Privacy

Privacy Policy

This policy explains what Homiary processes, what remains on your Android device, and the choices available to you.

EffectiveAugust 28, 2026

1. Scope and publisher

This Privacy Policy applies to the Homiary Android application and the Homiary legal website at homiary.web.app. Homiary is operated and published by KokoJDN, an independent developer based in Texas, United States (“Homiary,” “KokoJDN,” “we,” “us,” or “our”). Initial app availability is limited to the United States.

Homiary is intended for adults age 18 and older. It is not directed to children or minors.

2. Information stored on your device

Homiary is designed to organize property details, maintenance tasks and schedules, equipment, expenses, service providers, warranties, notes, and related home records. The current app stores onboarding and preference information through Android DataStore, structured home records through a local Room database, and captured or scanned attachments in Homiary's application-private storage. When you select a file through an Android document provider, Homiary may instead retain permission to read that specific provider-managed file.

Homiary does not currently upload, synchronize, back up, or restore your home records through a Homiary cloud service. Android application backup is disabled. Deleting an online account therefore does not remove locally held app state, and signing in does not upload it.

Homiary Plus can use an Android camera activity to capture equipment or receipt photographs, allow you to choose an image or file, scan a receipt into a PDF through the Google Play services ML Kit document scanner, and attach manuals, warranties, receipts, and other property documents. These files may contain an address, serial number, purchase information, or other sensitive details. Review each file before saving or exporting it. Homiary does not currently perform OCR or automatically extract receipt or document text.

A random installation identifier may be generated and stored locally for device-level app behavior. Homiary also stores the accepted Terms and Safety document version and acceptance status locally so the app can determine whether acknowledgement is current. This local information is not derived from a hardware identifier and is not a Homiary cloud account.

3. Optional account information

You may use Homiary without connecting an account. If you choose Continue with Google, Firebase Authentication and Google may process or provide:

  • a Firebase user identifier;
  • the Google account email address, display name, and profile image made available through sign-in;
  • authentication credentials and security information required to maintain and protect the session; and
  • provider details and technical timestamps associated with the account.

We use this information to authenticate you, display your account state, protect access, answer account requests, and associate a verified Homiary Plus entitlement with the correct account. Google sign-in does not enable cloud storage for home records.

4. Subscription and entitlement information

If Homiary Plus is offered and you purchase it, Google Play processes the transaction and payment method. Homiary does not receive your full payment-card or bank-account details.

To verify and restore subscription access, prevent fraud, acknowledge purchases, process lifecycle changes, and resolve billing issues, Homiary's protected backend may process or store the Firebase user identifier; an opaque billing-account binding; Homiary product and base-plan identifiers; a Google Play purchase token or token hash; an order-related identifier; subscription and renewal state; access-expiration time; and verification, acknowledgement, reconciliation, event, or update timestamps. It may also store a hashed lifecycle-event identifier, event category and result, retry count, and limited failure code so duplicate or delayed events can be handled safely.

Private purchase tokens and order-related records are restricted to trusted backend services. The Android app may read only a limited entitlement record needed to show Free or Plus access. Google Play remains the purchase source of truth. Homiary receives Google Play Real-time Developer Notifications as lifecycle-change signals, retrieves the current subscription state from the Google Play Developer API, and periodically rechecks known subscriptions to recover from delayed or missed notifications. Delivery or verification can still be delayed, so the app may offer a status or restoration check.

5. App and service integrity

The Firebase Android SDKs automatically process technical information needed to provide and protect their services. Depending on the service invoked, this can include IP address, Firebase Android App ID, Firebase user identifier, requested Cloud Function name, Firebase-user-agent and ordinary user-agent information, app and SDK versions, operating-system version, device model, brand and form factor, installation source, and a Firebase installation identifier that identifies an app installation rather than uniquely identifying a person or physical device. The Cloud Functions client may also transmit a Firebase Cloud Messaging token when a Function is called, even though Homiary does not currently use that token to send marketing messages.

For protected backend access, Firebase App Check and Google Play Integrity process attestation material, integrity tokens, app metadata, license status, and device or installation signals needed to validate that a request comes from a recognized Homiary installation. Firestore and Function requests made while signed in include the Firebase user identifier. We use these signals for app functionality, authentication, security, abuse prevention, account deletion, and purchase protection, not to profile your household or target advertising.

The Google Play services ML Kit document scanner processes scanned document images and generated results on the device and does not send that document content or output to Google's servers. Google Play services dynamically downloads the scanner interface, logic, models, and other required resources. ML Kit collects limited app and device information, device or per-installation identifiers, performance metrics such as latency, API configuration such as image format and resolution, input and output size, feature version, event type, and error codes for diagnostics and usage analytics. Google states that these collected metrics are encrypted in transit and are not transferred to third parties. Homiary receives only the scan result that you choose to return to the app.

Network connections to Firebase use encrypted transport, Firebase services provide encryption at rest for hosted data, Firestore Security Rules restrict client access, and private billing records are designed for server-only access. No system can guarantee absolute security, and Homiary data is not represented as end-to-end encrypted.

6. Why we process information

We process information to provide and secure account access; verify, restore, and administer subscriptions; prevent fraud and misuse; respond to support, privacy, safety, and deletion requests; maintain service reliability; comply with legal obligations; and resolve account, refund, chargeback, or purchase disputes.

7. Service providers and disclosures

Homiary uses Google services that may process information on our behalf or under their own terms:

  • Firebase Authentication for optional account identity;
  • Cloud Firestore and Cloud Functions for limited subscription entitlement and purchase-verification processing;
  • Firebase App Check and Google Play Integrity, when production protection is enabled, for service integrity;
  • Google Play Billing for subscriptions, payments, purchase history, and subscription management;
  • Google Play services ML Kit document scanner for optional on-device receipt scanning and related service metrics;
  • Firebase Hosting for these static legal pages; and
  • Gmail for messages sent to homiaryapp@gmail.com.

We may also disclose information when reasonably necessary to comply with law or valid legal process; protect users, the public, or our rights; investigate fraud or security incidents; or complete a business reorganization subject to appropriate safeguards.

Homiary does not sell or rent personal information. Homiary does not use personal information for targeted advertising and does not currently include advertising SDKs.

8. Support correspondence

If you email Homiary, Gmail processes the sender and recipient addresses, message headers, timestamps, subject, message content, and any files you voluntarily attach. KokoJDN uses that information to answer support, privacy, safety, billing, and deletion requests; verify account control when needed; prevent abuse; and document completion.

Do not email passwords, authentication codes, payment-card details, raw purchase tokens, full receipts, identity documents, or sensitive home files unless KokoJDN specifically explains why limited information is necessary and provides an appropriate method.

9. Analytics, crash reports, cookies, and website logs

The current Homiary app does not include a general product-analytics SDK, advertising, or Crashlytics crash reporting. The limited ML Kit service metrics described above are separate from Homiary product analytics. This website contains no JavaScript, analytics code, advertising technology, or cookies and loads no external visual assets.

Firebase Hosting and related Google infrastructure may still process technical request information such as IP address, request time, requested path, user agent, response status, and security signals to deliver and protect the site. Google controls the infrastructure retention applicable to those logs.

10. Retention

  • Local app information remains on the device until you delete a record or attachment in Homiary, clear Homiary storage through Android settings, or uninstall Homiary. Deleting an imported attachment from Homiary releases its retained access but does not necessarily delete the original file held by another application or document provider. Exported copies remain wherever you chose to save them.
  • Firebase account information remains while the account is active. After an eligible verified deletion request, active account information is deleted within 30 days. Firebase Authentication backup removal may take up to 180 days after active deletion.
  • Eligible Homiary entitlement, billing-identity, lifecycle-event, and purchase-verification metadata is deleted with a verified account-deletion request within 30 days. Without an account-deletion request, backend lifecycle-event records are scheduled for deletion 90 days after the event is first recorded, and raw purchase tokens are scheduled for removal 60 days after the backend confirms subscription expiration. Sanitized status, timestamp, token-hash, and ownership records needed to document and protect subscription access may remain while the account exists. KokoJDN does not intentionally retain a separate archive of deleted Homiary records.
  • Support and deletion correspondence, including the sender email, message content and headers, voluntarily attached files, verification result, completion date, and request outcome, may be retained for up to 24 months to document and resolve the request, protect account security, and demonstrate completion.
  • Google Play transaction records are controlled and retained by Google under Google's own terms and legal obligations. Deleting a Homiary account does not delete Google's purchase history.

11. Your choices and requests

You can continue on your device without a Google account, connect or sign out of an optional account, manage a Google Play subscription, clear local app storage, or request account deletion. The account-deletion page explains these separate actions.

You may ask to access, correct, or delete account-linked information by emailing homiaryapp@gmail.com. We may verify control of the connected account before acting. Verified deletion requests are acknowledged within 3 business days and eligible deletion is completed within 30 days, subject to the limited retention described above.

Depending on applicable law, you may have additional rights concerning access, correction, deletion, portability, restriction, or appeal. We will not discriminate against you for making a privacy request.

12. Adults-only audience

Homiary is intended only for adults age 18 and older and is not directed to children or minors. We do not knowingly seek personal information from anyone under 18. If you believe a minor has provided account information, contact us so we can investigate and remove eligible information.

13. Processing locations

Google and Firebase may process account-linked information in the United States and other countries where they operate. The current technical configuration uses Firebase Authentication's United States processing location, Cloud Functions in us-central1, the named Cloud Firestore database in the nam5 multi-region, and globally provided Firebase App Check services.

14. Changes to this policy

We may update this policy when Homiary's features, service providers, legal requirements, or information practices change. The current version and effective date will remain available at this URL. We will provide additional notice or request consent when required by applicable law.

15. Contact

KokoJDN
Independent developer and publisher of Homiary
Texas, United States
Email: homiaryapp@gmail.com