Homie Privacy Policy
Effective date: [TODO: effective date]
This policy explains what information Homie handles, why, and what your choices are. Homie is designed to be local-first: your content lives on your device, and we only receive data when it is needed to provide a feature you use.
1. Who we are
Homie is operated by [TODO: company legal name] (“we”, “us”),
[TODO: company registered address]. We provide the Homie app — a personal AI
assistant for tasks, notes, chats, and automations — and the services behind
it at homie.fyi and api.homie.fyi.
For privacy questions or requests, contact us at [TODO: privacy contact email].
2. Overview
- Your tasks, notes, chats, memories, and attachments are stored on your device, not on our servers, except in the specific cases described below (optional encrypted sync, and content you explicitly share with other people).
- When you use AI features, your messages and the context needed to answer them are sent to our servers and processed by AI models. We do not store the content of these requests on our servers.
- Optional integrations (Google Calendar, Gmail, device calendar, web search, location) are off by default and only do what you enable and approve.
- We use a small number of service providers (AWS, Stripe) and never sell your data or use it for advertising.
3. Information stored on your device
The core of Homie runs on your device. The following is stored in a local database on your device and is not uploaded to us unless you enable sync or sharing (described below):
- Tasks and notes, including attachments and links you add to them.
- Chat conversations with the assistant.
- Memories — facts the assistant has saved about you, which you can review, edit, and delete in the app.
- Automations you set up, and their run history.
- App settings, including integration preferences and API keys you supply for web search providers.
Deleting the app from your device deletes this local data.
4. Information we collect and store on our servers
We store the minimum needed to operate accounts, billing, and the optional
server-backed features. All server infrastructure runs on Amazon Web Services
(AWS) in the us-east-1 (N. Virginia, USA) region.
Account information
When you create an account we store your email address (used as your sign-in identifier and verified by a code we email you). If you sign in with Google, we also receive your name from your Google account. Accounts are managed in AWS Cognito.
We send transactional email (verification codes, password reset) from
noreply@homie.fyi via AWS SES. We do not send marketing email.
Subscription and usage information
If you subscribe, payment is handled by Stripe (see section 8). On our side we store: your subscription status and plan, your Stripe customer ID, trial/renewal dates, and a weekly AI usage counter (a token count — a technical measure of AI processing volume) used to apply your plan’s usage allowance. We do not store card numbers or other payment details.
Encrypted sync and backup (optional)
If you turn on sync & backup, your app data is end-to-end encrypted on your device before upload, using a key derived from a passphrase you choose (with a one-time recovery code as a backup unlock method). Our servers store only:
- the encrypted data blocks (ciphertext),
- an encrypted (“wrapped”) copy of your data key, which can only be unwrapped with your passphrase or recovery code, and
- bookkeeping counters used to order sync data.
We cannot read the content of your synced data, and we cannot recover it if you lose both your passphrase and recovery code. The app verifies synced data when it downloads it; if verification fails, the app warns you and pauses syncing.
Shared content (optional)
Sharing is the deliberate exception to local-first: when you share a note or task with someone, or add tasks to a family/group list, that content is stored on our servers in readable form so the people you shared it with can access it. This includes the shared item’s title and content, the list of people with access and their roles, and — if you invite someone by email — the invitee’s email address (kept so we can grant them access when they sign in). You can stop sharing an item or revoke a person’s access at any time in the app.
Feedback
If you submit in-app feedback (available in development builds), we store the feedback text you write, optional app context included with it, your account ID, and a timestamp.
Service logs
Our servers keep operational logs (in AWS CloudWatch) for reliability, security, and abuse prevention. For AI requests, logs record metadata only: your account ID, the model used, token counts, and timing — not the content of your messages. Logs are retained for [TODO: CloudWatch log retention period — currently not configured; set a window and state it here].
5. AI processing
When you send a chat message, run an automation, or use another AI feature,
your device sends the message and the context needed to answer it to our API
(api.homie.fyi). Depending on what you ask and what you have enabled, that
context can include relevant tasks, notes, memories, calendar events, email
content retrieved by an integration you approved, and your approximate
location (only if you enabled the location option).
Our server forwards the request to Amazon Bedrock, an AWS service that runs Anthropic Claude models (and Amazon Titan models for text embeddings). Per AWS’s Bedrock service terms, prompts and outputs are not stored by Bedrock and are not used to train models, and are not shared with the model providers.
Our server does not store the content of AI requests or responses. It records token counts against your weekly usage allowance and the metadata described in “Service logs” above.
6. Optional integrations
All integrations are off by default. You enable each one explicitly in the app, and you can disconnect any of them at any time. Actions that change things outside the app (for example creating a calendar event) additionally require your in-app approval per action — the assistant shows you what it wants to do and you can approve, edit, or decline it.
- Google Calendar — your device talks directly to Google’s Calendar API to read your events and, with your per-action approval, create events.
- Gmail (read-only) — your device talks directly to Google’s Gmail API with read-only access. You can restrict access to specific Gmail labels, and control whether the assistant may search and/or read full messages. See section 7 for how Gmail data is handled.
- Device calendar (Apple/Android) — read and write access to calendars you select, handled on your device through the operating system.
- Web search — you choose a provider (Brave, Tavily, or Google Programmable Search) and supply your own API key. The key is stored on your device, and search queries go directly from your device to that provider under the provider’s own privacy policy.
- Location — if you opt in, your device shares your approximate location (city plus coarse coordinates) with the assistant so it can give location-aware answers. It is included in AI requests and local-search queries when relevant, is refreshed at most every 30 minutes, and is not stored on our servers. Turning the option off clears it.
- Local events & places search — if you ask about local events or places, your search query (and your approximate location, if enabled) is sent to our search API to return results.
Google Calendar and Gmail access tokens are held only in your device’s memory while the app runs; they are not stored on our servers.
7. Google user data — Limited Use disclosure
Homie’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically, for data accessed through the Gmail and Google Calendar APIs:
- We use Google user data only to provide user-facing features you have requested: reading your email and calendar so the assistant can answer your questions and, with your explicit per-action approval, creating calendar events.
- We do not store Google user data on our servers. Gmail and Calendar data is accessed directly from your device. Portions of it are transmitted to our AI processing service (Amazon Bedrock running Anthropic Claude models) only as necessary to fulfill your specific request, are not stored there, and are not used to train models. Content you yourself choose to save into a task or note is stored on your device like any other content.
- We do not use Google user data for advertising of any kind.
- We do not use Google user data to train or improve generalized AI or machine-learning models.
- We do not transfer Google user data to third parties, except as necessary to provide the features you requested (the AI processing described above), to comply with applicable law, or as part of a merger or acquisition with prior notice to you.
- No humans read your Google user data, except with your explicit permission, where necessary for security purposes (such as investigating abuse), to comply with applicable law, or in aggregated, anonymized form for internal operations as permitted by the policy.
You can revoke Homie’s access to your Google data at any time by disconnecting the integration in the app, or from your Google Account at myaccount.google.com/permissions.
8. Payments (Stripe)
Subscriptions are processed by Stripe, Inc. When you subscribe, checkout and payment-method management happen on Stripe’s pages; your card details go to Stripe, not to us. Stripe sends us events about your subscription (for example that a payment succeeded or a subscription was cancelled) so we can activate or deactivate your plan. Stripe processes your payment data under its own privacy policy: https://stripe.com/privacy.
9. Service providers (subprocessors)
We share personal data only with the service providers needed to run Homie:
| Provider | Purpose | Location |
|---|---|---|
| Amazon Web Services (AWS) | Hosting: accounts (Cognito), API and AI proxy (Lambda/API Gateway), databases (DynamoDB), encrypted sync storage (S3), transactional email (SES), logs (CloudWatch), AI model hosting (Bedrock) | USA (us-east-1) |
| Anthropic Claude models via Amazon Bedrock | Generating AI responses. Served within AWS; prompts/outputs are not stored by Bedrock, not shared with Anthropic, and not used for training | USA (us-east-1) |
| Stripe | Payment processing and subscription billing | USA |
| Only if you use Google sign-in or connect Google Calendar/Gmail; governed by Google’s privacy policy and your Google account settings | per Google |
We do not sell personal data, and we do not share it with advertisers or data brokers.
10. Data retention
- On-device data stays until you delete it in the app or delete the app.
- Account data is kept while your account exists.
- Subscription and usage records are kept while your account exists; Stripe retains its own records per its policies and legal obligations.
- Encrypted sync data is kept while sync is enabled so your devices can stay in sync; older data blocks are compacted and deleted automatically as new snapshots are uploaded. [TODO: retention after account deletion or prolonged inactivity]
- Shared content is kept until the owner deletes it or stops sharing it.
- Service logs: [TODO: CloudWatch log retention period].
11. Deleting your data, and data export
- Export — you can export your tasks, notes, memories, and chats as a JSON file at any time from the app (Account → export).
- Delete individual items — you can delete tasks, notes, chats, and memories in the app at any time.
- Disconnect integrations — disconnecting Google Calendar or Gmail stops all access; you can also revoke access from your Google Account.
- Delete your account — in the app under Account → danger zone. This permanently deletes your account and cannot be undone. Your sign-in account is deleted immediately; server-side data associated with the account (encrypted sync data, subscription record, shared content you own) is also deleted. Data stored locally on your device is removed when you delete the app from the device.
You may also contact us at [TODO: privacy contact email] to request deletion.
12. Security
- All traffic between the app and our servers uses TLS.
- Optional sync/backup data is end-to-end encrypted on your device before upload (XChaCha20-Poly1305, with keys derived from your passphrase using Argon2id); the server additionally encrypts stored objects at rest.
- The local database key and sync key material on your device are stored in the platform’s secure storage.
- Server data stores are private, access-controlled, and encrypted at rest by AWS.
- Actions with outside effects (like creating calendar events) require explicit in-app approval, limiting what the assistant can do without you.
No system is perfectly secure; if we learn of a breach affecting your personal data we will notify you as required by law.
13. Children
Homie is not directed at children under 13, and we do not knowingly collect personal data from children under 13. If you believe a child has provided us personal data, contact us at [TODO: privacy contact email] and we will delete it.
14. Your rights
Depending on where you live, you may have rights to access, correct, export, delete, or restrict the processing of your personal data. Most of these you can exercise directly in the app (export, editing, deletion); for anything else, contact us at [TODO: privacy contact email] and we will respond as required by applicable law.
[TODO: jurisdiction-specific rights sections — add GDPR (lawful bases, EU/UK representative if needed) and US state privacy (CCPA/CPRA) sections as applicable before launch.]
15. International transfers
Our servers are located in the United States (AWS us-east-1). If you use Homie from outside the United States, your data is processed in the United States as described in this policy.
16. Changes to this policy
When we change this policy we will update the effective date at the top and publish the new version at this address. For material changes we will notify you in the app or by email before the change takes effect.
17. Contact
[TODO: company legal name] [TODO: company registered address] [TODO: privacy contact email]