Privacy Policy
Last updated: August 2, 2026
1. Overview
This Privacy Policy explains how Horme ("we," "us") collects, uses, stores, and shares information when you use our website and app. By using Horme, you agree to this Policy. For how the product works overall, see our Terms and Conditions.
2. Information we collect
- Account data: If you register, we collect information such as email address, name or display name, username, password (stored by our auth provider in hashed form), and OAuth profile details when you sign in with Google (for example email and profile picture).
- App content: Tasks, categories, team membership, achievements, preferences, avatars you upload, and similar content you create or configure.
- Guest / device data: In guest mode, task and preference data may be stored locally in your browser (for example localStorage). That data generally stays on your device unless you later create an account and sync.
- Optional integrations: If you connect a Gemini API key, Google Sheets/Calendar credentials, or similar BYOK secrets, we store what is needed to provide those features (often encrypted at rest for registered users). We do not use your keys for unrelated purposes.
- Notifications: If you enable push notifications, we store a push subscription endpoint and related keys so we can send reminders you requested.
- Usage and technical data: Basic logs and diagnostics may include IP address, device/browser type, timestamps, and error information needed to operate and secure the Service.
3. How we use information
We use information to:
- Provide, sync, and improve Horme (tasks, matrix, gamification, teams, profiles)
- Authenticate you and secure accounts
- Send transactional messages such as team invites (when you request them)
- Deliver push reminders you opt into
- Show public profile or leaderboard details only when you enable those settings
- Prevent abuse, debug issues, and comply with law
We do not sell your personal information.
4. Sharing
We share information only as needed to run the Service, including with:
- Infrastructure providers such as Appwrite (authentication, database, storage, functions)
- Auth and identity providers such as Google when you choose Google sign-in
- Email and messaging vendors used for invites or similar transactional mail
- Other users when you join teams, accept invites, or publish a public profile / leaderboard presence
- Legal authorities when required by law or to protect rights, safety, and the Service
5. Cookies and local storage
We use browser storage (such as localStorage) for themes, guest data, session fallbacks, and similar client-side state. Session cookies may be used when our API is served from a custom domain under the same site as the app. You can clear site data in your browser at any time; doing so may sign you out or erase guest progress.
6. Data retention
We retain account and synced content while your account is active and for a reasonable period afterward if needed for backups, dispute resolution, or legal obligations. Guest data persists until you clear it or your browser removes it. You may request deletion of account data by contacting us.
7. Security
We use industry-standard measures appropriate to our size and architecture (HTTPS, access controls, encrypted storage of certain secrets). No method of transmission or storage is 100% secure. Protect your devices, passwords, and API keys.
8. Children
Horme is not directed at children under 13 (or the minimum age in your region). We do not knowingly collect personal information from children. If you believe a child has provided us data, contact us and we will take appropriate steps.
9. International users
The Service may be hosted or processed in regions where our providers operate (for example Appwrite Cloud regions). By using Horme, you understand your information may be processed outside your home country, subject to appropriate safeguards where required.
10. Your choices
- Use guest mode without creating an account
- Update profile, public visibility, and notification preferences in Settings
- Disconnect optional integrations and remove stored keys where the UI allows
- Request access, correction, or deletion by emailing us
Depending on where you live, you may have additional rights under laws such as GDPR or CCPA. Contact us to exercise those rights.
11. Changes
We may update this Policy periodically. The "Last updated" date at the top will change when we do. Continued use after an update means you accept the revised Policy.
12. Contact
Privacy questions or requests: craftedbyom@gmail.com.