Privacy Policy
Last updated: 22 August 2026
This Privacy Policy explains what personal data Epimeleia collects, why, and how you can exercise your rights over it. Epimeleia processes personal data as a controller for the account and asset data you enter, in accordance with the EU General Data Protection Regulation (GDPR).
Who we are
Epimeleia is currently operated as an independent project. [Legal entity name, registration number and registered address to be added here before this page is treated as final.] You can reach us at hello@epimeleia.app with any privacy question or request.
Information we collect
Account data: your email address and authentication identifiers, managed by Supabase Auth, and — if you sign in with Google — the basic profile information Google shares with us for that purpose.
Asset data you provide: properties, items, documents, receipts, photos, services, meter readings, consumables, comments and any other content you choose to add. This may incidentally include personal information you enter yourself, such as a note or a document.
Service data: your notification preferences and push notification token (if you enable push notifications), your email preferences, and — only if you supply one — your own AI provider API key, which is encrypted at rest and never shown back to you in full after you save it.
How we use your information
We use your data to provide the service you signed up for: storing your assets and documents, calculating and sending reminders, running the AI features you enable, and sending account and, if you opt in, lifecycle email. We do not use your data for advertising, and we do not sell it.
Legal basis for processing
We process account and asset data to perform our contract with you — providing the service you signed up for. We process optional data, such as lifecycle email or a connected Google Drive account, only with your consent, which you can withdraw at any time. We process limited data for security and abuse prevention under our legitimate interest in keeping the service safe.
Who we share data with
We use a small number of infrastructure providers ("sub-processors") to operate Epimeleia, each of which processes data only on our instructions and only to the extent needed to provide their part of the service: Supabase (database, authentication, file storage and edge functions, hosted in Frankfurt, Germany — eu-central-1) and Vercel (web application hosting).
Resend (delivery of account and, where you've opted in, lifecycle email) and Expo (delivery of push notifications to your device, if enabled).
AI providers — OpenAI, Anthropic and/or Google — only when you use an AI feature: with your own API key, requests go directly to your chosen provider under your own account with them; for a limited number of free receipt scans per day without your own key, requests are processed through an app-managed account with one of these providers. If you connect Google Drive, Google also processes the files you choose to sync there, under your own Google account.
International transfers
Your account and asset data is stored in the EU (Supabase, Frankfurt). Some of our sub-processors — including Vercel, Resend, and the AI providers — are based outside the EEA. Where that means data crosses into a country without an EU adequacy decision, we rely on Standard Contractual Clauses or an equivalent safeguard offered by that provider.
Cookies
The web app sets only the strictly necessary cookies used to keep you signed in, managed by Supabase Auth. We do not currently use analytics, advertising or tracking cookies. If that changes, we'll update this policy and ask for your consent first, as required by law.
How long we keep your data
We keep your account and asset data for as long as your account is active. You can ask us to delete your account and associated data at any time by contacting us at hello@epimeleia.app; we aim to complete deletion requests within 30 days. (A self-service delete-account option is planned for the app itself.)
Security
Data is encrypted in transit (TLS) and, for AI provider API keys, encrypted at rest using Supabase Vault. Access to your data is enforced at the database level with row-level security, so only you — and, for a shared property, household members you've explicitly invited — can read it.
Your rights
Under the GDPR, you have the right to access, correct, delete, restrict or object to our processing of your personal data, and the right to receive your data in a portable format. You also have the right to withdraw consent at any time where we rely on it, without affecting processing carried out before you withdrew it.
To exercise any of these rights, email hello@epimeleia.app. If you're not satisfied with our response, you have the right to lodge a complaint with your local data protection supervisory authority — in Greece, the Hellenic Data Protection Authority (dpa.gr).
Children
Epimeleia is not directed at children, and we do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
Changes to this policy
We may update this Privacy Policy as the service changes. We'll update the "last updated" date above, and for material changes we'll make a reasonable effort to notify active users before the change takes effect.
Contact us
Questions about this policy, or a request to exercise your rights? Email us at hello@epimeleia.app.