← Homev0 draft — pending legal review

Privacy Policy

Effective: pre-launch · Version: 0.1
Sections
What we collectWhat we never collectHow we store itWho can see whatThird partiesRetention & deletionChildren’s dataContact us

What we collect

HomeQuest collects only what’s required for the feature you’re using. The full breakdown sits in our Terms of Service §1–4. In short:

  • Always: your account email, your household membership, the messages you send, and the Legal Ledger entries you author. Per ToS §1 and §2.
  • By default:minimal product usage metadata (page loads, errors, feature taps). Per ToS §3. You can turn this off in Settings → Privacy.
  • Only if you opt in: message content read by our cloud AI for tone coaching, pattern detection, and message drafting. Per ToS §4. Never default-on.

What we never collect

  • Your physical location, unless you explicitly attach it to an event.
  • Your contacts list, calendar from outside HomeQuest, or browsing history.
  • Anything from your microphone or camera unless you initiate a capture.
  • Message content for any feature except those listed under ToS §4 — and only if you opted in.
  • Co-parent message content for analysis when you have not opted into §4. We never use the opposing party as an excuse to collect more from you.

How we store it

All data is stored encrypted in transit and at rest. Lane-1 channels (attorney, Safe Harbor) are end-to-end encrypted with keys that live on your trusted devices — not on our servers. We can’t read those even if subpoenaed; we’d have to compel you for the key.

Legal Ledger entries are encrypted client-side before transmission. The plaintext never reaches our servers. The hash chain that proves entries haven’t been tampered with is computed against the ciphertext.

You can rotate your Lane-1 encryption keys any time in Settings → Security. Rotation re-wraps your existing channels and invalidates the old keys.

Who can see what

Visibility is enforced at the database layer via Row-Level Security (RLS). Even if our application code had a bug, the database itself refuses to return rows you’re not entitled to see.

Inside your household

  • Members see the channels they’re a participant in. Period.
  • The Head of Household manages members and channel admin. They cannot read attorney channels they’re not participants in.
  • Children see channels permitted to their age tier.

Outside your household

  • Your attorney, if you’ve invited them, sees what you’ve explicitly shared (attorney channels you’ve added them to + per-entry attorney-share opt-ins on the Ledger).
  • The other co-parent’s household sees only what cross-household features explicitly route — e.g. shared custody events, expense requests.
  • HomeQuest staff sees aggregated platform metrics only. We do not read your channels or your ledger. If we ever need to inspect a specific record for support, we ask you first.

Third parties

HomeQuest is hosted on Supabase (database, auth, storage) and uses cloud providers for the content-aware AI lane (Anthropic, Groq) only when you have opted in per ToS §4. Each third-party processor has a Data Processing Agreement on file; we will list them at /legal/subprocessors (coming soon).

When paid plans and addons go live, we will use Stripe for payment processing. Stripe’s data practices are governed by their own privacy policy. We will add them to the subprocessor list and update this section before any billing features are enabled.

Identity verification on HomeQuest uses Stripe Identity. When you complete a verification step — for example, to activate a professional account — Stripe collects your government-issued ID images and biometric data (a facial scan used for identity matching). HomeQuest does not store copies of your ID images or biometric data; that data is held by Stripe under their own privacy policy and data retention terms. Stripe Identity is activated only at explicit verification checkpoints and is never run without your awareness. This feature is not yet live; this section and the subprocessor list will be updated before it is enabled.

Retention & deletion

  • Legal Ledger:sealed entries are retained for 7 years (or your jurisdiction’s minimum, whichever is longer) per the forensic-record contract. Tear-up within the cooling window removes them entirely.
  • Messages: retention is set per channel by the Head of Household (default: indefinite for legal channels, 30 days for Daily Chatter).
  • Account deletion: within 30 days of request, your profile + private data is purged. Authored ledger entries remain in the household for the retention period above.
  • Backups: deletion propagates to backups on the next 90-day rotation.

Children’s data

HomeQuest is designed to include children of the household. A parent (Head of Household) creates child accounts; we do not knowingly accept signups directly from users under 13. Children’s messages stay within the household; nothing is shared with third parties beyond Supabase infrastructure storage. Content-aware AI (§4) is disabled for members under 13 and cannot be enabled by the parent. Members aged 13–17 follow the standard opt-in flow.

Contact us

Privacy questions, deletion requests, or data export requests: privacy@homequestapp.com. We respond within 7 business days.

HomeQuest · v0 draftLaw Enforcement Guidelines → · Terms of Service →