Privacy Policy

Last updated: March 23, 2026

1. Information We Collect

We collect the following types of information:

  • Account information: email address, name, and profile image (if signing in with Google).
  • Property data: home addresses, room layouts, appliance and system details, maintenance schedules, service records, and uploaded documents (manuals, receipts, photos).
  • Usage data: last active timestamp, notification preferences, and feature usage patterns.
  • Payment information: processed by Stripe. We do not store credit card numbers. We store your Stripe customer ID and subscription status.

2. How We Use Your Information

We use your information to:

  • Provide and maintain the Service
  • Send maintenance reminders and task notifications
  • Process subscription payments
  • Send transactional emails (password resets, trial warnings, invitations)
  • Improve the Service based on usage patterns
  • Respond to support requests

We do not sell your personal information. We do not use your data for advertising.

3. Data Storage and Security

Your data is stored in a PostgreSQL database hosted on Neon (cloud infrastructure). Uploaded files are stored on Cloudflare R2. All data is transmitted over HTTPS. Passwords are hashed with bcrypt. TOTP secrets for two-factor authentication are encrypted with AES-256-GCM at rest.

We implement reasonable security measures but cannot guarantee absolute security. You are responsible for keeping your account credentials safe and enabling two-factor authentication for additional protection.

4. Data Sharing

We share your data only in these circumstances:

  • Home collaborators: when you invite someone to a home, they can see property data for that home.
  • Service providers: Stripe (payments), Resend (email delivery), Neon (database), Cloudflare (file storage), Vercel (hosting), Google (OAuth, geocoding). Each provider has their own privacy policy.
  • Legal requirements: if required by law or to protect our rights.

5. Data Retention

We retain your data for as long as your account is active. Deleted homes are soft-deleted and recoverable for 30 days before permanent removal. If you delete your account, we will remove your data within 30 days, except where retention is required by law (e.g., billing records).

6. Data Export

You can export a complete JSON snapshot of any home's data (rooms, items, tasks, service records, documents, and research notes) at any time through the home settings page.

7. Cookies

We use essential cookies for authentication (session tokens) and the beta access gate. We do not use tracking cookies or third-party analytics cookies.

8. Your Rights

You have the right to:

  • Access your personal data (available through the app and data export)
  • Correct inaccurate data (editable through account and home settings)
  • Delete your account and associated data
  • Export your data in a portable format
  • Opt out of non-essential emails (notification settings)

9. Children's Privacy

The Service is not intended for children under 13. We do not knowingly collect personal information from children under 13.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes via email or through the Service.

11. Contact

For privacy-related questions or requests, contact us at privacy@dwellhq.app.