← Back to HomeMap
Privacy Policy
Effective Date: March 13, 2026 · Last Updated: May 3, 2026
IMR Creations LLC ("we," "us," or "our") operates the HomeMap mobile application and web service (the "App"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our App. We are committed to protecting your privacy and handling your data transparently.
1. Information We Collect
a) Information You Provide Directly
| Data Category | Specific Data Points | Purpose |
| Account information | Email address, full name, password | Account creation, authentication, communication |
| Profile information | Phone number (optional) | Account recovery, contact |
| Home data | Home name, street address, floor count, room names and layout | Core app functionality |
| Inventory & records | Items, tasks, service logs, deliveries, contacts, documents, shopping lists | Home management features |
| Collaboration data | Collaborator email addresses, invitation status, permissions | Multi-user access to shared homes |
| Photos & images | Blueprint uploads, item photos, receipt photos | Floor plan generation, item tracking, receipt OCR |
| Receipts | Receipt photos, extracted merchant name, date, total, line items, tax-deduction flag | Receipt scanning, spending analytics, tax-deduction tracking |
| Payment information | Processed by Stripe / app stores. We store only: Stripe customer ID, subscription status, subscription ID | Subscription management |
b) Information Collected Automatically
- We do not use analytics SDKs, tracking pixels, or advertising identifiers.
- We do not collect device identifiers, IP addresses (beyond standard server logs), browsing behavior, or location data for advertising or profiling purposes.
- Server logs: Our servers may temporarily log IP addresses and request timestamps for security and abuse prevention. These logs are automatically purged after 30 days.
- Local storage: The App stores data on your device using browser local storage or native app storage for offline functionality. This data does not leave your device unless you have a signed-in account.
c) Camera & Photo Library Access
The App may request access to your device camera or photo library to photograph items or documents. Photos are processed locally and, if you are signed in, synced to our servers. We do not access your camera or photos without your explicit permission, and you can revoke this permission at any time through your device settings.
AI processing: When you scan a receipt, identify an item with the Stuff "Scan with AI" tool, or request maintenance suggestions, the relevant photo and/or text is sent to Anthropic's Claude API to generate the response. Anthropic processes the request to produce the response and, per their commercial Terms of Service, does not use API inputs or outputs to train their models. Anthropic may retain inputs for up to 30 days for trust-and-safety abuse monitoring, after which they are deleted. We are pursuing a Zero Data Retention agreement that will eliminate this 30-day retention window; we will update this policy when it takes effect. See Section 5 for the full third-party services list.
d) Information We Do NOT Collect
- We do not collect biometric data (fingerprints, face scans).
- We do not collect precise geolocation data.
- We do not collect contacts from your device address book.
- We do not collect browsing history or activity outside the App.
- We do not collect financial account numbers or credit card details (handled entirely by Stripe / app stores).
2. How We Use Your Information
- To provide, operate, maintain, and improve the App's features and functionality.
- To create and manage your account and authenticate your identity.
- To process payments and manage subscriptions (Free, Premium, and Pro tiers) through Stripe and app store payment systems.
- To provide the 7-day free trial of Pro features for new users.
- To facilitate collaboration between home members you invite.
- To look up property details (beds, baths, square footage) based on addresses you voluntarily provide.
- To provide address autocomplete suggestions.
- To respond to your support requests and communications.
- To detect, prevent, and address technical issues, fraud, and security threats.
- To comply with legal obligations.
We do not use your data for: advertising, profiling, automated decision-making, selling to third parties, or any purpose unrelated to providing the App's services.
3. Legal Bases for Processing (EEA/UK Users)
If you are in the European Economic Area (EEA) or the United Kingdom, we process your personal data based on the following legal grounds:
| Legal Basis | Processing Activity |
| Contract performance | Account creation, providing App features, managing subscriptions, collaboration |
| Legitimate interest | Security monitoring, fraud prevention, improving the App |
| Consent | Camera/photo access, optional data entry, marketing communications (if any) |
| Legal obligation | Tax records, responding to lawful government requests |
4. Subscription Tiers & Data Access
HomeMap offers the following subscription tiers, which affect what data features are available:
| Plan | Price | Features | Collaborators |
| Free | $0 | Home, Tasks, Contacts, Shopping, Documents | None |
| Free Trial (7 days) | $0 | All Pro features | Up to 4 members |
| Premium | $7.99/mo | All features including tasks, service log, delivery tracking | 1 collaborator (2 people total) |
| Pro | $14.99/mo | All features, priority support | Up to 4 members (5 people total) |
When your free trial expires, your account is downgraded to the Free tier. Data you created during the trial is retained but not accessible until you upgrade. No data is deleted upon downgrade.
5. Third-Party Services
We use the following third-party services to operate the App:
| Service | Purpose | Data Shared | Privacy Policy |
| Mapbox | Address autocomplete | Address search queries | mapbox.com/legal/privacy |
| RentCast | Property information lookup | Property addresses | rentcast.io/privacy |
| Stripe | Payment processing (web) | Email, payment method (handled by Stripe) | stripe.com/privacy |
| Apple App Store | Payment processing (iOS) | Per Apple's terms | apple.com/legal/privacy |
| Google Play Store | Payment processing (Android) | Per Google's terms | policies.google.com/privacy |
| RevenueCat | Subscription management (mobile) | User ID, subscription status | revenuecat.com/privacy |
| Anthropic (Claude API) | AI processing of receipt and item photos (OCR, item identification, maintenance suggestions) | Photo content and text prompts. Per Anthropic's commercial Terms, inputs are not used to train their models; inputs may be retained up to 30 days for abuse monitoring, then deleted. | anthropic.com/legal/privacy |
| 17track | Package tracking (international shipments) | Tracking numbers, carrier codes | 17track.net/en/privacy |
| EasyPost | Package tracking (US shipments) | Tracking numbers, carrier codes | easypost.com/privacy-policy |
| Supabase | Database hosting (US) | All account and home data, encrypted at rest | supabase.com/privacy |
| Railway | API server hosting (US) | API request data, transient server logs | railway.com/legal/privacy |
| Resend | Transactional email delivery (account verification, deletion confirmations) | Email address, message content | resend.com/legal/privacy-policy |
| Sentry | Crash and error monitoring | Stack traces, anonymized error events (no PII payloads) | sentry.io/privacy |
We do not sell, rent, or trade your personal data to any third party. Data is shared with the services above only to the extent necessary to provide the App's functionality. AI inputs sent to Anthropic are not used to train their models; they may be retained up to 30 days for abuse monitoring per Anthropic's standard commercial policy. We are working toward a Zero Data Retention agreement that will remove this retention window; this policy will be updated when that agreement is in effect.
6. Data Sharing & Collaboration
- When you invite collaborators to your home, they can view and edit shared home data based on the permissions you configure.
- Your personal data (tasks, contacts, shopping lists, documents) is never shared with collaborators unless you explicitly grant access.
- Collaborators can only access homes they have been invited to.
- You can remove a collaborator's access at any time.
- We may disclose your information if required by law, court order, or government request, or to protect our rights, safety, or property.
7. Data Storage, Security & Encryption
a) How Your Data Is Stored
- All users: HomeMap requires an account. Your data is stored on our secure servers (Supabase, US region) and synced across your devices.
- Database: We use an encrypted database with write-ahead logging (WAL) for data integrity and crash recovery.
- Locally on your device: A copy of recently viewed data may be cached on your device for offline use; this cache is cleared when you log out.
b) Encryption
- Data in transit: All communications between the App and our servers are encrypted using TLS 1.2 or higher (HTTPS). No data is ever transmitted in plain text.
- Data at rest: Server storage volumes are encrypted. Database backups are encrypted.
- Passwords: Passwords are never stored in plain text. They are hashed using bcrypt with a cost factor of 12, making them computationally infeasible to reverse.
- Payment data: Credit card information is handled entirely by Stripe and app stores. We never see, process, or store your card numbers.
c) Authentication & Access Controls
- Authentication uses cryptographically signed JSON Web Tokens (JWT) that expire after 30 days.
- API endpoints are protected by authentication middleware that validates tokens on every request.
- House-level access controls ensure users can only access homes they own or have been invited to.
- Server security headers protect against common web vulnerabilities (XSS, clickjacking, MIME sniffing).
- Rate limiting protects authentication endpoints against brute-force attacks.
d) Infrastructure Security
- Our servers are hosted on infrastructure that provides physical security, network firewalls, and DDoS protection.
- We use CORS (Cross-Origin Resource Sharing) policies to restrict API access to authorized origins only.
- We monitor our systems for security threats and apply security patches promptly.
- In the event of a data breach, we will notify affected users and relevant authorities as required by applicable law (within 72 hours for GDPR, as soon as practicable for other jurisdictions).
8. Data Retention
- We retain your personal data for as long as your account is active or as needed to provide the App's services.
- When you delete your account, all associated data is permanently removed from our servers. See our Data Deletion Policy.
- Server logs (IP addresses, request timestamps) are automatically purged after 30 days.
- Encrypted backups may retain data for up to 90 days after account deletion, after which they are automatically purged.
- Data stored locally on your device remains until you clear it or uninstall the App.
- We may retain certain data as required by law (e.g., tax records, legal disputes).
9. Your Rights & Choices
Depending on your jurisdiction, you may have some or all of the following rights:
| Right | Description |
| Access | Request a copy of the personal data we hold about you. |
| Rectification | Request correction of inaccurate or incomplete data. |
| Deletion / Erasure | Request deletion of your personal data. See our Data Deletion Policy. |
| Data Portability | Request your data in a structured, commonly used format. |
| Restriction | Request that we limit processing of your data. |
| Objection | Object to processing based on legitimate interests. |
| Withdraw Consent | Withdraw consent at any time where processing is based on consent. |
| Non-Discrimination | You will not be discriminated against for exercising your privacy rights. |
To exercise any of these rights, contact us at support@myhomemap.app. We will respond within the timeframe required by applicable law (generally 30–45 days).
Additional Choices
- Camera permissions: You can revoke camera access at any time through your device settings. Without it, photo-based features (receipt scanning, item photos, AI Stuff scanner) are not available, but the rest of the app remains usable.
- Notification permissions: You can disable push notifications at any time through your device settings.
- Subscription management: You can upgrade, downgrade, or cancel your subscription at any time via the App Store, Google Play, or the web billing portal.
10. California Privacy Rights (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA), as amended by the California Privacy Rights Act (CPRA), provides you with specific rights regarding your personal information.
a) Categories of Personal Information Collected (Past 12 Months)
| Category (per CCPA) | Collected? | Examples |
| A. Identifiers | Yes | Email address, name, account ID |
| B. Personal information per Cal. Civ. Code §1798.80(e) | Yes | Name, address, phone number |
| C. Protected classification characteristics | No | — |
| D. Commercial information | Yes | Subscription status, purchase history (via Stripe) |
| E. Biometric information | No | — |
| F. Internet or network activity | Limited | Server logs (IP, timestamps) for security only; purged after 30 days |
| G. Geolocation data | No | — |
| H. Sensory data | Yes | Photos you voluntarily upload |
| I. Professional or employment information | No | — |
| J. Non-public education information | No | — |
| K. Inferences | No | — |
| L. Sensitive personal information | Yes | Account credentials (password stored as irreversible hash) |
b) Your CCPA Rights
- Right to Know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the sources, the business purposes, and the categories of third parties with whom we share it.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions.
- Right to Correct: You may request correction of inaccurate personal information.
- Right to Opt-Out of Sale/Sharing: We do not sell or share your personal information for cross-context behavioral advertising. There is no need to opt out because we never engage in these practices.
- Right to Limit Use of Sensitive Personal Information: We only use sensitive personal information (account credentials) for providing the App’s services.
- Right to Non-Discrimination: We will not discriminate against you for exercising your CCPA rights.
c) How to Submit a Request
Email us at support@myhomemap.app with the subject "CCPA Request." We will verify your identity using the email associated with your account. We will respond within 45 days (extendable by an additional 45 days with notice).
d) Do Not Sell or Share My Personal Information
We do not sell your personal information. We do not share your personal information for cross-context behavioral advertising. This has been our practice since the App’s inception and we intend to maintain it.
11. European Privacy Rights (GDPR)
If you are located in the European Economic Area (EEA) or the United Kingdom (UK), the General Data Protection Regulation (GDPR) and UK GDPR provide you with enhanced data protection rights.
- Data Controller: IMR Creations LLC is the data controller for your personal data.
- Legal Bases: See Section 3 above.
- Your Rights: You have the right to access, rectify, erase, restrict processing, data portability, object to processing, and withdraw consent (see Section 9).
- International Transfers: Your data is processed in the United States. We rely on Standard Contractual Clauses (SCCs) as the legal mechanism for transferring personal data from the EEA/UK to the US.
- Data Protection Authority: If you are unsatisfied with our handling of your data, you have the right to lodge a complaint with your local supervisory authority.
- Data Protection Officer: For GDPR inquiries, contact us at support@myhomemap.app.
- Breach Notification: In the event of a personal data breach that poses a risk to your rights, we will notify the relevant supervisory authority within 72 hours and notify you without undue delay.
12. Brazil Privacy Rights (LGPD)
If you are located in Brazil, the Lei Geral de Proteção de Dados (LGPD) provides you with the following rights:
- Confirmation of the existence of processing of your personal data.
- Access to your personal data.
- Correction of incomplete, inaccurate, or outdated data.
- Anonymization, blocking, or deletion of unnecessary or excessive data.
- Portability of your data to another service provider.
- Deletion of personal data processed with your consent.
- Information about public and private entities with which we have shared your data.
- Information about the possibility of not providing consent and the consequences thereof.
- Revocation of consent.
Legal basis for processing: We process your data based on the performance of a contract (providing the App) and your consent (where applicable). To exercise your rights under the LGPD, contact us at support@myhomemap.app.
ANPD: You may file a complaint with the Autoridade Nacional de Proteção de Dados (ANPD) if you believe your rights have been violated.
13. Japan Privacy Rights (APPI)
If you are located in Japan, the Act on the Protection of Personal Information (APPI) applies to our processing of your data.
- You have the right to request disclosure, correction, suspension of use, or deletion of your personal information.
- We will specify the purpose of use of your personal data and will not use it beyond that scope without your consent.
- We will take necessary and appropriate measures to ensure the security of your personal data.
- We will not provide your personal data to third parties without your consent, except as permitted by law.
- When transferring data to a country outside Japan, we ensure appropriate protections are in place.
To exercise your rights, contact support@myhomemap.app.
14. China Privacy Rights (PIPL)
If you are located in the People’s Republic of China, the Personal Information Protection Law (PIPL) applies.
- We process personal information based on your informed consent or as necessary for the performance of a contract.
- You have the right to know about and make decisions regarding the processing of your personal information.
- You have the right to request access, correction, and deletion of your personal information.
- You have the right to withdraw consent for data processing.
- You have the right to request an explanation of personal information processing rules.
- Cross-border transfers: Your data is processed in the United States. By using the App, you consent to this transfer. We take measures to ensure your data receives adequate protection.
To exercise your rights, contact support@myhomemap.app.
15. Russia Privacy Rights (Federal Law No. 152-FZ)
If you are located in Russia, Federal Law No. 152-FZ "On Personal Data" applies.
- We process your personal data with your consent and for the performance of a contract.
- You have the right to access, correct, block, or destroy your personal data.
- You have the right to withdraw consent for data processing at any time.
- Upon withdrawal of consent, we will cease processing and delete your personal data, unless retention is required by law.
- Cross-border transfers: Your data is processed on servers located outside of Russia. By using the App, you consent to this cross-border transfer.
To exercise your rights, contact support@myhomemap.app.
16. Other International Users
If you are located in a jurisdiction not specifically listed above but which has data protection or privacy laws, we are committed to respecting your rights. In general:
- We will process your data fairly and transparently.
- We will only collect data necessary for providing the App’s services.
- We will honor requests to access, correct, or delete your data.
- We will not sell your personal information.
- We will comply with applicable local laws.
Contact us at support@myhomemap.app for any privacy-related inquiry.
17. Children’s Privacy
The App is not directed at children under 16 (or the minimum age required in your jurisdiction). We do not knowingly collect personal information from children. If we learn that we have collected data from a child without verifiable parental consent, we will delete it promptly. If you believe a child has provided us personal information, please contact us at support@myhomemap.app.
18. Advertising & Tracking
HomeMap does not:
- Display advertisements of any kind.
- Use advertising SDKs or tracking pixels.
- Share data with ad networks.
- Track users across apps or websites.
- Sell, rent, or share your personal information with third parties for marketing or advertising purposes.
- Engage in cross-context behavioral advertising.
19. Cookies & Similar Technologies
The web version of the App uses browser local storage to maintain your session and store app data. We do not use tracking cookies, third-party cookies, or web beacons. The only storage used is strictly necessary for the App to function.
20. International Data Transfers
Your information is processed in the United States. If you access the App from outside the United States, your data will be transferred to and processed in the US. We implement appropriate safeguards for international data transfers:
- EEA/UK: Standard Contractual Clauses (SCCs) approved by the European Commission.
- Brazil: Compliance with LGPD cross-border transfer requirements.
- Other jurisdictions: Consent-based transfer and contractual protections.
21. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by:
- Updating the "Last Updated" date at the top of this page.
- Providing notice via email or in-app notification for significant changes.
- Where required by law (e.g., GDPR), obtaining your consent before applying material changes.
Your continued use of the App after the effective date of changes constitutes acceptance of the updated policy.
22. Contact Us
If you have questions about this Privacy Policy, wish to exercise your privacy rights, or have concerns about how your data is handled, please contact us at:
IMR Creations LLC
Email: support@myhomemap.app
Subject line: "Privacy Inquiry" or "Data Rights Request"
We will respond within the timeframe required by applicable law in your jurisdiction.