Android-specific privacy policy. This policy applies only to HouseHum package com.ryantinklepaugh.househum. It does not change the iOS app’s privacy policy or receipt history.
Scope and controller
Uncommon Weather LLC controls the processing described here. Contact team@uncommonweather.com. HouseHum is an appliance baseline-and-maintenance evidence record that documents one repeatable phone placement and operating state, qualifies a personal baseline with three agreeing captures, compares later checks, and preserves service events with honest before/after links.
Information handled
- appliance name, type, location, notes, documented phone placement, and operating state
- quality-qualified 27-band spectral fingerprints, relative levels, detected tonal peaks, baseline sessions, repeatability assessments, and condition-check results
- maintenance or service events, linked pre/post-service evidence, reminder cadence, and locally generated PDF/CSV reports
- purchase entitlement and legal-choice evidence
Microphone access activates only after the user starts a foreground capture. Temporary PCM samples are reduced on-device to a 27-band fingerprint and discarded; no replayable recording is retained and HouseHum never listens in the background. Notification permission is optional and used only for a reminder cadence the user chooses.
Product storage and providers
HouseHum stores appliance identity, documented phone placement and operating state, quality-qualified spectral fingerprints, three-run baseline assessments, relative drift results, maintenance events, linked before/after evidence, reminder choices, and local reports in app-private storage. Temporary PCM is discarded after fingerprinting, and reports leave only through a user-directed Android share action.
Google Play and RevenueCat process purchase and entitlement state. Supabase receives only privacy-minimal Legal6 choice evidence. HouseHum has no product-data backend and does not upload appliance records, microphone samples, fingerprints, or reports.
Legal-choice evidence and abuse prevention
To preserve your choice and prevent forged receipts, the app may send privacy-minimal evidence to Supabase-hosted services: package ID, document versions and hashes, acceptance or withdrawal state, coarse adult age band and role, timestamps, a random installation identifier, request identifiers, an Android Keystore public-key proof, and—when configured—Google Play Integrity verdict material. We also process connection metadata such as IP address, user agent, response status, and rate-limit state for security, reliability, and abuse prevention. We do not send your ordinary product records with legal-choice evidence.
Purchases
Google Play supplies transaction and purchase-token data, and RevenueCat supplies entitlement and offering state. We do not receive your full payment-card number.
Retention and deletion
Local records remain until the user deletes an appliance or all app data or removes the app. Temporary report files follow app-cache and deletion behavior. A deliberately shared report remains with the selected destination until removed there. Legal-choice evidence follows the separate evidentiary retention described below.
Server-side legal evidence is retained to prove and honor the choice, withdrawal, integrity, and retry history it records. Security logs are retained only as reasonably needed for fraud prevention, troubleshooting, and legal compliance. Contact us to request access or deletion; we may retain evidence where necessary to establish, exercise, or defend legal claims.
Choices and rights
You can deny optional Android permissions, decline or withdraw legal consent, manage purchases where applicable, and request privacy help. Depending on where you live, you may have rights to access, correct, delete, restrict, object, or appeal. We do not discriminate for exercising a privacy right.
Age boundary
The app is not directed to anyone under 18. We do not knowingly collect a precise birth date through the legal-choice flow.
Security and transfers
We use reasonable technical and organizational safeguards, but no device, network, or storage system is guaranteed secure. Providers may process information in the United States or other countries subject to applicable safeguards.