Privacy Policy
This policy describes how Renoflow handles personal information on our website, in the Renoflow application, and during our monitored pilot. It also covers information collected before an account is created, such as a waitlist request or invitation. “Renoflow,” “we,” and “us” refer to the operator of the Renoflow service.
1. Information we collect
- Waitlist and invitation information. Before you have an account, we may collect your email address, referral source, requested role, waitlist status, invitation status, and related timestamps. If you save a pre-account project plan, we also store the plan you supplied and make that handoff available for up to 30 days.
- Account and profile information. This includes your name, email address, account role, organization or business details, preferences, and authentication records.
- Renovation and project content. We process the messages, emails, texts, voice recordings or transcripts, documents, receipts, invoices, photos, addresses, budgets, schedules, approvals, contacts, and other project details that you or an authorized project participant provide. This content can contain information about homeowners, contractors, clients, vendors, and other people.
- Connected-account information. If you connect Google, we store the account email and protected authorization credentials and access the Gmail messages or Google Calendar events you authorize. If you connect QuickBooks, we store protected authorization credentials and the company identifier needed to synchronize the accounting data you request.
- Communications information. When messaging or calling features are enabled, we process sender and recipient addresses or phone numbers, message content, delivery information, call metadata, and any recording or transcript disclosed in the call flow. WhatsApp information is processed only if that channel is enabled.
- Billing and accounting information. Stripe processes payment-card, billing-address, tax, and transaction information. Renoflow stores provider customer and subscription identifiers, plan and payment status, and transaction records; we do not store full payment-card numbers. QuickBooks data is processed only when an account is connected and a requested synchronization runs.
- Device, security, and reliability information. We and our infrastructure providers may process IP address, browser and device details, route and request metadata, timestamps, authentication and rate-limit events, error messages, stack traces, and performance data. Error reports can include limited application context, so we restrict access to them.
Please provide only content you are authorized to share with Renoflow. If you submit information about another person, you are responsible for having an appropriate basis to do so and for giving any notice required by law.
2. How we use information
- Provide, personalize, support, and secure the Renoflow service.
- Turn submitted content into project records, drafts, budgets, schedules, approvals, reminders, and other requested work product.
- Connect and synchronize the third-party services you choose to use.
- Deliver service messages, invitations, receipts, alerts, and communications you request or authorize.
- Process subscriptions, administer the pilot, troubleshoot incidents, prevent abuse, and improve reliability and usability.
- Comply with applicable law and protect users, Renoflow, and others.
We do not sell personal information or use project content for targeted advertising.
3. AI processing and connected Google data
Renoflow uses configured AI services, currently Google Gemini and Anthropic Claude, to transcribe, classify, extract, summarize, and draft from the content needed for a requested feature. The relevant prompt, attachment text, audio, project context, and model output may be processed by the selected provider. Provider handling is governed by Renoflow’s configuration and the provider terms that apply to our account; we do not promise a provider retention or training setting that is not stated here. Automated output can be incomplete or wrong and should be reviewed before it is used for a financial, contractual, safety, or construction decision.
Gmail access is read-only and is used to find and process renovation-related messages you ask Renoflow to organize. Google Calendar access is read-only and is used to synchronize authorized event details. Renoflow does not write to Gmail or Google Calendar with these connections. Our use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. Google-derived content is shared with a configured AI processor only as needed to provide the extraction or organization feature you requested.
4. Providers and connected services
We disclose information to vendors acting for Renoflow only as needed to provide, secure, and support the service, and to connected services when you direct us to do so. The services currently used or built into the pilot include:
- Supabase — authentication, database, and file storage.
- Vercel — website and application hosting, request processing, and deployment infrastructure.
- Render — hosting for the shared Renoflow operations worker if it is deployed. That worker monitors platform health and limited operational events; it is not a personal agent for each customer and does not coordinate the customer-facing AI agents. It is not currently deployed for the monitored pilot, so Render is not currently processing pilot data through that worker.
- Resend — invitations, receipts, digests, and other outbound email, including recipient, content, attachment, and delivery metadata needed to send and troubleshoot the email.
- Google Gemini and Anthropic Claude — AI processing described above. Gemini may also process audio submitted for transcription.
- Twilio — SMS and voice communications, and WhatsApp if that channel is enabled. Twilio may process phone numbers, message or call content, recordings, transcripts, and delivery or call metadata.
- Stripe — checkout, recurring subscription billing, taxes, receipts, payment recovery, and the customer billing portal.
- Google — Gmail, Google Calendar, authentication, and Google Places functionality when you connect or use those features.
- Intuit QuickBooks — accounting synchronization that you connect and initiate, such as customers, invoices, and related accounting records.
- Sentry — application error, stack-trace, and limited performance telemetry used to diagnose failures.
- Upstash — shared rate limiting. Renoflow sends a one-way-hashed rate-limit key rather than the raw account identifier or IP address used to derive it.
- Axiom — web-performance telemetry only if that optional integration is configured. It is not currently configured for the monitored pilot.
Some providers, especially payment, telecommunications, Google, and Intuit, may also process information under their own terms for account security, fraud prevention, legal compliance, or services you hold directly with them. Disconnecting a service stops new Renoflow access but does not delete information held in your own account with that provider.
We may also disclose information to another project participant or message recipient when you direct the service to share or send it; to authorized Renoflow operators who need it for support, security, or incident response; in a business transaction such as a financing or acquisition subject to appropriate safeguards; or when reasonably necessary to comply with law or protect rights and safety.
5. Cookies, local storage, and analytics
Renoflow uses essential browser storage for sign-in sessions, security, OAuth connection state, preferences, drafts, and limited cached project data. Blocking that storage can prevent the application from working. We do not currently use advertising cookies.
Session-replay analytics are disabled for the monitored pilot. The application does not initialize PostHog even if a PostHog key is added to its environment. We will update this policy and add appropriate notice, consent, and masking controls before enabling session replay or comparable behavioral capture. Sentry error monitoring and optional aggregate web performance telemetry are not used for advertising.
6. Retention, account deletion, and provider records
We keep account and project information while it is needed to provide the service and for a limited period afterward for support, security, dispute handling, and legal obligations. The exact period depends on the type of record and why it is held.
- Pre-account records are separate. A saved prospect plan stops being available through its handoff after 30 days, and an invitation link can expire sooner, but waitlist, invitation, and delivery history do not necessarily disappear when the link expires. Because there may be no account to delete, email us if you want those records removed.
- Canceling a paid subscription does not delete an account. Use the account deletion process or contact us separately for deletion. Disconnecting Google or QuickBooks also does not delete the Renoflow account.
- Deletion is a verified process, not an instant promise. We may need to confirm identity, prevent new writes, finish or reconcile work already sent to a provider, and verify cleanup before marking a request complete. If provider cleanup cannot be confirmed, we may keep the request open for manual review rather than report an unverified deletion as complete.
- Some records have bounded exceptions. Payment, invoice, tax, refund, chargeback, fraud, security, audit, and legal-hold records may be retained when reasonably needed or required. We may retain limited non-content proofs or one-way fingerprints needed to prevent a deleted provider artifact from being reattached or reprocessed.
- Providers and backups have their own timelines. Deleted information may remain temporarily in protected backups, delivery queues, fraud systems, or a provider’s legally required records under its terms and configuration. Renoflow cannot delete information in a Google, QuickBooks, Stripe, Twilio, or other account that you control directly.
7. Security
Renoflow uses encrypted network connections, account-scoped database controls, restricted service credentials, and operational monitoring. Connected-account credentials are encrypted before database storage. Authorized operators and service processes can use elevated access only where needed to operate, support, secure, or delete data. No method of storage or transmission is completely secure, so we cannot guarantee absolute security.
8. Your choices and privacy requests
Depending on where you live, you may have rights to request access, correction, deletion, restriction, objection, or portability, and to appeal or complain to a regulator. You can disconnect supported external accounts in Renoflow or at the provider, manage billing separately through Stripe, and request an account-data copy or deletion. We may verify your identity and may decline or limit a request where permitted by law. These rights are not waived by this policy.
9. Children
Renoflow is a business and renovation-management service and is not directed to children or anyone under 18. Do not create an account if you are under 18. Adults should not knowingly submit a child’s information unless they are authorized and the use is lawful.
10. Processing locations
Renoflow and its providers may process information in the United States and other countries where they operate. Privacy protections may differ by location. Where applicable law requires a transfer safeguard, the relevant provider or Renoflow will use an available lawful mechanism.
11. Changes
We may update this policy as the pilot and service change. We will post the new date here and provide additional notice when required by law or when a change materially affects how we use personal information.
12. Contact
Privacy questions or requests: privacy@renoflow.app. Please do not send sensitive project documents in an initial email. See also our Terms of Service.