1. Controller and scope
OurHome Development, Germany, is responsible for processing. This policy covers Our Home (also displayed as OurHome in Google consent), the family organizer offered under the RIQELO brand for Android, iOS and Windows, and the public pages at ourhome.riqelo.com.
Privacy requests can be sent to the email address listed below.
2. Data we process
- Account: email address, password hash, display name, language, currency, time zone, and sign-in and session data.
- Family and profile: family name, membership, role, nickname, invitations, and an optional profile photo.
- Optional Google Calendar: account association, calendar list and imported events after your authorization. The dedicated Google Calendar section explains permissions, use, family access, storage and deletion.
- Organizer content: calendar events including title, description, location, time, participants and reminders; tasks including descriptions and assignments; shopping lists; checklists; notes; household budgets and expenses. We do not receive bank credentials or full credit-card details.
- For a Google Play subscription, we process purchase tokens, order, product and plan identifiers, account association, subscription status, auto-renewal and expiry to verify access. Google Play handles payment, not ourhome.riqelo.com.
- Device and notifications: pseudonymous device or installation identifier, push token, platform, app language, and notification preferences.
- Diagnostics: app and operating-system version, device model, app screen or technical component, error type, technical message, stack trace, time, and pseudonymous installation identifier.
- Public website: IP address and standard HTTP security logs; when applying for testing, also the submitted Google Play email address, consent, application status, and processing timestamps. For a contact request, we process name, email address, category, subject, message, consent, and verification timestamps.
3. Google Calendar
Connecting Google Calendar in the Android app is optional. Start under Calendar > Google Calendar and grant permissions directly with Google. One Our Home account can connect one Google account and up to five selected calendars. Other organizer features do not require this connection.
This optional processing of your Google data is based on your consent (GDPR Art. 6(1)(a)). You may withdraw it at any time for future processing as described below.
Permissions and their purposes
This integration does not request Gmail messages, contacts or permission to write Google events. Our Home does not create, change or delete original events or send Google invitations. Our Home does not receive your Google password.
Data accessed and stored
We store the Google account identifier and email address, calendar identifiers, names, time zones and default reminders. Imported events include the identifier, title, description, location, start and end, all-day status, time zone, recurring-event references and original start, and up to five popup reminder intervals. From attendee information returned by Google, we check your own response status to avoid reminders for declined invitations; an attendee list is not stored as such.
We also process OAuth authorization codes and tokens, technical synchronization identifiers, change-notification channels, connection status and timestamps. Google change notifications sent to our server contain no event text; the server then fetches changes through the Calendar API.
Synchronization and reminders
Selected calendars synchronize in the background to our server and are displayed in Our Home. The import window covers the previous 90 days and next 366 days; successful synchronization updates copies and removes those outside this window. If the connection is interrupted, existing copies may remain until synchronization resumes or you remove them.
The visible Remind me option starts enabled for selected calendars and can be turned off. Delivery requires app notifications to be allowed. Reminders go only to you, not automatically to family members. Google Firebase Cloud Messaging processes device tokens, event titles, event times and technical message identifiers for delivery. Reminders may appear on your lock screen; you control this in device settings. Google email reminders are not duplicated.
Personal copies and family sharing
Imported copies are initially visible only to you. Only after you enable Share with family for a calendar and save the selection can authorized members of your current family access all imported event details from that calendar, its name and your Our Home display name. This includes subsequently imported events and newly joining family members. Sharing is not limited to free/busy information.
Connection settings, your connected Google account email and OAuth tokens are not disclosed to family members as connection data. Email addresses you include in event text remain part of that text. Turning sharing off, removing the calendar or leaving the family ends further family access; rejoining does not restore sharing. Shares between different families do not extend access to Google calendars. We cannot retrieve copies already made by recipients.
Storage, recipients and protection
Copies are stored in a separate database schema on our backend. Server-side authorization limits access to you and explicitly authorized family members. Refresh tokens are encrypted on the server with AES-256-GCM; short-lived access tokens are not stored persistently. The app does not receive refresh tokens. Traffic between the app, public backend and Google uses HTTPS.
Our hosting and infrastructure providers process data on our behalf to operate this feature. Google processes OAuth/Calendar requests and, when reminders are enabled, the FCM delivery data described above. Google Calendar data is not sold or sent to advertising, analytics or AI services. The general information about recipients and international transfers also applies here.
Disconnect, revoke access and delete data
In the app, open Calendar > Google Calendar > Disconnect Google and confirm. Once processed successfully, our server removes the connection, calendar list, imported event copies and associated reminder jobs from the active database. Your Our Home account, other organizer content and Google originals remain. Alternatively, deselect individual calendars and save; their event copies and pending reminders are removed, while the calendar list remains until you disconnect.
Disconnecting queues revocation of Google access. Until revocation succeeds, this queue retains only the encrypted token needed for revocation and technical association data. Failures are retried for up to seven days; the entry is then removed in the next cleanup run. This deadline does not guarantee that Google has successfully processed revocation.
You can also revoke access on the Google account page linked below. This stops future Google access but does not automatically delete copies already held by Our Home. Also disconnect in Our Home or contact us to delete those copies. Uninstalling the app alone does not disconnect the server-side integration.
Actual deletion of your Our Home account also removes this active Google data and queues revocation. Merely requesting or approving account deletion does not yet delete it; the account-deletion section explains the 72-hour cancellation period. Technical records of sent reminders are cleaned up after 90 days during regular processing; disconnecting removes them with the calendar. General retention information applies to backups.
Google API Services User Data Policy and Limited Use
For information obtained through Google APIs, Our Home follows the Google API Services User Data Policy, including its Limited Use requirements. This covers use and transfer of that information. Google data is used only for the visible calendar features described here, not for advertising, profiling, credit decisions or training AI models.
Staff or contractors may access Google data only with your explicit agreement concerning the specific data, where necessary for security investigations, or where legally required. Technical administrative access is not permission to read data for other purposes. Different uses or recipients would require advance disclosure and, where required, fresh consent.
4. Purposes and legal bases
- Providing accounts, synchronization, family access, invitations, calendar sharing, and support to perform our service contract (GDPR Art. 6(1)(b)).
- Providing push notifications and optional features requested by the user; system permissions can be withdrawn at any time.
- Preventing abuse, troubleshooting, maintaining availability, and protecting the service based on our legitimate interest in a secure and reliable service (GDPR Art. 6(1)(f)).
- Managing voluntary testing applications based on consent (GDPR Art. 6(1)(a)). Consent can be withdrawn at any time.
- Handling voluntary contact requests based on consent (GDPR Art. 6(1)(a)) or to take pre-contractual or contractual steps (GDPR Art. 6(1)(b)).
- Complying with legal obligations where required (GDPR Art. 6(1)(c)).
6. Data on your device
The apps store session data, settings, and a local copy of synchronized content in protected app storage. If biometric sign-in is enabled, only the device system performs biometric verification. Our Home never receives fingerprints, face data, or biometric templates.
Allowing screenshots only changes local protection of the app window and does not send screenshots to us. Public pages do not use advertising or analytics cookies.
On the first page view, the web server maps the IP address to a country locally and selects German, English, or Russian. The IP address is not sent to an external geolocation service. The choice is stored without an expiry date in the essential “ourhome_locale” session cookie and ends with the browser session; a manual language choice overrides it.
After a testing application, email verification, or opening its private status link, the website stores an essential cookie for 30 days to recognize this browser and check approved Google Play access. It contains a random access token, not an email address. You can delete it in browser settings. In another browser, you can open the private status link or enter your email again and confirm it with a code sent by email.
After signing in to a support ticket, the website stores the essential HttpOnly “ourhome_ticket_session” cookie for 30 minutes. It contains a random session token, is bound to one ticket, and is deleted on sign-out. Every new sign-in requires the ticket email address and a new 8-digit code.
7. Security
Data is transmitted over HTTPS. Accounts use hashed passwords; server authorization and row-level rules limit family data to authorized members. Session data is kept in operating-system protected storage.
Before and after transmission, diagnostic text is checked for known email addresses, access tokens, JWTs, URL parameters, and UUIDs, then shortened or redacted. No online service can guarantee absolute security despite reasonable safeguards.
8. Retention
- Account, profile, and active family content is retained while the account or family space is needed.
- Deleted or replaced data may remain for a limited time in security backups and technical logs and is overwritten through normal deletion cycles.
- Diagnostic events are deleted after 30 days by default.
- Rejected testing applications are deleted after 180 days; other testing data is deleted when no longer needed to manage testing or when deletion is requested.
- Email verification codes for testing access expire after 10 minutes. The database stores only code and token hashes, timestamps, and verification attempt counts. Unconfirmed requests are removed by routine cleanup after one day; verified browser access expires after 30 days and is then deleted.
- Contact messages are delivered only after an 8-digit email code is entered. Until then, form content is encrypted with AES-256-GCM; the code, email address, and request identifier are stored only as HMAC hashes. The code expires after 10 minutes and permits no more than five failed attempts. Unconfirmed data is deleted within one day, and encrypted form content is removed from the database after successful delivery.
- Confirmed contact requests are stored as support tickets. Metadata, the private link token, and messages are encrypted with AES-256-GCM; lookup values, codes, and sessions are stored only as HMAC or SHA-256 hashes. Access codes expire after 10 minutes and sessions after 30 minutes. Closed tickets are deleted after 365 days unless legal retention is required.
- Data that must be retained for security or legal reasons is restricted to that purpose and deleted afterwards.
9. Delete your account and data
In Android, open Profile > App settings > Delete account and data to submit a confirmed request directly to support and view its status. Alternatively, use the email-verified form below or contact us by email. We verify identity and agreement to the consequences; a website request alone does not trigger automatic deletion.
After approval of an appropriately confirmed in-app request, the app shows the scheduled deletion time. You have 72 hours from approval to cancel. Deletion starts only after this period if the request has not been cancelled. Technical failures may delay execution; status and retries remain available. Simply signing out or uninstalling does not cancel the request.
Your account and its associated active personal data are deleted. If you own families, the confirmed family spaces and their shared content are deleted, while other members retain their accounts. To preserve a family space, transfer ownership before submitting a new request. For an ordinary member, shared content remains while personal authorship references and assignments are removed. Changes to the confirmed family ownership require renewed confirmation.
Google Calendar copies are removed as described in the Google Calendar section; Google originals remain unchanged. Deletion does not cancel a Google Play subscription: cancel that separately in Google Play. After completion, messages and contact data in the account-deletion request are removed; a minimal result record remains until routine cleanup of closed tickets after 365 days. Other support tickets, legal obligations and backups follow their own retention periods. We normally respond to privacy requests within one month and explain any permitted extension.
Local session data is removed by signing out. Cached app content is removed by clearing app data or uninstalling the app. Withdrawing push permission stops new notifications on that device.
Request account deletion10. Your rights
Subject to the GDPR, you may request access, correction, deletion, restriction, and portability, and may object to processing. Consent can be withdrawn for the future. You may also complain to a data-protection authority, particularly in your place of residence.
11. Children
Our Home is intended for adults organizing family life and is not directed to children under 13. Adults may enter information about family members only when authorized to do so.
12. Changes
We update this policy when features, providers, or legal requirements change. The current version and effective date are always available at this address.