Privacy Policy
Draft, not final. Renovate's operating business entity is not yet formally registered. The controller of your data is currently [Legal entity name, registered address, and jurisdiction: pending business formation], reachable in the meantime at support@renovate.app. This placeholder will be replaced with the real entity details before this policy is considered final, and the whole document is pending a lawyer's review of the GDPR/CCPA specifics before Renovate goes live.
Overview
Renovate is a home renovation management app. This policy explains what personal data we collect when you use it, why we collect it, who we share it with, and the choices and rights you have over it. We built Renovate to hold sensitive information about your home and your money, so we try to collect only what the product needs and to be plain about the rest.
In short: we collect your account details and the renovation data you choose to enter (budget, documents, contacts, and so on), we don't sell your data, and AI features only send data to an AI provider if you turn them on. Details below.
Information we collect
Waitlist signups
If you join the waitlist from our landing page before creating an account, we collect only the email address you submit. We use it for one purpose: to email you when Renovate launches. The form is hosted by Tally, which processes your submission on our behalf as a subprocessor. We don't add you to any other mailing list, and you can ask us to delete your waitlist entry at any time by contacting us (see Contact us).
Account information
- Identity and login: name, email address, and password (stored as a bcrypt hash, never in plain text), or, if you sign in with Google or Apple, the identifiers those providers give us to verify who you are.
- Passkey/biometric login: if you enable Face ID, fingerprint, or another passkey, your device generates a public/private key pair. We only ever receive and store the public key and a credential ID. Your fingerprint or face data never leaves your device and is never sent to us.
- Push notification tokens: if you enable reminders or notifications, we store a device token issued by Apple (APNs), Google (FCM), or your browser (Web Push) so we know where to deliver them.
Renovation content
The data you or your collaborators enter to plan and track a renovation, including:
- Projects, phases, rooms, themes, tasks/actions, and goals
- Budget items, payment schedules, installments, and funding sources
- Contacts (names, emails, phone numbers, and notes for contractors, suppliers, or advisors you add)
- Documents and photos you upload, including photos taken with your device's camera, stored in our object storage (Cloudflare R2)
- Discussions, comments, and polls between renovation collaborators
- Timeline and version history of the above, kept so you can see what changed and when
- Voice input: if you use voice dictation to add an item or ask the AI assistant a question, your speech is converted to text. On the web app, this uses your browser's built-in speech recognition, which for most browsers means your browser vendor's own servers process the audio (for example, Chrome sends it to Google) under that vendor's own privacy terms, not ours. On iOS and Android, speech recognition uses your device's own on-device or platform speech service, subject to your OS-level microphone and dictation settings. In all cases, we only receive and store the resulting text transcript, never an audio recording.
Payment information
If you subscribe to a paid plan, billing is handled by Paddle, our payment processor and merchant of record. Paddle collects your payment card details directly; we never see or store your full card number. We receive confirmation of your subscription status from Paddle.
Technical and usage information
- Product analytics: we use PostHog to understand which parts of the app get used, on servers located in the EU. We track page views and basic account attributes (your user ID, email, name, and role); we do not record your screen or session.
- Error monitoring: we use Sentry to capture crash reports and error details so we can fix bugs. This can include technical context like device type, app version, and the state of the app when an error occurred.
- Session data: on the web app, we set an httpOnly session cookie that keeps you signed in; it isn't readable by page scripts. The iOS and Android apps instead store a session token in your device's secure keychain/keystore, not a cookie.
How we use it
We use the information above to:
- Create and secure your account, and authenticate you when you sign in
- Provide the core product: storing, syncing, and displaying your renovation data across your devices
- Let you invite and collaborate with other people on a shared renovation
- Send transactional email (password resets, verification, invitations) via our email provider, Resend
- Send reminders and notifications you've asked for
- Process subscription payments and manage your plan
- Diagnose bugs, monitor reliability, and improve the product
- Meet legal obligations, and detect and prevent fraud or abuse
AI features
Renovate includes optional AI features (chat, summaries, entity extraction from text or voice, document comparison). These are off by default and use two separate layers of consent, because a renovation is typically shared by more than one person:
- Renovation-level consent: AI features stay off for a given renovation until an owner or admin of that renovation explicitly turns them on. This gates whether the AI can see that renovation's shared content at all, no individual collaborator can turn it on unilaterally for data other people contributed.
- Your personal AI settings: separately, your own account has privacy settings covering your consent to use AI features and how long your conversations are kept (see Data retention). This is yours to control regardless of what a renovation's owner has enabled.
Once both layers of consent are in place:
- Bring-your-own-key (BYOK): by default, AI features use an API key you provide for a provider of your choice (for example Anthropic, OpenAI, or a self-hosted Ollama instance). Your key is encrypted at rest. When you use these features, the relevant renovation content (for example, the project data needed to answer your question) is sent to that provider under their own privacy terms, not ours.
- Platform-provided AI: on paid plans that use Renovate's own AI key instead of BYOK, the same principle applies: content you send through AI features is transmitted to our configured AI provider to generate a response.
- Conversation history: we store your AI conversations and an activity log so you can revisit past answers and audit what was sent. You control how long this is kept and can delete it at any time from AI settings.
Sharing within your renovation
Renovate is built for collaboration. Anyone you invite to a renovation, or grant access to via a renovation share link, can see the data scoped to that renovation, subject to the role and permissions you set. This is a core part of how the product works, not a third-party disclosure, but it's worth being explicit that "private to you" generally means "private to your renovation," not necessarily private to a single person.
Google Calendar integration
If you choose to connect Google Calendar, Renovate requests access via Google's OAuth flow to read and write calendar events related to your renovation timeline. We only request the calendar scopes needed for that feature.
Renovate's use and transfer of information received from Google APIs to any other app adheres to the Google API Services User Data Policy, including the Limited Use requirements. In particular: we do not use data obtained through Google Calendar for advertising, we do not sell it, we do not allow humans to read it except with your consent, to investigate abuse or a security incident, to comply with the law, or for internal operations where the data has been aggregated and anonymized. You can revoke Renovate's access to your Google account at any time from your Google Account security settings, or by disconnecting the integration in Renovate's settings.
Who we share data with
We share data with the service providers who help us run Renovate, and only for that purpose. We do not sell your personal data, and we do not share it with advertisers.
| Provider | Purpose | What they receive |
|---|---|---|
| Tally | Waitlist signup form | Email address submitted before you have an account |
| Cloudflare R2 | Document and photo storage | Uploaded files |
| Resend | Transactional email | Email address, message content |
| Paddle | Payment processing (merchant of record) | Billing/payment details, subscription status |
| PostHog | Product analytics | User ID, email, name, role, page views |
| Sentry | Error monitoring | Crash/error diagnostics |
| Google / Apple | Social sign-in; push notifications (FCM/APNs) | Auth identifiers; device push tokens |
| Your chosen AI provider | AI features (only if enabled) | Renovation content relevant to your request |
| Application hosting | Running the app and database | All of the above (self-managed infrastructure operated by us, not a third-party cloud host, at the time of writing; this row will be updated if that changes) |
We may also disclose information if required by law, to protect the rights and safety of Renovate or our users, or in connection with a merger, acquisition, or sale of assets, in which case we'd tell you before your data is transferred and becomes subject to a different privacy policy.
If you connect optional integrations such as Google Calendar (see above) or a self-hosted Paperless-ngx instance, data flows to those services too, governed by your own agreement with them and the permissions you grant.
International transfers
Renovate stores documents and photos in a region matched to where you signed up: a US bucket or an EU bucket, so EU users' files stay in the EU. Other data (your account and renovation records in our primary database) may be processed in a different country than the one you live in. Where we transfer personal data out of the EU/UK, we rely on appropriate safeguards such as Standard Contractual Clauses with our processors.
Data retention
- Account and renovation data: kept for as long as your account is active. If you delete your account, we delete your personal data and remove your access to shared renovations, except where we're required to keep records for legal, tax, or fraud-prevention reasons.
- AI conversations and activity logs: kept for a retention period you configure in AI privacy settings (90 days by default). You can shorten this, or delete your AI history immediately, at any time.
- Backups: deleted data may persist in encrypted backups for a limited period before being purged on our normal backup rotation.
Security
We use industry-standard measures to protect your data, including encrypted connections (TLS) in transit, bcrypt password hashing, AES-256 encryption at rest for sensitive secrets (such as AI provider keys and share-link tokens), httpOnly session cookies on the web, and rate limiting on authentication endpoints. No system is perfectly secure, and we can't guarantee absolute security, but we take reasonable steps to protect your information and to detect and respond to incidents quickly.
Your rights (EU/UK users)
If you're located in the European Economic Area or the UK, you have rights under the GDPR/UK GDPR, including the right to:
- Access the personal data we hold about you
- Correct inaccurate data
- Request deletion of your data ("right to be forgotten")
- Restrict or object to certain processing
- Receive your data in a portable format
- Withdraw consent at any time, where processing is based on consent (such as AI features)
- Lodge a complaint with your local data protection authority
Our legal bases for processing are: performance of a contract (running the app you signed up for), consent (for AI features), legitimate interests (security, fraud prevention, and improving the product), and legal obligation where applicable.
You can exercise most of these rights yourself from within the app (editing your profile, deleting content, deleting your AI history, or deleting your account). For anything else, contact us at the email below.
California privacy rights
If you're a California resident, the CCPA/CPRA gives you the right to know what personal information we collect, use, and disclose about you, to request deletion or correction of it, and to not be discriminated against for exercising these rights. We do not sell or share your personal information for cross-context behavioral advertising, so there is no opt-out link for that. To submit a request, contact us at the email below; we may need to verify your identity first.
The categories of personal information we collect, mapped to the CCPA's statutory categories:
| CCPA category | Collected? | Examples |
|---|---|---|
| Identifiers | Yes | Name, email, account ID, IP address, device/push tokens |
| Customer records (Cal. Civ. Code §1798.80(e)) | Yes | Name and contact details tied to your account |
| Commercial information | Yes | Subscription/plan status; renovation budget, payment schedule, and funding-source records you enter (project data, not your bank or card details) |
| Internet or network activity | Yes | Page views and basic in-app usage events (PostHog) |
| Audio, electronic, visual information | Yes | Photos and documents you upload; text transcripts of voice input (not audio recordings) |
| Geolocation data | No | Not collected |
| Professional or employment information | No | Not collected about you; you may voluntarily enter it about a contractor as a contact |
| Sensitive personal information | Limited | A WebAuthn/passkey public key tied to biometric login. Your actual fingerprint or face data is never collected, only the device-generated public key |
| Inferences | No | We do not build behavioral or preference profiles about you |
Children's privacy
Renovate is intended for homeowners managing their own household finances and is not directed at children. You must be at least 18 years old to create an account. We do not knowingly collect personal data from anyone under 18. If you believe a minor has provided us with personal data, contact us and we'll delete it.
Changes to this policy
We may update this policy as the product changes. If we make material changes, we'll notify you by email or through an in-app notice before they take effect. The "effective date" above always reflects the latest version.
Contact us
Questions about this policy, or requests relating to your data, can be sent to support@renovate.app.