Privacy Policy
The Short Version
- We collect only what we need to make the app work
- We do not sell your data — ever
- We do not share your data with advertisers — ever
- Your passwords are encrypted before they are saved — we cannot read them
- Your email inbox is accessed read-only and only to fetch login codes on demand
- You are in control of what you share and with whom
- Sharing with family is always your explicit choice — nothing is shared without your action
- You can cancel your subscription at any time with one tap — no friction, no guilt trips
Who We Are
Huddle ("Huddle," "we," "us," or "our") is a family subscription manager and private password vault that allows families to store login credentials securely, share streaming service access instantly, fetch login codes on demand, track subscription costs, and manage shared access to services. Huddle is operated by its founder and is based in Maryland, United States.
What Information We Collect
Information you give us directly
When you create an account you provide:
- Your name
- Your email address
- A password to access your Huddle account
- A nickname for how your family sees you (optional)
When you use the Vault you provide:
- Service or website names
- Usernames or email addresses associated with those services
- Passwords — encrypted before storage, never readable by Huddle
- Notes associated with vault entries (optional)
- Category labels for each entry (streaming, banking, social media, etc.)
- Subscription details — cost, billing cycle, renewal date (optional)
When you use family features you provide:
- Services you choose to share with your family
- Access permissions you grant to family members
Information we collect automatically
When you use Huddle we automatically collect:
- Your account creation date and time
- Which features you use within the app
- Basic device information needed to send push notifications (device token)
- Log data including errors and app performance information
We do not use third party analytics tools. We do not track your behavior across other websites or apps.
Information from third party services
When you connect your Gmail or Outlook inbox to Huddle for code fetching:
- We request read-only access to your inbox
- We search your inbox only for emails matching streaming service keywords
- We only look back 5 minutes at a time when a code is requested
- We return only the single most recent matching email
- We do not read, store, or access any other emails in your inbox
- We do not store the full content of emails — only the extracted login code and the timestamp
Your inbox connection uses OAuth authentication provided by Google or Microsoft. We never see or store your email password.
The Vault — How We Handle Your Passwords
The Vault is Huddle's private password manager. We take the security of your stored credentials extremely seriously.
How passwords are stored
- Every password you save in the Vault is encrypted using AES-256-GCM encryption before it is written to our database
- Passwords are never stored as plain text under any circumstances
- Huddle cannot read your passwords — the encryption means even our team cannot access them
- Passwords are only decrypted on your device when you actively request to view them
What we store per vault entry
- Service or website name
- Username or email address
- Encrypted password
- Category (streaming, banking, social media, etc.)
- Notes (optional)
- Subscription details if applicable — cost, billing cycle, renewal date
- Whether the entry is shared with your family
- Which Huddle subscription it is linked to if applicable
Two types of vault entries
Linked entries are credentials for services already added to your Huddle. They have a subscription ID linking them to a shared service. When sharing is enabled family members can see the credentials you have chosen to share.
Standalone entries are credentials for anything else — bank accounts, email logins, social media, work tools, or any other service you want to store privately. These are always private regardless of any sharing settings. No family member ever sees them.
Sharing from the Vault
- All vault entries are private by default — only you can see them
- You can choose to share specific entries with your Huddle family by toggling sharing on
- When you share an entry family members can see the credentials you have chosen to share — they cannot see any other vault entries
- Huddle warns you before sharing sensitive account types including banking, government, health, social media, and email accounts
- You can turn sharing off at any time and family members immediately lose access
Sensitive category detection
Huddle automatically detects sensitive account categories based on the category you assign. When you attempt to share a sensitive category entry Huddle shows a warning and asks you to confirm. This warning is a safeguard only — the final decision is always yours.
When a family member leaves
When a family member leaves or is removed from your Huddle:
- They immediately lose access to all shared vault entries
- Huddle prompts you with a list of the specific services they had access to and recommends updating those passwords
- Vault entries they had access to are flagged with an amber indicator in your vault
- A Needs Attention section in your vault shows all entries that may need a password update
- You can dismiss these warnings at any time after reviewing them
How We Use Your Information
We use the information we collect to:
- Create and maintain your Huddle account
- Store and encrypt your vault entries
- Allow you and your family to fetch streaming service login codes
- Display subscription costs and spend information to your family as you choose
- Send you in-app notifications about activity in your Huddle
- Send you push notifications you have opted into
- Notify you when family members request access to your shared credentials
- Process payments for paid subscription plans via Stripe
- Respond to your support requests
- Keep the app secure and prevent fraud or abuse
We do not use your information for advertising. We do not sell your information. We do not share your information with data brokers.
How We Store and Protect Your Information
Database
Your account data is stored securely in Supabase, a cloud database service built on Amazon Web Services infrastructure. Supabase uses industry standard encryption for data at rest and in transit.
Passwords and credentials
All passwords stored in the Vault are encrypted using AES-256-GCM encryption before being saved to our database. This means:
- Your passwords are encrypted before they are stored
- We cannot read your stored passwords
- Our team cannot access your stored passwords
- Even in the event of a data breach your stored passwords are protected by encryption
- Passwords are only decrypted on your device when you actively request to view them
Website and app hosting
Huddle is hosted on Cloudflare Pages and protected by Cloudflare. Cloudflare provides DDoS protection, SSL encryption for all data transmitted between your device and our servers, and web application firewall protection.
Access controls
Access to your data within the app is controlled by Row Level Security policies in our database. This means:
- You can only see data you are authorized to see
- Family members can only see vault entries you have explicitly chosen to share with them
- Private vault entries are never visible to any other user under any circumstances
Database triggers
Huddle uses automated database triggers to keep subscription information and vault entries synchronized. These triggers run within our secure database environment and never expose your data to external systems.
Your Inbox Access
When you connect your Gmail or Microsoft email account to Huddle for code fetching, we want to be completely transparent about what we do and do not do:
- Request read-only permission to search your inbox
- Search for emails from streaming services when a family member requests a code
- Extract the login code from the matching email
- Return the code to the requesting family member
- Log the time the code was sent and retrieved
- Read any emails unrelated to code fetching
- Store the content of your emails
- Access your inbox unless a code is actively being requested
- Share your inbox access with any third party
- Use your inbox data for any purpose other than fetching login codes
You can revoke Huddle's access to your inbox at any time through your Google or Microsoft account settings. Revoking access does not delete your Huddle account or vault entries.
Family Access and Sharing
Huddle is built around explicit consent for all sharing. Here is how family access works:
The Admin model
The person who creates a Huddle becomes the Admin. The Admin pays the subscription and controls who is invited. All invited members receive the features of the Admin's plan at no additional cost.
What family members can see
- Vault entries you have explicitly shared with sharing turned on
- Subscription service cards for services you have chosen to share
- Your spend information only if you have opted in to share it (Pro tier only)
What family members cannot see
- Any vault entry you have not explicitly shared
- Your private passwords, banking information, or personal logins
- Standalone vault entries — these are always private regardless of any settings
- Your spend information if you have not opted in to sharing
New members
When a new member joins your Huddle existing access controls apply immediately. Services set to current members only or selected members require explicit approval before new members can access them. You are notified when a new member joins and can review their access to your services.
Removing members
When a member is removed or leaves they immediately lose access to all shared entries. Huddle prompts you to update your passwords for any services they had access to and flags those entries in your vault with amber indicators until you dismiss them.
Subscription Tiers and Features
Huddle offers three subscription tiers. The features available to you depend on the tier your Huddle Admin has subscribed to:
- Free — private vault up to 50 entries, share up to 5 services with family, code fetching on shared services, up to 4 members
- Huddle Family — unlimited vault entries, unlimited service sharing, credential sharing, spend dashboard, duplicate detection, renewal alerts, up to 10 members
- Huddle Pro — everything in Family plus opt-in family spend sharing, service level access control, unlimited members
Information Sharing
We do not sell, rent, or trade your personal information to any third party.
Within your Huddle family
Information you choose to share with your family — such as vault entries you have toggled sharing on, subscription costs, and spend data — is visible to the family members you have approved. You control exactly what is shared and with whom.
Service providers
We work with the following trusted service providers who process data on our behalf:
- Supabase — database, authentication, and vault encryption infrastructure
- Cloudflare — hosting, security, email routing, and content delivery
- Stripe — payment processing for paid subscription plans
- Google — OAuth authentication and Gmail inbox access for code fetching
- Microsoft Azure — OAuth authentication and Outlook inbox access for code fetching
- Expo — push notification delivery for mobile apps
- Resend — transactional email delivery
Each of these providers is contractually bound to protect your data and use it only for the services they provide to us.
Legal requirements
We may disclose your information if required to do so by law, court order, or governmental authority, or if we believe in good faith that disclosure is necessary to protect the rights, property, or safety of Huddle, our users, or the public.
Business transfers
If Huddle is acquired, merged, or its assets are transferred, your information may be transferred as part of that transaction. We will notify you before your information is transferred and becomes subject to a different privacy policy.
Data Retention
Cancellation and downgrade
When you cancel a paid subscription your account moves to the Free plan at the end of the billing period. We do not delete any of your data upon cancellation. Your vault entries, family memberships, and account information remain intact. Only paid features are locked until you resubscribe. No data is ever deleted as a result of cancellation or plan downgrade — only as a result of account deletion.
Account deletion
We retain your account data for as long as your account is active. If you delete your account:
- Your profile and account data is deleted within 30 days
- Encrypted vault entries are deleted immediately
- Shared credential access for family members is revoked immediately
- Payment records are retained as required by law
Notifications
Huddle maintains a notification system to keep you informed about activity in your Huddle. Notifications:
- Expire automatically after 30 days
- Are capped at the 20 most recent per user
- Can be deleted by you at any time
- Are never shared with third parties
Your Rights and Choices
Access — You can view all information associated with your account in the app at any time.
Correction — You can update your name, nickname, email, and other profile information in Settings at any time.
Deletion — You can delete your account at any time from Settings. This permanently deletes your data from our systems within 30 days. You may also request deletion by emailing privacy@huddleproject.com.
Portability — You can request a copy of your data by contacting privacy@huddleproject.com.
Revoke inbox access — You can revoke Huddle's access to your Gmail or Outlook inbox at any time through your Google or Microsoft account settings.
Push notifications — You can opt out of push notifications at any time through the Push Notifications section in Settings or through your device settings.
Vault control — You can edit, share, unshare, or delete any vault entry at any time. Turning off sharing immediately removes access for all family members.
Cancellation — You can cancel your paid subscription at any time from Settings with no friction and no required explanation.
Children's Privacy
Huddle is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child under 13 has created a Huddle account please contact us at privacy@huddleproject.com and we will delete the account and associated data promptly.
Given that Huddle stores sensitive credential information we strongly recommend that minors between 13 and 17 use Huddle only with parental awareness and supervision.
California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- The right to know what personal information we collect, use, and share
- The right to delete your personal information
- The right to opt out of the sale of your personal information (we do not sell personal information)
- The right to non-discrimination for exercising your privacy rights
To exercise these rights contact us at privacy@huddleproject.com.
International Users
Huddle is operated from the United States. If you are accessing Huddle from outside the United States please be aware that your information may be transferred to, stored, and processed in the United States where our servers are located and our central database is operated.
If you are located in the European Economic Area, United Kingdom, or Switzerland you have rights under the General Data Protection Regulation (GDPR) including the right to access, correct, delete, and port your data. Contact us at privacy@huddleproject.com to exercise these rights.
Changes to This Policy
We may update this Privacy Policy from time to time. When we make changes we will update the Last Updated date at the top of this page and notify you through the app. Your continued use of Huddle after any changes constitutes your acceptance of the updated policy.
Contact Us
| Inquiry | Contact |
|---|---|
| General questions | hello@huddleproject.com |
| Technical support and account issues | support@huddleproject.com |
| Privacy requests, data deletion, GDPR/CCPA | privacy@huddleproject.com |
| Billing and payment questions | billing@huddleproject.com |