Baton Privacy Policy
Last updated: August 5, 2026
Baton is an app for two people who share a household to split chores. This page explains what we collect about you, why, who else sees it, and what happens to it if you delete your account.
We don't use advertising or analytics services of any kind, and we don't sell your data.
What we collect, and why
Account info. Your email address and password, so you can log in. Your password is stored in a form we can't read (hashed), not as plain text. When you're logged in, your device also holds a session token locally, so you don't have to log in every time you open the app.
Your profile in the household. The display name and color you pick when you set up your profile, so your partner can tell whose turn it is at a glance. Also which household you belong to and the invite code that pairs you with your partner.
Chore data. The names of the chores in your household, and a record of when you personally marked one complete. This is what makes turn-rotation work, what powers the short "undo" window after completing a chore, and what a future balance feature would be built on.
Notifications. If you turn on notifications, we store a push token for your device, a code that lets us address a notification to you specifically, not your name or any personal detail. When your partner nudges you, we send a short message to that token, and it includes the chore's name, for example, "The dishes are yours." That message passes through Expo, and then Apple or Google, on its way to your device; we don't keep a copy after it's sent, but those providers handle its contents in order to deliver it. If you name a chore something personal, that name travels through those third parties in plain text to reach you.
Technical information collected automatically. Every request your device makes, whether logging in, loading your chores, or registering for notifications, passes through our infrastructure providers, and like any web service, they see the IP address it came from as a normal part of handling the request. Our login system also keeps its own internal record of sign-ins that includes things like timestamps, IP address, and device information, as part of how authentication systems normally work. That record belongs to Supabase and is governed by Supabase's own policies, not tracked or used by us directly.
Stored only on your device, never sent to us. Whether you've seen the app's intro screens yet, and a couple of basic device checks (like whether you're on a real phone rather than a simulator) that decide if notifications can be turned on at all.
What your partner can see
A household in Baton is two people, and almost everything in it is visible to both. Your partner can see your email address, your display name, and your color. They can see every chore in the household, and the record of who completed each one and when. A shared household means shared visibility, and that's how the app is designed to work. But it should be stated plainly rather than assumed.
Who we share it with
We use a small number of infrastructure providers to run Baton. We don't share your data with anyone beyond what's needed to provide the app:
- Supabase. Hosts our database and handles login.
- Resend. Sends our password-reset and email-confirmation emails on our behalf, which means it handles the email address they're sent to.
- Expo. Delivers push notifications. Your device talks to Expo directly to register for notifications, and our server talks to Expo again each time your partner nudges you, sending it the notification's contents (see "Notifications" above).
- Apple and Google. Actually deliver the notification to your device once Expo hands it off to them (Apple for iPhones, Google for Android).
Each of these providers receives your IP address as a normal, unavoidable part of handling your requests, the same way any website or app's infrastructure does. How long they keep that, or anything else they log on their own systems, is governed by their own privacy policies, not this one.
What happens when you delete your account
Deleting your account is available in Settings. Here's exactly what it does.
Deleted: your login (email and password), your profile in the household (display name and color), your own chore-completion history, and your push notification token.
If you have a partner, and they're still in the household: the household, its invite code, and every chore in it survive your deletion. They keep using the app exactly as before. This is intentional. Deleting your own account shouldn't take your partner's shared chore list away from them.
Your partner's own completion history also stays. The only change is that if one of their past records happened to reference you (as the person whose turn it was before they completed something), that specific reference is cleared. Their record itself isn't deleted.
If you're the only member of your household, meaning you haven't paired with anyone yet or your partner already left, deleting your account deletes the household too, along with its invite code and every chore in it. Nothing is left behind.
Two things we want to be upfront about, rather than let you assume:
- A session token issued before you delete your account can stay valid until it naturally expires. Deleting your account doesn't cut off an already-issued session instantly.
- We delete the data listed above from our active database when you use the delete-account feature. We haven't confirmed how long backups of our database are retained, or exactly what Supabase, Expo, Apple, and Google retain on their own systems afterward. Those are governed by their policies, not ours, and we're not going to claim a timeline we haven't verified.
Children's privacy
Baton isn't intended for children, and we don't knowingly collect data from them.
Changes to this policy
We may update this policy as the app changes. If we do, we'll change the date at the top.