Privacy
Last updated September 22, 2026
This policy covers two things: this website and its waitlist, and the Hearth app, which is in early access. The first part is about the website. The second part is about what you store inside Hearth and who can see it. Questions go to hello@myhearthhub.com.
Part one: this website and the waitlist
What we collect on the website
If you join the waitlist, we collect the email address you type and a label recording which form on the page you used. If you arrived from a link with campaign parameters (the kind an ad or a newsletter adds to a URL), we keep those alongside the signup so we know which of our efforts brought you here.
We also collect usage analytics: which pages are viewed, how long a visit lasts, the page that referred you, your browser and device type, and the country or region your connection comes from. This is aggregated to understand how the site is used. It is not used to build a profile of you across other sites.
The website does not ask for your name, your household, or anything about the people in it. There is no account to create on the website.
What we do with it
- Email you once when early access is ready for you.
- Occasionally email you about the launch. Every message has an unsubscribe link.
We do not sell, rent, or trade your email address.
Who processes website data
- Resend stores the waitlist and sends the email. Their privacy policy is at resend.com/legal/privacy-policy.
- Vercel hosts this site and keeps standard server logs, including IP addresses, for security and operations.
- PostHog stores the usage analytics and the signup event, on servers in the United States. Their privacy policy is at posthog.com/privacy.
Cookies on the website
This site sets one first-party analytics cookie, from PostHog, so a return visit is counted as the same visitor rather than a new one. It is readable only by this site. We run no advertising cookies and no cross-site tracking.
If you tell us you have joined the waitlist from an ad, we may send the fact that a signup happened, with your email address in hashed form, to the platform that showed the ad so it can measure the campaign. We do not do this today; the date at the top of this page will change when we start.
Keeping and deleting waitlist data
We keep your address until you unsubscribe or ask us to remove it. To be removed, use the unsubscribe link in any email or write to hello@myhearthhub.com and we will delete it.
Part two: the Hearth app
Hearth is a place a household keeps the things it otherwise re-looks-up: the wifi password, the door code, the pediatrician, a child's allergies, the sitter's instructions. Most of what goes into it is about people in your life. You decide what goes in, and you decide who sees it.
Your account
To create an account we collect your email address. You sign in with a six-digit code we email you, with a password if you choose to set one, or with Google. If you use Google, Google tells us your email address and basic profile information; we use the email address to identify your account and we do not post anything to your Google account.
What you store in Hearth
Everything below is entered by you or another member of your household. We collect none of it on our own.
- Your household: its name and time zone.
- People in it: adults, kids and pets, with names, birthdays, allergies, medications, notes, and for pets a species, breed and microchip number.
- Contacts: the doctors, sitters, neighbors, teachers and relatives you add, with names, phone numbers, email addresses, addresses, how they relate to your family, and whether they are an emergency contact for someone.
- Cards: the details you file under a person, a contact, a home or the household. The starting templates cover wifi, door and alarm codes, parking, trash day, school, medical (doctor, pharmacy, insurance plan and member ID), the vet, mortgage (lender and loan number), home insurance (provider and policy number) and utilities. You can add your own.
- Homes: a name, an address and notes, plus any documents you upload (deeds, policies, statements: PDFs, photos, Word and Excel files up to 25 MB each).
- Lists and wishlists: the items, notes, dates and repeat schedules you give them, and a record of when repeating items were completed.
- Shares: the label, PIN and expiry date of each share link you create, and which records it includes.
- Invitations: the email address of each person you invite into your household, the role you gave them, and the name you typed for them.
Codes, passwords and account numbers
Fields you mark as secret (door, gate and alarm codes, the wifi password, insurance member IDs, loan and policy numbers) are encrypted inside the app before they reach the database, with a key that is kept on the app server and never stored in the database. They are never searched or indexed. They are shown only when a member presses Show, or when someone holding a share link enters its PIN and asks to see them.
Who in your household sees it
Each member has a role. Owners and editors can add and change anything. Viewers can read what the household holds and tick items on a list, and nothing else. You add a member by inviting their email address; an invitation works for seven days and only for the address it was sent to. An owner can change roles and remove members. Anyone can leave.
Share links
A share link lets someone outside your household, such as a sitter or a grandparent, see a slice of it on their phone without an account. You choose what the link includes and set a PIN. Anyone who has the link and the PIN can open it, so treat both like a key.
- A link shows only the records you granted it. Documents are never included in a link.
- Secret fields stay hidden until the holder asks to see one, and each look is recorded.
- Every PIN entry is logged with the time, the visitor's browser type, and a hashed form of their IP address. Editors can read this log on the share's page. We keep this log for 90 days, then delete it.
- After five wrong PINs the link locks. You can end a link at any time, and it stops working immediately, including in any tab that has it open.
What we record automatically
Our hosting provider keeps standard server logs of requests to the app, including IP addresses. Our authentication provider keeps a record of sign-ins. The share log above is kept with your household's data. There is no analytics, advertising or tracking script inside the app.
Cookies in the app
The app sets a sign-in session cookie, a cookie remembering which household you are viewing if you belong to more than one, a cookie remembering your light or dark theme, and, for someone opening a share link, a cookie tied to that one link that remembers they entered the PIN. Nothing else.
Who processes app data
- Supabase runs the database, sign-in and file storage, in the United States (Ohio). Their privacy policy is at supabase.com/privacy.
- Vercel hosts the app and keeps standard server logs.
- Resend sends the app's email: sign-in codes, password resets and household invitations.
- Google, only if you choose to sign in with Google.
Each of these processes data on our instructions to run Hearth. None of them is permitted to use your household's information for their own purposes.
How we use app data
- To store your household's information and show it to the people you chose.
- To send the emails you or a member triggered: sign-in codes, resets, invitations.
- To keep the service secure, including the PIN lock and the share log.
- To answer you when you write to us.
We do not sell or rent it. We do not use it for advertising. We do not use what you store to train AI models. We do not read it except when you ask for help with your account or when we must to keep the service running.
Keeping and deleting app data
- Archiving a person, contact, card, home or list hides it from every screen and every share link. Removing a document deletes the file for good.
- Leaving a household removes your access to it. Your name and the records about you stay in that household, because they are the household's information; an owner can archive them.
- You can delete your account yourself from Settings. If you are the only member of a household, the household and everything in it are deleted with the account, including its documents. If other members remain, the household stays with them and your account is removed from it. If you own a household that other people belong to, the app asks you to make someone else an owner first.
- An owner can download a copy of the household from Settings: one file with every record in it. Private values such as codes and passwords are left out unless the owner chooses to include them, and links to documents in the file work for one hour.
- Our database provider keeps routine backups for a limited time; deleted data leaves those on the provider's schedule.
Children
Hearth is for the adults who run a household. Accounts are for adults. Information about a child is entered by that child's parent or guardian and is shown only to the people that adult chooses. We do not knowingly let anyone under 13 create an account, and a parent may give a child a share link that shows only what the parent selected. If you believe a child has created an account, write to us and we will delete it.
Security
Data travels over encrypted connections and is encrypted at rest by our providers. Secret fields carry a second layer of encryption described above. Every database table enforces household boundaries, so one household cannot read another's rows. Share links carry a PIN, a lock and a log. No service can promise perfect security; if we learn of a breach affecting your information, we will tell you by email without undue delay and as the law requires.
Where data lives
In the United States. If you use Hearth from elsewhere, you are sending your household's information to the United States, where it is stored and processed.
Your rights
Depending on where you live, you may have the right to access, correct, export, or delete the information we hold about you. Inside the app you can read and change what your household holds, archive what you no longer want, download a copy of your household and delete your account, all from Settings. For anything else, email hello@myhearthhub.com and we will handle it.
Changes
If this policy changes, the date at the top changes with it. Material changes will be emailed to everyone on the waitlist and to every account holder.
Contact
Questions go to hello@myhearthhub.com.