Your privacy at Holmigo

Updated: 4 October 2026

Who handles your data?

The operator of this service is its data controller. Use the contact below for privacy questions and requests.

UNIXOFT Kereskedelmi és Szolgáltató Betéti Társaság (UNIXOFT Bt.)

Company registration number: 01-06-613042

Account and service

To provide the service, we store your name, email, account creation date, preferences, permissions, invitations and inviter, notifications and activity history. Password accounts store a salted Argon2id password hash, never the password. AI usage is counted for monthly allowances.

Registration may be invitation-only or open, as configured by the operator. When you use an invitation, we record your inviter and joined group. The invitation creator is notified about your registration.

Purposes and legal grounds

Accounts, inventory, sharing and image recognition you request are processed to provide the requested service (GDPR Article 6(1)(b)). Abuse prevention and necessary operational logging rely on the legitimate interest in service security (Article 6(1)(f)). Optional browser storage and Gravatar requests rely on revocable consent (Article 6(1)(a)). We do not use your data for advertising.

Items, photos and groups

Holmigo stores items, descriptions, dates, photos and their history on its server. Shared branches are accessible according to group permissions; making a branch private also protects its descendants. Members see names, roles and inviters; invitation managers also see relevant email addresses. Images are resized and metadata is removed.

External services and AI

If you choose Google sign-in, Google provides basic profile details, verified email and an account identifier. Tokens are used during sign-in and are not stored in the database. We do not request Gmail, Drive, Calendar or contacts access. Revoking the Google connection does not delete your Holmigo account or existing sessions.

Gravatar loads only after consent in the current browser. A displayed user’s email hash may still be personal data; it is not an anonymous identifier. Without consent, automatic avatars use a generic icon. Uploaded profile photos are served from our server to you and reauthenticated siteadmins, and can be deleted in settings.

Image recognition can send item photos to the OpenAI API; results are stored as field suggestions. A local model may handle failures. Requests contain images and processing instructions, not your account email. OpenAI does not train on API data by default; abuse-monitoring data is generally retained for up to 30 days, with longer retention possible in specified exceptions. You can review and edit suggestions or choose manual entry. Cookie choices do not disable the image-recognition service.

Google, Automattic/Gravatar and OpenAI processing may extend outside the EEA. Their data and transfer terms are available at the links below.

Feedback and spam protection

Feedback is used to answer requests and improve Holmigo, based on our legitimate interest. We store the message, type, page path without URL parameters, account name and email or an optional guest reply email. Only siteadmins can read all messages; signed-in senders can read their own. Messages are deleted 30 days after closure, or 180 days after submission at the latest. Deleting an account removes its association with feedback; message and contact details remain until this retention period ends.

Guest feedback requires a local ALTCHA proof-of-work check. The browser solves a short computational challenge, verified by our own server; no CAPTCHA data is sent to a third party. Challenges expire after five minutes and can be used only once. We do not store IP addresses with messages. Hashed identifiers used for abuse prevention remain in server memory for at most fifteen minutes.

Retention and deletion

Account and service data are retained for the life of the account. Trashed items are permanently removed after 30 days, or sooner by an authorised user. Activity records and usage counters can remain after item deletion. Sessions last up to 7 days, Google sign-in protection 10 minutes, language cookies 1 year and cookie choices 180 days.

The operator manages logs and backups; deleted data may remain until backups are replaced. Ask the controller for the actual log and backup retention periods. Server and outer reverse-proxy logs may contain different information.

Your rights

You can request access, a copy, correction, erasure, restriction and, where applicable, portability. You can object to processing based on legitimate interests. Withdraw consent at any time in Cookie settings; withdrawal does not affect the lawfulness of earlier processing. Requests are generally answered within one month, with notice of any justified extension.

Send requests to the email address you can reveal below. We may ask for identity verification to protect your data. You can complain to Hungary’s NAIH or your local data-protection authority and seek judicial remedy.

· NAIH · Cookie notice

Back to home

Essential sign-in cookies always work. Remembering preferences in your browser and loading Gravatar avatars are optional. There is no advertising or analytics tracking.

You can change or withdraw your choice at any time using Cookie settings in the footer. We ask again after 180 days.

Cookie notice · Privacy notice

Feedback

Report a problem or share an idea. Please avoid passwords and sensitive information.

Built 2cb7c5d