We Should Probably ← Back
Legal

Privacy Policy

Last updated: 2026-09-15

We Should Probably is a household task management app. This policy explains what personal data we collect, why we collect it, and how you can exercise your rights. We are a Belgian company and this policy is written in accordance with the General Data Protection Regulation (GDPR).


1. Data Controller

Basilicom, Francisco Ferrerlaan 123, 9000 Ghent, Belgium. VAT: BE1018829008.

For privacy questions: [email protected]

2. What Data We Collect

Account information

When you create an account we collect your email address and, if you choose to provide it, your display name and profile photo. This is the minimum needed to identify you within a household.

Household and task data

We store the tasks, lists, and household data you create inside the app. This data belongs to you and your household members. We do not read or analyse the content of your tasks.

Subscription and payment information

Payments are processed by Stripe. We receive a Stripe customer ID, your subscription status, and basic billing information (plan, renewal date, card brand and last four digits). We never see or store your full card number.

Technical and usage data

We collect IP addresses, device type, operating system version, and app version for security and debugging purposes. We do not build behavioural profiles from this data.

Support communications

If you contact us by email, we keep the correspondence to resolve your request and for up to three years afterwards.

3. What We Do Not Collect

4. Legal Basis for Processing

We process your data on the following grounds:

5. Third-Party Processors

We share data only with processors that are necessary to run the service:

We have Data Processing Agreements in place with each processor. We do not share your data with any other third parties.

6. Where Your Data Is Stored

Your account and household data is stored on a VPS hosted by Contabo in the EU. Payment data is stored by Stripe in accordance with PCI-DSS standards. We do not transfer your personal data to countries outside the EEA without appropriate safeguards (adequacy decisions or Standard Contractual Clauses).

7. How Long We Keep Your Data

8. Your Rights

Under GDPR you have the right to:

To exercise any of these rights, email [email protected]. We will respond within 30 days. If you are unsatisfied with our response, you can lodge a complaint with the Belgian Data Protection Authority.

Account deletion

You can delete your account directly in the app under Settings → Account → Delete account. This removes your personal data from our systems within 30 days.

9. Cookies

The account web pages (app.weshouldprobably.com/manage) use a single session cookie set by Supabase to keep you signed in. No advertising or analytics cookies are set. The app itself does not use browser cookies.

10. Security

All data in transit is encrypted with TLS 1.2 or higher. Passwords are never stored — authentication uses Supabase's secure token system. We use multi-factor authentication internally and review access controls regularly.

In the event of a breach that poses significant risk to your rights, we will notify you and the Belgian Data Protection Authority within 72 hours of becoming aware of it.

11. Changes to This Policy

If we make material changes, we will notify you by email before the changes take effect. The latest version is always available at weshouldprobably.com/privacy.

12. Contact

Questions or requests: [email protected]