Skip to content

Legal

Privacy Policy

HomeSlate is a household ledger for tracking home services and payments. It works offline, and your ledger stays on your phone unless you choose to turn on cloud backup. This policy explains, in plain language, exactly what the app and this website hold, who else ever sees it, and how to get rid of it.

Last updated August 14, 2026 · Read the Terms of Service

The short version

HomeSlate is a household ledger that works offline. Your entries, services, and payments live on your phone. Nothing leaves your device unless you create an account to turn on cloud backup. If you never make an account, no ledger data of yours ever reaches us.

  • No account is required to use the app.
  • No contacts, no location, no photos, no advertising identifiers — ever.
  • We do not sell your data, and we do not share it with advertisers or data brokers.
  • An account is the only thing that sends your ledger off the device, and you turn it on yourself.
  • You can wipe everything from Settings → Clear all data, on your own, without asking us.

Who we are, and what this covers

HomeSlate is made by Kreativish AI, powered by SMAT Solutions Pvt. Ltd., a private limited company in India. Where this policy says "we", that is the company, and it is the one responsible for the data described here. This policy covers the HomeSlate mobile app on iOS and Android and the HomeSlate website. It does not cover the App Store, Google Play, or anything else you reach by leaving the app. For anything in this policy, write to kreativish.ai@gmail.com and a person will answer.

What stays on your phone

Almost everything. The app is built offline-first, so the ledger is written to your device's own storage and read back from there. With no account, this list never leaves the phone:

  • Services you set up — the name you gave the vendor, which template it came from, the rate, the unit, any monthly commission, and the delivery schedule.
  • Daily entries — the date and the quantity you logged, plus a snapshot of the rate at the time so old months do not change when a rate does.
  • Payments you recorded — amount, date, and which service it settled.
  • Preferences — currency, appearance, and the times you asked to be reminded.
  • Your notification inbox — the reminder messages the app has shown you.
  • Nothing else. There is no hidden second copy.

If you create an account

An account exists for one reason: so a lost or replaced phone does not cost you your ledger. It is optional, and the app is fully usable without one. When you make an account, this is what is held with our cloud provider (Supabase):

  • Your email address, and your password stored as a secure one-way hash — we cannot read your password, and neither can our provider.
  • A six-digit code sent to your email to confirm the address or reset a password.
  • A copy of your ledger — services, daily entries, payments, and your currency and setup preferences — so it can be restored on another device.
  • An optional display name, if you set one.

How your cloud copy is kept apart

Every synced row is stamped with your account id, and the database enforces at the row level that a signed-in account can only ever read and write its own rows. There is no shared table, no vendor-side view of your ledger, and no way for another HomeSlate user to reach your data. Your session token is held in your device's secure keystore — the iOS Keychain or the Android Keystore — not in ordinary app storage, and every request travels over an encrypted connection.

What we never collect

Some of this is worth stating flatly, because a ledger app could plausibly ask for all of it and this one does not.

  • No contacts or address book.
  • No location, at any precision, at any time.
  • No photos or camera access.
  • No advertising identifiers, no ad SDKs, no cross-app tracking.
  • No microphone, no calendar, no health data, no files outside the app.
  • No selling, renting, or sharing of your data with advertisers or data brokers. There is no version of HomeSlate where your ledger is the product.

Reminders and notifications

Reminders are scheduled by your phone, on your phone. When you set a nightly log reminder or a month-end settle reminder, the app asks the operating system to fire it locally at that time. No reminder content is sent to a server, there is no push service holding a device token, and the reminders keep working with the phone in aeroplane mode. Turning notifications off in Settings or in your OS settings stops them entirely.

Subscriptions and payments

Pro is sold by the App Store and Google Play, and subscription status is managed through RevenueCat. Payment itself never touches HomeSlate.

  • We never see, receive, or store your card, UPI, or bank details. The store handles payment end to end.
  • RevenueCat holds an anonymous purchase identifier and your entitlement status so the app knows whether Pro is active and can restore it on a new device.
  • Your ledger is not sent to RevenueCat or to the stores.
  • Cancelling is done in your App Store or Google Play account, not here — we cannot cancel it for you.

Crash reports and diagnostics

When crash reporting is enabled in a release build, an unexpected error sends a technical report so the bug can be found and fixed. The report is scrubbed before it is sent: the email address and IP address are stripped from it, and authorization headers are removed. It carries the error and where in the code it happened — not your entries, amounts, vendor names, or account details. Only a sample of ordinary performance traces is collected, and no report is sent at all if diagnostics are not configured for that build.

Usage analytics

The app marks a small number of anonymous product events — that onboarding finished, that an entry was saved, that the paywall was seen. These carry a step name or a service-template name and never an amount, a vendor's name, a date from your ledger, or anything identifying you. In the current build these events are not transmitted anywhere: no analytics provider is wired up, and they exist only in developer logs. If that ever changes, this policy changes first.

Sharing a statement

When you share a month's statement, the image is drawn and captured entirely on your device and handed to your phone's own share sheet. HomeSlate does not upload it, does not keep a copy, and never sees where it went. You choose the app and the recipient — and once you have sent it, that statement is governed by whatever app you sent it through, not by this policy. A statement only ever contains the one service you shared it from.

The website

The HomeSlate website is a separate surface from the app, and it is deliberately quiet.

  • No cookies are set, and there is no cross-site or advertising tracking.
  • Both fonts are served from this site, so reading a page makes no request to a font network.
  • Videos are linked out rather than embedded, so no third-party player loads on the page.
  • Aggregate, cookieless measurement — page views and loading speed — is collected by our host (Vercel) so we can tell which pages are read and which are slow. It builds no profile of you and follows you nowhere.
  • The price you are shown is chosen from your browser's own language setting. There is no IP location lookup, and that preference is not stored or sent anywhere.
  • If you write to us through the contact form, the name, email, category, and message you typed are saved so we can answer, and a copy is emailed to us and to you.

Who else touches your data

We use a small number of established providers, each for one job, and none of them for advertising:

  • Supabase — accounts and cloud backup, if you create an account.
  • Apple App Store and Google Play — selling and billing subscriptions.
  • RevenueCat — knowing whether your subscription is active so it can be restored.
  • Sentry — crash and error reports, scrubbed as described above, when enabled.
  • Vercel — hosting the website and its cookieless page measurement.
  • An email provider — delivering account verification codes and replies to your support messages.

Where your data lives, and how long

Data on your phone stays until you delete it — the app never expires your ledger, and old months remain readable for as long as you keep the app installed.

  • Cloud backup data is held on our provider's servers, which may be outside your country. Where that means your information crosses a border, it travels encrypted and is held under the same terms described here.
  • Your cloud copy is kept while your account exists, and is removed when the account is deleted.
  • Support messages are kept while we need them to answer you and to recognise a repeat issue.
  • Crash reports age out on our provider's standard retention schedule.
  • Website measurement is aggregate and is not tied to you at all.

Your rights, and how to use them

You have the right to see your data, correct it, take it with you, and have it deleted, and to withdraw consent for anything you switched on. Most of it you can do yourself, immediately, without writing to anyone:

  • See and correct — every entry, rate, and payment is editable in the app.
  • Take it with you — sign in on the new device and your ledger restores.
  • Delete from the device — Settings → Clear all data.
  • Withdraw consent — sign out to stop cloud sync; turn off reminders to stop notifications.
  • Delete everything, including the cloud copy and the account itself — email kreativish.ai@gmail.com from the address on the account and we will remove it.
  • We answer requests within 30 days, and we do not charge for them.

Deleting your data

Settings → Clear all data removes entries, payments, services, and preferences from your device immediately and permanently — there is no undo and no recycle bin, so use it deliberately. If you have an account and want the cloud copy and the account gone as well, email kreativish.ai@gmail.com from the address on the account and we will delete it. Deleting the app alone removes the local ledger but does not delete a cloud account.

Children

HomeSlate is a household bookkeeping tool made for adults and is not directed at children. We do not knowingly collect anything from a child under 13, or under the minimum age of consent where that is higher. If you believe a child has created an account, write to kreativish.ai@gmail.com and we will delete it.

Security, honestly stated

Connections are encrypted in transit, passwords are stored only as one-way hashes, session tokens are held in the device's secure keystore, and the database refuses cross-account reads at the row level. That said, no app or service can promise perfect security, and we will not pretend otherwise. Choose a password you use nowhere else, and keep the lock screen on the phone that holds your ledger. If we ever discover a breach affecting your data, we will tell affected users and the relevant authority as the law requires.

Changes to this policy

As the app grows, this policy will be updated — the date at the top always says when. If a change is material, such as collecting something new or adding a provider, we will say so in the app before it takes effect rather than quietly changing the text. Earlier versions of this document are kept in the project's public repository history.

Contact

Questions about privacy, or a request to see or delete your data: kreativish.ai@gmail.com. A person reads that inbox, and you will get an answer.


This is the same text the app shows under Settings → Privacy Policy. If the two ever disagree, tell us at kreativish.ai@gmail.com — that is a bug, not a technicality.