Privacy policy
This covers the CoHiro app, and the cohiro.app website itself (section 10). The niugio.com website policy is separate and covers only that website.
Last updated: 14 September 2026.
The short version
CoHiro stores your email address, a display name, and whatever you and the other members of your household put into your shared list and inventory. It is stored in Frankfurt, Germany; some data passes through service providers outside the EU, as explained in section 5. There is no advertising, no tracking, no profiling, and nothing is sold or shared with anyone for marketing.
Three things surprise people, so read them first: notifications quote what you typed, your display name can default to the part of your email address before the @ sign, and deleting your account does not delete what you added to a shared household.
1. Who is responsible
Niugio UG (haftungsbeschränkt), Urbanstraße 71, 10967 Berlin, Germany.
Email: support@cohiro.app.
Company details: Impressum.
2. What data we process, and why
Your account. Your email address is how we tell accounts apart, and where we send a code if you forget your password. You type it at sign-up, or Apple or Google passes it to us, already verified, when you use their sign-in. A CoHiro password is stored only in protected form, never as readable text; with Apple or Google there is no CoHiro password at all, and we never receive the one you use with them. One email address means one account, however you sign in.
The provider confirms who you are and shares your verified email address, a user id, and, if you agree, your name; we do not ask for anything else. If you use Apple's Hide My Email, the relay address Apple creates is the address we hold and write to: we never learn your real one, and forwarding is controlled from your Apple ID settings.
Your display name. Choosing one is optional; having one is not. If you skip it, we use the name Apple or Google shared, and failing that the part of your email address before the @ sign. You can change it at any time under Account.
What you and your household put in. What the app is for: item names, shopping-list lines and the notes on them, the names of your shelves, stores and household, whether something is in stock or running low, and a history of who changed what. All of it is free text, so it contains whatever you type.
Your devices. If you allow notifications, we store a push token so we can reach that device, plus your time zone and, if you set them, your quiet hours, so notifications respect your local clock. While the app is open, your household can see a green dot against your name: it is on by default, you can switch it off under Account, and it disappears the moment you close the app. We do not collect your location, your contacts, or your advertising identifier. The camera is used to scan an invite code to join a household and to scan product barcodes when you add items. It takes no photos, and no image ever leaves your device. Only the information read from the code or barcode is processed. When you scan a product we do not yet recognise and give it a name, we send the barcode together with the name, shelf and brand you chose to improve our shared product catalogue. This contribution is not linked to you, your account or your household.
Feedback you send us. If you use the feedback sheet, we store what you wrote, the app version, the platform, and basic diagnostic details of the device it came from (its model, operating-system version, screen size, text-size setting and app language), so we can reproduce the problem, and whether you agreed to be contacted about it; if you agreed, we use your account's email address, and only about what you sent. These device details are diagnostic, not identifying: no advertising ID, serial number or other persistent device identifier. Screenshots are optional and stored privately, and before upload the app removes the photo metadata that pictures normally carry, including location. Feedback is not household content: your household cannot see it, or see that you sent it.
What is required. An email address is the one thing we cannot do without: there is no account, and no household, without one. Choosing your own display name, notifications, quiet hours, the online dot, feedback and screenshots are optional: declining any of them only means that feature is unavailable. No law requires you to give us any of this.
Children. CoHiro is not intended for anyone under 16, and we do not knowingly allow anyone under 16 to create an account. If you believe a child has one, write to us and we will remove it.
3. Legal bases
The GDPR requires a legal ground for every use of your data. Ours are:
- Contract (Article 6(1)(b)): creating, providing and closing your account, everything your households put in, invites, and the features you turn on: the data that providing CoHiro consists of.
- Legitimate interests (Article 6(1)(f)): crash and diagnostic reports (learning the app is broken so we can fix it), the online dot (household coordination), reading the feedback you choose to send, and keeping what you added to a shared household after your account is deleted (the remaining members' interest in the list they still use, section 8). You can object to any of these at any time (section 9).
- Consent (Article 6(1)(a)): contacting you about your feedback. The switch is off unless you turn it on, and you can withdraw consent at any time.
- Legal obligation (Article 6(1)(c)): the processing the law itself requires of us, such as acting on the data-protection rights in section 9.
The notification permission prompt is your phone asking, not us collecting legal consent: our ground is that you asked for the feature.
4. Sharing within your household
CoHiro is a shared app, and that is the point. Everything you add to a household is visible to every other member of it, including your display name against the things you added. Do not put anything in a note you would not want your household to read. Feedback you send us is the one exception: it stays between you and us.
5. Service providers and international transfers
Your account, and everything in your households, is stored in the European Union, in Frankfurt. Three things are narrower: notifications leave the EU to reach your phone (section 6), brief server tasks may run outside the EU without storing your data, and our providers' support and platform operations can involve access from outside the EU, covered by the safeguards below.
We use the following service providers and other recipients:
| Who | What for | Where |
|---|---|---|
| Supabase | Storing your account and everything in your households | Frankfurt, Germany (the database and sign-in, running on Amazon Web Services) |
| Sentry | Crash and diagnostic reports | European Union (the reports themselves) |
| Resend | The emails we send you, and your feedback, which reaches us as email | Sent from Ireland via Amazon SES, stored in the United States |
| Expo, Apple, Google | Delivering notifications, only if you turn them on | Outside the EU |
| Google Workspace | Our support inbox: receiving and storing the email you send us, feedback included | Google's data centres, inside and outside the EU |
Where a provider processes personal data on our behalf, it is contractually bound to process it only on our documented instructions, except where the law requires otherwise. Where personal data is transferred outside the European Economic Area, we use the applicable GDPR transfer mechanism: an adequacy decision, including the EU-US Data Privacy Framework for participating US organisations, or the European Commission's standard contractual clauses. Write to us to learn which safeguard applies to a particular transfer, or for a copy of the applicable clauses.
Apple and Google may also process data as independent controllers, for example when you use their sign-in or their platform services; their own privacy policies apply to that processing.
Signing in with Apple or Google happens with the provider, under its own privacy policy, so the provider learns that you use CoHiro; what it passes to us is stored in Frankfurt like everything else.
6. Notifications
When someone starts a shop or calls one off, the household gets a notification. It can include your household's name, members' display names, and any note that was written. That text passes through Expo's push service and Apple's or Google's notification service, and it can appear on a locked screen. A note is not confined to Germany, or to the app: keep that in mind when writing one.
7. Crash reports and diagnostics
When the app fails, it sends a crash report to Sentry so the fault can be fixed: the error, where in the code it happened, and technical details such as the device model and operating system version. Reports do not contain your name, your email address, or your household's content, and they are keyed to a random identifier not linked to your account. The app can also send occasional technical diagnostics of the same kind. Crash reporting cannot currently be turned off; it is how we learn that something is broken. We use no advertising or analytics services, and there is no profiling of any kind.
8. Retention and account deletion
Your account and its contents are kept until you delete them: there is no automatic expiry, and we do not delete inactive accounts. The household activity history is removed automatically after two years. Feedback is deleted at the latest two years after it was sent. Crash reports are deleted by Sentry after 30 days.
You can delete your account yourself, in the app under Account; full instructions are on the account deletion page. Deletion removes your email address, display name, settings, device records, the identity Apple or Google passed to us, and any screenshots you attached to feedback. The words of your feedback are kept, no longer linked to you, while they remain relevant to the issue you reported, and are then deleted; the same applies to the copy in our support inbox. Email us if you want them removed sooner. Once a deletion completes, we keep no record of the account beyond short-lived operational logs.
What deletion does not remove: in a household you shared with others, the things you added stay, because the others still use them; they simply stop carrying your name. If you ran that household, the role passes to another member. If you were its only member, the household is deleted with your account, immediately and irreversibly.
9. Your GDPR rights
You can ask us for a copy of your data, to correct it, to delete it, to restrict how it is used, to object to its use, or to receive what you gave us in a portable, machine-readable form. Much of this you can do in the app; for the rest, write to support@cohiro.app.
Where we rely on a legitimate interest (crash reports, the online dot, reading feedback, entries kept for your former household), you can object at any time: use the off switch where one exists, or write to us. Where we rely on your consent (being contacted about feedback), you can withdraw it at any time, without affecting anything done before.
You also have the right to complain to a supervisory authority. Ours is the Berliner Beauftragte für Datenschutz und Informationsfreiheit.
10. Website hosting
cohiro.app is a static website hosted by GitHub, Inc. (San Francisco, United States) as our processor. GitHub receives the connection data every web server receives, your IP address among it, and processes it for us to deliver the page and keep it secure: our legitimate interest under Article 6(1)(f), with logs deleted after a short period and the objection right of section 9. GitHub is certified under the EU-US Data Privacy Framework, with standard contractual clauses in place as well; details are in GitHub's privacy statement. The website sets no cookies and runs no analytics.
If this policy changes in a way that affects you, we will say so in the app rather than quietly updating this page. The date at the top always reflects the current version.