DomoSign in

Privacy Policy

Last updated July 30, 2026

Domo holds the details of somebody’s house — the address, what’s in it, what it cost, who worked on it. That is genuinely personal, and this page is the plain account of what happens to it. No advertising, no data sale, no third-party tracking.

1. Who’s responsible

Domo is run by Nick Tassone, an individual based in Canada, who is the person accountable for the data described here. For anything on this page — a question, a copy of your data, a deletion request — write to privacy@domohouse.app.

2. What Domo collects

Your account

  • Your email address and name. Required — the email is how invitations are matched and how you sign in.
  • If you sign in with Google: Google gives us your email address, your name, and your profile picture. Nothing else, and never your Google password.
  • If you sign in with a password: we store a scrypt hash of it, never the password itself. Password reset and sign-up links are stored only as hashes too, and expire.
  • A profile picture, if you upload one or one comes from Google.

What you put in

Everything you enter about a home, which is the substance of the product: the home’s name and street address, its rooms, systems (including make, model and serial numbers), appliances, finishes, projects and their budgets and spend, tasks, comments, the trades you work with and their contact details, and accounts — the utility or vendor, an account number, a login page link, and monthly cost. Domo has no field for a password, and the terms ask you not to put one anywhere else.

Files

Any photo, manual, receipt or document you attach, along with its filename, size and type. Files are stored in Cloudflare R2 and are served only through short-lived signed links — they are never on a public URL.

Feedback

If you send feedback from inside the app, we keep what you wrote and which account sent it, so it can be answered.

Records of what happened

An append-only log of membership and administrative events — invitations, joins, removals, staff actions — so an account’s history can be reconstructed if something goes wrong. Ordinary server logs (IP address, browser, requested path, errors) are produced by our hosting provider and kept for a short period for security and debugging.

Analytics

Domo uses Cloudflare Web Analytics, which is cookieless and does not fingerprint or follow visitors between sites. It records page views and the path visited. Paths contain record identifiers but no names, no content and no email addresses. There are no advertising or social-media trackers anywhere in the app.

3. Cookies and local storage

Only ones that make the app work. Specifically:

  • A session cookie that keeps you signed in. Without it there is no way to use Domo.
  • Preference cookies and local storage — the light/dark theme, which home you last had open, whether completed tasks are shown, list and view settings. These stay on your device and identify nothing.

No advertising cookies, and nothing shared with an ad network. That’s the whole list.

4. What it’s used for

To run Domo, and nothing else: showing your home to you and its members, signing you in, sending the handful of emails the app sends (invitations, password resets, sign-up links), storing and serving your files, answering your feedback and support requests, keeping the service secure and working, and understanding roughly how much it’s used.

Your content is never used to train machine-learning models, never sold, never rented, and never shared with anyone for their own purposes.

5. Who else touches it

Domo is built on other people’s infrastructure, and each of these handles some data on our behalf, under their own terms, for the single purpose listed:

  • Fly.io — runs the application. Primary region Toronto.
  • Neon — the Postgres database everything above is stored in.
  • Cloudflare — R2 object storage for your files, and the cookieless analytics beacon.
  • Google — only if you choose to sign in with Google.
  • Resend — sends invitations, sign-up links and password resets. It sees the recipient address and the message.
  • Mapbox — powers the address autocomplete. What you type into an address field is sent to Mapbox to fetch suggestions. Type nothing there and Mapbox sees nothing.

Beyond those, we’ll only disclose data if the law requires it — and if we’re permitted to tell you, we will.

6. Who can see your home

  • Every member of the home. Membership is all-or-nothing: there are no per-record permissions, so anyone you invite can see everything in that home.
  • Anyone holding a share link. A share link renders a minimal preview — item name, type, home name, and a project’s status. Never budgets, files, notes or tasks. These pages are excluded from search engines, but the link itself is the only key, so treat one as public.
  • Us. Running and supporting Domo means the operator can technically reach the data in it. That access is used for operating the service and for support — investigating a problem, usually one you’ve reported — and not for browsing. Administrative actions are written to the audit log described above.

7. Where it lives

The application runs in Toronto, Canada. Our database, storage and email providers are international companies, so data may be stored or processed in Canada, the United States, or elsewhere those providers operate — and may be subject to the laws of those countries.

8. How long it’s kept, and how to have it deleted

Your content is kept as long as your account exists — it’s a house record, meant to outlast the year you created it. Sign-up and password-reset tokens expire quickly. Server logs are short-lived. Analytics data holds no identifier tied to you.

There is no self-serve account deletion yet. Email privacy@domohouse.app from your account address and we’ll delete your account, and the homes you alone own, along with their files — normally within 30 days. Deleting one member of a shared home does not delete the home’s records, since they belong to the other members too. Backups roll off on their own schedule, so a deleted record can persist in a backup for a short while after it disappears from the app.

9. Security

Everything travels over HTTPS. Passwords are stored as scrypt hashes. Files sit in private object storage reachable only through expiring signed links. Every query is scoped to the home you’re a member of, and file-storage credentials are brokered rather than kept as static keys in the app.

None of which is a guarantee. No service can promise perfect security, and Domo is a beta run by one person — please keep your own copies of anything irreplaceable. If a breach affects your data, we’ll tell you and the relevant regulator as the law requires.

10. Your rights

Under Canadian privacy law — and comparable law elsewhere, if you’re writing from outside Canada — you can ask us to:

  • tell you what personal information we hold about you, and give you a copy;
  • correct anything that’s wrong;
  • delete your account and its contents;
  • explain how a piece of information is being used.

Write to privacy@domohouse.app and we’ll answer within 30 days. There’s no charge. If you’re unsatisfied with the answer, you can complain to the Office of the Privacy Commissioner of Canada, or to your local privacy regulator.

11. Children

Domo isn’t for children. It’s invite-only and intended for people aged 16 and over. We don’t knowingly collect information from anyone younger; if we learn we have, we’ll delete it.

12. Changes to this policy

This policy will change as Domo does. The date at the top is the current version, and material changes will be announced in the app or by email before they take effect rather than slipped in quietly.

13. Contact

privacy@domohouse.app — for questions, corrections, copies of your data, deletion requests, or anything else on this page.