This Privacy Policy explains how HOA AI ("we," "us," "our") collects, uses, stores, and protects your information when you use the HOA AI iOS app, the HOA AI web app at hoaai.ai, and related services (the "Service"). By using the Service, you agree to the practices described here. This Privacy Policy is incorporated by reference into our Terms of Service.
We collect the following categories of information:
(a) APPLE ID IDENTIFIER. When you Sign in with Apple, Apple provides us with a stable, unique identifier for your Apple ID. We use this identifier as the permanent primary key for your account. We do not receive your Apple password.
(b) NAME. On the first Sign in with Apple, Apple may transmit your full name to us. For an email account, you choose a name after verifying your email address. We store either value as your initial "display name." You can edit your display name at any time from the Account screen or web Account page. Apple does not re-send your name on subsequent sign-ins. IMPORTANT: your display name — both its initial value AND any edits you make — is shown to the Admins, Managers, and Board Members of every HOA profile you belong to. The name visible to those roles is always whatever name is currently on your account at the moment they view the member list. There is no way to belong to an HOA profile and conceal your display name from those roles. (Property Owner role members cannot see the member list; see Section 5 below.) See Section 3(f) and 3(g) of the Terms of Service for the full description.
(c) EMAIL ADDRESS AND AUTHENTICATION DATA. For Apple-based accounts, we do NOT collect or store an email address; any email value Apple transmits is ignored. (If an Apple-based account holder makes a web purchase, Stripe asks for an email address for receipts on its checkout page. It is kept on the Stripe customer record, of which we hold a synchronized billing copy — see Section 1(h). It is not attached to your HOA AI account and is never used for sign-in.) For email accounts, we store the email address for sign-in, verification, password reset, and transactional email. We also store a one-way SHA-256 hash of the normalized address for lifetime-trial enforcement and restoration after deletion. Passwords are stored only as salted one-way bcrypt hashes; we never see or store plaintext passwords. An email address is shown only to its account holder on their web Account page and is NEVER shown to another member.
(d) PENDING VERIFICATION AND SECURITY RECORDS. Before an email account is created, we store a pending record containing the email address, a one-way hash of the single-use verification token, and requesting IP address. The link expires after 24 hours and expired records are automatically purged about 7 days after expiry. Password-reset tokens are one-way hashed and expire after 1 hour. We temporarily process IP addresses to rate-limit sign-in, sign-up, and password-reset requests; IP addresses held solely for rate limiting are purged after the limiting window, at most 12 hours. The website visit log described in Section 1(k) keeps IP addresses separately, for 30 days.
(e) SESSIONS AND INVITATIONS. Web sessions use a server-side session record and an HttpOnly, Secure hoa_session cookie valid for up to 30 days. Logging out revokes the session. Invitations use single-use 6-digit codes generated from the Account screen or web Account page, expire after 1 hour, and are rate-limited per inviter. We perform no email lookup, address-book scan, or user-directory search.
(f) HOA PROFILES, DOCUMENTS, AND IMAGES YOU UPLOAD. We store the HOA profiles you create, the documents (PDFs, Word, Excel, text files, images) you upload to those profiles, and any images you attach to AI conversations. Documents and images are stored in cloud object storage; metadata is stored in our database.
(g) AI CONVERSATIONS. We store your AI conversation messages — both your prompts and the AI-generated responses — so that you can revisit them and so that the AI assistant can reference recent conversation history when generating answers. Your conversations within a shared HOA profile are permanently deleted when you leave that profile or are removed from it (Section 7(i)).
(h) SUBSCRIPTION AND PURCHASE METADATA. For iOS purchases, Apple handles payment data. For web purchases, Stripe handles payment through its hosted pages and collects the name and email address used at checkout, payment details, and purchase history. For email accounts, we pass your account email address and display name to Stripe so they are prefilled at checkout. For Apple-based accounts, we hold no email address for you, so Stripe's checkout page asks you for one; Stripe keeps it on your Stripe customer record and uses it for receipts, invoices, and failed-payment notices. That address is not attached to your HOA AI account, is never used for sign-in, and can be changed from the Billing Portal. To operate web billing, we store a Stripe customer identifier and keep a synchronized copy of the Stripe records for your customer: customer details (including the name and email address on the Stripe record), subscriptions, invoices, charges, refunds, disputes, and payment-method summaries such as card brand, last four digits, and expiry month and year. The Company never receives or stores full card numbers. RevenueCat sends us subscription state and entitlement metadata for both Apple and Stripe subscriptions.
(i) USAGE DATA. We record query counters, tier history, purchased-credit and HOA bonus-query balances, document counts, and timestamps needed to enforce subscription limits, the lifetime free trial, and the one-time bonus-query grant.
(j) DIAGNOSTIC AND CRASH DATA. We may collect basic diagnostic data (error messages, crash reports, request timestamps) for the purpose of debugging and maintaining service reliability. We do not collect device advertising identifiers and do not use third-party analytics that build cross-app advertising profiles.
(k) WEBSITE AND WEB APP VISIT LOG. When a page of hoaai.ai or of the web app is opened, our own server records the time, the page and requested path, the IP address, the browser's user-agent string, the referring website when you arrive from another site (its address without any query string) and, if you are signed in to the web app, a reference to your account. This is a first-party log kept to understand how the website and web app are used, such as which pages are viewed and where visitors come from. We use no third-party analytics service, tracking pixel or advertising identifier on hoaai.ai, and the log is never shared or sold. The IP address, user-agent string, referring website, account reference and exact path are kept for 30 days after the visit and then deleted from the entry; only the time and the page remain, which hold no personal data, so page counts can be kept indefinitely. The iPhone app is not logged in this way.
We use the information we collect for the following purposes only:
(a) TO PROVIDE THE SERVICE — authenticating you, storing your HOA profiles and documents, generating AI responses, and enabling collaboration features.
(b) TO PROCESS PAYMENTS AND ENFORCE SUBSCRIPTION LIMITS — using Apple, Stripe, and RevenueCat purchase and entitlement metadata to grant access on both platforms.
(c) TO ENFORCE THE LIFETIME FREE TRIAL AND BONUS PROGRAM — the Apple identifier for Apple-based accounts or normalized-email hash for email accounts, together with historical usage, tier, and credit fields, prevents repeat trials or repeat one-time bonus grants after deletion and restoration. See Section 7 below.
(d) TO PROVIDE SUPPORT — responding to your questions and reports of abuse or security issues.
(e) TO MAINTAIN SECURITY AND PREVENT ABUSE — managing server-revocable sessions, rate limiting authentication requests, and detecting account sharing, fraudulent payments, or other violations of the Terms of Service.
(f) TO SEND TRANSACTIONAL EMAIL FOR EMAIL ACCOUNTS — verification links, password-reset links, and courtesy notices that an account already exists. We do not send marketing or newsletter email.
(g) TO COMPLY WITH LEGAL OBLIGATIONS — responding to lawful requests from government authorities and complying with applicable law.
(h) TO UNDERSTAND HOW THE WEBSITE AND WEB APP ARE USED — using only the first-party visit log described in Section 1(k). We do not use third-party analytics.
WE DO NOT SELL YOUR PERSONAL INFORMATION. WE DO NOT USE YOUR DATA TO TRAIN ARTIFICIAL INTELLIGENCE MODELS THAT WE OFFER TO OTHER CUSTOMERS, AND WE DO NOT MONETIZE YOUR DATA THROUGH ADVERTISING.
When you submit an AI query, the contents of your message — including any text you typed, image attachments, and the contents of HOA documents that the AI selector chooses as relevant — are sent to a third-party artificial intelligence provider (currently OpenAI) for processing. The AI provider returns a generated response, which we deliver back to you and store in your conversation history.
We have entered into a commercial API agreement with our AI provider that, to the best of our knowledge based on that provider's published policies, prohibits the provider from using your prompts or document content to train its public models. However, the AI provider may temporarily retain your data for abuse-monitoring and service-reliability purposes per its own policies. We may change AI providers at any time without notice.
BY USING THE AI FEATURES OF THE SERVICE, YOU EXPRESSLY CONSENT TO THE TRANSMISSION OF YOUR PROMPTS, IMAGES, AND DOCUMENT CONTENT TO THIS THIRD-PARTY AI PROVIDER. IF YOU DO NOT CONSENT, DO NOT USE THE AI FEATURES OF THE SERVICE.
We rely on the following third-party providers to operate the Service. Each provider is a "subprocessor" that may receive limited categories of your data strictly as needed to perform its function:
(a) APPLE, INC. — authentication (Sign in with Apple), in-app purchases, App Store distribution, push notifications.
(b) OPENAI — AI-generated responses (see Section 3).
(c) REVENUECAT — management and entitlement synchronization for Apple and Stripe subscriptions, including webhook delivery.
(d) STRIPE, INC. — web payment processing through Stripe-hosted Checkout and the customer portal. Stripe receives your display name, your account email address (email accounts) or the email address you enter at checkout for receipts (Apple-based accounts), payment details, and purchase history, and stores the payment method. We keep a synchronized copy of the resulting Stripe billing records as described in Section 1(h).
(e) RESEND — delivery of transactional email for email accounts. Resend receives the recipient email address and email content.
(f) CLOUD HOSTING AND OBJECT STORAGE PROVIDERS — server hosting, PostgreSQL database, and document/image object storage.
We may add, remove, or replace subprocessors at any time without notice as we evolve the Service. Each subprocessor's own terms and privacy policy govern their handling of data they receive.
We share your information only in the following narrow circumstances:
(a) WITH SUBPROCESSORS — as described in Section 4, for the limited purposes of operating the Service.
(b) WITH OTHER MEMBERS OF SHARED HOA PROFILES — when you join an HOA profile, certain other members of that profile can see your display name and role (subject to the role-based visibility rules in Section 6 of the Terms of Service). SPECIFICALLY, ADMINS, MANAGERS, AND BOARD MEMBERS OF AN HOA PROFILE YOU BELONG TO CAN SEE YOUR DISPLAY NAME — both the initial value supplied by Apple or chosen during email registration (until you edit it) AND any edited value you later set. The name they see at any given moment is always whatever is currently stored on your account, whether initialized by Apple or chosen during email registration. Property Owner role members cannot see the member list at all and therefore cannot see your name. The role shown next to your name is your role in that profile, except that Admins may choose a cosmetic "displayed role" label (see Section 6 of the Terms of Service); a disguised Admin's actual role remains visible to members who hold member-management access. An account email address is never included in member lists or shown to another user. The documents you upload are visible to all members of the same HOA profile.
(c) FOR LEGAL COMPLIANCE — in response to a valid subpoena, court order, or other lawful request, or where we have a good-faith belief that disclosure is necessary to protect the rights, property, or safety of the Company, users, or the public.
(d) IN A CORPORATE TRANSACTION — if the Company is acquired, merged, or sells all or substantially all of its assets, your information may be transferred to the successor entity, subject to a commitment to honor the material terms of this Privacy Policy.
(e) WITH AUTHORIZED ADMINISTRATORS — a small number of authorized Company personnel have administrative access to the underlying database for the limited purposes of (i) operating, maintaining, and securing the Service; (ii) responding to support requests you initiate; (iii) investigating suspected violations of our Terms of Service, fraud, or abuse; (iv) complying with legal obligations; and (v) preventing imminent harm to users or third parties. Administrative access is logged, restricted to personnel with a legitimate operational need, and never used to monetize, sell, or share your information with third parties.
WE DO NOT SELL OR RENT PERSONAL INFORMATION TO ADVERTISERS, DATA BROKERS, OR ANY OTHER THIRD PARTY FOR THEIR INDEPENDENT MARKETING PURPOSES.
The Service is operated from the United States. Your information is stored on servers located in the United States. If you access the Service from outside the United States, your information will be transferred to and processed in the United States, which may have data-protection laws different from those of your country.
The iOS app and web app use the same servers and, when you use the same account, the same HOA profiles, documents, chats, usage, subscription, purchased-credit, and bonus-query data. Changes synchronize in near real time.
(a) WHILE YOUR ACCOUNT IS ACTIVE — we retain your account, profile, document, and conversation data for as long as your account exists, except that your conversations within an HOA profile are deleted when you leave that profile or are removed from it (subsection (i)).
(b) WHEN YOU DELETE YOUR ACCOUNT — from the Account screen or web Account page, the following happens immediately: your conversations and messages are permanently deleted; you are removed from all shared HOA profiles; all of your active sessions are invalidated; HOA profiles you created are reassigned to a backup Admin if one exists, or otherwise to the most senior remaining member (Manager first, then Board Member, then Property Owner), who becomes the new profile owner — profiles with remaining members always continue to exist for those members; your display name, your initial authentication name, email address and password hash for an email account, and your RevenueCat subscriber link are erased from our records; and any unused invite codes you generated are immediately and permanently invalidated so they can never be used. ORPHAN HOA PROFILES — DOCUMENTS PERMANENTLY DELETED: If, at the time you delete your account, you are the only remaining member of any HOA profile (i.e., no other user holds a membership in that profile and no other user is its owner), that HOA profile and every document belonging to it are permanently deleted from our object storage and database at the time of account deletion. There is no grace period, no backup of orphan-profile documents outside the standard encrypted database backups described in subsection (e), and no way to restore those documents after account deletion. HOA profiles in which other members remain are preserved for those remaining members, and their documents are not deleted.
(c) MINIMAL POST-DELETION RECORD — for Apple-based accounts, we retain the Apple identifier, historical query counters, tier fields, remaining purchased and bonus credits, and deletion timestamp. For email accounts, we retain the one-way normalized-email hash and those same usage, tier, credit, and deletion fields. For any account that made a web purchase (Apple-based or email), we also retain the Stripe customer identifier and the synchronized Stripe billing records described in Section 1(h) — for Apple-based accounts these include the email address entered at checkout — for financial records, refunds or chargebacks, tax, and fraud prevention. Stripe separately retains transaction records under its policy and legal obligations. We erase the email address, password hash, display name, documents, conversations, and all other personal data. Retained records enforce one lifetime trial per Apple ID or email address, preserve purchased credits, and prevent repeat bonus grants. They are not visible to other users or used for marketing.
(d) IF YOU RETURN — signing in with the same Apple ID or completing registration again with the same email address restores the retained account record, including usage counters, tier history, and remaining purchased or bonus credits. Your prior conversations, documents, personal details, and memberships are NOT restored.
(e) BACKUPS — encrypted backups of our databases may retain your data for up to 30 days after deletion before they are themselves rotated out. Backups are access-controlled and used only for disaster recovery.
(f) APPLE SUBSCRIPTION — deleting your HOA AI account does NOT cancel your Apple subscription. Apple manages all billing independently. To cancel your subscription and stop being billed, use your Apple ID account settings on your device.
(g) WEB SUBSCRIPTION — deleting your account immediately cancels an active Stripe web subscription. Unused time in the current paid period is not refunded.
(h) VISIT LOG — as part of account deletion, the account reference is removed from your entries in the website and web app visit log. The other visitor details in those entries are kept for the normal 30 days after each visit and then deleted, as described in Section 1(k).
(i) LEAVING OR BEING REMOVED FROM AN HOA PROFILE — when you leave a shared HOA profile, or when a member with member-management access or the Company removes you from it, all AI conversation messages you exchanged within that profile are permanently deleted from our database at that moment, together with your membership. They are not restored if you are re-invited. Your conversations within other HOA profiles and the rest of your account are not affected. Encrypted backups may hold the deleted messages for up to 30 days, as described in subsection (e).
Depending on where you live, you may have the following rights with respect to your personal information:
(a) ACCESS — request a copy of the personal information we hold about you.
(b) CORRECTION — correct inaccurate information. You can directly correct your display name at any time from the Account screen or web Account page.
(c) DELETION — request deletion of your account and associated data. You can do this directly from the Account screen or web Account page.
(d) PORTABILITY — receive your data in a portable format (where applicable under your local law).
(e) OPT-OUT OF SALE — we do not sell personal information; this right is therefore inapplicable, but we honor it by default.
(f) NONDISCRIMINATION — we will not retaliate against you for exercising any of these rights.
To exercise any right that cannot be exercised directly in the Service, contact us at info@hoaai.ai. We will respond within the time required by applicable law.
If you are a California resident, you have the rights described in Section 8 above under the California Consumer Privacy Act ("CCPA") as amended by the California Privacy Rights Act ("CPRA"), including the right to know what personal information we collect, the right to delete it, the right to correct it, the right to opt out of "sale" or "sharing" of personal information, and the right to limit use of "sensitive personal information." We do not "sell" or "share" personal information as those terms are defined under the CCPA. Categories of personal information we collect are described in Section 1 above.
If you are located in the European Economic Area, the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation ("GDPR") and equivalent local laws, including the rights of access, rectification, erasure, restriction of processing, data portability, and objection. Our legal bases for processing are: (i) performance of the contract (Terms of Service) for service delivery, (ii) legitimate interests for security, abuse prevention and understanding how the website and web app are used (Section 1(k)), (iii) your consent for AI processing of your inputs, and (iv) compliance with legal obligations. You may lodge a complaint with your local data-protection authority.
The Service is not directed to, and we do not knowingly collect personal information from, anyone under the age of 18. The Terms of Service require all users to be at least 18 years old. If we learn that we have collected information from a person under 18, we will delete that information promptly. If you believe a minor has used the Service, contact us at info@hoaai.ai.
We use commercially reasonable technical and organizational safeguards to protect your information. The web app is HTTPS-only and uses HSTS, security headers, CSRF protections, rate limiting, salted one-way password hashes, hashed verification and reset tokens, server-revocable sessions, access-controlled cloud infrastructure, and least-privilege internal access. The apps maintain an open connection to our servers for near-real-time change notifications using only the existing session and no additional personal data. However, no system is completely secure, and we cannot guarantee that your information will never be subject to unauthorized access. See Section 21 of the Terms of Service for the full security disclaimer and incident- notification commitment.
The Service is designed for HOA-related materials. You agree not to upload categories of sensitive data described in Section 22 of the Terms of Service, including Social Security numbers, payment card data, driver's-license numbers, protected health information, login credentials for other systems, biometric data, or any data subject to specialized regulatory regimes such as HIPAA, GLBA, PCI-DSS, FERPA, or COPPA. The Service is not certified for processing such data.
The iOS app uses no cookies and stores authentication tokens and minor preferences in secure local device storage. We do not engage in cross-app tracking and do not request the iOS App Tracking Transparency permission.
On hoaai.ai, we use strictly necessary cookies only: the HttpOnly, Secure hoa_session cookie, valid for up to 30 days, and a short-lived state cookie, valid for 10 minutes, used only during the Sign in with Apple hand-off. Browser storage may hold non-identifying interface state. We use no advertising, analytics, or third-party tracking cookies on hoaai.ai; page views are counted by our own server as described in Section 1(k), without any analytics cookie. Stripe-hosted checkout and portal pages and Apple's sign-in pages may set their own cookies under their own policies.
We may update this Privacy Policy from time to time. If we make material changes, we will notify you through the Service or by reasonable means before the change takes effect, and we will update the Effective Date at the top of this document. Your continued use of the Service after the Effective Date of any update constitutes your acceptance of the revised Privacy Policy.
If you have questions about this Privacy Policy or our data practices, please contact us at: info@hoaai.ai