Privacy
Privacy Policy
Last updated August 27, 2026
House Manual is local-first, has no advertising tracking, and does not sell personal data.
Local-first home information
House Manual is a local-first home-care toolkit operated by Seth Imbrunone under the House Manual name. You can use the core app without an account. In that mode, the house details, reminders, emergency contacts, contractor notes, bills, planning records, chats, photos, and documents you add stay on that device unless you deliberately use an online feature.
Data collection
The app does not include advertising tracking, build advertising profiles, or sell personal data. You can choose to create an account for automatic shared-home sync and secure backup. House AI uses an online service to process requests, verify included access, manage usage, and return answers or useful home updates.
Optional account and home sync
If you choose Continue with Apple, Apple provides a stable account identifier and may provide your name and email address or Apple private relay address, depending on your Apple choices. House Manual stores the account profile, a protected Apple authorization credential, hashed session and device identifiers, a device label, app build, and recent account activity needed to keep you signed in and show connected devices. The rotating account credential on your iPhone is kept in the iOS Keychain and is not exposed to the web app.
Signing in alone does not upload, merge, or replace a home. You must first choose which home to connect. After that explicit connection, record changes sync automatically so authorized devices can stay current. Conflicting edits to the same record stop for your choice instead of replacing the whole home.
The synchronized home is sent over encrypted HTTPS and encrypted with AES-256-GCM before database storage. This is service-managed encryption, not end-to-end encryption; House Manual controls the service key needed to restore the home. It can include the home profile and address, equipment, maintenance and calendar records, bills and due schedules, contractor contacts, Binder record details, projects, service history, and approved Home Memory facts.
Utility account numbers, House AI chats, App Store purchase proof, diagnostics, and device notification settings are excluded from the synchronized home. Photos, PDFs, warranties, receipts, and other supported Binder files use the separate Secure Cloud Binder process described below.
House Manual keeps the current encrypted home and up to ten recent encrypted revisions. Account refresh sessions expire after 30 days. Short-lived sign-in challenges and hashed network or device abuse-control records expire within 24 hours. A hashed receipt for an Apple account-change notification is kept for 30 days to prevent delayed retries from affecting a recreated account. Expired and revoked records are removed by scheduled maintenance.
Shared homes and private records
Each adult joins with a separate Apple account. Household admins can invite or remove people and choose who is an admin. Shared house records and files are available to active members. A Binder item marked private, including its title, metadata, content, and existence, is available only to the account that owns it.
Removing a member or leaving a shared home ends that account's access and sessions. Shared records remain for the other members. Private Binder items owned by the departing account in that home are permanently removed and their encrypted objects are queued for deletion. Copies someone already exported, downloaded, or captured cannot be recalled.
Secure Cloud Binder
When Secure Cloud Binder is available and you add a supported photo or PDF to a connected home, House Manual validates the file, encrypts its contents on the device with AES-256-GCM, and sends only ciphertext to private object storage. The service stores the wrapped encryption key and the minimum metadata needed to identify, authorize, version, search, and recover the file, including its title, original filename, type, size, visibility, and integrity hashes. This is service-managed encryption, not end-to-end encryption.
Private files are limited to their owner. Shared files are available to active household members. A device may keep an encrypted offline copy protected by an account-and-home-specific key in the iOS Keychain. That cache and key are cleared when the managed home is erased or access ends.
Original photos may contain location or camera metadata added before House Manual receives them. Encrypted originals preserve their original bytes; generated thumbnails and previews remove that metadata. You can remove location details in Photos before uploading or delete the Binder item later.
Cloud Binder keeps immutable file versions so a homeowner can view and export the record that was actually saved. Deleting one Binder item starts a 30-day recovery period, after which its encrypted objects and wrapped keys are permanently purged. Completed transfer records and expired usage counters are removed after their operational retention period. Security audit events contain identifiers, event type, coarse byte count, result, and time, never file content or encryption keys, and are kept for no more than one year.
House AI processing
When you use House AI, the message you write and the relevant saved home details for that request are sent to House Manual's online service, operated by Seth Imbrunone, and to OpenAI to generate a response. Exact addresses and serial numbers stay off unless you choose to include them. Only a photo or document you actively attach or select for that request is sent; House AI does not read unrelated Binder files.
Normal House AI context is limited to useful home setup, equipment, maintenance, replacement timing, service-record headings, Binder titles, project names and status, and approved Home Memory. Bills, personal contractor contacts, financial details, utility accounts, project notes and budgets, and unrelated file contents stay on your device unless you deliberately attach or include them in that request.
House Manual sends OpenAI API requests with response storage turned off. OpenAI states that API inputs and outputs are not used to train its models by default. OpenAI may retain abuse-monitoring logs containing request content for up to 30 days, unless law requires longer retention.
Hosted House Manual does not store the full AI message, response, photo, or home-context payload as a server chat history. Chats stay private to the person on their device. House Manual stores bounded usage and reliability metadata such as an account or installation identifier, House AI access state, feature area, approximate request size, model/provider information, cost totals, result, and timestamps so the service can manage access, cost, abuse prevention, support, export, and deletion.
Durable home facts and records that House AI saves through the app's normal safety rules become part of the connected home and can be visible to household members. Content taken from an attached document is treated as untrusted evidence and is not automatically added to Home Memory merely because it appeared in the file.
Service providers may process House AI data only to deliver and protect the requested service. House Manual does not permit them to use it for advertising or to sell it.
Connected ChatGPT
You can optionally connect ChatGPT to one protected House Manual home. Before approval, House Manual shows the requesting service, selected home, and every requested permission. Read tools return only the bounded household-visible details needed for the request; they exclude the exact address, full serial numbers, private-member records, raw files, account numbers, and credentials.
If you approve reviewed saves, ChatGPT may prepare only the specific kinds of changes listed on the consent screen. A prepared change does not alter the home. House Manual resolves the saved record, checks membership and permission again, and shows the current and proposed values in a review card. The change is committed only when you deliberately choose Save. House Manual keeps bounded operation receipts and security audit metadata to prevent stale or repeated writes, support an eligible Undo, and investigate reliability; these records do not contain raw file contents, account credentials, or unrelated home data.
You can disconnect the integration from House Manual or ChatGPT. Expired, revoked, wrong-home, removed-member, or missing-scope requests are blocked. The integration never sends a message, places a call, books a professional, pays a bill, starts a purchase, or uploads a file automatically.
Ideas and product feedback
House Manual offers two different paths. Private feedback receives the message you write, an optional category and contact email, the House Manual build, app or website source, platform, broad screen-size band, and submission time. It is never published or placed on the Community Ideas board. A keyed one-way network token limits spam and accidental repeats; the network address is not stored in the feedback record, and the token is eligible to be cleared after 30 days.
Community Ideas require your House Manual account. The private submission record contains your internal user identifier, original title and description, publication agreement, app or website source, platform, build, and timestamps. It does not automatically attach your name, email, household, address, home records, House AI chats, photos, files, filenames, or device diagnostics. Your original words and account identifier are available only to authorized moderators.
If an idea is selected, a moderator may edit it or combine it with similar submissions to create a separate anonymous community idea. The website shows only that moderated title, description, truthful status, vote total, and publication dates. It never identifies the submitting or voting homeowners. Signed-in accounts may add one reversible vote per idea and may report a concern. Reports and moderation actions are retained only as needed to operate and protect the community.
Pending community submissions can be withdrawn from My submissions. Deleting the House Manual account deletes its private submissions, votes, reports, restrictions, and rate events. Independently moderated anonymous idea copy may remain because it no longer identifies an author; privacy support can review a removal request tied to the original receipt. Private feedback, optional contact information, and moderation records are kept only as long as reasonably needed to review product needs, protect the service, document product decisions, and meet legal obligations.
Trusted Pros and contractor drafts
For this release, your saved ZIP is matched on your device against House Manual's approved Trusted Pro service areas. Contractor request drafts, including any name, phone number, home details, or exact address you choose to add, stay on your device until you deliberately send or copy the prepared message.
If you send a draft by text, email, or another sharing service, the recipient and that service handle the information under their own privacy terms. House Manual does not send a contractor request automatically. Any future tracked-request service will require an updated disclosure and privacy review before it is enabled.
Reliability records
House Manual keeps a small first-party reliability history on this device. It can record a feature category, outcome, coarse timing range, closed error code, app build, bounded count, and random request identifier. It does not record the related photo, filename, OCR or document text, chat message, address, account number, serial number, signed purchase data, or saved house fact.
The device keeps no more than 200 of these records and removes records older than 30 days. They are included in operational-events.json in the homeowner export, expire automatically, and are removed when House Manual's local app data is cleared. You can also prepare a smaller diagnostic report from Support, review its complete text, and choose whether to share or save it. It is never sent automatically.
When an online service fails, House Manual may write the same content-free fields to a short-lived server log for reliability and abuse prevention. Request bodies, filenames, signed URLs, encryption keys, and provider error messages are not written to these logs. Server operational logs are retained for no more than 30 days and are not used for advertising or cross-app tracking.
House AI and previous purchases
House AI is included with House Manual in this release; it does not require a separate purchase or trial. If you bought House Manual Plus in an earlier release, Apple may still provide signed purchase status so House Manual can restore, support, and describe that previous purchase accurately. House Manual does not receive your payment-card details. Deleting House AI service records does not cancel a previous subscription or delete purchase history held by Apple under Apple's App Store privacy terms.
Export and deletion
The Your data screen creates a readable ZIP of the records available to the current person. When connected services can be verified, it also includes authorized Cloud Binder file versions and House AI service records. An unavailable or damaged cloud file is named in the export report rather than silently omitted.
Separate controls delete online House AI records, one recoverable Binder item, this iPhone copy, an Apple-linked House Manual account, or an entire shared home. Deleting House AI records does not delete the connected home or files. Erasing this iPhone clears its managed cache, private chats, offline files, reminders, and export cache but leaves the online home and other members unchanged.
Deleting an account removes that Apple-linked account, its sessions, private synchronized records, private Binder items, and account-linked House AI records. If other members remain, their shared home and shared files remain. If it is the only account in the home, the encrypted home and all Cloud Binder files are also removed. Deleting a shared home removes its shared and private records, all file versions, invitations, and member access while leaving each person's Apple-linked app account intact.
Deleting app data does not cancel a previous App Store subscription or remove Apple's purchase records. Any previous subscription billing is managed separately through Apple and is not required for House AI in this release. Privacy support remains available if an in-app control cannot verify access.
Backups and device behavior
Information kept only on one device can be affected by device settings, browser or webview storage behavior, app deletion, system cleanup, or device backup settings controlled by Apple. Before replacing a meaningful device-only home with an account home, House Manual requires a readable export.
Signing out switches back to the separate device-only home and clears the encrypted offline file cache, while the online account home remains protected for a later sign-in. Leaving, removal, account deletion, shared-home deletion, and erasing this iPhone have different effects described above and in the confirmation shown before each action.
Contact
For privacy or support questions, use the support page or email privacy support directly.