Short Version
Homi is operated by Boe Ventures AS in Norway. We collect your account information, property search data, and AI interaction data to provide our property search service. We use PostHog (EU-hosted) for analytics, and Vercel for hosting. We process your data using AI models from Anthropic and Google to generate property reviews and evaluations. We do not sell your personal data. You have full GDPR rights, including access, correction, deletion, and portability. For details, read on.
1. Who We Are
Homi is an AI-powered collaborative property search platform operated by:
- Company: Boe Ventures AS
- Country: Norway
- Role: Data controller under the General Data Protection Regulation (GDPR)
- Contact: privacy@homi.so
When we say "Homi", "we", "us", or "our" in this policy, we mean Boe Ventures AS.
2. What We Collect
2.1 Account Information
When you create an account, we collect the following depending on your chosen authentication method:
- Google OAuth: name, email address, profile picture URL, and Google account identifier
- Email/password: email address and a securely hashed password (we never store plaintext passwords)
- Magic link: email address
2.2 Property and Collection Data
Data you actively submit or generate through your use of the Service:
- Property listing URLs you submit for import and the extracted property data (address, price, features, images, descriptions)
- Collections you create, including their names, settings, evaluation prompts ("stories"), and pipeline stage configurations
- Reviews, comments, ratings, and reactions you leave on property listings
- Organization and team configurations, including membership and roles
- Images you upload (stored in Vercel Blob storage)
2.3 AI Interaction Data
When you use our AI-powered features, we collect:
- Text chat messages exchanged with Homi's AI assistant during collection interviews and property evaluation conversations
- Voice chat audio transcriptions (we process voice input to text; raw audio is not stored after transcription)
- Your evaluation prompt ("story") — a narrative of your search preferences, lifestyle, and priorities, built through AI conversations
- AI-generated property reviews, scores, and recommendations associated with your collections
2.4 Automatically Collected Data
When you access the Service, we automatically collect certain technical information:
- Device information: browser type and version, operating system, device type, screen resolution
- Usage information: pages visited, features used, click patterns, session duration, referral sources
- Network information: IP address (anonymized for analytics), approximate geolocation derived from IP
- Cookies and similar technologies: see Section 10 below
2.5 Browser Extension Data
If you use the Homi browser extension (available for Chrome), the following data is collected:
- Page URL and content: When you click "Add URL" or "Add Page Content" (or use the keyboard shortcut), the extension reads the current page URL and HTML content from the active tab. This data is sent to Homi servers for property data extraction.
- Local preferences: Your selected collection ID is stored in the browser's local storage so the extension remembers your preference between sessions. This data stays on your device.
- Authentication: The extension authenticates using your existing Homi session cookies — no additional credentials are collected or stored by the extension.
The browser extension does not:
- Collect or access your browsing history
- Run in the background or collect data when you are not actively using it
- Access data from websites other than the active tab when you trigger a capture
- Store any personal data outside of the browser's local storage and the Homi servers described in this policy
3. How We Use Your Data
We use the data we collect to:
- Provide the Service: create and manage your account, store your collections, import property listings, and enable collaboration with teams and organizations
- Power AI features: generate personalized property reviews and evaluations by sending your story and property data to AI models (Anthropic Claude, Google Gemini); conduct voice and text chat interviews; run automated portal scouting with AI agents
- Improve the Service: analyze usage patterns to improve user experience, fix bugs, and develop new features
- Communicate with you: send transactional emails (account verification, password resets, collection invitations), service announcements, and, with your consent, product updates
- Ensure security: detect and prevent fraud, abuse, and unauthorized access; monitor for security threats
- Comply with legal obligations: respond to lawful requests from authorities, enforce our Terms of Service, and protect our legal rights
4. Legal Basis for Processing (GDPR)
Under the General Data Protection Regulation, we process your personal data based on the following legal grounds:
| Processing Activity | Legal Basis | GDPR Article |
|---|
| Account creation and management | Performance of contract | Art. 6(1)(b) |
| Property data import and storage | Performance of contract | Art. 6(1)(b) |
| AI-powered reviews and evaluations | Performance of contract | Art. 6(1)(b) |
| Voice chat transcription and processing | Performance of contract | Art. 6(1)(b) |
| Collaboration features (teams, organizations) | Performance of contract | Art. 6(1)(b) |
| Analytics and service improvement | Legitimate interest | Art. 6(1)(f) |
| Error tracking and security monitoring | Legitimate interest | Art. 6(1)(f) |
| Marketing communications | Consent | Art. 6(1)(a) |
| Non-essential cookies and analytics | Consent | Art. 6(1)(a) |
| Legal compliance and fraud prevention | Legal obligation / Legitimate interest | Art. 6(1)(c) / Art. 6(1)(f) |
Where we rely on legitimate interest, we have conducted balancing tests to ensure our interests do not override your fundamental rights and freedoms. You may request details of these assessments by contacting us at privacy@homi.so.
5. Who We Share Your Data With
We do not sell your personal data. We have never sold personal data and have no plans to do so.
We share your data with the following categories of recipients:
- AI model providers: Anthropic (Claude) and Google (Gemini) receive property data and your evaluation story to generate AI-powered reviews. Chat messages and voice transcripts are sent to AI providers to generate responses. These providers process data under their data processing agreements with us.
- Infrastructure providers: Vercel (hosting, serverless functions, blob storage), Neon (PostgreSQL database hosting), and Ably (real-time features) process data as part of providing their infrastructure services.
- Web scraping services: ScrapFly and Zenrows receive property listing URLs to fetch page content for data extraction. They do not receive your personal data.
- Browser automation: Browserbase provides cloud browser infrastructure for AI agent portal scouting. Search criteria derived from your story may be used in automated browsing sessions.
- Analytics and monitoring: PostHog (EU-hosted analytics) and Vercel Analytics (performance) receive anonymized or pseudonymized usage data.
- Authentication providers: Google (when using Google OAuth) processes your authentication data.
- Your collaborators: When you share collections with organizations, teams, or individuals, those collaborators can access the collection data (property listings, reviews, comments) according to their assigned roles.
- Legal requirements: We may disclose data to law enforcement, regulatory authorities, or other parties when required by law, court order, or to protect our legal rights.
- Business transfers: In the event of a merger, acquisition, or sale of all or a portion of our assets, your data may be transferred as part of that transaction. We will notify you of any such change.
6. International Data Transfers
Boe Ventures AS is based in Norway, which is part of the European Economic Area (EEA). Your data is primarily stored and processed within the EEA.
Some of our service providers are located outside the EEA, primarily in the United States. When we transfer personal data outside the EEA, we ensure adequate protection through one or more of the following mechanisms:
- EU-U.S. Data Privacy Framework (DPF): where the recipient is certified under the DPF
- Standard Contractual Clauses (SCCs): EU Commission-approved contractual clauses that provide adequate data protection guarantees
- Adequacy decisions: where the European Commission has determined that the recipient country provides an adequate level of data protection
You may request a copy of the applicable transfer safeguards by contacting us at privacy@homi.so.
7. Data Retention
We retain your personal data only for as long as necessary to fulfill the purposes for which it was collected. Specific retention periods are:
| Data Type | Retention Period |
|---|
| Account information | Duration of account + 30 days after deletion |
| Property collections and listings | Duration of account + 30 days after deletion |
| AI chat messages and voice transcripts | Duration of account + 30 days after deletion |
| Evaluation stories | Duration of account + 30 days after deletion |
| Reviews and comments | Duration of account + 30 days after deletion |
| Uploaded images | Deleted when removed by user or on account deletion |
| Analytics data (PostHog) | 24 months from collection, then anonymized or deleted |
| Server logs | 30 days |
| Database backups | 30 days (rolling), then permanently deleted |
We may retain certain data for longer periods where required by law (e.g., for tax or accounting obligations) or to resolve disputes and enforce our agreements.
8. Your Privacy Rights
8.1 Rights for Everyone
Regardless of where you live, you have the right to:
- Access the personal data we hold about you
- Request correction of inaccurate data
- Request deletion of your account and associated data
- Object to direct marketing communications
- Withdraw consent where processing is based on consent, without affecting the lawfulness of processing before withdrawal
8.2 GDPR Rights (EEA Residents)
If you are located in the European Economic Area, you have the following additional rights under the GDPR:
| Right | Description | GDPR Article |
|---|
| Right of access | Obtain confirmation of whether we process your data and receive a copy | Art. 15 |
| Right to rectification | Correct inaccurate or incomplete personal data | Art. 16 |
| Right to erasure | Request deletion of your personal data ("right to be forgotten") | Art. 17 |
| Right to restriction | Restrict processing of your data in certain circumstances | Art. 18 |
| Right to data portability | Receive your data in a structured, machine-readable format and transfer it to another controller | Art. 20 |
| Right to object | Object to processing based on legitimate interests, including profiling | Art. 21 |
| Right regarding automated decisions | Not be subject to decisions based solely on automated processing that produce legal or similarly significant effects | Art. 22 |
To exercise any of these rights, contact us at privacy@homi.so. We will respond to your request within 30 days, as required by the GDPR. If we need additional time (up to 60 additional days for complex requests), we will inform you of the delay and the reasons.
You also have the right to lodge a complaint with your local data protection supervisory authority. In Norway, the supervisory authority is the Datatilsynet (Norwegian Data Protection Authority).
8.3 CCPA Rights (California Residents)
If you are a California resident, you have the following rights under the California Consumer Privacy Act (CCPA) and the California Privacy Rights Act (CPRA):
- Right to know: You may request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes, and the categories of third parties with whom we share it.
- Right to delete: You may request deletion of personal information we have collected, subject to certain exceptions.
- Right to correct: You may request correction of inaccurate personal information.
- Right to opt out of sale/sharing: We do not sell or share your personal information for cross-context behavioral advertising. No opt-out is required, but you may contact us to confirm this.
- Right to non-discrimination: We will not discriminate against you for exercising your CCPA rights.
To exercise your CCPA rights, contact us at privacy@homi.so. We will verify your identity before processing your request and respond within 45 days.
8.4 Response Times
- GDPR requests: 30 days, extendable by 60 days for complex requests
- CCPA requests: 45 days, extendable by an additional 45 days
- Account deletion: Processed within 30 days; backups purged within 30 additional days
9. Automated Decision-Making and AI Processing
Homi uses automated processing, including AI models, to generate property evaluations and scores. These evaluations are:
- Informational only — they do not produce legal effects or similarly significantly affect you
- Personalized — they are based on your evaluation story and preferences
- Not solely automated decisions — they are presented as suggestions alongside the original property data, and you make all final decisions
If you have concerns about how AI processes your data, you may contact us to request human review of any AI-generated output or to object to specific automated processing.
10. Cookies and Similar Technologies
We use the following categories of cookies:
10.1 Strictly Necessary Cookies
Required for the Service to function. These include session cookies for authentication, CSRF protection tokens, and consent preference cookies. These cookies cannot be disabled.
10.2 Analytics Cookies
Used to understand how visitors interact with the Service. We use PostHog (EU-hosted) and Vercel Analytics. These cookies are only set with your consent.
- PostHog: tracks page views, feature usage, and user journeys. Data is hosted in the EU. You can opt out through our consent mechanism.
- Vercel Analytics: measures page performance (load times, web vitals). Privacy-focused with no personally identifiable information collected.
10.3 Functional Cookies
Enable enhanced functionality such as remembering your preferences, display settings, and recently visited collections. These cookies are only set with your consent.
10.4 Managing Cookies
When you first visit Homi, you will be presented with a consent mechanism allowing you to accept or reject non-essential cookies. You can change your preferences at any time through the cookie settings in the Service footer. You may also configure your browser to block or delete cookies, though this may affect the functionality of the Service.
11. Data Security
We implement appropriate technical and organizational measures to protect your personal data, including:
- Encryption in transit: All data transmitted between your browser and our servers is encrypted using TLS (HTTPS)
- Encryption at rest: Database data is encrypted at rest using AES-256 encryption provided by our database host (Neon)
- Access controls: Role-based access controls limit who can access data within our systems; employees access production data only when necessary for support or debugging
- Authentication security: Passwords are hashed using industry-standard algorithms; OAuth tokens are securely managed
- Infrastructure security: Our hosting provider (Vercel) maintains SOC 2 Type II certification and implements comprehensive security controls
- Monitoring: We use Vercel's built-in error tracking and monitoring to detect and respond to potential threats
While we strive to protect your data, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security but are committed to promptly addressing any security incidents.
12. Children's Privacy
The Service is not intended for anyone under the age of 18. We do not knowingly collect personal data from individuals under 18 years of age. If we become aware that we have collected personal data from a person under 18, we will take steps to delete that data as soon as possible. If you believe a child under 18 has provided us with personal data, please contact us at privacy@homi.so.
13. Third-Party Links
The Service may contain links to third-party websites, including property listing portals (e.g., Finn.no, Zillow, Rightmove, Hemnet, Funda). We are not responsible for the privacy practices or content of these third-party sites. We encourage you to review the privacy policies of any third-party sites you visit through links on our Service.
14. Data Breach Procedures
In the event of a personal data breach that is likely to result in a risk to your rights and freedoms, we will:
- Notify the supervisory authority: Report the breach to the Datatilsynet (Norwegian Data Protection Authority) within 72 hours of becoming aware of it, as required by GDPR Art. 33
- Notify affected individuals: If the breach is likely to result in a high risk to your rights and freedoms, we will notify you without undue delay, as required by GDPR Art. 34
- Document and remediate: We will document the breach, its effects, and the remedial actions taken, and implement measures to prevent recurrence
15. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technology, legal requirements, or other factors. For material changes, we will:
- Post the updated policy on this page with a revised "Last updated" date
- Notify you by email or through a prominent notice in the Service at least 30 days before the changes take effect
- Where required by law, obtain your consent to the updated policy
We encourage you to review this policy periodically. Your continued use of the Service after the effective date of any changes constitutes your acceptance of the updated policy.
16. Contact Us
If you have questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us:
If you are not satisfied with our response, you have the right to lodge a complaint with a supervisory authority. In Norway, the supervisory authority is:
You may also refer to our Terms of Service for additional information about how we operate the Service.