1. Scope and roles
This Privacy Policy applies to the hosted CORE Family Hub service operated by Wacky Engineering, including core.wackyengineering.com and official preview environments. A separately operated or self-hosted CORE deployment may have a different operator and privacy policy.
The household owner controls the household workspace and invites or provisions other accounts. Dedicated shared-display accounts are device identities controlled by the household owner, not independent people.
2. Information CORE processes
| Category | Examples | Why CORE uses it |
|---|---|---|
| Account and access | Email address, authentication identifiers, household role, invitations, policy acknowledgments, and security events. | Sign-in, household access, authorization, fraud prevention, and support. |
| Household and family profiles | Household name; nicknames or names; role; profile icon, color, avatar, birthday; adult PIN hashes; display settings. | Personalization, attribution, access control, birthdays, and shared-display operation. |
| Household content | Calendar events, chores and completion history, rewards, lists, groceries, pantry inventory, meal plans, recipes, notes, whiteboards, maintenance tasks, chat content, feedback, and uploaded logos or screensaver photos. | Provide the features the household chooses to use. |
| Location and environment | Location search or approximate coordinates selected by an adult, weather results, time zone, and holiday region. | Weather, date, schedule, and household context. |
| Device and technical data | Session tokens, browser/device information, push subscription endpoints, logs, network information, build version, and diagnostic errors. | Keep CORE signed in, deliver notifications, secure the service, recover failures, and diagnose incidents. |
| Optional integration data | Home Assistant entity identifiers, state, rooms and commands; Kroger/Dillons authorization and cart/store information; AI key configuration, approved household context sent with a request, and AI output. | Perform an integration action specifically enabled or requested by the household. |
| CORE Community | A pseudonymous Community name, recipe snapshot, contribution consent version and time, moderation state, imports, and ratings. | Review, publish, import, rate, withdraw, and delete Community submissions. |
3. Where information comes from
CORE receives information from an account holder, other authorized people in the same household, a shared display used in the household, enabled integrations, and the device or browser used to access CORE. A household adult may enter information about other family members. People using a shared display should understand that other household members can see and change unprotected household content.
4. How CORE uses information
- Provide, personalize, synchronize, and secure household features.
- Apply household roles, adult-area protection, and shared-display restrictions.
- Run actions requested by a user, including optional AI and integration actions.
- Send requested notifications and service communications.
- Moderate Community submissions and respond to deletion, privacy, safety, or copyright requests.
- Detect abuse, investigate failures, maintain backups, comply with law, and improve reliability.
5. Service providers and optional integrations
CORE uses service providers as needed to operate: Supabase for authentication, database, storage, realtime, and server functions; Vercel for frontend hosting and delivery; browser or device push services for notifications; Open-Meteo for selected-location weather and geocoding; and Nager.Date for public-holiday data.
If a household enables an optional feature, CORE may also interact with Google Gemini for AI responses, Kroger/Dillons for grocery account or cart actions, and the household's own Home Assistant installation for allowlisted smart-home status and commands. CORE uses provider authorization tokens for Kroger/Dillons and does not receive or store the user's grocery-account password. Those providers process information under their own terms and privacy notices. CORE does not send optional-feature data to a provider until the household enables or invokes the feature.
CORE may disclose information when required by law, to protect users or the service, during a business transfer subject to appropriate safeguards, or with the account holder's direction. CORE does not sell household information or share it for cross-context behavioral advertising.
6. Privileged operational access
Household information is not routinely reviewed. Authorized Wacky Engineering personnel and service providers with privileged system access may technically access database records, uploaded files, logs, and other household information only when reasonably necessary to operate or secure CORE, troubleshoot a reported problem, respond to a privacy or support request, investigate abuse or a security incident, enforce the Terms, protect users or the service, or comply with law. Privileged access is restricted through appropriate authentication and access controls.
7. AI and automated features
AI is optional. When enabled, CORE sends the prompt and the minimum approved household context needed for that request to the configured AI provider. AI output may be incomplete or wrong and should be reviewed. Household API keys are restricted to server-side use but remain sensitive credentials. The sensitive-content limits below apply to AI prompts and every other CORE feature.
A signed-in user can report a specific AI response as incorrect, harmful, inappropriate, a privacy concern, or another concern. A report privately stores the reported response excerpt, a cryptographic fingerprint, the selected category, the user's optional explanation, the reporting account, and the household for moderation and abuse prevention. It does not automatically submit the rest of the chat. Safety reports may be retained after the chat or account is deleted when reasonably necessary to investigate abuse, document the response, or comply with law.
8. Information CORE is not designed to store
CORE is intended for ordinary household organization. Do not use CORE as a system of record for Social Security numbers, government identification, payment-card or bank credentials, tax records, passwords or private authentication keys, detailed medical or clinical records, legal-privileged documents, intimate images, surveillance recordings, or other highly sensitive or regulated information. Supported third-party credentials should be entered only through the designated integration controls. Ordinary household context—such as an appointment title, allergy, food preference, or medication reminder—is permitted, but CORE is not a medical-record system.
9. Children and managed profiles
CORE is a general-audience household service intended to be established and administered by an adult. Children and teens may not create or receive individual CORE sign-in accounts. An adult may create and control a managed family profile and may allow supervised use of a household shared display. Managed-profile information may include a nickname or name, birthday, avatar, chores, rewards, events, and activity associated with that profile.
A parent or guardian can review, correct, export, or delete a managed child's information from household settings or by contacting Wacky Engineering. CORE does not knowingly sell or behaviorally advertise using children's information. If Wacky Engineering learns that a minor created or received an individual sign-in account, it will investigate and delete or restrict that account and associated information as appropriate.
10. Community privacy
The CORE Community Cookbook is disabled for a household by default. A household owner or adult must deliberately enable it before household members can browse, import, rate, block contributors, or submit content. Private household recipes remain available when the Community feature is off.
Household recipes stay private unless a signed-in adult deliberately submits a snapshot and checks the Community consent box. Nothing is discoverable until approved. Pending submissions and accompanying images are intentionally reviewable by authorized moderators for approval, safety, privacy, rights, and policy review. The members-only catalog shows the approved recipe and Community name—not the contributor's email, household, account ID, or Family Profile. Contributors should use a pseudonym and must not include personal information in recipe text or imagery. Signed-in users can report a listing and block a contributor from their household's Community results.
Withdrawal hides a listing immediately. A permanent-deletion request hides it immediately and queues the Community-hosted content for deletion after a 30-day security and audit period. Independent recipe copies already imported into other households are not controlled by the contributor and cannot be recalled.
11. Retention and deletion
CORE keeps active household information while it is needed to provide the service and as directed by authorized household users. Individual items can be deleted within CORE where the feature provides that control. A signed-in adult can permanently delete the adult account from Settings → Account Security; instructions are also available at core.wackyengineering.com/delete-account.html. If another adult remains, household ownership is transferred or the deleting account leaves the household. If the account is the household's last adult, deletion also removes the household and its private data. The confirmation screen explains the applicable outcome before deletion.
Account, household, or broader privacy deletion requests can also be sent to the contact below. Limited data may remain temporarily in provider backups, rate-limit and security logs, fraud or safety records, AI-response reports, or legal records for their applicable retention periods.
Community erasure follows the 30-day process described above. CORE does not keep children's information longer than reasonably needed for the household purpose for which it was provided.
12. Security and incidents
CORE uses role-based authorization, row-level database controls, restricted server functions, private storage, server-verified PINs, dedicated display identities, input validation, rate limits, and encrypted network transport. No system is perfectly secure. Household owners should use strong unique passwords, protect adult PINs and API keys, remove unused accounts and displays, and report suspected access promptly.
If Wacky Engineering learns of unauthorized access to information, it will investigate, take reasonable containment and remediation measures, and provide notices required by applicable law. No online service can guarantee absolute security.
13. Privacy choices and rights
Depending on location, a person may have rights to know, access, correct, export, delete, restrict, object, or appeal, and to avoid discrimination for exercising a privacy right. Requests are verified to protect the household. A household owner can manage much of the data directly in CORE. Requests may also be sent to the contact below.
14. International processing and changes
CORE is operated from the United States, and providers may process information in the United States or other countries. Applicable safeguards will be used where required. Wacky Engineering may update this policy as CORE changes. A material update will receive a new version and normal accounts will be asked to acknowledge the current Terms and Privacy Policy again.
Email: [email protected]
