☀ Home ManualLast updated: September 11, 2026

Privacy Policy

This Policy explains what Home Manual (the “Service”) collects, how we use and share it, and the choices you have. It works alongside our Terms & Conditions; where the two differ on data handling, this Policy controls.

1. What we collect

  • Account data — your email address, used for passwordless sign-in.
  • Your Content — the home data you enter or upload: address and property details, systems, appliances, projects, contacts, photos, and the original documents you import (e.g. inspection reports, invoices, insurance policies), plus the structured records the Service derives from them.
  • Sharing settings — whether a share link is enabled, the tokens for your share and guest links, which sections you have chosen to share on the share link (the guest link always shows the same fixed, narrower set), and which individual documents you have marked as shared.
  • Operational data — basic logs and error reports generated when the Service runs (for reliability and security), plus a first-party record, tied to your account, of which AI operations you run (this is what enforces your monthly quota) and of your progress through setup. We do not use third-party advertising trackers.
  • Stored in your browser — small first-party cookies, which are sent back to us with each request:
    • hm-lang — the language you have chosen, so a page can render in it before you have signed in.
    • hm-tz — the time zone and date format your browser reports, so a page that greets you by time of day is right when it first renders instead of correcting itself a moment later.
    • hm-remember — whether you asked us to keep you signed in, which is what sets how long a sign-in lasts.
    • hm-sid — a rolling id that groups one visit’s activity within the setup-progress records described above. Each request extends it; thirty minutes of inactivity ends it and the next visit gets a new one.
    • hm-src — if you arrived from a manual someone shared with you, which of our two share links you followed. It is set only on arrival from such a link, it holds nothing about you or about their home, and it is used once: to record that a home you go on to create began with somebody else’s manual.
    • sh_collapsed — whether you have collapsed the “Start here” panel.
    • your sign-in tokens, set by Supabase (their names begin sb-), which are what keep you signed in.

    None of these are advertising or cross-site tracking cookies. We also keep some things in your browser’s own local storage — which sections you have open, drafts you have begun but not saved, and whether you have seen the product tour. That stays on your device and is not sent to us. Clearing this site’s data in your browser removes all of the above, and signs you out.

2. How we use it

We process your data only to operate and improve the Service for you — specifically to:

  • build and display your home manual and keep it current;
  • use AI to extract structured facts from the documents and photos you provide, to read an uploaded floor plan, and to draft the things you ask for and review — a project scope, a message to a contractor, a check of a quote, an illustrative render;
  • render read-only share links according to your per-section choices;
  • send you the weekly reminder digest (if enabled) — you can unsubscribe from any such email;
  • secure the Service, prevent abuse, and diagnose problems.

We do not sell your personal information, and we do not use Your Content to train our own models. Our AI providers are used on paid API tiers, whose terms do not permit training on what we send them — on a free tier at least one of them reserves the right to, so this rests on the commercial account we hold rather than on anything the software can enforce. If that ever changes for a provider, we will say so here before it takes effect.

3. Service providers we share with

We use a small set of processors to run the Service. They act on our instructions and only for the purposes above:

  • Supabase — database, authentication, and file storage.
  • Vercel — application hosting.
  • Anthropic — reading your documents and photos into structured records; this also covers an uploaded floor plan and any tenant message you paste in. It drafts the text you ask for (a project scope, a message to a contractor, a check of a quote, a rewritten reply), and facts from your manual are sent with those requests so the draft is specific to your home.
  • Google (Gemini) — AI generation of illustrative project renders, and of an illustrated cover for your manual if you ask for one. A render of a project is made from one of your own photographs of that space — a photo already stored in your manual — and that photograph is sent to Google with the request. A render sketched from a description alone sends only the text. An illustrated cover is drawn from a photograph you choose, which is sent with the request in the same way. We offer it only for a photograph your record identifies as the building itself, and it refuses a photograph of people.
  • Resend — delivery of the reminder-digest emails.

Building your manual also looks facts up from public sources. We send them the property address or its coordinates — never your name, email, or anything you have marked private:

  • Geocoders and public records — the US Census geocoder, OpenStreetMap (Nominatim and Overpass), FEMA, USGS, USDA, and county, city and state record services, to turn an address into a location and to find aerial imagery, flood zone, seismic, parcel, and permit records.
  • Rentcast and Regrid — market estimates and parcel boundaries, where those are configured.
  • Apple WeatherKit and AirNow (US EPA) — the seven-day forecast, the hour-by-hour detail and the UV reading on your manual’s “This week” card come from Apple; the air-quality reading comes from AirNow, the US Environmental Protection Agency’s service. Your browser talks only to us: it sends your home’s coordinates to our server, and our server asks Apple and AirNow — so neither of them sees your IP address. On a share link: the shared copy carries your home’s location only to within about a kilometer, which is the precision the forecast is looked up at anyway. A reader’s browser asks our server for the weather in that area and never receives your exact coordinates. Separately, our own scheduled job sends your home’s coordinates to the same forecast service from our server, on a regular schedule and whether or not you open your manual, so that a weather warning can be prepared for you. That request carries your coordinates but no IP address of yours.

If your browser offers dictation in our text fields, that audio goes to your browser or operating system vendor (Google or Apple), not to us.

When you import a document or photo, its contents are sent to the relevant AI provider to be read.

Look-up services that receive your address

To describe your specific property, the Service looks your address up against public mapping and public-records sources. Your address, or the map coordinates derived from it, is sent to these as you type it and when a home is created:

  • Mapping & geocoding — OpenStreetMap’s Nominatim service (address suggestions, as you type), the OpenStreetMap Overpass API and a community-run Overpass mirror (nearby streets and paths), and the U.S. Census Bureau geocoder. The street map on your Neighborhood page is drawn by our own map renderer, which runs on Google Cloud and receives only your home’s coordinates — no third-party map provider is involved, and the picture is rendered once and stored with your manual rather than fetched each time someone opens it.
  • Government hazard & environmental data — FEMA (flood zone), the U.S. Geological Survey (seismic), the U.S. Department of Agriculture (aerial imagery), and the National Park Service (historic districts). Your plant-hardiness zone comes from phzmapi.org, an independent community-run service rather than a government one, which receives your ZIP code.
  • County, city and state records — the assessor, parcel, permit and GIS services for the jurisdiction your home is in. Which ones apply depends entirely on where you live.
  • Property-data providers — where configured, commercial property and permit-history services.

Some of these are public bodies or volunteer-run projects rather than vendors we hold a contract with, and they will have their own terms and logging. We send them only what a look-up needs — an address or a coordinate — never your documents, photos, or anything else from your manual. If our AI provider performs a web search on your behalf, your address may form part of that search.

We otherwise disclose your data only as required by law or to protect the Service and its users.

4. Storage & security

Your data is stored with our providers and protected by row-level access controls so that, by default, only your account can read it. Original documents are kept in a private store that is not publicly accessible. No system is perfectly secure, but we take reasonable measures to protect your data and limit access to it.

5. Sharing is your choice

Nothing is public unless you enable a share link. You control, section by section, what a link reveals: the sections of your manual are included on a link you enable, and you switch off the ones you don’t want a guest to see. A guest link is narrower still — it carries only the emergency and guest cards, no matter what else you have switched on.

One section works the other way round: the “Prepared by” card, which names the professional who put your manual together, is private by default. It always appears on your own view, and it is included on a share link only if you switch it on. It names someone other than you, so publishing it is your decision to make rather than ours.

Some things are never on a link at all, whatever you switch on. Your upkeep costs, insurance details and the value side of a sale are not part of the shared manual — they live on your own signed-in pages, which have no share link. And within the sections you do share, specific details are stripped: neighbors’ names, the brands and values of your furnishings, and service-provider account details and costs. Money figures are also blanked inside Home systems, Floor plans & furnishings, Yard & exterior, and History, including the vendor and total we record when you upload an invoice, which show on your own view only. That blanking is not universal. A figure you type into another section, such as a contact’s details or the house-sitter card, appears on a link exactly as you wrote it. If a figure should not be seen, take it out of the entry or switch that section off. Your original documents work the other way round — a file appears only if you mark that individual file as shared.

You can disable or regenerate a link at any time. That stops the page and its pictures: images on a share link are served through a route that re-checks the link on every request, so revoking it takes effect immediately rather than leaving previously-issued picture addresses working. Two limits worth knowing. An image the browser is already fetching can finish for up to two minutes. And the per-request check asks “is this a photo of this home?”, not “is this photo on this link?” — so a photograph in a section you have switched off is still reachable by someone who knows its exact address. Those addresses are random identifiers that never appear in a shared page, so this is unguessable rather than merely unlinked.

On deleting a photograph specifically: removing one in the editor takes it out of your manual, and nothing on a link can reach it after that — but the stored file itself is removed when you delete the home it belonged to, and any left over from an earlier edit when you delete your account.

6. Retention

We keep Your Content for as long as your account and homes exist so the Service can function. When you delete a document, home, or your account, we delete the associated records and stored files (including originals and photos) on a best-effort basis, and any retention the law requires. Two specifics worth stating: a photograph you removed from a home before deleting it is cleared when you delete your account rather than with that home; and the public-records data we retrieved about a property — assessor, parcel and permit facts, which are public records in their own right — is keyed to the property rather than to you and is not deleted with your home.

7. Your rights & choices

  • Access & export — you can download your account’s homes and their records, your reminder settings and your saved savings outcomes, as a JSON file. It is the stored records themselves, not your uploaded photos or original document files. The button is on the Records tab of any of your homes; with no homes yet there is nothing to export.
  • Correction — edit your home’s data directly in the app.
  • Deletion — delete individual documents or homes, or delete your entire account, which removes your homes, files, and settings.
  • Email — unsubscribe from the reminder digest via any digest email.

Depending on where you live (e.g. the EU/UK or California), you may have additional rights over your personal data; contact us to exercise them and we will honor applicable requests.

8. Children

The Service is not directed to children under 13 (or the minimum age in your jurisdiction), and we do not knowingly collect their personal data. A home’s records may mention household members; you are responsible for the personal data you choose to enter about others.

9. Changes

We may update this Policy as the Service evolves. We will revise the “Last updated” date above and, for material changes, take reasonable steps to notify you.

10. Contact

Questions or requests about your data? Contact us at support@thehomemanual.ai.

← Back to Home Manual · Terms & Conditions