Privacy Policy
How Tokarea handles the data it needs to make your group work.
Last updated: 21 August 2026
Tokarea lets people organise messages, tasks, shopping lists and expenses in groups accessed with a code. This policy explains what information the app needs, how it is used, and how you can delete your account and exercise your rights.
The app works without mandatory sign-up. When you start, it creates a pseudonymous technical account linked to the installation, and you choose the name or nickname you use in each group. You can voluntarily protect that same account with Apple, Google or an email address verified with a one-time code so that you can recover it or use it on another device.
Controller and contact details
Alfonso González Ariza is the controller of the personal data processed by Tokarea. For privacy questions, support or to exercise your rights, email support@tokarea.com.
Postal address of the controller: Calle Alejandro Dumas, 17 · Oficinas · 29004 Málaga, Málaga · España.
The personal email address used to manage the Apple account is not published or used as a support channel.
Data we store
- Group, team and participant names or nicknames entered by people in the group.
- Group-chat messages, their date and technical authorship and, when you reply, the reference to the quoted message. Messages are shared only within the group. Adding one or more chat photos is free and does not require Tokarea Pro: each photo is a separate message with an opaque photo key; text or caption and the quoted-message reference are attached only to the first.
- If someone adds a chat photo, their device stores an encrypted local copy. The service may deliver the ordinary encrypted content for up to 30 days after preparation; it then keeps it inaccessible and queues it for asynchronous physical deletion with retries if deletion fails. It also processes the technical identifiers for the group, message, photo, sender, quoted message and sending and recipient devices, key envelopes and public keys, size, dimensions, status, and preparation, association, expiry and deletion dates.
- Tasks, categories, notes, ratings, assignments, points and activity history.
- Shopping-list items, quantities, units, categories, assignees, notes, price and purchase status or history. If the group enjoys Tokarea Pro and someone chooses to add a photo, their device stores an encrypted local copy and the service temporarily retains only the encrypted content, together with the technical identifiers for the group, item, photo, revision and recipient devices, key envelopes, size, dimensions, upload status, and preparation and expiry dates. Over time, this information may reflect the group’s habits.
- Shared expenses and payments, including descriptions, amounts, participants and calculated balances.
- A technical user identifier used to link this installation to its groups and to the selected person.
- So that a compatible installation can receive future encrypted photos from its shared groups, it registers a random device identifier and two public encryption and signing keys. The corresponding private keys remain in the device’s secure store and are not sent to the service.
- If you buy Tokarea Pro: the product, store —Apple or Google Play—, store environment, original transaction identifier or encrypted purchase token, expiry date where applicable, and the technical account identifier linked to the purchase. Tokarea does not receive or store your card details.
- If you voluntarily protect the account: the linked method —Apple, Google or email—, that identity’s provider identifier, the real or private email address that is shared and the authentication metadata needed for the service. Apple or Google may also provide a name and, in Google’s case, profile information such as an image; Tokarea does not need that data for group content. A one-time code is used to verify access and is not added to group content.
- If you enable notifications: a technical push token, platform, app version, the minimum language preference (es or en), notification level, and paused or enabled groups.
- To deliver and check notifications: identifiers for the event and recipient account, the minimum technical content needed for the notification, status, provider ticket and delivery error, where applicable.
- Technical operational data such as IP address, platform, version, request, security and delivery logs, and the minimum technical information about a failure that may be generated while providing or updating the service.
- To record acceptance of the Terms of Use, the service stores the technical account, the accepted version and the date. This device also keeps a local copy of that version and date; the local copy does not include the invitation code or a group identifier.
- If you use the privacy centre: the request type, an opaque reference, handling language, optional note, status, dates and, where applicable, a response or the reason and date for an extension. The export is generated on request as a JSON file. It does not add invitation codes, tokens or technical identifiers belonging to other accounts as structured fields. It does reproduce notes and comments you submitted and responses addressed to your account; do not enter secrets or unnecessary information about other people in those fields.
- If you report content from the app: the type and technical identifier of the item, the group, a limited private copy of the fields visible when you submit the report, the reason, an optional comment, the case reference, review status and dates, together with the technical identifiers needed to verify membership. If the reported shopping item or message has a photo and the device can still retrieve and decrypt that revision, the app warns before submission that, once the report is confirmed, it may provide the case with a separate, sanitised JPEG copy that Tokarea can view for review. This is contextual material supplied by the reporting device: linking it to the case does not cryptographically prove that it matches the exact content of the ordinary encrypted file. This evidence does not extend retention of that file. A direct participant report created by an earlier version may be linked to the reported account; an editable task, shopping item or expense is not attributed to a person by default.
- If an account is blocked from a group: the group, affected identity, account applying the measure, optional reason, dates and revocation status. This information is not shown to the rest of the group.
Anonymous usage analytics
To understand which features are used and improve the app, Tokarea records anonymous product events — for example, “a group was created” or “the Tokarea Pro screen was opened” — together with technical data only: platform, app version and language. These events never include what the group writes: no names, no messages, no amounts, and no chore, shopping or expense content.
Each signal is tied to a random installation identifier that is not derived from any personal data and is additionally hashed with SHA-256 before it leaves the device. TelemetryDeck GmbH (Germany) processes the signals in the European Union, re-anonymises the identifier with its own salt and does not store the IP address. The public website tokarea.com sends the same provider equally anonymous page-view and download-link-click events, with no cookies and no identifier that outlives the visit, honouring the browser's Do Not Track and Global Privacy Control signals. Configured this way, the signals cannot identify you or follow you across apps, which is why no tracking technologies requiring your prior consent are used.
How we use the data
- To synchronise information and changes between devices that belong to the same group.
- To deliver the ordinary encrypted content of shopping and chat photos to recipient devices for up to 30 days; after that, the service stops delivering it, keeps it inaccessible and queues it for asynchronous physical deletion with retries if deletion fails. Devices may continue to display encrypted copies that they have already stored locally.
- To calculate assignments, scores, balances, histories and suggestions for settling expenses.
- To remember which person uses each device and restrict access to the groups it has joined.
- At your request, to link a sign-in method to the technical account so that you can recover it or open the same groups on another device, without replacing it with a new account.
- To send the notifications you have chosen and avoid notifying you about your own actions.
- To distribute compatible updates, protect the service and diagnose operational or delivery errors.
- To prepare a portable copy of data verifiably associated with your technical account, and to receive, handle and document privacy requests.
- To prevent abuse, receive reports for human review, remove or restore content, and apply or lift blocks and access suspensions in a proportionate way. In chat, the message is hidden locally on the reporting device; the report does not remove or hide it from the rest of the group before review.
Legal basis
The technical account, group membership, synchronisation, calculations and features you request are processed because they are necessary to provide the service under the Terms of Use and to take the steps you request before creating or joining a group. If you choose to protect the account, the minimum Apple, Google or email data is processed to carry out that recovery and cross-device access request.
Security, abuse prevention, minimum diagnostics, service continuity and incident handling rely on the legitimate interest in keeping Tokarea secure and operational, balanced against the rights of the people affected.
Certain information may be processed where necessary to comply with a legal obligation, respond to a rights request, or establish, exercise or defend a legal claim. If a future feature required consent, it would be requested separately and could be withdrawn just as easily.
The Privacy Policy provides information about this processing: confirming that you have read it does not make every processing activity consent-based.
Information required to use Tokarea
The technical account and group membership are required to share and synchronise information. Without them, you can view the public pages but cannot use a shared group. You can use a nickname and enable only the modules you need.
You do not need to link Apple, Google or an email address to use Tokarea on the current installation. Linking is voluntary and is needed only if you want to recover the same account after losing the session or use it on another device.
Chat, task, shopping and expense content is processed only when someone in the group chooses to enter it. Adding one or more free chat photos, saving or sharing a photo, adding a Pro photo to a shopping item, enabling notifications and contacting support are optional: if you do not use them, the rest of the group will continue to work.
Data Tokarea does not require
The app does not require an email address, phone number, contacts or photos to use a group. It receives an email address only if you choose to protect the account using email, Apple or Google; Apple lets you share a private address. Google may include profile information in the identity it provides to Supabase Auth.
Only when you choose to add a Pro photo to a shopping item does Tokarea open the system photo picker so that you can choose one image, without requesting general access to your photo library. It does not open the camera or upload other photos: it re-encodes only the selected image as a JPEG up to 1280 pixels per side and 1 MB, removes EXIF, GPS, comments and IPTC metadata, checks the copy on the device, and encrypts it before transmission. The original is not added to the service.
If you choose to add free chat photos, the limited picker lets you select between one and five images without granting general photo-library access. Tokarea separately re-encodes and sanitises each image as a JPEG up to 1280 pixels per side and 1 MB, removes EXIF, GPS, comments and IPTC metadata, and checks and encrypts it locally before any durable persistence or transmission. Each image becomes a separate message; prepared text or reply is attached only to the first. It does not require Tokarea Pro, open the camera or add the originals to the service.
Tokarea does not request GPS permission or obtain your precise location. Removing photo metadata prevents Tokarea from using any location that the original file may contain. Technical providers may infer an approximate location from your IP address when providing or protecting the service.
Tokarea does not include advertising or use this data to track you across apps or websites. Providers’ technical logs are limited to operating, updating, securing, diagnosing and improving the service.
If you choose to email support, we will receive your email address and the content you include so that we can respond to your request. The support@tokarea.com mailbox uses iCloud Mail to receive and reply to messages.
Where the data is processed
Shared data is hosted by Supabase, which provides the database, pseudonymous technical account, authentication, real-time synchronisation and private storage for the encrypted content of shopping and chat photos. The service does not receive a device’s private key or the key that encrypts an ordinary photo. During the intended operation, Tokarea and its providers cannot decrypt that content; they do know the operational metadata required to provide the feature: the related group and item or message, opaque key and revision where applicable, technical sender and quoted chat message, sending and recipient devices, public keys, size, dimensions, status and dates. The service supplies the directory trusted when each device is observed for the first time, and keys that have already been observed are pinned locally. This trust-on-first-use or TOFU protection detects later substitution of observed keys, but cannot detect a new device inserted by a malicious service before that device’s first observation, even after earlier use, and is not equivalent to the WhatsApp or Signal protocol.
The encrypted file has no permanent public URL. Until expiry, an authorised recipient device receives a short-lived signed link to download it. The device may keep an encrypted local copy that is excluded from backups and, inside Tokarea, creates a decrypted JPEG copy only temporarily to display it or hand it to the system sheet when you choose “Save photo”. If you save or share the image, the destination receives a sanitised copy outside Tokarea’s encryption and lifecycle; this does not renew remote retention or create another copy on Tokarea servers. Private keys are stored in the operating system’s secure store and are not synchronised.
If you choose to protect the account with Apple or Google, that provider authenticates the identity and sends Supabase Auth the data you authorised so that it can be linked to the existing technical account. Apple can replace the real email address with a private relay address. If you choose email, Supabase Auth manages the address and verification with a one-time code; Resend, with sending infrastructure in the European Union, delivers that message and processes the address and the essential technical metadata needed to deliver it, without using them for any other purpose.
If you enable notifications, Expo Push Service and Apple’s or Google’s notification service are involved, depending on the platform. Expo also provides the technical infrastructure used to distribute compatible app updates.
To notify the service owner about new reports, Tokarea may use Resend as its operational email provider. When that channel is active, Resend receives the alert sender and recipient, the TKR reference, content type, date and a random technical case identifier used as an idempotency key; it does not receive the reported text, names, amounts, group code or account identifiers.
Cloudflare provides the domain, network protection and public pages. If external restore protection is activated, Cloudflare D1 keeps the deletion receipt outside Supabase —a random request identifier, encrypted account digest and dates— and minimum alert-delivery receipts —a random case identifier, fingerprint, provider, receipt and acknowledgement dates— for the documented recovery and response window. It does not keep group text, names, amounts or invitation codes.
Supabase, Expo, Cloudflare and their subprocessors may process technical identifiers, IP address, operating system or platform, app version, requests, failures and essential technical interactions. Expo Updates may also use a random installation or update identifier to distribute and diagnose compatible versions. This information is used for operation, security, diagnostics and service improvement, never for advertising or tracking across apps or websites.
The main Supabase project is hosted in Ireland. Some providers or subprocessors may process information from countries outside the European Economic Area. Where an international transfer applies, it must be covered by an adequacy decision or another safeguard recognised by law, such as Standard Contractual Clauses. You can request current information about the provider and applicable safeguard using the contact email address.
Who can see group information
Messages and other shared information are shown to devices that belong to the same group. A shopping or chat photo can be delivered only to the registered recipient devices included when it is prepared; a new or rejoining member, or a device registered later, does not receive the historical key. Anyone with the invitation code can confirm that they wish to join and then see the group’s ordinary data, so you should protect it like an access key.
Someone in the group may enter another person’s name or other information about them. In that case, the source of that data is the person who adds it to the group, and the other participants can view and edit it through the collaborative features.
We recommend using nicknames or the minimum information needed and not entering or photographing particularly sensitive data in messages, tasks, notes, shopping items or expense descriptions.
Reports submitted in the app and private blocking or moderation records are not shared with the group. They can be accessed only by the person responsible for the service, or someone acting under their authority, for the purpose of reviewing the incident. When a message is reported, it is hidden locally on the reporting device but is not removed or hidden from the rest of the group: an authorised person reviews the case before deciding whether to keep it, temporarily withdraw it, restore it, remove it or apply an access restriction.
Retention and deletion
You can delete the technical account from Privacy and data, available in Settings and on the start screen. Before you confirm, Tokarea shows which groups will remain available to other people and which will be deleted in full.
Deleting the account removes its credentials, sessions, linked sign-in methods, memberships, preferences, notification tokens and acceptance records linked to that technical account. Where applicable, Tokarea also requests revocation of the authorisation granted to Apple or Google. In shared groups, the link between the account and the selected identity is removed; that identity is shown as “Deleted participant” and cannot be claimed again.
Any Tokarea Pro entitlement linked to that account is also deleted. Deleting the Tokarea account or uninstalling the app does not cancel an Apple App Store or Google Play subscription: you must cancel it separately in the store where you subscribed. Tokarea requires you to protect the technical account with Apple, Google or email before buying Pro. After changing device or reinstalling, recover that account first and then restore with the same Apple ID or Google Play account; Tokarea checks the purchase directly with the relevant store.
Unlinking a sign-in method does not by itself delete the technical account or its groups. Full deletion is initiated through the “Delete account” flow. Identity providers may separately retain the account you hold with them under their own terms.
Where Tokarea has verifiable technical authorship information, it deletes from shared groups the messages, tasks, shopping items and activity descriptions created by the account. Photos linked to removed or replaced items enter a private deletion queue. Expenses and payments must retain their accounting effect so that other people’s balances are not changed: the amount, teams and date are retained, but the description is replaced with generic wording and the authorship link is removed. Assignments and point movements needed to preserve the ranking are also retained without that link; if an attributable bonus contains a free-text note, the note is deleted. Older rows without provable authorship and the necessary numerical history may remain as group information, without technical attribution to the deleted account.
A shared group’s name, teams, other identities and the relationships needed for the remaining people to continue using it are also retained; the technical link to the account that created them is removed. The identity used by the account is anonymised and removed, and its name is replaced with “Deleted participant” in team labels generated by Tokarea as well. Other people in the group can edit or delete the shared structure using the available features.
If the account is the only one with access to a group, that group and its data are deleted from the active service. The device also deletes its groups, synchronisation copy, change queue, notification preferences and local record of acceptance of the Terms. Only the selected appearance is retained; it does not contain an account or group identifier.
While a group remains active, its content is retained for the people who still participate until they delete it using the available features or the group is closed. Credentials, memberships and technical preferences are retained while the account exists or until they are no longer needed for the relevant feature.
An ordinary photo’s technical deadline is fixed at 30 days after preparation and is not renewed when viewed. The service may stop issuing new short-lived links shortly before that deadline, so remote delivery lasts for up to 30 days. At the deadline the encrypted content, its key envelopes and cryptographic metadata that is no longer needed enter the asynchronous physical-deletion queue. If deletion fails, the file remains inaccessible and enters retries and technical monitoring until it is deleted. The item or message retains only the minimum state needed to show that the photo is no longer available.
When a shopping photo is removed or replaced, or a message with a photo is withdrawn, the service stops issuing new links and its encrypted content enters the deletion queue; the withdrawn message’s opaque `photo_key` becomes `null`, so restoring its text later does not announce the photo again. It also stops issuing new links for an account that loses authorisation by leaving, being removed or blocked, or being deleted. In either case, a read link that was already issued may keep working until its short lifetime expires. The app attempts to delete encrypted and temporary local copies when content is removed, the account leaves or is removed from the group, is blocked, or is deleted. It cannot withdraw a screenshot, export, or a copy saved or shared outside Tokarea through the system sheet. A confirmed report does not extend the ordinary file: if the reporting device supplies an image, it creates a contextual, separate, sanitised JPEG evidence copy that Tokarea can read; linking it to the case does not cryptographically prove that it matches the exact content of the ordinary file. It is retained while the case is open or under review; once 90 days have elapsed after closure it enters the deletion queue, and a technical failure only causes retries.
The notification token and its minimum language preference may remain linked to the account while it remains active so that the configuration and notification language are preserved. When notifications are turned off, the token is no longer used for new deliveries. If the provider indicates that it is no longer valid, Tokarea disables it and does not use it again; its technical record and language preference are deleted with the account.
Notification events and deliveries may retain for up to 90 days the technical UUID, token, minimum notification content, ticket, status and error needed to retry, check delivery, prevent duplicates and diagnose incidents. Support or complaint emails are retained for as long as needed to handle and document the request and then for the period necessary to address any potential liabilities or obligations.
Privacy requests are retained with their text for as long as needed to handle them, document the action taken and address possible claims or obligations. If the account is deleted, its link to the request, the note, response, language and any reason for an extension are removed; only an opaque receipt containing the type, status and dates remains.
In-app reports remain while they are open or for as long as necessary to document the decision and address a claim or applicable obligation. When an account is deleted, its technical identifiers and linked comments are removed from those case files; if it was the reported person, the link to their identity is also broken and the stored copy of their name is deleted. The limited textual copy of other reported content is retained only while needed to review and document the case; once 90 days have elapsed after closure, the separate JPEG copy provided as evidence enters the deletion queue. This rule does not extend the ordinary encrypted file. Only a revoked, anonymised record of a block may remain, containing the group and dates but no account, identity, reason or authors, to provide aggregate evidence that the measure existed.
To safely resolve a retry caused by a network interruption, a random request key is retained for seven days without a user identifier or content. After that, only aggregate monthly totals of requests, deleted accounts, deleted groups and departures from shared groups remain.
Deletion from active systems may not immediately remove technical copies, backups or operational logs held by providers. Those copies remain subject to the providers’ documented retention periods and must not be used for ordinary operation; if a system has to be restored, deletion requests will continue to apply.
Your choices and rights
You can request access to, rectification or erasure of, restriction of processing of, and portability of information concerning you, and you can object to its processing, where each right applies. From Settings → Privacy and data, an active session can download an immediate JSON copy, submit an access, portability, rectification, restriction or objection request, and view its reference and status. Account erasure has a separate flow on the same screen. You can also email support@tokarea.com, particularly if you can no longer access the app. If any processing were based on your consent, you could also withdraw it without affecting the lawfulness of processing carried out beforehand.
An active session demonstrates control of the technical account, whether it remains linked only to the installation or was opened using a linked method; it does not verify a person’s legal identity or create a right to receive information about other people in the group. The JSON copy facilitates access and portability but does not necessarily exhaust every right. It includes account data and, where present, the email address, linked sign-in methods and Tokarea Pro entitlements; it also includes notification preferences without the token, legal acceptances, submitted requests and reports, and the reference, group, status and dates of blocks concerning the account. If the account is active, groups it can still access add only the technical group identifier, join date, notification preference, selected identity identifier and technical contribution metadata —the item type and identifier, group, dates, and whether the account is recorded as creator or latest editor. The copy does not include votes or shared text from groups, teams, participants, chores, shopping items, expenses or activity. A suspended account retains its copy of account data, preferences, acceptances, requests, reports and sanitised blocks, but cannot retrieve memberships or contribution metadata from live groups. The copy also does not add invitation codes, tokens, private report snapshots or targets, block actors, reasons or identities, or identifiers belonging to other accounts as structured fields. Included notes, comments and responses are free text and may reproduce what was written in them.
Tokarea will provide information on the action taken without undue delay and in any event within one month of receiving the request. Where necessary because of the complexity or number of requests, that period may be extended by up to two further months; the extension and reasons for it will be communicated within the first month. These are response periods for information about the action taken, not a guarantee that every request must be granted.
Tokarea may request the minimum additional information needed where there are reasonable doubts that the request relates to the account or person affected. Do not send the invitation code. If you submitted a report from an item’s screen, use the TKR-… reference returned by the app; a PRV-… reference identifies a privacy request and does not grant access either.
Privacy and data shows a technical UUID reference for your own account that you can select or share. Keep it and include it in an external request where possible. If an anonymous account was never protected with Apple, Google or email and the session, that reference and every PRV-… or TKR-… reference are lost, it may be impossible to locate the account or safely establish who controls it. Tokarea does not delete another account based on a nickname or group code.
If you believe a request has not been handled correctly, you can contact the data protection authority that applies to you. In Spain, this is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).
Children
Tokarea is intended for adults organising a household or group and is not specifically designed as a children’s service. A child under 14 must not create or manage a Tokarea account independently; their parent or guardian must authorise and supervise its use. Tokarea does not ask for a date of birth or use that data to create profiles.
Where processing relies on the consent of a child under 14, consent must be given by the person who holds parental responsibility or guardianship. An adult who adds a child’s name or information to a family group must limit it to what is needed and obtain any required authorisation.
Changes and contact details
If this policy changes materially, we will update its date and the information available in the app. For any privacy question, email support@tokarea.com.