1. Who we are
My Tomte is made by Happy Dance Project (ABN [pending]) (“we”, “us”), based in New South Wales. This policy covers My Tomte at mytomte.app, our website at meetmytomte.com, our help centre, and our emails and support.
My Tomte is a household organising tool. It helps households plan meals, shopping and calendars using the rules and preferences they set. It isn’t a health service, and it doesn’t assess, treat or give advice about anyone’s health.
We handle personal information in line with the Australian Privacy Principles in the Privacy Act 1988 (Cth).
2. What we collect
About you
- Your name and email address
- If you sign in with Google: your name, email address and profile picture from your Google account
About your household
- The names of the people in your household, and their birthdays if you add them
- Dietary details: dietary rules, allergies, intolerances (for example, coeliac disease), pregnancy if added as a dietary rule, and nutrition targets
- Food ratings (Love it, Like it, Not for us)
- Children’s profiles, created and managed by a parent or guardian: name, dietary needs, activities, chores and reward tokens
- Friends and family you add: names, birthdays and dietary needs
- Guest Wi-Fi network name and password, if you add them for the QR code
- The household’s location, if you turn on weather [confirm: how it’s set, e.g. suburb or coordinates, and whether it’s optional]
About your kitchen and meals
- Meal plans, recipes, and photos or PDFs you upload to create recipes
- What’s in your fridge, freezer and pantry
- Receipts you upload, including the store, items, prices and date
- Shopping lists, household tasks, events and notes
From calendars you connect
- Events from the Google, iCloud or Microsoft 365 calendars you choose, including titles, times, locations, attendees and notes
- With two-way sync, the family events we create or update in those calendars
About payments
- Your plan, subscription status and payment history
- From Stripe: card type, last four digits, expiry date and billing country. We never see or store your full card number.
When you use our sites and app
- Technical information: IP address, browser, device, and the approximate time of each request
- Error reports when something breaks (see section 7)
- Usage analytics (see section 7)
When you contact us or send feedback
- Your message, and anything you attach
- If you tick the box to include them: a screenshot of the screen you’re on, and recent technical error messages from your browser. You see the screenshot before it’s sent, and you can remove it.
3. Dietary details
You add dietary details so My Tomte can suggest meals that follow your household’s rules. Privacy law treats information about allergies, intolerances, coeliac disease, pregnancy and similar things as health information, a kind of sensitive information, even though My Tomte isn’t a health service. So we handle it with extra care:
- We collect it only with your consent, which you give when you add it (with the notice shown on that screen).
- We use it only to suggest meals that follow the rules you set, and to show nutrition information.
- We never use it for marketing, never sell it, and never share it except with the service providers who store it for us or process a Smart Action you ask for.
- You can remove it at any time, and it’s gone from your household straight away.
My Tomte’s meal suggestions are guidance for your household, not medical or dietary advice. Always check ingredients and allergen labels.
4. Children
My Tomte accounts are for adults (18 and over). Children don’t have accounts or logins. A parent or guardian creates and manages each child’s profile, and we keep only what’s needed for meals, activities, chores and reward tokens. Children may see their own token progress on a household device; they can’t change settings or see anything outside their household.
A child’s profile can be seen only by the people in that household. We don’t collect analytics about individual children, and we never use children’s information for marketing. A parent can delete a child’s profile at any time.
5. How we use your information
- To run My Tomte: plan meals, build shopping lists, track your kitchen, sync calendars and show your household’s information to its members
- To apply each person’s dietary rules when planning
- To run Smart Actions when you ask for them (section 6)
- To take payments and manage your subscription
- To send service emails: your trial reminder, renewal reminders, payment notices and account changes
- To answer questions, support requests and feedback
- To keep My Tomte secure, find and fix problems, and improve it
- To send news and offers, only if you’ve agreed, with an unsubscribe link in every one
We don’t sell your information. We don’t use it for advertising, and we don’t allow advertising trackers on our sites or app.
6. Smart Actions and AI
Smart Actions (planning by asking, photo to recipe and receipt reading) are processed by Google (Gemini) and Anthropic. When you use one, we send what that request needs: your request, the photo, PDF or receipt, and the household details needed to answer it safely (for example, dietary rules when you ask for meals). [confirm exactly what context is sent]
- Neither provider may use your information to train its AI models.
- Both may keep requests for a limited time to detect misuse, then delete them (Anthropic: up to 30 days). [confirm Google’s retention on the paid tier]
- AI can make mistakes. Always check a recipe or receipt the tomte has read for you.
7. Analytics and error reports
Analytics (PostHog). We count how features are used, so we can make them better. We’ve set this up to protect your privacy:
- Events are grouped by a one-way scrambled code for your household, never by person, and that code can’t be linked back to you by anyone holding only the analytics data
- Events never include names, recipe titles, ingredients, shopping items or any free text
- No automatic click tracking, and no screen recordings
- Page addresses are stripped of identifying details before they’re sent
Analytics are processed on PostHog’s EU region. [confirm: whether analytics wait for consent in the app. See the Cookie policy.]
Error reports (Sentry). When something breaks, a technical report is sent so we can fix it. It doesn’t include your name or email, it’s filtered before it leaves your device, and we never record your screen. [confirm Sentry region]
8. Who we share information with
Only with the services that help us run My Tomte, and only what each one needs:
| Service | What for | Where |
|---|---|---|
| Supabase | Stores your household’s data | Australia |
| Render | Backup copy | Singapore [confirm] |
| Vercel | Hosts the website | [confirm] |
| Cloudflare | Domain, network and security | Global network |
| Stripe | Payments | United States and other countries |
| Google (Gemini) | Smart Actions | United States [confirm] |
| Anthropic | Smart Actions | United States |
| PostHog | Analytics | European Union |
| Sentry | Error reports | [confirm] |
| Resend | Sending emails | [confirm] |
| Atlassian (Jira Service Management) | Support requests | [confirm] |
| Open-Meteo | Weather for your household’s location | [confirm] |
| Google, Apple, Microsoft | Calendar sync, when you connect a calendar | Under their own privacy policies |
We also look things up in public databases (Open Food Facts for product barcodes and Open Library for cookbooks) without sending any personal information.
We may share information if the law requires it, to respond to a lawful request, or to protect someone’s safety. If Happy Dance Project is ever sold or merged, your information may pass to the new owner, who must keep protecting it under this policy, and we’ll tell you first.
9. Information handled overseas
Your household’s data lives in Australia, with a backup copy in Singapore. Some services above process information in other countries, mainly the United States, Singapore and the European Union. We choose providers with strong security and privacy commitments, and we take reasonable steps to make sure they protect your information.
10. Who at My Tomte can see your household
Only Danny and Rowena (and anyone who works with us later, under the same rules) can access household information, and only to answer a support request or feedback you’ve sent, fix a problem, keep the service secure, or when the law requires it. Access is through restricted admin tools. [confirm]
11. Keeping it safe
Information is encrypted in transit, and at rest [confirm for Supabase and Render]. Access is limited to what’s needed, and backups run daily. If a data breach is likely to cause you serious harm, we’ll tell you and the Office of the Australian Information Commissioner, as the Notifiable Data Breaches scheme requires.
12. How the planner suggests meals
My Tomte uses a computer program to suggest meals. It uses each person’s dietary rules, allergies, nutrition targets, ratings and calendar (who’s home), and what’s in your kitchen. It leaves out any recipe that isn’t marked safe for someone eating, and ranks the rest. You can always see why a slot is empty, change any meal, or plan manually. The planner doesn’t make any decisions about you beyond suggesting meals, and its suggestions are guidance, not advice.
13. How long we keep it
- Your household’s information: for as long as your household exists
- When you delete your household: it’s permanently deleted straight away, with no recovery. Copies in backups are removed within 30 days.
- Feedback screenshots and diagnostics: deleted with the household [confirm any earlier deletion]
- Payment and tax records: 5 years, as Australian tax law requires
- Support requests: [period] [confirm]
- Analytics and error reports: [the retention set in PostHog and Sentry] [confirm]
14. Your choices and rights
- See or correct your information: most of it is in the app. For anything else, email [email protected].
- Delete health information, a person, a child’s profile or your whole household at any time.
- Disconnect a calendar at any time; syncing stops straight away.
- Analytics: see the Cookie policy for how to say no.
- Marketing emails: unsubscribe using the link in any of them.
We’ll respond within 30 days.
15. Complaints
Email [email protected], and we’ll respond within 30 days. If you’re not satisfied, you can contact the Office of the Australian Information Commissioner (oaic.gov.au).
16. Changes to this policy
If we make an important change, we’ll tell you by email or in the app before it takes effect. The date at the top shows the latest version.
17. Contact
Happy Dance Project · ABN [pending] · [email protected]