Privacy Policy

Last updated: 2026-08-21

This Privacy Policy explains how Mojave Labs LLC (“Mojave Labs,” “we,” “us,” or “our”) handles personal information when you use the HomeCrew mobile application or visit the HomeCrew website (together, the “Service”). Mojave Labs LLC is the controller responsible for that information. We are based in Illinois, United States, at 2501 Chatham Rd, Suite N, Springfield, Illinois 62704, United States.

Information we collect

Calendar access stays on your device

Calendar sync is optional. If you enable it and grant permission, HomeCrew creates or updates chore events in a device calendar named HomeCrew and reads that calendar to keep those events synchronized. Calendar event content and the selected calendar ID are not uploaded to Mojave Labs, Supabase, PostHog, or Sentry. PostHog receives only aggregate counts of events created, updated, or deleted. Your system calendar provider may sync the calendar under the provider account and terms you configured on the device.

Minimum age and children’s privacy

The HomeCrew Terms require account holders to be at least 18 years old. HomeCrew does not ask for or collect your date of birth, is not directed to children, and does not knowingly collect personal information from children under 13. If you believe someone under 18 has created an account or provided personal information to HomeCrew, contact us so we can suspend and delete the account and associated information.

Why we use information and our legal bases

Service providers and disclosures

We disclose only the information needed for these processors to provide their services on our instructions:

We may also disclose information when required by law, to protect rights and safety, or as part of a merger, financing, acquisition, or sale after appropriate notice and protections. We do not sell personal information, show ads, disclose data to data brokers, or share HomeCrew data for cross-context behavioral advertising.

International transfers

Mojave Labs and these providers may process information in the United States and other countries whose laws may differ from those where you live. Where required, we use recognized safeguards such as contractual data-protection terms and Standard Contractual Clauses. You may contact us for information about safeguards relevant to your data.

Data retention & deletion

We use the following maximum periods, unless a longer period is required by law or needed for an active legal claim:

Data class Retention
Account, email/sign-in identity, membership, and active household content While the account or household is active. Live account records are removed when account deletion completes. A shared household’s chores and history remain until that household is deleted, but the departing account’s direct attribution is removed.
Database backups Up to 7 days after deletion under the production backup schedule. Backups are isolated for disaster recovery and are not used to restore a deleted account into the live Service.
Invitations Deleted no later than 30 days after the invitation expires.
Unsuccessful invitation-claim timestamps Deleted after 30 days.
Push tokens and delivery records Active tokens remain until replaced or the account is deleted; invalid tokens are deleted within 30 days. Completed or cancelled delivery jobs are deleted after 90 days.
In-app notifications Deleted after 365 days or earlier with account/household deletion.
Authentication and email-delivery records Supabase retains your authentication identity while the account is active. Our current email delivery provider retains email message and event data for up to 30 days. If we terminate that provider account, remaining customer data is deleted within 90 days, except where a longer period is required by law.
PostHog analytics Retained while your account is active. When you delete your account or submit a verified erasure request, the linked person, events, and recordings are queued for deletion.
Sentry diagnostics Deleted after 30 days.
Supabase service, API, authentication, and security logs Up to 7 days under the production plan.
HomeCrew website request logs Cloudflare request logs are not retained by default. If temporary retention is enabled to investigate abuse or an incident, we delete them within 30 days.
Support communications and rights-request records Support content is deleted within 3 years after the matter closes. A minimal compliance record may be kept for up to 7 years.

You can permanently delete your account in HomeCrew from Settings → Delete account. See our account-deletion page for the data removed, the limited shared-household records that may remain, and an assisted request option if you cannot use the app.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, restrict, or receive a portable copy of personal information; to object to certain processing; to withdraw consent; and to appeal our response. You may also complain to your local data-protection authority. We will not discriminate against you for exercising a privacy right.

Use Settings → Delete account, follow the account-deletion instructions, or email us to exercise a right. We may need to verify your identity. An authorized agent may submit a request where applicable law permits it, subject to verification of the agent’s authority.

Security

We use administrative, technical, and organizational safeguards designed to protect information, including encrypted network transport, access-controlled service accounts, and row-level database authorization. No system is completely secure, so we cannot guarantee absolute security.

Changes to this policy

We may update this policy as HomeCrew or applicable law changes. We will post the revised policy with a new “Last updated” date and provide additional notice when required.

Contact

Mojave Labs LLC
2501 Chatham Rd, Suite N
Springfield, Illinois 62704
United States
support@heyhomecrew.com

← Back to HomeCrew