Privacy Policy
Last updated: August 28, 2026
This privacy policy applies to MetElkaarOnline, a private space for partners, housemates, and small households. It explains which personal data we process, why we process it, and what choices you have.
Service status and transparency
MetElkaarOnline is currently a private beta under active development. The production environment currently collects no real subscription payments; Premium can only be tested without a real charge during this phase.
We therefore do not currently process production payments through Stripe or Google Play. Before paid subscriptions go live, we will publish the applicable payment provider, business and registration details, and final payment terms. You can always contact support@metelkaar.online with questions.
The main metelkaar.online domain was registered in 2026. We do not hide that this is a young service: changes to this document therefore carry a clear revision date at the top of the page.
What data do we process?
We only process data needed to run your account and the service:
- Account data, such as your name, email address, security settings, devices, and group membership.
- Usage and security data, such as logins, error reports, simple visit counts and approximate country based on IP address (not precise location), and information needed to prevent fraud and abuse.
- Subscription data, such as a group's Premium status. The current private beta does not collect real production payments, so production payment-card data is not sent to Stripe.
Your notes, plans, lists, tasks, and goals are stored encrypted. In the standard setup, MetElkaarOnline does not hold a key that lets employees read the original group content. Development Feedback is a separate voluntary exception that is only enabled when all group members consent. See “Private content and encryption” for details.
Private content and encryption
Your group content is stored encrypted. In the standard setup, only group members can open that content; MetElkaarOnline cannot view or decrypt the original content for you.
Development Feedback is an optional exception: only when every group member enables it do we keep a secure recovery option and allow content to be processed automatically as described below.
Keep the recovery code for group content in a safe place. If all group members lose both access and the recovery code, and nobody is still signed in, the content can technically be lost permanently. That consequence follows from the encryption model; it does not change any rights you have under applicable law.
Content can still be readable on an unlocked device, in a notification, or in a downloaded export. An export file is not encrypted.
Development Feedback
Development Feedback is voluntary and is only enabled when all group members give consent.
When Development Feedback is enabled:
- we keep a secure recovery option;
- content may be analysed automatically to improve the service;
- we collect general information about how features and goal types are used;
- we may be able to help if you lose access to the group.
Employees do not view original notes, plans, or other private text. They only work with anonymised or aggregated results.
Development Feedback is turned off as soon as one group member refuses or withdraws consent. The recovery option is then removed and new analyses stop. Results that are already fully anonymised may be retained.
We do not use private content for advertising and we do not sell it.
What do we use data for?
We use personal data to:
- manage accounts and groups;
- handle access, devices, and security;
- handle notifications and subscription status;
- prevent fraud and abuse;
- fix errors and keep the service stable;
- keep aggregated business statistics (such as new accounts and visits);
- provide support;
- improve the service when Development Feedback is enabled.
Legal basis
Depending on the purpose, we process data because it is necessary to provide the service, to keep the service safe and reliable, with consent, or to meet a legal obligation.
You can withdraw consent at any time.
Two-factor authentication and recovery codes
Two-factor authentication is optional. You can view and manage signed-in devices.
There are two different recovery codes:
- a recovery code for two-factor authentication;
- a recovery code for encrypted group content.
Keep both codes safe. The group-content code is not a password that support can reset: if nobody has access or a valid recovery code, the encrypted content can no longer be decrypted.
Cookies and tracking
Hosting, service providers, and transfers
The core application, database, uploads, and operational backups run on a server stack we manage. The current public server is hosted by netcup GmbH in Germany, so this core storage remains within the European Economic Area (EEA).
Where necessary, we also use external service providers for functions such as email, push notifications, or optional integrations. When such a provider processes personal data outside the EEA, the required safeguards for international transfers apply.
Live payments are currently disabled. No real production payments are therefore processed through Stripe or Google Play during the private beta. If that changes, we will update this policy before activation with the relevant provider and transfer information.
We do not sell personal data and we do not share decrypted group content for others’ commercial purposes.
Security
We take measures to protect personal data, including encryption, secure password storage, access restrictions, two-factor authentication, and abuse monitoring.
No service can guarantee complete security. If a security incident occurs, we take appropriate measures and inform those affected and regulators when legally required.
Retention periods and backups
Account and group data remain in the active database for as long as needed for an active account, group membership, and the features you use. When an account or group is permanently deleted through the applicable deletion flow, the active copy is removed from the primary service except where we must retain specific data for a legal obligation or a concrete security purpose.
The production environment creates an operational backup daily by default. The backup service is configured to keep the 7 newest successfully verified backups and remove older successful backups after a new successful backup. Deleted information may therefore remain temporarily in an older backup. A failed backup attempt may be retained longer for technical inspection; such folders are not treated as a normal recovery source and are not used to restore deleted user data automatically.
Security and abuse data are kept only for as long as needed for the relevant security purpose. Fully anonymised results may be kept longer because they are no longer linked to a person.
The Development Feedback recovery option is removed as soon as that feature is disabled.
Account deletion, leaving a group, and group deletion
You can delete your own account after leaving your groups or after a group has been deleted. A group-wide deletion removes shared data belonging to multiple people and may therefore require consent from all group members.
That shared consent is intended to prevent one member from unilaterally destroying other members’ shared data. If you only want to stop using the service yourself, the whole group does not need to be deleted: leave the group first, then delete your own account.
Privacy within the service
MetElkaarOnline is not a social network. There are no public profiles or public posts. Group information is only for the members of your group — partners, housemates, or anyone else you invite.
Your privacy rights
Where the law allows, you can:
- access your personal data;
- have incorrect data corrected;
- have data deleted;
- restrict processing;
- have data transferred or exported;
- object to certain processing;
- withdraw consent.
You can download an export of group content from group settings. That file is not encrypted.
In the standard setup, we cannot open encrypted group content for you. Fully anonymised data is no longer linked to a person and therefore cannot be accessed or exported.
For questions or requests, email support@metelkaar.online.
Complaints
If you have a complaint about how personal data is processed, contact us at support@metelkaar.online.
You can also lodge a complaint with the Dutch Data Protection Authority (Autoriteit Persoonsgegevens) or with the privacy regulator in the country where you live.
Need help?
Can't find what you're looking for? Our team is happy to help with questions about your account, privacy, or security.