Table of Contents
Privacy Policy
Last updated: January 18, 2026
Your privacy is important to us. This policy explains how we collect, use, and protect your data.
1. Introduction
HOMEFolio™ ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our property management platform.
2. Information We Collect
Information You Provide Directly
Account Information
- Name and email address
- Password (encrypted)
- Phone number (optional)
- Profile information
Property Data
- Property addresses and details
- Uploaded documents and photos
- Equipment and appliance information
- Tenant and vendor communications
Information Collected Automatically
- Usage Data: Features used, pages visited, time spent, click patterns
- Device Information: Browser type, operating system, device identifiers
- IP Address: For security, fraud prevention, and rate limiting
- Cookies: Session management, preferences, analytics
- Log Data: Timestamps, API calls, error logs for debugging
3. How We Use Your Information
| Purpose | Legal Basis (GDPR) |
|---|---|
| Provide the Service Organize documents, track maintenance, manage properties | Contract Performance |
| AI Features Generate insights, automate tasks, smart suggestions | Legitimate Interest |
| Communication Service updates, maintenance reminders, support | Contract Performance |
| Security & Fraud Prevention Monitor for abuse, prevent unauthorized access | Legitimate Interest |
| Analytics & Improvement Usage patterns, feature popularity, bug fixes | Legitimate Interest |
| Legal Compliance Respond to legal requests, enforce Terms | Legal Obligation |
5. AI Services & LLM Processing
Our AI features use Large Language Models (LLMs) from OpenAI and Anthropic to analyze your documents and generate property management insights.
What We Do
- Transient processing — data discarded after use
- Your data does not train models
- Encrypted HTTPS/TLS transfer
- Only relevant excerpts sent
- AI opt-out available in settings
What We DON'T Do
- LLM providers don't permanently store your data
- Your data isn't used to improve models
- LLM providers can't share with others
6. Upload Links Data Collection
When external parties use your upload links, we collect IP address, upload timestamp, file metadata, and user agent for security and rate limiting purposes.
Your Responsibility: When sharing upload links, inform recipients that their IP and upload metadata will be collected.
7. Data Security
Encryption
TLS 1.3 in transit
AES-256 at rest
AWS Infrastructure
SOC 2 certified
Regular security audits
Access Controls
Limited employee access
Need-to-know basis
8. Data Retention
| Data Type | Retention Period | Reason |
|---|---|---|
| Account Information | Until account deletion | Service provision |
| Property Documents | Until you delete or account closes | Service provision |
| Usage Logs | 90 days | Debugging, analytics |
| Upload Link Audit Trails | 1 year | Security, compliance |
| Billing Records | 7 years | Tax, legal compliance |
| Deleted Account Data | 30 days (backup retention) | Recovery, compliance |
10. Your Privacy Rights
Access
Request a copy of your data
Correction
Fix inaccurate information
Deletion
Delete your account and data
Portability
Export your data
Object
Opt out of certain processing
Restrict
Limit how we use your data
To exercise these rights, contact us at privacy@homefolio.ai. We will respond within 30 days.
11. GDPR Rights (EU Users)
If you are in the EEA, UK, or Switzerland, you have additional rights under GDPR. We process your data based on contract performance, legitimate interest, consent, or legal obligation. For GDPR inquiries, contact gdpr@homefolio.ai.
12. CCPA Rights (California Residents)
California residents have rights to know, delete, opt-out of sale, and non-discrimination.
To exercise CCPA rights, contact privacy@homefolio.ai. We will respond within 45 days.
13. Children's Privacy
HOMEFolio is not intended for children under 18. If you believe we have collected information from a child, contact privacy@homefolio.ai and we will promptly delete it.
14. International Data Transfers
Your data may be processed in the United States or other countries where our service providers operate. For EU-US transfers we rely on Standard Contractual Clauses and provider certifications.
15. Data Breach Notification
In the event of a breach affecting your rights, we will notify you within 72 hours via email and in-app notification, describe the breach and affected data, and report to relevant authorities.
16. Policy Changes
We may update this Privacy Policy and will notify you via email of material changes with 30 days' notice. Continued use constitutes acceptance.
17. Contact Us
Privacy Inquiries
Email: privacy@homefolio.ai
GDPR: gdpr@homefolio.ai
Mailing Address
HOMEFolio AI™
Attn: Privacy Officer
Effective as of January 18, 2026