Privacy Policy
Last updated 31 August 2026
Caju (“the app”, at caju.casa) is a private, subscription-funded application for managing one household’s day-to-day life — one sealed home per family — calendar, tasks, trips, health, finances, and the people you keep in touch with. Each home is used only by the household members its owner invites. The subscription is the whole business: there are no ads, no analytics or tracking scripts, and your information is never sold or used to build advertising profiles.
Who we are
Caju is built and operated from London, United Kingdom, by the family behind it. The operator of caju.casa is the data controller for the personal data described in this policy. For anything in this policy, write to lucas@yac.tech — a person answers.
Information we collect
- Your Google account. When you sign in with Google we receive your name, email address, and profile picture (the
openid,email, andprofilescopes) to identify you and admit you to your household. - Your Google Calendar. With your permission, Caju accesses your Google Calendar (the
https://www.googleapis.com/auth/calendarscope) to show your events alongside the rest of the household and to create or update events you ask it to. It keeps an offline (refresh) token so it can do this on your behalf while you’re signed in. - What you put into the app. The household data you or other members enter — members, trips, tasks, notes, health entries, financial figures, and similar.
- Technical data. The minimum needed to run the app securely: a session record for each signed-in device and standard server logs.
How we use it
Your data is used only to provide the app to you and your household: to sign you in, to merge and display your calendars, and to run the features you use. It is not used for any other purpose.
Under UK GDPR, our lawful bases are: performance of a contract for running the app and its features for your household; legitimate interests for keeping the service secure (sessions, server logs, the invite allowlist); and consent where you connect an optional integration (your Google Calendar, a smart scale, a bank feed) — which you can withdraw by disconnecting it.
Google user data & Limited Use
Caju’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google Calendar and profile data are used solely to provide the household features described above, are not transferred to anyone except the hosting processors listed below (as necessary to run the app), and are not used for advertising.
The companies that process data for us
We never sell or share your data for anyone else’s purposes — it is visible only to you and your household. Running the app does rely on a small set of processors, and we name all of them:
- Railway — hosts the app and its database (everything you put in).
- Google — signs you in; holds your calendar if you connect it; resolves commute routes.
- Anthropic — when you hand Caju a document to read (a payslip, a diet plan, a trainer’s message), the Claude API parses it once. Under Anthropic’s commercial terms, API inputs are not used to train their models.
- Apple — delivers push notifications to household iPhones (notification content and device tokens).
- Cloudflare — receives booking emails you forward to the house’s import address, and stores our encrypted-at-provider nightly backup copies.
- Integrations you connect — a smart scale (Withings), budgets and bank feeds (YNAB, Pluggy, brokerage exports), a bakery account (Gail’s): data flows to and from each at your direction, under its own terms, only once you connect it.
- Utility lookups — transit (TfL, National Rail) and weather (Open-Meteo) queries carry only what the answer needs (a journey, coordinates), never your identity.
If this list ever grows, the promises page and this policy change before the code does.
International transfers
The app and its database both run in the EU — Railway’s Amsterdam (Netherlands) region. Some processors above (Google, Anthropic, Apple, Cloudflare) process data in the US; those transfers rely on the processors’ standard contractual protections (SCCs / the UK Addendum, and the EU–US Data Privacy Framework where certified).
Storage, retention & security
Data is stored in the app’s own database on its hosting provider (SOC 2 Type II certified) and transmitted only over HTTPS, with HSTS. The most sensitive stored credentials are additionally encrypted by the app itself. Access is protected by Google sign-in and passkeys behind an invite-only allowlist, and each session is a database record you can revoke, device by device.
We keep your household’s data while your home is active. When you ask us to delete it (or your home closes), we delete it within 30 days, and it falls out of backup copies as they rotate. If your data is ever exposed, we will tell you plainly and without undue delay — and notify the ICO within 72 hours where required.
Your choices & deleting your data
You can revoke Caju’s access to your Google account at any time from your Google account permissions. You can download everything your household has put in — as one plain JSON file — from Settings at any time. To have your Caju data deleted, or to ask any question about this policy, email lucas@yac.tech and we will remove it within 30 days.
Your rights
Under UK GDPR you have the right to access, correct, export (portability — the Settings download exists for exactly this), restrict, object to the processing of, and erase your personal data, and to withdraw consent for any optional integration by disconnecting it. Write to lucas@yac.tech to exercise any of them. If you’re unhappy with how we handle your data, you can complain to the UK Information Commissioner’s Office at ico.org.uk.
Children
Caju is a private household tool and is not directed to the general public or to children as a standalone service.
Changes
If this policy changes materially, we will notify every household before the change takes effect — in plain words, not a quiet edit — and the date above will be updated.
Contact
Questions? Email lucas@yac.tech.