Legal
Privacy Policy
Effective Date: July 2, 2026 · Last Updated: July 2, 2026
1. Introduction
App of Things ("App of Things," "we," "us," or "our") is operated by Ricky Landino, an individual. This Privacy Policy explains how we collect, use, disclose, and protect information about you when you use our website, mobile applications, and related services (collectively, the "Service").
By creating an account or using the Service, you agree to the collection and use of information in accordance with this Privacy Policy. If you do not agree, please do not use the Service.
This policy should be read alongside our Terms of Service and Cookie Policy.
2. Who We Are (Data Controller)
The data controller for your personal information is:
Ricky Landino
Email: [LEGAL CONTACT EMAIL]
If you are located in the European Economic Area (EEA) or the United Kingdom, Ricky Landino is the data controller under the General Data Protection Regulation (GDPR) and UK GDPR.
3. Information We Collect
We collect the following categories of information:
3.1 Account Information
- Email address, required to create an account and sign in. The web application supports email and password sign-in; the mobile application uses magic link / one-time passcode (OTP) only. Passwords are hashed by our authentication provider (Supabase) and are never received or stored in plaintext by us.
3.2 Profile and Application Data
Information you actively enter into the Service, which may include:
- Names and details of household members you add to your account
- Home and property information (descriptions, rooms, addresses, purchase dates, photos)
- Vehicle information (make, model, year, VIN, mileage, service history)
- Maintenance records, service logs, and notes
- Checklist templates and completed instances
- Provider contacts (names, phone numbers, email addresses, notes)
- Reminder and notification schedules
- Spaces and shared household configurations
- Any other content you choose to enter into the Service
3.3 Usage Data
Information collected automatically when you use the Service:
- Features accessed and actions performed
- Timestamps of activity
- Error logs and diagnostic information
3.4 Technical and Device Data
Information collected automatically by our infrastructure:
- IP address
- Browser type and version (web)
- Operating system and device type
- Referring URLs
- Authentication session identifiers
3.5 Communications
If you contact us by email or other means, we retain the content of your communications and your contact information.
4. How We Use Your Information
We use the information we collect for the following purposes:
- Authentication: To verify your identity and allow you to sign in to the Service via magic link.
- Providing the Service: To operate, maintain, and deliver all features including household sharing, maintenance tracking, reminders, checklists, and provider management.
- Notifications: To send reminders and notifications you configure within the Service.
- Household Sharing: To enable you to share data with household members you have invited and who have accepted your invitation.
- Support: To respond to your questions, requests, and feedback.
- Security and Fraud Prevention: To detect, investigate, and prevent unauthorized access, abuse, and security incidents.
- Legal Compliance: To comply with applicable laws, regulations, and legal processes.
- Product Improvement: To analyze usage patterns and improve the functionality and user experience of the Service.
We do not use your information for targeted advertising. We do not sell your personal information to third parties.
5. Household Sharing
App of Things includes features that allow you to create a household and invite other registered users to share access to certain data (the "Household Sharing" features).
Your responsibilities as household owner
By inviting household members and entering data about other individuals, you represent and warrant that:
- Any individual whose personal information you enter into the Service has provided their consent for that information to be stored and used within the Service;
- Invited household members are required to explicitly accept your invitation before gaining access to shared data;
- You will not enter personally identifying information about children under the age of 13.
Member data visibility
When you share a household with another user, they will have access to household-level data as configured within the Service. Before accepting a household invitation, the scope of shared data will be disclosed to the invitee.
Leaving or removing a household member
When a household member leaves or is removed, their personal account and personal data remain intact. Shared household data (homes, vehicles, reminders, etc.) remains with the household. Members may request deletion of their personal data at any time per Section 8 of this Policy.
Household deletion
If you are the sole remaining member of a household and delete your account, all household-level data associated with that household will also be permanently deleted.
6. How We Share Your Information
6.1 Within your household
As described in Section 5, household members who have accepted your invitation may view household-level data as configured within the Service.
6.2 Service providers (sub-processors)
We share information with the following third-party service providers who process data on our behalf under data processing agreements:
| Provider | Purpose | Data location |
|---|---|---|
| Supabase, Inc. | Database, authentication, and file storage | Amazon Web Services (AWS), region per project configuration |
| Vercel, Inc. | Web application hosting and content delivery | United States and global edge network |
These providers are permitted to use your data only to provide services to us and are contractually required to protect your data in accordance with applicable law.
6.3 Legal requirements
We may disclose your information if required to do so by law, subpoena, court order, or other legal process, or if we believe in good faith that disclosure is necessary to protect our rights, investigate fraud, or respond to an emergency involving risk to life.
6.4 Business transfers
If we are involved in a merger, acquisition, bankruptcy, or sale of assets, your information may be transferred as part of that transaction. We will provide notice of any such change and information about your choices.
6.5 With your consent
We may share your information for other purposes with your explicit, informed consent.
We do not sell your personal information to third parties, and we do not share it with advertisers.
7. Data Retention
We retain your personal information for as long as your account is active or as needed to provide the Service:
- Account and application data — retained until you delete your account. Upon deletion, data is removed from active systems within 30 days and from backups within an additional 30 days.
- Authentication and security logs — retained for up to 90 days.
- Support communications — retained for up to 2 years for recordkeeping.
- Legal hold data — retained for as long as required by applicable law if subject to a legal hold or government request.
8. Your Rights and Choices
8.1 All users
Regardless of your location, you have the following rights:
- Access: Request a copy of the personal information we hold about you.
- Correction: Request correction of inaccurate or incomplete information.
- Deletion: Delete your account at any time from within the Service (Settings → Account → Delete Account), or by emailing [LEGAL CONTACT EMAIL]. We will process deletion requests within 30 days.
- Data export: Request a machine-readable copy of your data by emailing us.
- Notification preferences: Manage notification settings within the Service at any time.
To submit a request, email [LEGAL CONTACT EMAIL]. We will respond within 30 days (or as required by applicable law).
8.2 European Economic Area and United Kingdom users (GDPR / UK GDPR)
If you are located in the EEA or UK, we process your personal data under the following lawful bases:
- Contract performance — processing your email address and account data to provide the Service.
- Legitimate interests — processing usage and technical data to improve the Service, detect fraud, and ensure security, where our interests are not overridden by your fundamental rights.
- Legal obligation — processing required by applicable law.
- Consent — where we have obtained your consent for a specific processing activity (e.g., non-essential cookies).
In addition to the rights above, EEA and UK users also have the right to:
- Restrict processing in certain circumstances (e.g., while we verify a correction request).
- Data portability — receive your data in a structured, machine-readable format.
- Object to processing based on legitimate interests, including profiling.
- Withdraw consent at any time where processing is based on consent, without affecting the lawfulness of prior processing.
- Lodge a complaint with your local data protection supervisory authority. A list of EU supervisory authorities is available at edpb.europa.eu.
8.3 California users (CCPA / CPRA)
If you are a California resident, you have the following rights under the California Consumer Privacy Act:
- Right to know: Request disclosure of the categories of personal information we collect, the purposes for which we use it, and the categories of third parties with whom we share it.
- Right to delete: Request deletion of your personal information, subject to certain legal exceptions.
- Right to correct: Request correction of inaccurate personal information.
- Right to opt out of sale or sharing: We do not sell or share personal information for cross-context behavioral advertising.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To submit a California privacy request, email [LEGAL CONTACT EMAIL] with "California Privacy Request" in the subject line. We will respond within 45 days.
9. Children's Privacy
The Service is not directed to children under the age of 13. We do not knowingly collect personal information from children under 13. By creating an account, you confirm that you are at least 13 years of age.
If you are a parent or guardian and believe that your child has provided personal information to the Service without your consent, please contact us at [LEGAL CONTACT EMAIL] and we will promptly delete the information.
10. Data Security
We implement the following technical and organizational measures to protect your personal information:
- Encryption of data in transit using TLS (Transport Layer Security)
- Encryption of data at rest via our database provider (Supabase)
- Row-level security (RLS) policies in our database that restrict data access so each user and household can only access their own data
- Passwords are never stored in plaintext — all password hashing is handled by our authentication provider (Supabase) using industry-standard algorithms. The mobile app uses magic link / OTP authentication only, with no password required.
- Access controls limiting who can access production systems
No security system is completely secure. While we take these measures seriously, we cannot guarantee the absolute security of your information. If you believe your account has been compromised, contact us immediately at [LEGAL CONTACT EMAIL].
In the event of a data breach that poses a high risk to your rights and freedoms, we will notify affected users without undue delay and report to applicable supervisory authorities as required by law.
11. International Data Transfers
We are based in the United States. If you access the Service from outside the United States, your information may be transferred to, stored, and processed in the United States or other countries where our service providers operate.
For transfers from the EEA or UK to the United States, we rely on appropriate safeguards, including Standard Contractual Clauses (SCCs) incorporated into our data processing agreements with sub-processors such as Supabase and Vercel. You may request a copy of these safeguards by contacting us at [LEGAL CONTACT EMAIL].
12. Cookies and Web Technologies
We use cookies and similar technologies on our web application. For full details about the cookies we use, how to manage them, and your choices, please see our Cookie Policy.
In summary: we use strictly necessary authentication cookies (set by Supabase) to maintain your signed-in session, and we store your theme preference in browser local storage. We do not use advertising or tracking cookies.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. When we do, we will update the "Last Updated" date at the top of this page. For material changes, we will notify you by email at the address associated with your account, or by a prominent notice within the Service, at least 30 days before the change takes effect.
Your continued use of the Service after the effective date of an updated Policy constitutes your acceptance of the changes. If you do not agree to the updated Policy, you must stop using the Service and delete your account.
14. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
Ricky Landino
Email: [LEGAL CONTACT EMAIL]
Privacy Policy questions: include "Privacy" in the subject line for fastest routing.