Toach Privacy Policy
Overview
Toach is a household coordination application, operated by TransformNative LLC (“Toach,” “we,” “us”), that helps a family share tasks and calendars and coordinate meetups. This policy explains what information Toach collects, how it is used, who it is shared with, and the choices available to you.
Toach supports multiple independent households on a single server. You can create your own household, or join an existing one with an invite code shared by its administrator. An account can belong to more than one household; if yours does, you can switch between them in Settings. Each household’s data is scoped to that household.
Information We Collect
Information you provide
- Account information. If you sign up with a username and password, both are stored; passwords are stored only as one-way cryptographic hashes. If you sign up with Sign in with Apple, we store the stable identifier Apple assigns to your account for Toach, the name you authorize Apple to share at first sign-in, and the email address Apple provides — your real address or Apple’s private relay address, whichever you choose in Apple’s dialog. That identifier works only for Toach; every sign-in requires a fresh token signed by Apple. Sign in with Apple itself is operated by Apple; the choices you make in Apple’s sign-in dialog control what Apple sends us.
- Household membership. Records of which households you belong to, your role in each (admin or member), and the date you joined.
- Invite codes. If you generate an invite code as an admin, the code and its expiration are stored against your household. A code lets someone ask to join — an admin must approve each request before they become a member and see any household data. Codes expire automatically (after 14 days unless you set otherwise) and can be rotated or revoked at any time from Settings; an expired or revoked code stops working for new requests. If you ask to join a household using a code, the request — and, once approved, your membership — is recorded as described above.
- Profile and preferences. Display name, notification preferences (which kinds of alerts you receive and their timing), and time zone.
- Tasks and household chores. Titles, descriptions, estimates, priorities, categories, due dates, scheduled times, completion status, and time-tracking entries.
- Plans. An occasion you are preparing for (its name, date and optional start time), the ordered preparation steps with the “how we do this one” notes you write, who holds each step, and whether it is done. Steps become ordinary household tasks as their day approaches. Plans are visible to your household, and Toach chases them on your behalf: the person holding an overdue step is reminded, and if it stays open the plan’s owner is told so they can send a nudge. If you save a plan as a template it is kept for your household. You can also describe an occasion in your own words and have the assistant draft the steps — that sentence is processed as described under the AI assistant, and the plan is saved when you confirm the draft.
- Credits, prizes and family funds. Credits are an in-app reward parents can attach to chores. Toach stores the value set on each chore, a ledger of credits earned and spent, the prizes a parent creates, redemptions, and contributions to shared family funds. Credits are a household’s own scorekeeping: they are not money, have no cash value, cannot be bought, sold or exchanged for currency, and exist only inside your household.
- Chore trades. Members can swap chores by asking the assistant (for example, “ask Marco to trade my dishes for his recycling”). Toach records the proposal, who accepted or declined it, and whether the swap was carried out, so the trade can be honored and fairness stays accurate.
- Chat messages. Text you send to the AI assistant and the assistant’s responses. When you dictate, your speech is turned into text on your device by iOS, and the resulting text is sent to Toach’s servers.
- Photos and uploads. Images, screenshots, or PDFs you submit for schedule extraction.
- MeetUps connections. If you use MeetUps to keep up recurring get-togethers, Toach stores what you enter about each connection: a first name for the adult you coordinate with (optionally a second first name for the friend’s other parent, under the same rules), optionally a first name and care notes (such as allergies) for a child friend, your frequency goal, tone, venue and scheduling preferences (such as when meetups usually work and a rough travel time), hosting history, and the state of each proposal. When you link a connection — either adult — to a card in your iOS Contacts, Toach stores only an opaque Contacts identifier — the person’s phone number, surname, and photo stay on your device and are resolved from Contacts at the moment you view or send a message. When you decline the Contacts link, Toach stores the phone number you type. Care notes about children are entered by you and kept in Toach until you delete the connection. Every outreach message is sent by you from your own Messages app.
Information from connected services
When you authorize Toach to connect to a third-party service, Toach reads, and in some cases writes, data on your behalf:
- Sign in with Apple. Apple sends a signed identity token containing your stable Apple identifier and, at first authorization, the name and email address you chose to share — your real address or Apple’s private relay alias. Toach verifies the token’s signature against Apple’s published keys and uses it to create or sign in to your Toach account.
- Google Calendar. Calendar events, including titles, times, locations, and attendees. Write access is used to carry out instructions you give the assistant. A direct instruction (“add dentist Thursday at 4”) is carried out as asked, and the assistant restates what it created so a mistake is visible right in the reply; when a request is ambiguous, or the idea came from something the assistant read (an event title, a photo) rather than from you, it is designed to ask before acting. Deleting an event takes two steps — the assistant shows you the matched event and the server acts only on your explicit yes. Events extracted from photos or PDFs are shown as a review list and added only after you confirm them.
- Limited Use of Google user data. Toach’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar data is used only to display and coordinate your household’s schedule and to create events you explicitly confirm; it is not sold, not used for advertising, and not transferred to third parties except as needed to provide these features.
- Microsoft Calendar. Calendar events from connected Microsoft accounts.
- iPhone Calendar (optional). If you turn on “Sync iPhone Calendar” in Settings, the Toach app reads the calendars on your device through iOS’s Calendar permission and uploads a snapshot of those events — titles, times, locations, notes and which calendar each came from — to Toach’s server, so they appear alongside your other calendars and in your household’s Family View. Please note that the iPhone calendar aggregates every calendar your device subscribes to, which may include a work or school account; only turn this on if you are content for those events to be pooled. The snapshot is replaced each time the app syncs. Toach can also add, change or remove events on your device calendar when you ask it to — those instructions are queued on the server and carried out by the app on your phone, because Apple provides no server API for iCloud calendars. Turning the setting off, or disconnecting the iPhone calendar in Settings, deletes the stored snapshot and any queued instructions.
- Email. The email address on your account is used for service messages: verification and password-reset codes, the children’s-privacy notice when you add a child’s account, responses to questions you send us, and important notices about your account, the Service, or these policies (for example a security or billing issue). Toach does not send marketing email without your separate consent.
- Subscription status. When your household subscribes through the Apple App Store, Apple sends Toach the plan you chose, its renewal status and expiry, and an anonymous transaction identifier so the subscription can be attached to your household. Payment details — card numbers, billing address — are handled by Apple.
Information collected automatically
- Device location (optional, permission-gated). With your permission, the iOS app periodically reports your device’s location (latitude/longitude — the app requests kilometer-level accuracy from iOS, though iOS may deliver a more precise fix) so Toach can estimate your drive to upcoming calendar commitments — the airport when a flight is on your calendar, or an event’s listed location (such as an appointment or meeting) — and tell you when to leave. Only your most recent location is kept. If you deny or revoke location permission (iOS Settings → Toach → Location), departure alerts fall back to a default travel estimate or are skipped, and everything else works normally.
- On-device copies (widgets and Apple Watch). If you add a Toach home-screen widget or use the Apple Watch app, a small amount of household content — your next step, today’s counts, and your credit balance — is copied into a shared storage area on your own device so those extensions can display it without opening the app. It stays on your device, and note that a home-screen widget may display that content on a locked screen. Removing the widget or signing out clears it.
- Authentication tokens. Session tokens stored in the app’s own storage on the devices you sign in with (iPhone and Apple Watch).
- App Lock (Face ID / passcode). The optional App Lock is enforced on your device by iOS; Toach stores only an on/off preference.
- Server logs. Access logs, error logs, and scheduler activity, including timestamps and request paths. Logs may incidentally include IP addresses provided by Cloudflare.
- Usage metadata. Drag-to-schedule actions, completion times, notification deliveries, and similar interaction events used to power the Today screen, Family View, and Review.
How We Use Information
Toach uses the information above to:
- Authenticate you and maintain your session.
- Display your tasks, calendar events, and household activity.
- Suggest fair chore assignments based on calendar availability and rotation history.
- Deliver notifications on your chosen channels.
- Process AI chat, voice input, and schedule photos through the assistant.
- Sync events to and from your connected calendars.
- Let members of your household add or edit events on your synced calendars through Toach’s assistant, if you allow it. You control this per-account (Settings → Calendars → “Who can edit my calendar”: whole household, parents only, or just you), and cross-member additions are visibly attributed in the event notes. Household admins may also delete events from your calendar — allowed by default, and you can turn it off at any time (Settings → Calendars); deletions through the assistant require the acting admin’s explicit confirmation of the exact event first. Toach’s record of cross-member changes stores who acted on whose calendar, the action, the provider’s opaque event identifier, and when. The event’s name does appear, briefly, in the two places you would expect: the assistant conversation where the change was asked for (kept at most 3 days, erasable anytime from the Assistant screen) and the notification telling the calendar’s owner what happened (its log is kept 3 days) — see Data Retention. Your calendar provider remains the source of record for the events themselves.
- Estimate when to leave for the airport when a flight is on your calendar, using your most recent device location (if you allow it) and the departure airport read from the event — assuming standard airport buffers (two hours international, one hour domestic) plus your estimated drive.
- Send plan reminders: the person holding a step is reminded when it comes due, and if it stays open the plan’s owner is told so they can send a nudge.
- Keep a household’s credit balances, prize list and family funds, and record chore swaps between members.
- Operate and secure the platform: authenticate requests, enforce plan seats and rate limits, detect and prevent abuse, and keep backups so your household’s data survives a failure.
- Diagnose errors and improve reliability and quality.
- Understand and improve Toach. We analyze how features are used — counts, timings, error rates, and similar measures drawn from service data — to see what is working and fix what is not. This analysis stays internal to the operator.
Toach does not use your information for advertising, does not sell it, and does not use your content to train AI models; our AI provider processes assistant requests under API terms that prohibit training on them (see Third-Party Services).
Third-Party Services
Some features rely on external providers. When you use those features, the relevant data is sent to the provider and is subject to the provider’s own privacy practices.
| Provider | Purpose | Data shared |
|---|---|---|
| Anthropic (Claude API) | AI chat and suggestions, drafting MeetUp messages and plan steps, extracting a schedule from a photo, and composing each member’s daily morning note (generated once each morning, and again when a member asks for a refresh) | Your message text (dictation is transcribed on your device first), uploaded images, and the task, plan and calendar context relevant to the request or the day being summarized |
| Calendar sync and OAuth | Calendar events, OAuth tokens, account email | |
| Microsoft | Calendar sync and OAuth | Calendar events, OAuth tokens, account email |
| Apple (Push Notification Service) | Web push delivery to iOS devices | Device push token, notification payload |
| Apple (Sign in with Apple) | Account creation and sign-in | Apple stable identifier, optional name and relayed email |
| Apple (Maps Server API, optional) | Traffic-aware drive-time estimates before a flight or a located calendar event, and resolving an event’s location text to coordinates | Approximate device location (origin), destination coordinates, and the event’s location text — no account identifiers |
| Resend | Email delivery of service messages: verification and password-reset codes and the children’s-privacy notice | Email address, message content |
| Backblaze B2 | Encrypted off-site database backups | A complete encrypted copy of the Toach database |
| Cloudflare | Tunnel and request routing | IP address, request metadata |
We do not sell personal information. We do not share personal information with advertising networks or data brokers.
Data Storage and Security
- Your data is stored on servers we operate, with regular encrypted off-site backups.
- All access is over HTTPS — encryption in transit.
- Passwords are stored only as one-way cryptographic hashes, not in a form Toach can reverse.
- Third-party OAuth tokens (Google, Microsoft, and Apple) are encrypted at rest and used only to make authorized requests to the connected services.
- No system is perfectly secure. We make reasonable efforts to protect data but cannot guarantee absolute security.
Households and Multi-User Sharing
Toach is designed for shared household visibility. Each household is a separate scope: data created in a household is visible to that household’s members.
Within a household you belong to:
- Other members can see chores you mark as “household” scope, your household-chore completion counts (which power fair auto-assignment and which the assistant can report when someone asks about fairness), and household-scoped tasks assigned to or by you.
- Calendar events from your connected Google and Microsoft calendars are pooled into the Family View for that household’s date range, tagged with your name so others can see whose calendar an event came from.
- The AI assistant, when you chat with it inside a household, can read household-scoped tasks, chores, fairness data, and the pooled calendar so it can answer questions like “is anyone free at 3pm.”
- Your 1:1 AI chat history and your account-level settings are visible only to you.
- Ordinary tasks — including your own solo tasks — are part of household coordination and may be visible to other members through shared features such as the family view, morning briefs, and the AI assistant (for example, a parent asking what is on a child’s plate). They stay off other members’ own task lists, and only you and your household’s parents/admins can change them.
- A solo task you mark “Keep it private” is different: it is visible to you alone. Family chores stay visible to the household, because a task somebody else may need to pick up has to be findable.
Joining and leaving households:
- You join a household with an invite code generated by an admin of that household. The code creates a join request; an admin of that household must approve it before you become a member or see any of its data. You can withdraw a pending request at any time.
- Admins can rename their household, generate or revoke invite codes, and view the member list and member roles.
- If you leave a household, you stop seeing its content and its members stop seeing future content from you, but content you previously contributed (household chores you completed, plan steps you held, MeetUps you coordinated) remains visible to remaining members. Keeping those records preserves the household’s shared history and fairness accounting.
- If you are the only admin of a household and choose to leave, you must either promote another member to admin or delete the household entirely. Deleting a household deletes its shared content — MeetUps connections and care notes, plans, prizes, credit history, trades, and household settings — along with its membership records. Rows that belong to a member personally (their own tasks, their private assistant chat, their calendar connections) stay with that member’s account, and parental-consent records are retained as compliance evidence.
Information is not shared with anyone outside your household except through the third-party services listed above, which are necessary to deliver the features you have enabled.
Children’s Privacy
Toach is intended to be used by family households, which may include minors added by a household admin. In this policy, “children” means household members under 13 and “minors” means members under 18; both are protected by the rules below, with the strictest rules applied to children. A child’s account — one carrying the protections below — is created by a parent or household admin inside the app, through the consent step described here; it cannot be set up with an invite code. Toach cannot tell the age of a person who signs up with an invite code on their own, so that door has two safeguards: an admin must approve every join request before the person sees any household data, and admins are prompted to set each new member’s family role — marking someone as a kid asks for parental consent and applies every protection from that moment. Creating a child’s account requires the parent’s affirmative consent. The setup step presents a notice of what Toach collects from the child’s account and how it is used; the parent must agree before the account can be created; the agreement is recorded with a timestamp and the version of this policy in effect; and a copy of the notice is emailed to the parent’s verified address. The same consent is asked for, recorded, and echoed by email when a parent enters or changes the child’s age, and when an admin marks an existing member of the household as a child (for example, someone who joined with their own account). Toach shows no advertising and does not use children’s data for any purpose beyond operating the household features described in this policy.
- What a child’s account collects. The name a parent gives the account, the child’s tasks, chores, credits, and calendar items shared into the household, and the device push token needed to deliver their notifications. A child’s birth month and year is stored solely to apply the age rules below.
- The AI assistant is not available to any household member under 18. This is a fixed rule with no override — no setting exists to enable it for a minor. Members of every age still receive their one-way morning note — a summary of their own day generated from household data, into which the child types nothing.
- Children type less by design. A child under 13 can request a playdate only by picking from the list their parents have curated — free-typed names and notes are not accepted from their account. A minor aged 13–17 can add a short note to a playdate request; the note goes only to their own parents.
- Location is off by default for children. A child’s device location is not collected unless a parent turns it on, and the child’s device also has to grant the iOS permission. As with all members, only the single most recent fix is kept.
- No hidden corners. A child’s account cannot mark tasks private — a parent or admin can review everything on a child’s account.
- Parents’ rights. A parent or household admin can review a child’s information in the app — their day in Family view, their chores, credits and history in Tasks, and their profile, age, and permissions in Settings → Family — delete any of it or the whole account (Settings → Family), and refuse further collection by removing the account, which withdraws consent. Requests can also be sent to the operator listed below and are honored after verifying the requester is the child’s parent or the household admin.
Information about other families’ children. MeetUps lets a parent record a child friend’s first name and care notes (for example, a food allergy) so playdate messages can include them. This information is entered by the parent, not collected from any child. It is minimized by the form’s design: Toach asks only for a first name and care notes — there are no fields for a child friend’s surname, birth date, or contact details, and no way to reach the child is stored in Toach. It is visible only inside your household subject to the connection’s privacy setting, and deleted when you delete the connection — including when the whole household is deleted. Child-role accounts in MeetUps see only their own friends’ names and their own upcoming MeetUps.
Your Choices
- Sign-in method. You can sign up with a username and password, or with Sign in with Apple. You can later link an Apple ID from Settings, or unlink one once the account has another way to sign in (a password) — unlinking an account’s only credential is refused.
- Active household. If you belong to more than one household, you can switch between them in Settings. Switching changes which household’s data the app shows and which household the AI assistant scopes its answers to.
- Leave a household. You can leave any household you belong to from Settings. If you are the only admin, the app will prompt you to promote a successor or delete the household entirely. If your Apple ID pays for the household’s subscription, leaving or deleting the household does not cancel it — subscriptions are managed in iOS Settings → Subscriptions, and the app reminds you at that moment.
- Invite codes. If you administer a household, you can generate, rotate, or revoke an invite code from Settings; joining with a code requires an admin’s approval (see above).
- Advertising. Toach shows no advertising of any kind: no third-party ads, no promoted content, and no marketing aimed at children. Toach does not sell personal information and does not share it for advertising — there is no targeted advertising to opt out of. Prompts about Toach’s own subscription — the paywall, or a note that your plan’s assistant allowance has run out — are part of the Service, not advertising. If any of this changes, this policy changes first and you will be asked to acknowledge it.
- Parents. The children’s controls — reviewing, deleting, and stopping further collection for a child’s account — are described under Children’s Privacy above.
- Notifications. You can choose which kinds of alerts you receive, and their timing, in Settings → Notifications.
- Connected calendars. You can disconnect Google or Microsoft at any time. Revoking access in the provider’s account settings will also stop calendar sync.
- Location. Location reporting is entirely optional. Decline the iOS permission prompt, or turn it off later in iOS Settings → Toach → Location, and flight departure alerts simply use a default travel estimate.
- Export your data. Settings → Your data → Export downloads everything Toach stores about you as a JSON file, at any time, without contacting anyone.
- Delete your account. Settings → Your data → Delete account permanently erases your account and personal data directly in the app. Some information in shared threads or shared task history may remain visible after account deletion, with personal identifiers removed where feasible. You can also contact the operator listed below for access, correction, or deletion requests.
- Sign out. Signing out clears your session token and active-household preference from that device.
Data Retention
Toach retains your information for as long as your account is active, and applies shorter windows to specific categories:
- Account, personal tasks, calendar connections, coins. Kept until you delete your account (Settings → Your data → Delete account), which erases them: your login, personal tasks, chat history, calendar connections and their tokens, credits, trades, and device records. Household chores you were assigned or completed stay with the household, de-identified — the pointers to you are removed along with your account, so they can no longer be tied to you. If you were a household’s only member, the household and its shared content are deleted with you.
- Assistant chat. Only a rolling window of your most recent messages is kept for conversational context (currently the last 50), and no message is kept longer than 3 days regardless; older messages are deleted automatically, and you can erase the whole history at any time from the Assistant screen.
- Sent notifications. A short log of the push notifications Toach sent you (title and text) is kept for 3 days so the assistant can tell you what a recent alert said, then deleted automatically. The assistant can read only your own notification log, not another member’s.
- Device location. Only your single most recent location fix is stored; each new fix overwrites the last. No location history exists.
- MeetUps. Connections, proposals, and care notes are kept until you delete the connection or delete your account. Deleting a connection does not touch the contact card on your phone.
- Calendar events. Event data from connected calendars is held in a short-lived, in-memory server cache covering roughly one year back and one year ahead, refreshed about every five minutes and replaced in full on each refresh — your provider remains the source of record. Disconnecting an account deletes its stored credentials and stops fetching.
- Deleting a calendar event. When you delete a calendar event through Toach — including when you ask the assistant to — the deletion is carried out at your calendar provider and Toach keeps no copy of the deleted event. The provider treats it as a normal cancellation: if the event had invited guests, they receive the provider’s standard cancellation notice, exactly as if you had cancelled it from the provider’s own app. Recovery, where available, is through your provider’s own bin (for example Google Calendar’s Trash or Outlook’s Deleted Items, typically kept for 30 days), which is outside Toach’s control and governed by their policies; the assistant can walk you through those steps.
- iPhone Calendar snapshot. Replaced in full each time the app syncs, and deleted when you turn the setting off or disconnect the iPhone calendar.
- Plans, credits and trades. Plans are kept until you delete them, leave the household, or delete your account. Credit ledgers and chore-trade records are the household’s fairness history and are kept while the household operates; your trade records are deleted when you delete your account.
- Operational records. Server logs and aggregate AI-usage metering (token counts and costs, not message content) are retained for operations and debugging and rotated on a fixed schedule.
- Backups. A complete encrypted copy of the database is taken daily, stored off-site, and kept for about 30 days; deleted data leaves the backup set as those copies rotate out.
Each third-party processor listed above handles data under its own data-processing terms (Anthropic’s Data Processing Addendum, Google’s Data Processing Terms, Microsoft’s DPA, and Apple’s developer terms).
Changes to This Policy
We may update this policy as Toach evolves. Changes will be posted on this page and reflected in the “Last updated” date above; material changes are announced with an in-app notice shown to each user the next time they open Toach.
Contact
Toach is operated by TransformNative LLC. Questions, requests, or concerns about this policy or your data can be sent to the household administrator or to the operator at info@toach.app.