Your home is personal.
App privacy notice · 12 September 2026
Who looks after your information
Housetold is the service described in this notice. Legal operator and data controller: Karl Harris, trading as Housetold. Business postal address: 7 Whimbel Drive, Cannock, WS11 9BB. Email [email protected] for account, support or privacy requests. Property owners are separately responsible for the information they choose to add and share, including their use of tenant records outside this app.
Information used by the app
We store account and sign-in details, property memberships and addresses, room layouts and scans, selected photos and documents, equipment and contractor details, repairs, utility and meter records, tenancy details and manually recorded finances, messages, safety reports, notification preferences and tokens, and subscription status. Other authorised members may add records that concern you. Processing requests and their results are saved with status and usage information.
Why we use it
We use account details and saved records to provide the service you request under our agreement with you. Necessary security and limited operational diagnostics support our legitimate interests in protecting accounts and keeping the service reliable. We also process information where required by law. Optional notifications and optional information sharing use your choices and, where required, consent. Only add information you are entitled to use and share.
Who can see it
Access depends on your role, membership dates and each record's sharing settings. Direct messages are limited to their participants. Reporting a message copies selected evidence into a private safety report. The authorised operator can access necessary information to handle support, privacy or safety concerns and investigate failures. Blocking messages does not remove access to shared property records. Exported copies remain under their recipients' control, and an offline device cannot learn about an access change immediately.
Information sharing for suggestions
With your permission, requested assistance sends relevant home details, room geometry, questions and selected photos or documents to OpenAI. This supports layout reading, item identification, illustrations, document reading, drafting a repair from a message you choose, and property answers. Relevant context can include contractor contact details and repair notes. A message is sent only when you ask for that one message to be read, and only its text and this home's room names are sent — not the sender's name or the rest of the conversation. A selected document is sent in full, including any personal information it contains; asking for dates does not remove other content before transmission. Original uploads remain separate from generated pictures. Check suggestions against your originals.
Changing sharing choices
Permission for suggestions and document reading is remembered for your account on this device. Account → Information sharing makes the app ask again before the next request on this device. It does not recall previous inputs or delete saved results. You can keep organising your records manually. Local-service address research has a separate choice in Property details.
Finding local services
For UK local services, your postcode is checked with Postcodes.io and government council listings. To find a likely water supplier, our server sends the latitude and longitude derived from that postcode to Esri's ArcGIS service to check published supply boundaries. This map point represents the postcode area and may not be the exact property. This lookup does not use your phone's GPS or track your movements. Your saved address and postcode remain linked to your home and account. Provider processing and log-retention practices apply; we do not promise that every lookup is immediately erased. This home's postcode is sent to PropertyData to read what public registers hold about it — the council tax band and what that band costs, the energy certificate, any licence on the national HMO register, and the recorded floor area. A floor area is also sent there to estimate what rebuilding this home would cost. The postcode and property characteristics sent for a lookup can relate to your home. Results are dated and hidden from normal app access after sixty days unless refreshed; hiding a result does not by itself erase the underlying stored row. This happens as part of keeping the record and is not optional; leave the postcode out and none of it is asked. Separately, when background research is enabled in Local services, your address is sent to OpenAI web search to find bin days and local suppliers, and that one you can turn off there. You can turn this off there to stop future research. Results and saved bin dates are shared with the home's members; reminder preferences are private to your account. Opening a council, supplier or other source takes you to that service and its privacy practices. Research may not find your exact bin day or supplier.
Providers and processing locations
Supabase provides sign-in, database and private file storage; the primary database is in Ireland. OpenAI processes requested assistance and enabled address research. Where available in your build, Google sign-in uses Google to verify your chosen account and Supabase to create your app session. Store purchases use Apple on iOS or Google Play on Android, with RevenueCat handling subscription status; we do not receive full payment-card details from store purchases. Optional push notifications use Expo with Apple on iOS or Google Firebase Cloud Messaging on Android. These provider arrangements do not mean that every feature is available in every private test build. Sentry receives crash and error reports so we can fix faults; reports can include device and operating-system details, app version, installation identifiers, an account identifier when signed in, network-derived IP and approximate location information, error details and a trail of screen names before a failure. Default collection of names and email addresses is disabled, but the account identifier links a report to your account. Screenshots, view hierarchies and performance tracing are disabled in our app configuration. Error messages and diagnostic context may contain information about a failed operation. Sentry processes reports in our European-region project, subject to its provider terms. Cloudflare hosts our website and support pages. Providers can process information internationally; the database location is not a promise that all processing stays in Ireland or the UK. Provider security, retention and applicable transfer terms also apply.
App performance information
Expo Observe measures app startup and screen-navigation timings, with device, operating-system and app-version information and an installation identifier. We filter identifying route parameters such as account, home, document and conversation references from these measurements. This helps us find slow screens and improve reliability. This operational reporting is separate from optional website analytics and from your choice to request assistance with home records.
Optional identity checks
You can choose to confirm your identity, or respond to an owner's request to do so, through Didit. This involves photographing an identity document and taking a selfie in Didit's verification page. Didit processes the document, photographs and biometric face comparison, together with technical and fraud-prevention information such as IP address, browser, device and inferred location. Housetold receives a verification result and keeps the name on the document, date of birth, document type, issuing country, expiry date, face-match outcome, check date and provider reference. The verification photographs are not copied into Housetold's property storage. An owner who requested a check sees its progress and, after completion, the name, document type, country and date; they do not see your birth date, document expiry, face-match detail or photographs. People invited to an owner's home can see whether and when that owner completed a check. Housetold does not require a check to use the app, and does not make tenancy eligibility decisions. This is not a Right to Rent check. Didit's verification notice explains its processing, consent, international transfers and rights. Contact us about your check or to request its removal.
Identity-check retention
Housetold's current maximum retention for an account's own check is 3,650 days from creation, and 730 days for a check requested for a tenancy. Removing the relevant account or tenancy, withdrawing a request, or an accepted deletion request can remove a record sooner. Expired records are hidden and removed by a scheduled process, which queues an instruction to erase the associated Didit session. Provider erasure is retried if it fails; removing our record is not proof that the provider has already completed erasure. Didit's separate retention, legal obligations and privacy-erasure terms apply to its records. Contact us if you need removal before the displayed retention date.
Apple account changes
Apple sends us notifications when sign-in permission, email forwarding or an Apple Account changes. We record the relevant account state and review problems; an Apple notice does not automatically delete your Housetold records. Where Apple sign-in confirmation is available in your build, we use a one-use confirmation challenge to check the Apple Account already linked to you. Challenges expire after five minutes; successful confirmation removes its challenge, and expired challenge records are removed on a later confirmation request or account deletion. This handling does not retain the original notifications or raw Apple confirmation tokens. Account-linked notification state and confirmation challenges are removed when your account is deleted. Minimal unlinked fingerprints of notification references and payloads may remain to recognise repeats and prevent an old notification being applied again. Provider logging and retention practices apply separately.
Keeping records
Records remain while the relevant account or home is retained and the records serve their property-history purpose, subject to applicable deletion and privacy rights. Archiving a home keeps its records. Ending a tenancy does not automatically erase shared property history. Our operational logs use request references, operation names, outcomes and timings; provider connection and security logs have separate retention. Backups and provider records do not disappear immediately when an app record is removed. Contact us about information that no longer needs to be kept.
Deleting an account
Delete your account from Account, then Delete my account. Email [email protected] if you cannot sign in. The deletion process removes your login, owned homes and their files, private messages and personal contact details. It also removes your contributions and uploaded originals from another person's home while preserving other people's independently authored records and files. Where older or mixed records do not establish who contributed each part, the request is held for review before completion so your information can be removed without deleting another person's work. Account access is blocked once the request is accepted; a request under review is not complete. Completed deletion receipts and minimal account/home references expire after 30 days; this is not a 30-day rule for all backups, logs, cached copies or provider records. Account deletion does not cancel an Apple or Google Play subscription; cancel through the store where you purchased it.
Your choices and rights
Account lets you change your name, control preferences and export accessible home records as JSON. Save original photos, scans and documents separately. Email us to request access, correction, deletion, restriction, an objection or a portable copy. Rights depend on applicable law and may have exceptions; we may need to verify your identity. UK users can complain to the Information Commissioner's Office; others can contact their local privacy regulator. This notice's date identifies its version.
Provider information and contact
- Contact support
- Help & support
- Supabase data-processing terms
- OpenAI data controls
- RevenueCat privacy information
- Expo notification privacy
- Apple privacy information
- Google privacy information
- Firebase privacy information
- Cloudflare privacy information
- Esri privacy information
- Didit verification privacy notice
- Contact the ICO