Photos & privacy

Where your photos live, and what we never collect

Before and after photos are optional in Tidywell. When you do use them, here's where they go, how long they stick around, and the bits about storage we'd rather be upfront about than hide in a privacy policy.

How to

Taking a before and after

The Photo action isn't a separate screen you have to hunt for, it lives inside the action sheet you already use for a task. Tap a task row on Today or inside a room, and the sheet that opens has a Photo tile in its "More" section, alongside Move, Assign and Edit.

PhotoBefore ready
Wipe the hob
📸 Before ready · 5 min · Every 2 days
BEFORE
AFTERTap to add
RetakeRemove
Save

Illustration of the Photo tile with its Before ready label, the task row note, and the paired capture screen, using the app's own labels. Not a screenshot.

Taking a before, on a task you haven't done yet

Tap Photo on a task that's still outstanding and the capture screen opens with a single BEFORE slot. Tap the slot, choose Take photo or Choose from library, and save with Save before photo. Once it's saved, the task's Photo tile picks up a small Before ready label and a sage dot in its corner, and the task's row on the list gains a "📸 Before ready" note ahead of its other details. That's the app telling you a before is waiting for its after.

Ticking the task

There's nothing extra to do here. When you tick the task, whatever before photo is waiting gets folded onto that completion automatically. You don't need to open the Photo screen again just to attach it.

Adding the after, on a task you've already done

This is the part that's easy to miss: tap the task row again. On Today and in a room, tapping a task that's already done still opens the action sheet, it doesn't just do nothing. Tap Photo, and because the task now reads as done and has a completion behind it, the screen opens with both slots this time, BEFORE (already filled in with the one you took) and AFTER. Tap the empty AFTER slot to add it.

There's no deadline on this: the app looks up your most recent completion for the task however long ago it happened, not just the last few minutes, so you can add the after later the same day, or even days on. A task that's done but has no completion behind it, say it was backdated, only ever offers a before, because there's nothing for a pair to attach to.

The other way in is the celebration that appears right after you tick a task. Its "📸 Take before/after photo" line opens straight into the same paired screen.

Retaking or removing a pending before

Any filled slot has Retake and Remove underneath it. Retake reopens the same choice between camera and library. Remove only clears that slot on screen, it doesn't delete anything by itself, you need to tap Save afterwards for it to actually go. Removing a before and saving with nothing left in either slot is how you delete a pending before for good, it's the only way to do it manually.

Where you see the pair afterwards

Once a before and after are attached to a completion, you'll find them from the "View photos" badge on that entry, on a room's detail screen and on My Home. If a parent has approvals switched on for a kid's profile, the same before and after show on the approval screen when they review that completion.

Good to know

Photo capture is a Premium feature. Every route into the Photo screen checks for Premium first, and a household without it is sent to the upgrade screen instead of the camera. In a Premium household, a child profile can still use the Photo tile and the celebration link. If the household isn't Premium, a kid tapping Photo sees a message asking them to check with a grown-up rather than a paywall. There's no per-photo delete button anywhere, no share option on a photo, and no gallery screen that lists every photo on its own, you only ever reach a photo through the task or completion it belongs to.

Optional, useful

Photos are an optional extra, not a requirement

Photos are a Premium feature: every route into the camera checks for Premium first, and a household without it is shown the upgrade screen instead. You can use Tidywell forever without attaching a single photo, and most people don't bother. Where they earn their keep is on tasks where you want a record: a before-and-after for a deep clean, proof a kid's chore got done before pocket money lands, or a reminder of where the grout actually was last time.

If approval is on for a profile (typically a kid's), the parent reviewing the completion sees the attached photo in the approval envelope. There's a separate guide on how approvals work end-to-end at /guide/approvals.

Storage path

Your phone, then a private bucket, then your household

When you attach a photo while signed in, online and part of a household, it goes from your phone up to Tidywell's storage backend (Supabase). The bucket is private. Reading a photo back into the app needs a signed URL the app generates on your behalf. Nothing about the photo is publicly listed or indexable. If you're using the app without an account, have no household yet, or the upload fails, the photo stays local to your phone instead and only that device can see it.

Your phone

Captured by the camera or chosen from your library

Private bucket

Tidywell's Supabase Storage, named task-photos

Your household

Visible only to members you've invited

Plain English: nobody else's account can see your photos. The app doesn't ship a tool that lists everyone's uploads. Database-level rules (the next callout) enforce this in the database itself, not just app behaviour.

Not public, not indexable

The bucket is set to private. There is no public link to your photo. Search engines can't crawl it. The only way to view a photo is for the app to mint a signed URL after checking you're a member of the right household.

Row-level security at the database

Photos are stored under a path scoped to your household ID. Postgres row-level security blocks any read or list attempt from a different household, even if someone had a valid app session. The rule is enforced in the database itself, not in the client.

Storage limits

10 photos for 7 days on free, 50 for 35 days on premium

Photos take up real disk space, so there is a cap. With Premium the app keeps your 50 most recent photos for 35 days each; after that the oldest are deleted automatically. The numbers below are exact.

If Premium ends

Photos

10

Days kept

7

With Premium

Photos

50

Days kept

35

Premium is sized so a household can keep a month's worth of context, plus a buffer for the odd long-running project. If your Premium ends, photos you already took stay viewable but the allowance shrinks to the 10 most recent, kept 7 days, and the app trims to that straight away.

Cleanup runs on app open, and when Premium ends

A photo past its window is cleaned up the next time you launch the app, not on the dot of day 35. So you might briefly see a slightly-over-window photo if you re-open after a long gap. The one exception is Premium ending: the moment the app notices, it trims to the smaller allowance without waiting for the next launch.

At the cap, the next photo is blocked

Once you're at 50, attaching another shows a "Photo storage full" message with a Delete 3 oldest button. That button deletes three at once and retries your save; there's no picking which three. Separately, the automatic cleanup trims your oldest photos by age and then by count without asking, so the cap is a ceiling, not a promise to keep everything.

What's not in the picture

Things we don't pull off your photos

When you attach a photo, the file goes up along with the task ID, the household ID, and the timestamp of the upload, and the completion record it sits on notes who completed the task. That's it. Specifically, here's what we don't do.

No GPS or location

We don't read or store location data from photo metadata. The fact that a photo was taken at home isn't useful to us, and broadcasting where you live isn't useful to anyone.

No model training

Your photos are never used to train models. Not ours, not OpenAI's, not anyone's. The AI task breakdown feature is text-only and ignores photos entirely.

No marketing use

Photos don't show up in adverts, in case studies, in tweets, or in App Store screenshots. The photos in our marketing are stock or staged.

No third-party sharing

Photos aren't sold, shared with marketers, or handed to data brokers. The only third party in the chain is our storage provider, who processes the upload on our behalf and is covered in the caveats below.

Removing photos

Two ways to get rid of a photo

Auto-cleanup handles old ones once they're past the retention window. You can also delete on demand whenever you like.

Deleting one photo

There's no per-photo delete button. What you can do is remove a before photo that's still waiting for its task: open the Photo screen for that task, tap Remove on the before, then tap Save. That's the only manual way to delete one. Beyond that, photos clear out through the automatic cleanup, the Delete 3 oldest button in the storage-full alert, or deleting your account.

Delete your account

Settings → Account → Delete Account removes your account and your local data. If you're the only admin in a household, the household is deleted with it. We're working on tightening the cascade so every server-side photo blob is cleared in the same step. Until then, anything still attached to your account is wiped, and old uploads age out under the normal retention rules.

The honest bits

What we'd rather you knew up front

There are a few things that would feel sneaky to leave buried in a privacy policy. Reading them shouldn't worry you, but you deserve to know.

Signed URLs last 10 years

When the app loads a photo, it gets back a temporary URL signed by the storage layer. We set the validity to 10 years so photos don't fail to load mid-session. Practical effect: if you copy that URL out of the app and post it somewhere public, anyone with the link could view that one photo until the URL expires. Treat a copied photo URL like any other private link.

Photos are stored in plaintext

We don't apply client-side or end-to-end encryption to photo files. They're stored in the bucket as you uploaded them, protected by access rules rather than by per-file encryption. This is the industry-standard setup for app photo storage. We mention it because we'd rather not let you assume something stronger than what's true.

Supabase is the subprocessor

Supabase processes photo uploads and storage on our behalf. They're listed in our privacy policy with the rest of our subprocessors. They don't use your photos for anything beyond running the storage service for us.

Want the full version with all the legal phrasing? It's in our privacy policy.

FAQ

Common questions

Can other households see my photos?
No. Photos are scoped to your household at the database level via row-level security. A different household trying to read your photos gets blocked by Postgres before the request reaches any app code. Only members of your household, who you've explicitly invited, can see them.
Are photos used for AI or model training?
No. Your photos never leave Tidywell's storage for any AI service. The AI task breakdown feature, which is the only place we send anything to OpenAI, is text-only and doesn't see photos. We don't train our own models on your photos either.
What happens to my photos when I cancel premium?
Your existing photos stay viewable, but the allowance shrinks to the 10 most recent photos kept for 7 days, and the app trims to that the moment it notices Premium has ended, not just on the next launch. Taking new photos needs Premium. If you re-subscribe, the larger limits return.
Can I save a photo out of Tidywell?
There's no share or export button on the photo screen. Getting a copy of a before/after photo out of Tidywell means doing it manually, outside the app (a screenshot, for example).
What if I share a photo URL with someone?
Signed URLs the app generates are valid for 10 years. If you copy one out and send it to a friend, anyone with that link can view that one photo until the URL is rotated. Don't share photo URLs publicly or in places you wouldn't share, say, a private cloud-drive link.
Can a kid see another kid's photos?
Photo history isn't split by profile. The Activity timeline on My Home and on each room is shared across the whole household, and any entry with a photo shows its View photos badge to whoever's looking, regardless of which profile completed the task. The approval screen also shows the photo to the parent reviewing a completion.
I ticked a task after taking a before photo, now where do I add the after?
Tap the same task row again, it still opens the action sheet once the task is done. Tap Photo and, because the task now has a completion behind it, the screen opens with both slots, showing the before you already took plus an empty AFTER slot. There's no time limit on this, so it doesn't have to happen right away.
What does "Before ready" mean on a task?
It shows up once you've saved a before photo but haven't yet ticked the task and paired it with an after. You'll see it as a label under the Photo tile and as a note on the task's row, both are just the app remembering a before is waiting.
Can I delete a before photo without ticking the task?
Yes. Open the Photo screen for that task, tap Remove on the before, then tap Save. Clearing the slot on its own doesn't delete it, saving afterwards is what actually removes it.