Security and your data in OurTab
A shared household ledger only works if you trust it. Here is precisely how your data is separated, stored and handled.
Each household is isolated at the database, not the screen
Separation between households is enforced by row-level security in the database itself, not by the app hiding things. Every query is checked against your household membership before any row is returned, so a bug in the interface cannot expose another household's ledger. Review actions are guarded by a database rule too — the database refuses to let anyone approve their own expense, regardless of what the app asks for.
Where your data lives
Household data is stored in a London (UK/EU) region. Data is encrypted in transit. Payment card details never reach us at all — Stripe handles payment and we receive only a subscription status.
Who else processes it
- Supabase — database and sign-in, London region.
- Vercel — hosting and delivery.
- Stripe — payments for AI Chef.
- Anthropic — powers AI Chef. What you send is used to generate the reply and is not used to train models.
- Resend — sign-in links, password resets, invites.
- Plausible — cookie-free analytics with no personal data and no profiles; we see aggregate visits only.
What sharing means
OurTab is built for shared use, so anyone in your household can see the shared ledger, list, inventory and meal activity. That's the point of it — but it does mean you should only invite people you intend to share that with. Removing a member stops their future access; it can't unsee what they already saw.
Your data is yours
Ask us to delete your account and your personal data goes within 30 days, apart from limited records we're legally required to keep. Email kris.deane93@gmail.com for access, correction, export or deletion. Full detail is in the privacy policy.