CommonDue Privacy Policy

Last updated: August 27, 2026

What CommonDue Is

CommonDue is a local-first app for apartment buildings, households, shared expenses, and property operations. It helps users keep property records, expenses, payments, payment instructions, maintenance information, documents, announcements, governance records, and local Provider Requests organized.

Local-First Storage

CommonDue is currently designed for local use on the user's device. Core local app flows do not require a backend account.

Data is stored locally on the device unless the user chooses to export, copy, share, or send it outside the app. Some sensitive settings may use device security features such as Keychain or app lock where supported.

Optional Connected Services

A connected account is optional for hosted property membership, property-scoped group and private messaging, a permissioned shared document vault, bounded encrypted backup/restore, Provider Concierge intake/status, server-verified CommonDue Pro access, and explicitly enabled PRAESI AI requests. These services use Supabase infrastructure in the Central EU / Frankfurt region. Online checkout and payment processing are disabled in this release.

Connected services may store the authenticated account identifier and profile, property identity/type, membership/role/unit shell, coarse district/area, hosted messages and collaboration metadata, files and document-vault metadata the committee explicitly uploads, committee-selected maintenance completion photos, bounded Concierge request/status information, and encrypted first-slice backup metadata/objects. They do not turn the app's full local database into broad live cloud sync.

Data Users May Enter

Users may choose to enter or create:

• Property details, such as property type, name, address, district, area, and notes.

• Apartment or unit details, including ownership, occupancy, shares, or related records.

• Owner, tenant, committee, member, or contact details where the user chooses to record them.

• Expenses, payments, recurring payment details, partial payments, overpayment credits, due dates, notes, and categories.

• Published charge runs, frozen source-expense and unit-allocation snapshots, effective-dated unit financial profiles, unit charges, ledger adjustments, contributions, credits/refunds, and building account-statement entries.

• Payment instructions or bank details entered by the user, such as IBAN/reference text for copying.

• Bank import review data from files, text, or statement photos the user manually imports for reconciliation review.

• Receipt photos and on-device text-recognition suggestions the user chooses to review before saving an expense.

• Provider Requests, including category, urgency, area, summary, details, contact preference, and optional contact details.

• Hosted Provider Concierge request intake and status history if a connected Provider Concierge build is enabled and the user explicitly submits a non-emergency request.

• Hosted group/private threads, text messages, attachments, informal poll questions/options/votes, read state, pinned announcements, optional FaceTime call preference/events, APNs device-token metadata after notification opt-in, message report categories, and moderation status if connected messaging is enabled.

• Encrypted first-slice cloud backup metadata and encrypted backup objects if connected cloud backup is enabled and the user explicitly chooses backup.

• Documents, attachments, notices, contracts, minutes, photos, PDFs, invoices, receipts, bank statements, or related building files if added locally or explicitly uploaded by an authorised committee member to the hosted document vault.

• Maintenance completion photos that an authorised committee member explicitly selects and confirms after hosted work is completed or closed.

• Announcements, governance decisions, proposals, votes, maintenance records, work orders, vendors, and audit/activity records.

• Privacy preferences, consent settings, retention settings, security settings, and local app activity or diagnostic information.

• Apple-verified subscription or credit-pack metadata, including product, transaction and original-transaction identifiers, environment, purchase/expiry/revocation times, ownership type, connected-account binding, and a cryptographic digest. CommonDue does not receive payment-card details or store the raw signed transaction.

• Privacy-safe PRAESI AI request metadata, such as property/profile references, capability, selected source categories, requested budget, status, token/cost totals, rejection class, and timing, only when customer AI is explicitly enabled. CommonDue does not intentionally store the prompt, answer, selected source content, or raw provider payload in the AI request ledger.

What Is Not Currently Implemented

The current app does not provide:

• A required backend account for core local use.

• Broad live cloud sync, recurring automatic sync, automatic restore, or broad server backup.

• A bank API, Open Banking, or Revolut connection.

• CommonDue custody of funds, a pooled CommonDue balance, CommonDue-hosted card entry, online checkout, payment-provider onboarding, payment processing, or CommonDue bank account verification.

• Automatic Provider Request submission to CommonDue without explicit user action, or automatic submission to providers.

• A provider marketplace or automatic provider matching.

• Emergency response.

• In-app VoIP, group calls, call recording, call transcription, Contacts access, or AI message processing.

• Paid PRAESI AI credit-pack purchasing, autonomous AI actions, or unmetered/unlimited AI access.

CommonDue Pro Purchases And AI Credits

CommonDue uses Apple's StoreKit for CommonDue Pro subscriptions and, only when enabled, one-time PRAESI AI credit packs. Apple processes payment and tax information. CommonDue receives only Apple-signed transaction facts needed to verify the product, connected-account ownership, entitlement, expiry, revocation, refund, duplicate delivery, and credit balance. The raw signed transaction and payment-card information are not intentionally stored.

The service keeps a server-authoritative entitlement and an integer credit ledger so the same purchase cannot be credited twice, refunds can remove unused credits, and provider spending can be bounded. A refunded pack whose credits were already used may create a credit-debt amount. Family-shared purchases are not accepted in this release because the recipient cannot be safely bound to the purchasing connected profile.

PRAESI AI Assistant

Customer PRAESI AI is available only to signed-in eligible CommonDue Pro TestFlight accounts. The user must explicitly accept the AI disclosure and choose a supported assistant action and approved source categories. CommonDue sends the user's bounded request and only the role-permitted source fields needed for that request through a server-side function to OpenAI. The OpenAI API key is never included in the iOS app or returned to the user.

The provider processes the submitted prompt and selected source content to return a structured answer or draft. Provider processing and retention are governed by the approved API account settings and provider terms; CommonDue must not promise zero provider retention without confirming those settings. CommonDue's own AI request ledger is designed to retain safe operational metadata, citations, category coverage, token/cost totals, and rejection class rather than prompt text, answer text, documents, bank details, or raw provider responses.

The Assistant may let a user select a photo, PDF, or plain-text file for on-device text extraction. The raw attachment is not uploaded by that control. Extracted text is shown to the user and enters an AI request only after the user explicitly inserts and reviews it while customer AI is active. Inserted text is marked as untrusted document content and remains subject to the same role, consent, size, credit, cost, and safety limits as typed text.

Requests fail closed when consent, role access, active Pro, credits, quotas, model/rate configuration, schema, citations, length, required concepts, or the hard global spending budget are not valid. AI output remains a draft for human review and does not by itself mutate financial, governance, messaging, maintenance, or provider records. Paid AI credit packs remain unavailable in this TestFlight release.

Manual Sharing And Export

Users may manually export, copy, share, or send information from the app, such as CSV files, PDF files, prepared messages, local request summaries, or other exported records.

When data is shared outside the app, the recipient's handling of that data may be different from CommonDue's local app storage. Users should check what they are sharing before sending it and avoid sharing information that is not needed.

Receipt And Statement Scanning

Users may choose to photograph or select receipt and bank-statement images. Apple on-device text recognition is used to suggest editable expense fields or statement rows. The scanner does not upload images or recognized text to CommonDue, Supabase, OpenAI, or another external recognition service. Suggestions are not saved, matched, or marked as paid automatically; the user must review and confirm them. A receipt image is retained locally only when the user chooses to save it as an attachment.

Online Payments Disabled

Online checkout, merchant onboarding, payment processing, online refunds, and payment disputes are disabled in this release. The app does not send card or merchant-bank details to CommonDue or a payment processor.

Users may store payment instructions and manually record or reconcile transactions that happen outside the app. CommonDue does not hold or pool resident funds, connect to bank APIs, verify bank accounts, or automatically confirm an external transfer.

Provider Requests

Provider Request drafts are saved locally in the app unless the user manually shares, copies, exports, or sends them, or explicitly chooses Submit to connected concierge.

Local drafts are never submitted automatically. Contact details should be included in prepared messages or exports only when contact-sharing consent is on.

Users with connected access may explicitly submit a bounded non-emergency Provider Concierge request to CommonDue. The MVP intake is designed for request category, urgency, summary, details, district/area, contact preference, contact-sharing consent intent, and public-safe status history. It is not designed to store provider-facing contact fields, attachments, payments, refunds, provider assignments, provider bids, bank data, raw app snapshots, credentials, or emergency dispatch information.

After that explicit connected submission, CommonDue may automatically send a minimal operations notification to [email protected]. The email is limited to a request reference, property name, allow-listed category and urgency, district/area, preferred contact method, consent flag, and submission time. It does not include the request summary or details, contact values, message bodies, attachments, documents, bank/payment data, app snapshots, credentials, or a raw delivery-provider receipt. The protected connected queue remains the source of truth if email delivery is delayed or unavailable.

CommonDue is not an emergency response service. For urgent danger, active damage, safety issues, fire, flooding, electrical risk, trapped persons, or similar emergencies, users should contact emergency services, building management, utility providers, or a qualified professional directly.

Provider availability, pricing, quality, and response are not guaranteed by CommonDue.

Connected Messaging

Connected hosted group threads are stored for active members of the same hosted property. Private one-to-one threads are limited to their exact participants while both remain eligible members.

Users may explicitly send text, supported files, and informal poll choices. Private one-to-one chat and hosted attachments use the same participant and current-membership boundaries. Hosted attachments are stored in a private bucket, checked against a size/type allow list, verified by size and SHA-256 before becoming visible, and downloaded through short-lived signed links. Users should review files before sending them and avoid uploading secrets or unnecessary personal, bank, or payment information.

Before authored text or attachment metadata is posted, CommonDue applies a narrow deterministic English/Greek screen in server memory for clearly high-severity abusive, threatening, exploitative, or explicit terms. It does not send content to an AI or third-party moderation service. Rejected content is not intentionally inserted into hosted messaging tables or included in the rejection response, and the matched rule is not returned. This baseline does not inspect the bytes inside uploaded files and cannot detect every harmful item.

Read state and pinned-message state may be stored to provide unread counts, bounded sent/read indicators, and admin announcements. Poll records may include the question, options, the member's current choice, result counts, and close status.

Users may optionally save a FaceTime email address or phone number for allowed private-call handoff. CommonDue reveals it only when another eligible private-chat participant starts an allowed call. The call opens in FaceTime; CommonDue does not carry, record, transcribe, or store call media.

If the user asks for chat notifications, the app may send an APNs device token and environment metadata to CommonDue. Notification previews are designed to be generic and do not include message text, filenames, poll choices, call addresses, payment data, or raw payloads. Notification permission can be changed in iOS Settings.

Message reports are designed to store metadata only, such as message/thread/building references, reporter profile reference, category, status, and review timestamps. The MVP report model should not store free-form report details, screenshots, attachments, raw payloads, invite codes, tokens, credentials, or bank/payment details.

Members may block or mute another eligible member within the same hosted property. Block/mute records contain property, owner/target profile references, state, and timestamps. Admins/managers may be able to hide or delete messages. Current moderation deletion is a visibility/status action and should not be described as instant physical database deletion unless a tested physical deletion process and legal/privacy wording are approved.

Connected Cloud Backup

If connected cloud backup is enabled, backup is optional and must be started by the user. The first backup scope is designed for an encrypted selected-building first slice only: building metadata, district/area, and apartment/unit shell fields.

The first backup scope is not designed to upload raw app snapshots, credentials, recovery keys, device preferences, diagnostics, expenses, payments, bank/payment data, providers, documents, polls, discussions, hosted messages, or Provider Concierge request details.

CommonDue does not store the user's recovery key. Users must keep their own recovery key safe. Support can explain the backup and restore-preview flow, but cannot decrypt a backup, bypass the recovery key, or recover a lost recovery key.

Restore is preview-first. Local data should not be overwritten unless the user explicitly confirms the restore/apply step.

Connected Document Vault

Authorised committee administrators and managers may explicitly upload a

supported property file to a private hosted document vault. The uploader

chooses the title, category, folder, audience, optional unit, optional expiry

date, and optional links to property records. Depending on that choice, a file

may be visible to all active property members, committee members only,

committee/accountant roles, or one unit plus the committee.

The hosted vault stores the file, filename, type, size, checksum, version and

permission metadata, property/member references, timestamps, expiry/archive

state, and selected links. Supported files are size/type limited and verified

by byte count and SHA-256 before becoming visible. Storage is private and

downloads use short-lived signed links after a fresh membership/access check.

Users should not upload credentials, recovery keys, access tokens, unnecessary

personal information, or files they are not authorised to share. A file can

contain financial information, such as an invoice, receipt, or bank statement,

only when an authorised user intentionally selects it. The current boundary

does not automatically scan file contents for malware or sensitive information.

Expiry and archive controls do not by themselves guarantee immediate physical

deletion; deletion/export and legal-retention handling require the approved

support process.

For maintenance completion evidence, the app prepares a new JPEG copy on the

device before upload, limits its dimensions, and does not carry the selected

source image's location, TIFF, or camera metadata into that copy. Upload occurs

only after an authorised committee member selects and confirms the photo. A

completion photo is linked to one completed or closed request, uses an

all-member or exact-unit audience based on that request, and becomes immutable

after finalisation. This processing is separate from on-device receipt and

bank-statement recognition.

Data Retention

Local data stays on the device until the user deletes it, removes the app, or retention settings apply where supported.

Some retention settings may clean up selected local records. Other records may need manual deletion. Exported or shared data is outside the app's direct control after the user sends it.

Visible connected messages, attachments, polls, read state, pins, and related collaboration metadata may remain available while the property, thread, and content remain active. Hidden messages are excluded from normal member message lists. Limited report, moderation, security, call-event, notification-token, and audit metadata may be retained where necessary for app operation, safety, support, legal obligations, or dispute handling.

Hosted document files, folders, versions, access metadata, links, and archive

state may remain while the hosted property and document record remain active or

while support, accounting, legal-retention, dispute, or audit needs apply.

Maintenance completion evidence is intentionally immutable through the public

app interface once finalised; removal requires the approved support,

legal-retention and audit process rather than a member metadata edit.

Connected Provider Concierge request and status records may be retained while the request is active and for a limited period afterward for support, audit, legal, and dispute handling.

Connected payment attempts, receipts, refunds, dispute status, provider-event digests, and linked accounting entries may be retained for property accounting, reconciliation, support, fraud prevention, chargeback, audit, legal, and tax obligations. CommonDue does not retain the raw provider payload or card/bank credentials.

Verified StoreKit transaction fields, entitlement status, cryptographic digest, credit balances, credit-ledger events, and bounded AI reservation/cost metadata may be retained for purchase delivery, renewal/expiry, refund/revocation, duplicate prevention, fraud and abuse controls, support, accounting, and legal obligations. CommonDue does not intentionally retain the raw Apple JWS, payment-card data, AI prompt, AI answer, selected source content, or raw AI-provider payload in these records.

Connected backup metadata and encrypted backup objects follow the approved backup deletion/export/recovery policy. General account export is backup metadata only by default, not recovery keys, signed URLs, storage object keys, encrypted object bytes, or decrypted payloads. Backup object deletion depends on account/property deletion review, property integrity, legal retention, and the user's local/exported copies being outside CommonDue's direct control.

User Rights And Choices

Where supported in the app, users can:

• Export a local personal data package.

• Delete local personal data from the device.

• Request connected account export or deletion where connected account features are enabled.

• Review backup readiness, backup history, and restore preview where connected cloud backup is enabled.

• Adjust privacy, consent, and retention settings.

• Manually choose whether to export or share data.

• Choose whether to request chat notifications or share a FaceTime address for private-call handoff.

• Report a hosted message and block or mute another eligible hosted-property member.

• Download documents their current hosted-property membership permits them to

read; committee roles can manage folders, versions, permissions, and archive

state.

Users can contact support for privacy questions, export/delete help, or concerns about data they have shared manually.

Children And Minors

CommonDue is not intended for children. Users should not enter children's personal data unless they have the right and a clear reason to do so for legitimate building administration.

Security

CommonDue uses local storage protections and device-supported security features such as encrypted local storage, Keychain-backed sensitive settings, and app lock where supported.

No app or storage system can guarantee absolute security. Users should protect their device, use a strong device passcode, keep iOS updated, and avoid sharing sensitive exports with people who do not need them.

Contact

Data controller: PRAESI Technologies Ltd, Cyprus.

Support contact: [email protected]

Privacy contact: [email protected]

Support page: https://praesi-technologies.com/koinoxrista-support