical and organizational measures designed to protect personal information — including encryption of data in transit, encryption of credential material such that we cannot reverse it (§2), access controls on the systems that hold personal information, and, for apps offering end-to-end encryption, encryption of certain content such that we cannot read it (§12). No method of transmission or storage is perfectly secure; we cannot guarantee absolute security.
12. End-to-End Encryption and Household Key Recovery
For any app or feature offering end-to-end encryption (E2EE), we want to be precise, because "end-to-end encrypted" is easy to over-read:
- What we cannot see. The content of E2EE communications and items is encrypted on your device and readable only by the intended recipients' devices. We store it only as ciphertext and cannot read, search, scan, or hand over its plaintext — we do not hold the content-encryption keys.
- What we do process (metadata). E2EE protects content, not metadata. We necessarily process data about your communications and content — the existence of a message/item, participants, timestamps, ordering, approximate sizes, delivery/read state, and the device/technical information in §2 — to operate the Service. E2EE does not hide this from us.
- Household key recovery for Child Accounts. As a deliberate family-safety design, a Child Account's private key is escrowed (in encrypted form) to every household administrator. A household administrator can therefore recover a Child Account's key and decrypt that Child Account's E2EE content. We store these escrow envelopes but they are encrypted so that only a household administrator — not we — can open them. See House Terms §10.3 for the full description, including how issuing/reissuing a child's login code re-wraps and re-escrows the key.
- Adults are not escrowed. Only Child Account keys are escrowed. A Household Adult's private key is not escrowed to anyone, and there is no comparable recovery path for adult-to-adult E2EE content — by us or by another household member.
- Consequence. Because we cannot decrypt E2EE content, if all key-holders lose access to their keys (and no household administrator can recover a Child Account's escrowed key), that content may be permanently unrecoverable, including by us.
13. Contact
Field's Edge Software LLC — the controller identified in Terms §3. Public contact page: https://hundredfoldhome.com/support. You can also reach us through the support and contact details published in the Service (in-app, under Settings). Use that address for privacy questions and for the data-subject requests described in §3 and §8. A street mailing address will be published on the public support page when it is available.