This Policy explains what data the Comfort Home app collects, why we use it, and what rights you have. Operator: Comfort Home. Privacy contact: privacy@comforthome.app.
1. Who we are
Comfort Home is a mobile service for property reviews by address. Data is processed to operate the App, ensure security, run analytics, and (with your consent) for monetization.
2. What data we collect
2.1. Account data
- Firebase Authentication identifier (UID);
- email, name, profile photo — if you sign in with Google or Apple (per the provider's settings);
- user role (e.g., user, paid, moderator) for feature access.
2.2. Content and activity
- review text, moderation results and statuses, ratings, searched addresses, and saved addresses/reviews;
- reactions (likes/dislikes), if you use them;
- notification settings for saved addresses (if enabled).
2.3. Technical and analytics data
- in-app events (screens, buttons, errors) via Firebase Analytics / Crashlytics;
- analytics session identifier, device model, OS and App version;
- FCM token for push notifications (if you grant permission).
2.4. Purchase data
- whether you have a subscription and the plan type (via StoreKit / the paid role in Firestore);
- Apple processes payment data; we do not store card numbers.
2.5. Advertising (if enabled)
- advertising identifiers (IDFA) — only after your consent via App Tracking Transparency (iOS);
- ad impression/click data via Google AdMob, per Google's policy.
2.6. Location and maps
Address search uses Google Places / Maps. We may send search queries to the maps provider; we do not keep precise GPS tracking running without your action in the App.
2.7. Automated review moderation
New and resubmitted reviews are screened for safety before or immediately as they are published:
- the server first performs local automated checks for obvious email, Ukrainian phone-number, and apartment-number patterns;
- if those checks already identify potential personal data, the text is not sent to OpenAI and remains non-public until a moderator reviews it;
- otherwise, the review text is sent to the OpenAI Moderation API to classify potentially harmful content;
- we do not intentionally attach your UID, email, profile name, or saved addresses to the OpenAI request. However, any information you include in the review itself may be processed as part of that text;
- a clean result may be approved automatically; flagged or ambiguous text is not automatically rejected and waits for a moderator's decision.
We retain the review text, its status, and limited moderation-result categories in Firestore for moderation and audit purposes. The internal audit log does not duplicate the full review text, the secret API key, or the complete OpenAI response.
3. Why we use data
- to provide and improve App features;
- content moderation and abuse prevention;
- notifications about new reviews for saved addresses (for subscribers);
- processing subscriptions and restoring purchases;
- showing ads to free users (if enabled);
- analytics, stability, and bug fixes.
Legal basis (GDPR): performance of a contract (providing the Service), legitimate interest (security, analytics), and consent (push, ad tracking, optional features).
4. Who we share data with
- Google / Firebase — hosting, database, auth, analytics, crashlytics, messaging;
- Apple — Sign in with Apple, In-App Purchase;
- Google — Sign-In, Maps, Places, AdMob (where applicable);
- OpenAI — processing review text only through the Moderation API for automated content-safety screening;
- other providers — only when needed and under appropriate data processing agreements.
According to OpenAI's current API documentation, API data is not used to train models unless the customer explicitly opts in, and the /v1/moderations endpoint lists no customer-content retention for abuse monitoring or application state. Current processing terms are described in OpenAI's API data controls documentation.
We do not sell your personal data to third parties in the sense of "selling a customer base".
5. Storage and security
Data is stored in Firebase (the region depends on project settings). We apply Firestore access rules, HTTPS, and role restrictions. No system is 100% secure; report incidents to privacy@comforthome.app.
6. Retention
- reviews and profile — while the account exists or until deleted on request;
- limited moderation results — with the review, or longer only where reasonably needed for safety, audit, or legal requirements;
- analytics — per Firebase settings (default retention periods);
- data required by law or for disputes — to the extent permitted by law.
7. Your rights
Depending on applicable law (including GDPR / Ukraine's "On Personal Data Protection" law) you may:
- access your data;
- correct inaccurate data;
- delete your account and related data (in-app feature or by email request);
- restrict or object to processing (where applicable);
- withdraw consent for push / ad tracking in iOS settings;
- lodge a complaint with a supervisory authority.
8. Children
The Service is not intended for children under 16. We do not knowingly collect children's data. If you believe a child has provided data, contact us for deletion.
9. International transfers
Providers (Firebase, Google, Apple, OpenAI) may process data on servers outside Ukraine/the EU with appropriate safeguards (standard contractual clauses, etc.).
10. Changes to this Policy
We update this page when features change (advertising, subscriptions, push). The date at the top reflects the current version.
11. Contact
Email: privacy@comforthome.app
General support: support@comforthome.app