Tokarea

Privacy Policy

How Tokarea handles the data it needs to make your group work.

Last updated: 21 July 2026

Tokarea lets people organise tasks, shopping lists and expenses in groups accessed with a code. This policy explains what information the app needs, how it is used, and how you can delete your account and exercise your rights.

The app does not require an email address or password. When you start, it creates a pseudonymous technical account linked to the installation, and you choose the name or nickname you use in each group.

Controller and contact details

Alfonso González Ariza is the controller of the personal data processed by Tokarea. For privacy questions, support or to exercise your rights, email [email protected].

The personal email address used to manage the Apple account is not published or used as a support channel.

Data we store

  • Group, team and participant names or nicknames entered by people in the group.
  • Tasks, categories, notes, ratings, assignments, points and activity history.
  • Shopping-list items, quantities, units, categories, assignees, notes and purchase status or history. Over time, this information may reflect the group’s habits.
  • Shared expenses and payments, including descriptions, amounts, participants and calculated balances.
  • A technical user identifier used to link this installation to its groups and to the selected person.
  • If you enable notifications: a technical push token, platform, app version, the minimum language preference (es or en), notification level, and paused or enabled groups.
  • To deliver and check notifications: identifiers for the event and recipient account, the minimum technical content needed for the notification, status, provider ticket and delivery error, where applicable.
  • Technical operational data such as IP address, platform, version, request, security and delivery logs, and the minimum technical information about a failure that may be generated while providing or updating the service.
  • To record acceptance of the Terms of Use, the service stores the technical account, the accepted version and the date. This device also keeps a local copy of that version and date; the local copy does not include the invitation code or a group identifier.
  • If you report content from the app: the type and technical identifier of the item, the group, a limited private copy of the fields visible when you submit the report, the reason, an optional comment, the case reference, review status and dates, together with the technical identifiers needed to verify membership. Only a direct report about a participant is automatically linked to the reported account; an editable task, shopping item or expense is not attributed to a person by default.
  • If an account is blocked from a group: the group, affected identity, account applying the measure, optional reason, dates and revocation status. This information is not shown to the rest of the group.

How we use the data

  • To synchronise information and changes between devices that belong to the same group.
  • To calculate assignments, scores, balances, histories and suggestions for settling expenses.
  • To remember which person uses each device and restrict access to the groups it has joined.
  • To send the notifications you have chosen and avoid notifying you about your own actions.
  • To distribute compatible updates, protect the service and diagnose operational or delivery errors.
  • To prevent abuse, receive and review reports, remove content, and apply or lift blocks and access suspensions in a proportionate way.

Legal basis

The technical account, group membership, synchronisation, calculations and features you request are processed because they are necessary to provide the service under the Terms of Use and to take the steps you request before creating or joining a group.

Security, abuse prevention, minimum diagnostics, service continuity and incident handling rely on the legitimate interest in keeping Tokarea secure and operational, balanced against the rights of the people affected.

Certain information may be processed where necessary to comply with a legal obligation, respond to a rights request, or establish, exercise or defend a legal claim. If a future feature required consent, it would be requested separately and could be withdrawn just as easily.

The Privacy Policy provides information about this processing: confirming that you have read it does not make every processing activity consent-based.

Information required to use Tokarea

The technical account and group membership are required to share and synchronise information. Without them, you can view the public pages but cannot use a shared group. You can use a nickname and enable only the modules you need.

Task, shopping and expense content is processed only when someone in the group chooses to enter it. Notifications and contacting support are optional: if you do not use them, the rest of the group will continue to work.

Data Tokarea does not request

The app does not ask for your email address, phone number, contacts, photos or access to other content on your device. It does not request GPS permission or obtain your precise location. Technical providers may infer an approximate location from your IP address when providing or protecting the service.

Tokarea does not include advertising or use this data to track you across apps or websites. Providers’ technical logs are limited to operating, updating, securing, diagnosing and improving the service.

If you choose to email support, we will receive your email address and the content you include so that we can respond to your request.

Where the data is processed

Shared data is hosted by Supabase, which provides the database, pseudonymous technical account and real-time synchronisation. The device also keeps a local copy so that it can remember the group and provide a more continuous experience.

If you enable notifications, Expo Push Service and Apple’s or Google’s notification service are involved, depending on the platform. Expo also provides the technical infrastructure used to distribute compatible app updates.

Resend delivers operational alerts about new reports to a private mailbox. It receives only the sender and recipient of the alert, the TKR reference, content type and date; it does not receive the reported text, names, amounts, group code or account identifiers.

Cloudflare provides the domain, network protection and public pages. Supabase, Expo and their subprocessors may process technical identifiers, IP address, operating system or platform, app version, requests, failures and essential technical interactions. Expo Updates may also use a random installation or update identifier to distribute and diagnose compatible versions. This information is used for operation, security, diagnostics and service improvement, never for advertising or tracking across apps or websites.

The main Supabase project is hosted in Ireland. Some providers or subprocessors may process information from countries outside the European Economic Area. Where an international transfer applies, it must be covered by an adequacy decision or another safeguard recognised by law, such as Standard Contractual Clauses. You can request current information about the provider and applicable safeguard using the contact email address.

Who can see group information

Information is shared with devices that belong to the same group. Anyone with the invitation code can confirm that they wish to join and then see the group’s data, so you should protect it like an access key.

Someone in the group may enter another person’s name or other information about them. In that case, the source of that data is the person who adds it to the group, and the other participants can view and edit it through the collaborative features.

We recommend using nicknames or the minimum information needed and not entering particularly sensitive data in tasks, notes, shopping items or expense descriptions.

Reports submitted in the app and private blocking records are not shared with the group. They can be accessed only by the person responsible for the service, or someone acting under their authority, for the purpose of reviewing the incident.

Retention and deletion

You can delete the technical account from Privacy and data, available in Settings and on the opening screen. Before you confirm, Tokarea shows which groups will remain available to other people and which will be deleted in full.

Deleting the account removes its credentials, sessions, memberships, preferences, notification tokens and acceptance records linked to that technical account. In shared groups, the link between the account and the selected identity is removed; that identity is shown as “Deleted participant” and cannot be claimed again.

Where Tokarea has verifiable technical authorship information, it deletes from shared groups the tasks, shopping items and activity descriptions created by the account. Expenses and payments must retain their accounting effect so that other people’s balances are not changed: the amount, teams and date are retained, but the description is replaced with generic wording and the authorship link is removed. Assignments and point movements needed to preserve the ranking are also retained without that link; if an attributable bonus contains a free-text note, the note is deleted. Older rows without provable authorship and the necessary numerical history may remain as group information, without technical attribution to the deleted account.

A shared group’s name, teams, other identities and the relationships needed for the remaining people to continue using it are also retained; the technical link to the account that created them is removed. The identity used by the account is anonymised and removed, and its name is replaced with “Deleted participant” in team labels generated by Tokarea as well. Other people in the group can edit or delete the shared structure using the available features.

If the account is the only one with access to a group, that group and its data are deleted from the active service. The device also deletes its groups, synchronisation copy, change queue, notification preferences and local record of acceptance of the Terms. Only the selected appearance is retained; it does not contain an account or group identifier.

While a group remains active, its content is retained for the people who still participate until they delete it using the available features or the group is closed. Credentials, memberships and technical preferences are retained while the account exists or until they are no longer needed for the relevant feature.

The notification token and its minimum language preference may remain linked to the account while it remains active so that the configuration and notification language are preserved. When notifications are turned off, the token is no longer used for new deliveries. If the provider indicates that it is no longer valid, Tokarea disables it and does not use it again; its technical record and language preference are deleted with the account.

Notification events and deliveries may retain for up to 90 days the technical UUID, token, minimum notification content, ticket, status and error needed to retry, check delivery, prevent duplicates and diagnose incidents. Support or complaint emails are retained for as long as needed to handle and document the request and then for the period necessary to address any potential liabilities or obligations.

In-app reports remain while they are open or for as long as necessary to document the decision and address a claim or applicable obligation. When an account is deleted, its technical identifiers and linked comments are removed from those case files; if it was the reported person, the link to their identity is also broken and the stored copy of their name is deleted. The limited copy of other reported content is retained only while needed to review and document the case. Only a revoked, anonymised record of a block may remain, containing the group and dates but no account, identity, reason or authors, to provide aggregate evidence that the measure existed.

To safely resolve a retry caused by a network interruption, a random request key is retained for seven days without a user identifier or content. After that, only aggregate monthly totals of requests, deleted accounts, deleted groups and departures from shared groups remain.

Deletion from active systems may not immediately remove technical copies, backups or operational logs held by providers. Those copies remain subject to the providers’ documented retention periods and must not be used for ordinary operation; if a system has to be restored, deletion requests will continue to apply.

Your choices and rights

You can request access to, rectification or erasure of, restriction of processing of, and portability of information concerning you, and you can object to its processing, where each right applies, by emailing [email protected]. If any processing were based on your consent, you could also withdraw it without affecting the lawfulness of processing carried out beforehand.

Tokarea may request the minimum information needed to verify that the request relates to the account or person affected. Do not send the invitation code. If you submitted a report from an item’s screen, use the TKR-… reference returned by the app; the general option in Settings prepares a technical group reference that is different from the code and also does not grant access.

If you believe a request has not been handled correctly, you can contact the data protection authority that applies to you. In Spain, this is the Spanish Data Protection Agency (Agencia Española de Protección de Datos).

Children

Tokarea is intended for adults organising a household or group. It is not specifically designed as a children’s service and does not ask for a date of birth.

If an adult adds children’s names or information to a family group, they should limit it to the data needed and obtain any required authorisation.

Changes and contact details

If this policy changes materially, we will update its date and the information available in the app. For any privacy question, email [email protected].

Email [email protected]Read the Terms of UseHelp and supportSupabase Privacy PolicyExpo Privacy PolicyResend Privacy PolicySpanish Data Protection Agency
Tokarea · Legal information and support