Payment information
Stripe processes payments. We do not receive or store full payment-card numbers. Stripe maintains its own security and privacy program.
Website and database safeguards
- HTTPS protects supported browser traffic.
- Security headers restrict framing, content types, referrers, and unnecessary device permissions. Camera access is permitted only for the first-party issue form.
- Public form payloads are size-limited, allowlisted, normalized, and rate-limited.
- Raw network addresses are not stored for rate limiting. Temporary one-way hashes expire.
- Portal passwords are salted and hashed. Secure first-party session cookies are HTTP-only and expire automatically.
- Every issue and photo query checks the authenticated user's workspace on the server.
- Issue photos are limited by type, count, and size, processed through an image decoder, resized, re-encoded to WebP, stripped of ordinary image metadata, and stored in a private bucket.
- Private images are served only through an authenticated, no-store route.
- Owner authorization uses an exact server-side email allowlist. Client-side visibility is never treated as authorization.
- Administrative and portal responses use no-store caching.
Data minimization
The public form is for initial fit and support. The beta accepts limited tasks, assets, vendor records, issue symptoms, and non-sensitive property photos. Do not enter passwords, access or alarm codes, precise property addresses, identity documents, full financial details, medical information, information about minors, private itineraries, security plans, or emergency instructions. Do not photograph people, documents, keys, access controls, surveillance systems, family images, plates, or other identifying details.
AI and issue-photo boundaries
When AI triage is configured, the server sends only re-encoded, metadata-stripped photos that users confirm exclude sensitive content, plus limited issue context, to the designated model API with response storage disabled. Exact addresses are not included. The model cannot generate a dollar amount, approve a referral, or make the final human-review decision. A deterministic policy controls emergency handling and a versioned database rule controls any eligible planning band. Every non-emergency AI assessment remains preliminary until an authorized reviewer decides that exact evidence revision.
Each stored photo has a 30-day application access cutoff. After the cutoff, authenticated image routes and analysis reject it even if asynchronous physical deletion is still being retried. Requesting earlier deletion immediately makes the image inaccessible, increments the evidence revision, cancels pending review, and invalidates any open provider options before private-storage deletion is processed. The referral beta does not send issue photos or other customer data to providers.
Human-review and referral controls
Reviewer claims expire, decisions are recorded against an immutable assessment version, and an approved or overridden decision produces a versioned work-order summary. A provider request must reference that same assessment, review decision, work-order version, and photo-evidence revision. If evidence changes, provider matching and contact release are locked until the new revision is reviewed. These controls reduce stale-decision risk; they do not turn remote review into an inspection, diagnosis, quote, or guarantee.
Property review records
A separate Property Operations Review begins only after an agreement defines the minimum necessary records, approved participants, transfer method, retention, deletion, confidentiality, and incident contacts. The issue-photo workflow is not an approved channel for review records.
Responsible reports
Use the contact form to report a suspected vulnerability and select “General question.” Include the affected public URL and steps to reproduce, but no sensitive data. Do not access another person's data, disrupt service, perform destructive testing, or publicly disclose an unresolved issue.
No guarantee
No website, transmission, authentication, or storage method is completely secure. These practices reduce risk but do not guarantee that an incident will never occur. The beta must not be the only record for critical operations.