Last updated 31 July 2026
DoorMate holds access codes for people's homes. That deserves a plain answer about what is kept and why, so this policy is written to be read rather than to cover anyone.
That's all. There is no analytics, no advertising, no tracking of any kind, and no third-party trackers in the app.
Only the people you invite into your organization. One organization can never read another's data. This is enforced on the server by database security rules, not merely hidden in the app — a device belonging to another business cannot fetch your codes even if it asks for them directly.
Nothing is sold, rented, or shared with anyone else. Ever.
In Google Firebase — Firebase Authentication for sign-in and Cloud Firestore for the data. Google processes it on DoorMate's behalf and stores it in encrypted form. Traffic between your device and the servers is encrypted in transit.
Access codes are held in the app's memory while you're using it and are not written to your device's storage.
You can delete your account inside the app: Settings → Name, email, password → Delete my account. It asks for your password, and it is permanent.
Deleted data is gone from the live database immediately. Backups held by the hosting provider roll off on their own schedule.
DoorMate is a tool for businesses and is not directed at children.
If this policy changes in a way that affects what is collected or who can see it, the app will say so rather than quietly updating this page.
Questions, or a request to see or remove your data: connect@lutomsky.co.