1. Introduction
Boost Innovation (“we,” “us,” or “our”) operates Homesteady (“the Service”). This Privacy Policy explains how we collect, use, disclose, and safeguard your personal information when you use our Service. We are committed to compliance with the Personal Information Protection and Electronic Documents Act (PIPEDA) and applicable provincial privacy legislation.
2. Information We Collect
2.1 Information You Provide
- Account Information: name, email address, password (hashed)
- Property Information: address, city, province, postal code, year built, square footage, property type
- Assessment Responses: answers about your home systems (HVAC type, plumbing, roof material, etc.)
- Task Data: completion notes, photos, maintenance history
- Documents: files you upload (manuals, warranties, receipts)
- Payment Information: processed securely by Stripe; we do not store credit card numbers
2.2 Information Collected Automatically
- Geolocation: approximate latitude/longitude derived from your property address (used for climate-aware scheduling)
- Device and Browser Information: browser type, operating system, screen resolution
- Usage Data: pages visited, features used, task completion patterns, session duration
- Timezone: automatically detected from your browser
3. How We Use Your Information
- Generate and deliver personalized maintenance schedules
- Calculate your SteadyScore™ and provide actionable recommendations
- Incorporate local weather and climate data into task scheduling
- Send email reminders and overdue notifications
- Process payments and manage subscriptions
- Improve the Service through anonymized analytics and usage patterns
- Develop new features, including predictive maintenance models
- Comply with legal obligations and enforce our Terms of Service
4. Data Sharing and Disclosure
We do not sell your personal information. We may share information with:
- Service Providers: Supabase (database and authentication), Stripe (payments), Resend (email delivery), Vercel (hosting), Anthropic (AI-powered room analysis for the Reimagine feature). These providers process data on our behalf under contractual obligations.
- AI Processing: When you use the Reimagine feature, photos you upload are sent to Anthropic’s Claude API for analysis. Photos are processed in real-time and are not retained by Anthropic beyond the request. The AI-generated recommendations are stored in your account.
- Legal Requirements: When required by law, subpoena, or court order.
- Business Transfers: In connection with a merger, acquisition, or sale of assets, your data may be transferred to the acquiring entity.
- Aggregated Data: Anonymized, aggregated data may be shared for research, benchmarking, or commercial purposes.
5. Data Ownership
All data stored within the Service — including user accounts, property records, task completions, assessment responses, SteadyScore™ calculations, and aggregated analytics — is owned by Boost Innovation. While users retain rights to their personally identifiable property data, the Service’s database infrastructure, derived insights, and algorithmic outputs are the exclusive intellectual property of Boost Innovation.
6. Data Security
We implement industry-standard security measures including:
- Encryption in transit (TLS 1.3) and at rest
- Row-level security (RLS) policies ensuring users can only access their own data
- Hashed and salted passwords (bcrypt)
- Regular security audits and dependency updates
- Principle of least privilege for internal access
No system is 100% secure. We cannot guarantee absolute security but are committed to protecting your information using commercially reasonable measures.
7. Data Retention
We retain your personal data for as long as your account is active. If you delete your account, we will delete your personal data within 30 days, except where retention is required by law or for legitimate business purposes (e.g., fraud prevention, legal claims). Anonymized, aggregated data may be retained indefinitely.
8. Your Rights
Under PIPEDA and applicable provincial legislation, you have the right to:
- Access: Request a copy of the personal information we hold about you
- Correction: Request correction of inaccurate or incomplete data
- Deletion: Request deletion of your account and associated personal data
- Withdraw Consent: Withdraw consent for non-essential data processing
- Data Portability: Request an export of your data in a machine-readable format
To exercise any of these rights, contact us at privacy@livehomesteady.app. We will respond within 30 days.
9. Cookies and Tracking
The Service uses essential cookies for authentication and session management. We do not use third-party advertising trackers. Analytics may be implemented in the future with appropriate consent mechanisms.
10. Children’s Privacy
The Service is not intended for individuals under the age of 16. We do not knowingly collect personal information from children. If we become aware that a child has provided us with personal data, we will take steps to delete it promptly.
11. International Data Transfers
Your data may be processed and stored on servers located outside of Canada (e.g., in the United States) through our third-party service providers. By using the Service, you consent to such transfers. We ensure appropriate contractual safeguards are in place.
12. Changes to This Policy
We may update this Privacy Policy periodically. Material changes will be communicated via email or in-app notification. The “Last updated” date at the top of this page reflects the most recent revision.
13. Contact Us
For privacy inquiries or to exercise your rights:
Boost Innovation — Privacy Office
Email: privacy@livehomesteady.app