Private by design

Homie is built local-first: your tasks, notes, chats, and memories live in a database on your device — not on our servers. Data leaves your device only to power a feature you're using, and this page explains exactly when and why.

What stays on your device

The core of Homie runs on your phone. All of this is stored locally and is not uploaded to us unless you turn on sync or share something:

What reaches our servers, and why

When you ask Homie something, your message — plus the context needed to answer it, like relevant tasks or calendar events — is sent to our API and processed by AI models running on Amazon Bedrock (Anthropic Claude). That's what makes the assistant work. Our servers don't store the content of these requests; per AWS's Bedrock terms, prompts and outputs aren't stored there or used to train models. Server logs record metadata only (account, model, usage volume, timing) — not what you said.

Beyond AI processing, our servers hold only what accounts and optional features need: your email address for sign-in, your subscription status, encrypted sync data if you enable it, and content you explicitly share with other people.

The exception: sharing is server-side

Sharing is the deliberate exception to local-first. When you share a task or note with someone, or add tasks to a household group list, that content is stored on our servers in readable form — that's what lets the people you invited see it. You can stop sharing an item or revoke someone's access at any time, and unshared content goes back to being yours alone.

Homie asks before it acts

Anything the assistant wants to do with outside effects — creating a calendar event, for example — is shown to you first as an approval card: what it will do, with every detail visible. You approve, edit it, or decline. Automations run only with the capabilities you granted them, and their run history shows you what they did.

Integrations are opt-in and scoped

Sync is end-to-end encrypted

Optional sync & backup encrypts your data on your device before upload, with keys derived from a passphrase only you hold (plus a one-time recovery code). Our servers store ciphertext we cannot read. The app verifies synced data when it downloads it — if verification fails, Homie warns you and pauses syncing. The honest trade-off: if you lose both your passphrase and recovery code, we can't recover your synced data for you.

Where your data lives

DataOn your deviceOn our serversThird parties
Tasks, notes, chats, memoriesYes — the primary copyOnly as unreadable ciphertext, if you enable encrypted syncNo
AI requests (messages + context)Composed hereTransit our API to Amazon Bedrock for processing; content not stored, metadata loggedProcessed by Claude models within AWS; not stored, not used for training
Shared & household contentYesYes — readable, so invited people can access itNo
Google Calendar / Gmail dataAccessed directly from your deviceNot stored; portions transit AI processing only for your requestHeld by Google under your Google account
Account email & subscription statusYes (accounts & billing)Payment details go to Stripe, not us
Web search queriesSent from hereNoYour chosen provider, under your own API key

Deletion and export

What we don't do