Privacy Policy

Outline — placeholder, not final.

Draft — not final. This page is a working outline, not reviewed or approved by an attorney. It is not a binding legal agreement yet and should not be relied on as one.

Who this applies to

Builder/business staff, homeowner end users of the client portal, and prospective customers.

Data we collect

  • Contact info (name, email)
  • Project and selections data
  • Financial fields (allowance, cost — visible to staff only, not homeowners by default)
  • Photos (product photos, maintenance-log photos, as-built documentation)
  • Floor plans
  • Chat messages sent to the AI assistant
  • Basic usage/log data

Who we share it with

Service providers (“subprocessors”) that help operate Hearthline:

  • Supabase — hosting, database, authentication, file storage
  • Vercel — application hosting
  • Resend — transactional email
  • Anthropic — AI features (the Claude API), for chat and document-extraction features

AI processing

The chat assistant and document-extraction features send relevant data to Anthropic's API to generate a response.

Data retention

[Retention periods per data category — to be defined.]

Your rights

Access, correction, and deletion of your data. Additional rights may apply depending on your state's privacy law (e.g. CCPA/CPRA-style rights).

Children's privacy

Hearthline is not directed at children, and we do not knowingly collect data from them.

Security

Encryption in transit, row-level access control scoping every query to a project or home, and private storage where applicable.

Cookies & tracking

Currently minimal — a session cookie only. This section will be updated if analytics or marketing cookies are ever added.

Changes & contact

[How we'll notify you of changes, and contact information — to be defined.]