Do What

Privacy Policy

Last Updated: July 31, 2026
Effective Date: July 31, 2026

What changed on July 31, 2026

What changed on July 29, 2026

Do What ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application ("App"). Please read this policy carefully.

1. Information We Collect

1.1 Information You Provide

When you use Do What, you may provide us with:

1.2 Information Collected Automatically

When you use the App, we may automatically collect:

1.3 Analytics

Analytics tell us which features are used and where people get stuck, so we can decide what to improve. We collect feature-usage events (for example, "a to-do was created" or "the shopping screen was opened") together with the device and app-version information needed to interpret them.

Analytics events are anonymized before they leave your device. They never include:

Your choice: analytics are off by default and opt-in during setup. You can change your mind at any time in Settings > Privacy & Analytics. Turning them off stops collection; it does not affect any app feature.

1.4 Crash Reporting

When the App crashes or hits an unexpected error, a crash report helps us find and fix the cause. A report contains the technical state of the app at the moment of failure: the error type, the stack trace showing which code was running, your device model, operating system version, and the app version.

Crash reports are scrubbed of personal content before being sent. They never include:

Your choice: crash reporting is off by default and opt-in during setup. You can change it at any time in Settings > Privacy & Analytics. Turning it off means we will not learn about crashes you experience, which may make them slower to fix.

1.5 Permissions We Request

Permission Purpose When Requested
Camera Scan barcodes for shopping list items Only when you tap the scan button
Location Location-based reminders (geofencing) Only when you create a location reminder
Background Location Trigger reminders when you arrive/leave locations Only after you enable location reminders
Calendar (Read Only) Display device calendar events alongside family activities Only when you enable calendar sync
Notifications Send reminders, chat messages, and family updates During app setup

2. How We Use Your Information

We use the information we collect to:

What We DO NOT Do

3. Location Information

3.1 Background Location Usage

Do What uses background location access exclusively for location-based reminders (geofencing). This feature allows you to receive notifications when you arrive at or leave specific locations you've chosen.

Examples:

3.2 What Location Data We Collect

3.3 What We DO NOT Do With Location

3.4 Your Location Rights

4. Data Storage and Security

4.1 Where Your Data is Stored

Data Type Storage Location
App preferences and settings Your device (protected by Android app sandboxing and device security)
Cached data for offline access Your device (protected by Android app sandboxing and device security)
Account and authentication data Firebase (Google Cloud)
Family data (todos, shopping, notes, chat) Firebase (Google Cloud)
File attachments Firebase Cloud Storage (Google Cloud)

4.2 Security Measures

We implement industry-standard security measures to protect your data:

5. Data Sharing

5.1 Within Your Family

When you join a family in Do What:

5.2 Third-Party Services

We use the following third-party services to operate the App. Each receives only the data listed:

Service Purpose What it receives
Firebase (Google) Authentication, database, storage, cloud functions Your account details and the family data you choose to sync
Firebase Cloud Messaging Push notifications A device push token
Google Play Services Location services for geofencing Location data on your device, to evaluate geofences
Google AdMob Ads in the free tier Advertising ID, IP-derived approximate location, and ad interaction signals. Never your family content. See Advertising.
Google Places Address search when you add a location reminder The text you type into the place search box
Google Weather Forecasts and commute context An approximate location to fetch a forecast for
Open Food Facts Product lookup for scanned barcodes The scanned barcode number only — never the image, and never your account
UPCitemdb Product lookup for scanned barcodes not found above The scanned barcode number only — never the image, and never your account

These services are governed by their own privacy policies. Barcode scanning itself runs entirely on your device using Google ML Kit; no image ever leaves your phone.

5.3 Legal Requirements

We may disclose your information if required by law, such as in response to a subpoena, court order, or government request.

6. Your Rights and Choices

6.1 Access and Export

6.2 Correction

6.3 Deletion

6.4 Opt-Out

7. Data Retention

8. Reporting and Blocking

You can report a chat message, a family note, or another family member from inside the App, and you can block another member in a direct (one-to-one) conversation. This section explains what happens to your data when you do.

8.1 What a report contains

When you send a report, we receive:

Reporting an encrypted message shares that message with us

Direct and group chats can be end-to-end encrypted, which normally means we cannot read them — the keys live on your device and the recipient's, not on our servers.

A report is the one exception, and it has to be. Because we cannot decrypt the message ourselves, your device sends us the readable text along with the report. That one message stops being private to you and the other participants, and becomes readable by us. Nothing else in the conversation is affected, and no other message is sent to us.

The App tells you this before you confirm a report. If you would rather not share the text, do not send the report — blocking the person requires no content at all. If your device cannot decrypt the message, we receive the report without any text, and we say so on the report.

8.2 How long we keep reports

An open report is kept until we have reviewed and acted on it. Once it is resolved, we keep it for 90 days and then delete it automatically. We keep it that long so we have a record of the complaint and what we did about it, which is what an app store or a regulator would ask us for.

If you delete your account, reports you filed are deleted with the rest of your data. Reports about you are stripped of everything that identifies you — your account ID, your name and the reported content are all removed — and only the record that a complaint was received and resolved remains.

8.3 Blocking

Blocking someone in a direct conversation stops messages in both directions: neither of you can send anything new there while the block is in place. Messages already sent stay where they are, and nothing changes in family chat, shared tasks, shopping lists, or the calendar. A block record contains only who blocked whom and when. You can remove your own block at any time; you cannot remove one that someone else placed.

9. Children's Privacy

Do What is designed for family use and may be used by children under parental supervision. We do not knowingly collect personal information from children under 13 without parental consent. If you believe we have collected information from a child under 13, please contact us immediately.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your country of residence, including the United States where our service providers (Google/Firebase) maintain servers. We ensure appropriate safeguards are in place for such transfers.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy in the App and updating the "Last Updated" date. You are advised to review this Privacy Policy periodically for any changes.

12. California Privacy Rights

If you are a California resident, you have specific rights under the California Consumer Privacy Act (CCPA):

13. European Privacy Rights (GDPR)

If you are in the European Economic Area (EEA), you have rights under the General Data Protection Regulation (GDPR):

14. Advertising

The free tier of Do What shows ads, served by Google AdMob. Ads are how the free tier pays for itself. A Premium subscription removes all ads, and when you are subscribed the App makes no ad requests at all.

We never request personalized ads

Every ad request Do What makes is flagged as non-personalized. This applies in every country and to every user — not only where privacy law requires it. Ads you see are based on the app you are using and general context, never on a profile built from your behavior.

13.1 What AdMob Receives

To serve and measure a non-personalized ad, Google AdMob processes:

13.2 What AdMob Never Receives

13.3 Consent and Your Controls

In the EEA, UK, and other regions where it is required, Do What uses Google's User Messaging Platform (UMP) to present a consent form and record your choice before any ad is requested. Because we never request personalized ads anywhere, that consent governs whether ads may be shown to you at all, not whether they may be targeted.

You can also:

Google's handling of ad data is described in the Google Privacy & Terms and the AdMob help center.

15. Contact Us

If you have any questions about this Privacy Policy or our data practices, please contact us:

Email: support@dowhat.family
Website: https://dowhat.family