HomeFlow Legal & Trust
Privacy Policy
This draft explains the information HomeFlow handles, why it is used, and the controls currently available to homeowners.
Pre-Launch Draft — Pending Legal Review
1. Who we are and scope
HomeFlow LLC is based in Syracuse, New York, United States. HomeFlow helps homeowners organize information about their home. This draft applies to the HomeFlow application and the services that support it. It is not yet a commercially effective policy and has no assigned effective date.
2. Information you provide
Depending on the features you use, HomeFlow may handle account details, a property address, home-profile and property information, maintenance tasks and records, inventory and warranty information, Home Binder documents, receipts, manuals, budget and expense information, insurance, mortgage and property-administration records, notes, photos, and uploaded files or attachments.
Not every field is required. You decide which optional home records and files to add. Account credentials are handled through the authentication service rather than displayed as ordinary HomeFlow records.
3. Information HomeFlow generates
HomeFlow uses available records to produce organizational information such as Home Health scores and existing recommendations, Home Passport completion and intelligence, Timeline history, reminders, and notifications. These results depend on the information in HomeFlow and may be incomplete or outdated.
4. Local and cloud persistence
HomeFlow uses local application storage and Supabase-supported authentication, database, and private file-storage infrastructure. Information may therefore be processed on your device and by service providers operating HomeFlow infrastructure. Uploaded files may be stored with their metadata in private cloud storage.
Signing out ends the account session, but some feature-specific local information or device backups can persist differently. The verified whole-account deletion flow performs an attributable local purge for the deleted account and terminates its session.
5. How information is used
- Authenticate accounts and maintain account sessions.
- Provide, synchronize, and support the HomeFlow features a homeowner chooses to use.
- Store and display home records, documents, attachments, history, reminders, and notifications.
- Calculate existing derived information and recommendations.
- Maintain service operation and security and respond to support, privacy, or security requests.
The verified application baseline does not implement advertising, product analytics, attribution, behavioral tracking, session replay, or marketing telemetry.
6. Service providers and disclosure
Information is processed by Supabase-supported infrastructure and other applicable providers as needed to operate HomeFlow. A homeowner may also direct HomeFlow to open a temporary link to an uploaded document in another browser or application.
The verified application does not implement public homeowner profiles, homeowner-to-homeowner sharing, advertising transfers, or data-broker integrations. This draft does not name additional subprocessors or promise a finalized disclosure framework that has not been approved.
7. Retention
HomeFlow has not adopted a final public retention schedule. Information may remain while an account or record exists, and provider backups, service logs, deletion-operation records, or legally required records may follow different retention periods. This draft does not promise immediate removal from every provider backup or log.
A 30-day cleanup default for completed deletion-operation records has been engineered, but its legal and business approval remains pending and is not stated here as a binding retention obligation.
8. Record and account deletion
Applicable HomeFlow features provide controls for deleting certain individual records and attachments. Feature-specific deletion may not remove every separate historical entry, notification, device backup, or provider backup associated with a source record.
A signed-in homeowner can use Settings → Legal & Privacy → Account & Data Deletion to permanently delete the account-scoped HomeFlow records and HomeFlow-managed uploaded files covered by the verified deletion workflow. The flow requires acknowledgement and reauthentication, is irreversible once completed, purges attributable local state, terminates the session, and returns the application to a signed-out state. See the Account Deletion page for details.
9. Security
Verified protections include account authentication, user-scoped access controls for home records, private managed file access, secure network transport supported by service-provider infrastructure, server-side deletion authorization, and safeguards intended to isolate one homeowner’s data from another’s. No system can guarantee absolute security.
10. Your controls
You control which optional records and files you add and can edit or delete supported records through applicable features. You can sign out, use the verified account-deletion workflow, or contact HomeFlow about privacy questions. This draft does not claim jurisdiction-specific privacy rights that have not been approved.
11. Children
HomeFlow’s current product position is that the service is intended for adults age 18 and older. This position remains subject to legal review before commercial launch.
12. Updates and contact
HomeFlow may update this draft as the product, providers, legal requirements, and business decisions develop. A final policy will identify its effective date and version after approval.
Privacy questions: privacy@homeflow247.com
General support: support@homeflow247.com
Security reports: security@homeflow247.com