Household Index

Privacy

Draft of 27 September 2026

Draft, not legal advice

This page is a working draft that has not yet been reviewed by a lawyer, and its wording may change. It describes how Household Index works today.

Household Index looks at photos of your home, so this page tries to say plainly what we keep, where it lives, who can see it and how to remove it. On this page, “we” means Household Index. If anything here is unclear, write to gflorence3@gmail.com.

What we collect

  • Your account. Your name, email address and password when you sign up. Passwords are stored by our sign-in provider, Supabase, only in scrambled (hashed) form.
  • Photos of your home. The room photos and inspiration photos you upload (JPEG, PNG or WebP, up to seven per room).
  • What you tell us about the room. The room’s name, your answers about what you want from it (for example goals, taste and budget) and any questions or requests you type.
  • What we make for you. Room reports, new pictures of your room, plans, shopping suggestions and the Yes or No choices you make on them.
  • Your email from the taste quiz, once the quiz asks for it, and only if you choose to give it (see below).
  • Membership and payment records, if you become a member: your plan, when you paid, what you were charged, your renders, and the renewal wording you agreed to and when (see “Payments”).
  • Basic usage counts, such as a product link being opened (see “Cookies and analytics”).

Photo files can carry hidden details saved by your camera, such as the location where the photo was taken, the device used and sometimes the owner’s name. When an upload finishes, we remove these details (EXIF, XMP, IPTC and text comments) by saving a fresh copy of the picture, and only that copy is kept. We keep the picture itself, its orientation and its colour profile. One exception: your browser sends the original file to our private storage first, and we swap in the cleaned copy when the upload completes. If an upload starts but never completes, that original file, with its hidden details, stays in private storage until it is deleted. That file is not attached to any room, and it is never shown to anyone or sent to an AI provider. No automatic clean-up of these files runs yet. We remove them when we delete your account, and you can ask us to remove them sooner.

Photos of your home

Where they are stored. Your photos, and the pictures we make from them, are kept in private file storage run by Supabase, in the United States. The rest of your room (report, plan, choices) is kept in a Supabase database. The website itself runs on Vercel.

Who can see them.

  • You, when signed in. Photos are private by default; the app shows them through links that expire after a short time.
  • Anyone you send a share link to, for the parts described under “Share links” below.
  • Our AI model providers, for the moment they need to analyse a photo or make a new picture (see below).
  • The small team that runs Household Index, only when needed to run the service, fix a problem or answer a request from you.

We do not sell your photos, make them public, or use them in our marketing without asking you first.

AI analysis. To read your room and make new pictures of it, we send your photos, your answers about the room and your requests to an AI model provider. Today that is Google (the Gemini API) and OpenAI; which one handles a step depends on how the service is set up. To find products similar to the pieces in your plan, we send a short text description of each piece and your budget to Google’s Gemini API with Google Search; your photos are not part of that search. These providers process the data under their terms for business API customers, which set how long they may keep it.

Safety checks. Before anything is made, saved or shown, we check what you type, the photos you upload and every new picture for content we don’t allow (listed in the Terms). These checks use our own rules and Google’s Gemini API. If a check can’t run, nothing is made or saved.

Please only upload photos of places you have the right to photograph, and avoid photos that show people, documents or anything you would not want stored.

Email from the taste quiz

The taste quiz asks for your email address before showing your taste report. We only collect it if you enter it and agree, and we store the address, your quiz result and a record that you agreed and when.

The box you tick says we may email you your taste report and occasional updates, and that you can unsubscribe at any time. That is all we use the address for. We will not sell it or give it to advertisers. We don’t send these emails yet; when we start, every update will include an unsubscribe link.

Unsubscribing. You can ask us to stop at any time at gflorence3@gmail.com, or to delete the address altogether.

Separately, our sign-in provider, Supabase, sends account emails you need, such as confirming your address or resetting your password.

Share links

You can make a view-only link to a room’s plan. Anyone who has the link can open it, without signing in. Links are long and random so they cannot be guessed, but they can be forwarded, so only send them to people you trust.

A share link shows the room’s name, the pictures we made for it with their report notes, and your Yes or No choices. It does not show your original photos, your answers about the room, your budget or your account details. The pictures we make are based on your room, though, so they show its layout and features. People with the link cannot change anything.

You can stop sharing at any time. The link stops working straight away, and sharing again makes a new link.

Keeping and deleting your data

We keep your rooms, photos and the pictures we made until you delete them or close your account.

How to delete. Deleting rooms and accounts from inside the app is not available yet. Until it is, email gflorence3@gmail.com from the address on your account and say which rooms, or the whole account, you want deleted. We will confirm and complete it within 30 days.

What deletion removes. For a room: its photos, the pictures we made, its report, plan and choices, and any share link, which stops working. For an account: all of your rooms as above, your account details and the product link clicks linked to it. Step counts for your rooms lose their link to the room and become anonymous totals.

What we keep. Copies may remain in our providers’ backups for up to 7 days before they are overwritten. We keep totals that cannot identify you (for example, how many reports were made in a week), and anything we are required to keep by law, such as records of payments and refunds, which Stripe and we keep for tax and accounting. An address given in the taste quiz is not deleted with your account unless you ask; we are happy to do both.

Cookies and analytics

We use only the cookies needed to keep you signed in. We do not use advertising cookies, ad trackers or third-party analytics scripts, and we do not sell or share your data for advertising.

To understand how the product is used, our own servers count a few events, such as a product link being opened. We also count how many people reach each step: a visit to the home page, a room photo being uploaded, a report being made, an email being given in the taste quiz and a share link being created. Each of these counts records only the step and the day. It holds no email address, IP address, browser details or cookie, and cannot follow you from one visit to the next. Counts for steps inside a room are tied to that room, and so to your account, until the room is deleted; home page visits and taste-quiz emails are never linked to you. Product link clicks are linked to your account when you are signed in, and so is a record of each free picture, which we use to keep free pictures within a daily limit. All of this is stored in our own database and is not shared with advertisers.

Some choices you make on a plan are also remembered in your browser’s local storage so the page looks the same when you come back. Clearing your browser data removes them.

To keep out automated sign-ups, sign-up, sign-in and requests for new pictures run a bot check from Vercel, our hosting provider. It looks at technical signals from your browser to tell a person from a bot; it does not use advertising cookies.

Some pages load fonts from Google Fonts, which means your browser contacts Google and shares your IP address with it. Product pictures in shopping suggestions load directly from the retailer’s site, which works the same way. Our hosting provider, Vercel, also receives standard request details such as your IP address and browser type to deliver the site and keep it secure.

Payments

Memberships are paid through Stripe. When you pay, you enter your card details on Stripe’s checkout page, not ours; we never see or store your full card number. Stripe handles your payment under its own privacy policy and sets its own cookies on its pages.

We keep what we need to run your membership: your Stripe customer and subscription references, your plan, payment and renewal dates, amounts, any promo code used, your renders, any refund, and the renewal wording you agreed to with the time you agreed. The Refund page explains refunds.

Your choices and rights

You can ask us for a copy of your data, to correct it, or to delete it, by writing to gflorence3@gmail.com. We answer these requests for everyone, wherever you live, and we won’t treat you differently for making one. We don’t sell your personal information, and we don’t share it for cross-context behavioural advertising (targeted ads based on your activity across other sites). Depending on where you live, you may have further rights, including the right to complain to your local data protection authority.

Children

Household Index is not meant for anyone under 18, and we do not knowingly collect their data.

Changes

We will update this page when our practices change and change the date at the top. If a change matters, we will let you know before it takes effect.

Contact

Household Index. Email gflorence3@gmail.com, or see the contact page.