Legal
Privacy policy
Effective September 1, 2026 · Version 1.1
LLastMile, LLC, a Delaware limited liability company ("we", "us") operates RenoVisions. This policy explains what personal information the service handles, why, who else sees it, how long we keep it, and what you can ask us to do.
Every factual statement here was written against the running system and is evidenced in `data-inventory.md`.
In short
- We handle photographs of homes and their street addresses. That is the sensitive part, and most of this policy is about it.
- Location metadata is removed from every photograph on upload. We rewrite the image bytes and discard EXIF and GPS before the image is usable.
- Photographs are stored privately. Nothing is publicly readable. Every view is a short-lived signed URL issued after a permission check.
- Photographs and descriptions are sent to an AI provider to produce a visualization. That is the whole product; it cannot work otherwise.
- We do not use your photographs, your conversations, or your generated images to train AI models, and we do not sell or share personal information for advertising.
- We never see your card number. Payment is handled by Stripe.
- Opening a private link needs no account. If you opened one, we hold a pseudonymous session record about that link — not your name or your email — unless you chose to send a contact request. A homeowner who buys a pack has an account like an agent's, described in section 2.1.
- A private link is a key: whoever holds the URL can open the page. The agent who sent it controls who has it and can revoke it at any time.
1. Who this policy is for, and who controls the data
Three groups use RenoVisions, and their relationship to us differs.
Agents are real-estate professionals who subscribe to the service, and homeowners who buy a pack use the same accounts and the same controls for their own home. An account's organization decides which properties, addresses, photographs, and notes enter the service. For that information, the organization is the controller and we act as its processor — we handle it on the organization's instructions to provide the service. If you are a homeowner with a question about why a particular property or photograph is in the system, the agent who put it there is the right first contact, though you can always reach us.
Recipients of a private link — usually a homeowner shown a property by an agent — need no account. We hold very little about them, described in section 2.5.
Waitlist applicants for products that are not yet open — contractors and homeowners — submit a form. For that information, and for our own account, billing, support, security, and analytics data, we are the controller.
2. What we collect
2.1 Account information (agents and pack buyers)
Your email address, an identifier from our authentication provider, your name where you gave it, your organization's name, your role in it, and timestamps of when your account was created and last used.
We never see or store your password. Sign-in is handled by Google Identity Platform; we receive only a verified token.
Where we issue an invitation — for example to add a colleague to an existing organization — we keep the invitation record: the email address invited, a hashed form of the invitation token, when it expires, whether it was redeemed, and any note the operator attached.
2.2 Billing information
When you subscribe or buy a pack, our payment processor Stripe collects and holds your card details and your billing address in their own hosted checkout. We never see or store your card number, and we do not store your billing address either.
What we keep is deliberately minimal. For a subscription: a Stripe customer identifier, a subscription identifier, the subscription's status in Stripe's own vocabulary, whether an introductory promotion is running, and when the current period ends. For a pack: a record of each purchase with the number of visualizations it granted, the amount paid, and Stripe's identifiers for the checkout, the payment, the price, and the customer — kept so a later price change cannot alter what you already bought, and so a refund can find the purchase it refunds. No card data and no invoices — those live in Stripe, and Stripe issues your receipts and hosts the page where you manage the card on file.
2.3 Waitlist information
If you join the contractor waitlist: your name, email, company, primary service area, the trades you listed, whether you consented to be contacted, and any note.
If you join the homeowner waitlist: your name, email, optionally a market, and whether you consented to be contacted. This is deliberately narrower — the row exists to send one message when the homeowner seat opens.
2.4 Property information (entered by agents)
Property label, street address, city, state or region, postal code, country, and free-text notes. Project titles, renovation goals, and the renovation categories selected.
A street address identifies a specific home and, indirectly, the people who live there. Free-text notes and goals can contain anything the agent typed. Agents should not enter more about a household than the visualization needs, and the terms of use require that they have the right to enter what they do.
2.5 Homeowner information
If you opened a private link, we create a pseudonymous session: a hashed form of the link token, a status, an expiry, and first-seen and last-seen timestamps. It does not contain your name, your email address, or your IP address.
If you choose to send a contact request to the agent, we store what you typed: your name, your email address, optionally your phone number and a message, the concept you selected if you selected one, and a record of your explicit consent to be contacted. Sending a contact request is always your choice; nothing else on the page requires it.
2.6 Photographs and generated images
The photographs uploaded to visualize a property, and the images the AI produces from them. For each we keep the file type, size, original filename, and internal storage location.
On upload, we rewrite every image and discard its embedded metadata, including EXIF and GPS coordinates. An image is not readable through the service until that has happened. This is enforced in code, not by policy: the read path requires the stripped flag to be set.
2.7 Assistant conversations
If you use the AI assistant to describe a renovation, we store the conversation — every message, and the structured description of the renovation it proposed. This is durable and can contain personal detail about a home, so it is subject to the same access controls and deletion as everything else attached to the property.
Dictation is the browser's, not ours. Where the composer offers a dictation button, it uses the speech recognizer built into your browser. On Safari and Chrome that recognizer streams your audio to the browser vendor's service to transcribe it. We never receive the audio — only the text it produces, once you send it. Dictation starts only when you press the button and stops on the next press or on send.
2.8 Technical and operational information
- Records of emails we send (recipient, subject, template, delivery status) so we can tell whether a message actually arrived.
- An audit log of security-relevant actions: what happened, to which record, by which account.
- Rate-limiting counters on public pages. These are keyed by a salted cryptographic digest of the network address, not the address itself. The salt exists precisely so this table cannot be read back as a record of which address opened which private link.
- Server logs for security and debugging. We do not log share-link tokens, credentials, or the text of a generated prompt.
2.9 Analytics
Where enabled, we use PostHog to understand which pages are used and whether the product's main steps get completed. Its configuration is deliberately narrow:
- Session recording is off. We never record your screen.
- Autocapture is off. We do not collect every click and keystroke.
- Page views are sent manually so that private link tokens are removed first. A path of
/s/<token>is transmitted as/s/:share_token. The token itself never leaves your browser. - A short, fixed list of named events, each recording that one step happened and a category or two about it. None of them carries anything you typed, an address, a photograph, an email address, or a link token. The complete list:
| Event | Recorded when | What it carries |
|---|---|---|
packages_cta | You press a button on the packages page | Which package: homeowner, agent, or contractor |
checkout_bound | A purchase completes and is attached to your account | Your account type, and whether it was a repeat purchase |
property_created | Your first photo becomes a property | Whether you are using the homeowner pack or the agent product |
concept_generated | A visualization is generated | The same, and whether it started from the latest concept, an earlier one, or the original photo |
compare_scrubbed | You move the before/after slider, counted at most once per concept per visit | Whether you are using the homeowner pack or the agent product |
generation_cap_hit | A homeowner pack runs out and the top-up offer is shown | The same |
client_share_created | You create a private link | The same, and whether the link is the limited kind. The link itself is never sent. |
generated_download | You save a generated image as a file | The same |
When a purchase completes, we also tell PostHog which account the browser belongs to, using only the random identifier our own database assigned to the account and the account type. That identifier means nothing outside our database. We never send your email address or your name to PostHog, and nothing in these events identifies you on its own.
Every one of these is sent from your browser and only after you have consented; there is no server-side analytics that could bypass the banner. PostHog sets a cookie and stores an identifier in your browser, and it does not load at all until you consent. Section 8 covers cookies and your choices. Analytics is disabled entirely when it is not configured for an environment.
2.10 What we do not collect
No card numbers — those go to Stripe and never reach us. No government identifiers. No biometric data. No health data. No precise device location. No advertising or cross-site tracking identifiers, and no third-party advertising pixels.
3. Why we use it, and our legal bases
| Purpose | Information used | Basis |
|---|---|---|
| Providing the service — creating properties, generating visualizations, sharing links | Account, property, photographs, conversations | Performance of a contract; processing on the organization's instructions |
| Taking payment and managing your subscription or pack | Billing information | Performance of a contract |
| Authenticating you and protecting accounts | Account, audit log | Contract; legitimate interest in security |
| Preventing abuse and controlling cost | Rate-limit counters, audit log | Legitimate interest in protecting the service |
| Sending transactional email | Email address, delivery records | Contract |
| Contacting waitlist applicants who consented | Waitlist information | Consent |
| Passing a homeowner's contact request to the agent | Contact request | Consent — you chose to send it |
| Understanding product usage | Analytics | Consent |
| Meeting legal obligations and resolving disputes | As required | Legal obligation; legitimate interest |
We do not use your photographs, property information, or assistant conversations to train, fine-tune, or improve any AI model — ours or a provider's.
4. Who else sees it
We do not sell personal information, and we do not share it for cross-context behavioural advertising. We share only with service providers who process it on our behalf under contract:
| Provider | What it handles | Where |
|---|---|---|
| Google Cloud Platform | Application hosting, database, private file storage, background job queue, authentication | United States |
| OpenAI | Generates the visualization from the photograph and description; powers the AI assistant | United States |
| Stripe | Subscription and pack payments, and receipts | United States |
| Resend | Sends transactional email | United States |
| PostHog | Product analytics, where enabled and consented to | United States |
About the AI provider. To make a visualization, the photograph and the description are sent to OpenAI. This is inherent to the product. Under our agreement with them, that content is used only to return the result and is not used to train their models. Requests to the AI provider are made only by our backend — never from your browser — by the private worker that generates images and by the service that powers the assistant while an agent is signed in. Provider credentials are held server-side in a managed secret store and are never present in any client.
We may also disclose information when legally required, to enforce our terms, to protect against fraud or harm to someone's safety, or to a successor in a merger or acquisition — in which case this policy continues to apply until you are given notice of a change.
All processing takes place in the United States. The service is intended for use in the United States, and we make no representation that it is appropriate elsewhere.
5. How long we keep it
We keep information for as long as we need it to provide the service, and then delete it. Deleting a property deletes the projects, photographs, generated images, conversations, briefs, share links, and homeowner sessions attached to it — that cascade is enforced by the database, not by application code remembering to do it. Closing your account and asking us to delete your content removes it on the same basis.
We may keep information longer where we must to comply with law, resolve a dispute, or enforce our terms.
If you want to know how long we hold a particular category, ask us at jon@renovisions.ai and we will tell you.
6. How we protect it
- Photographs are never public. Storage is private and every view is a short-lived signed URL — ten minutes for viewing, fifteen for uploading — issued only after we check that the requester is entitled to see it.
- Location metadata is stripped from every image before it can be viewed.
- Private link tokens are stored hashed. We hold a one-way digest, not the token. Someone with database access could not reconstruct a working link.
- Tenant isolation. Every property belongs to exactly one organization and every query is scoped to it.
- Card numbers never reach us. Payment details are collected by Stripe in their own hosted checkout.
- AI credentials never reach a client. They are held in a managed secret store and mounted only on the backend services that call the provider — the private generation worker, and the service that powers the assistant for signed-in agents. They are never present in the browser.
- Encryption in transit (TLS) and at rest.
- Audit logging of security-relevant actions.
- Automated rate limiting on public surfaces.
No system is perfectly secure. If a breach affects your personal information we will notify you and any regulator as the law requires.
The most important limitation is not technical. A private link is a key: anyone who has the URL can open the page. There is no password, by design, so a homeowner does not need an account. Whoever creates a link controls who receives it, and can revoke it at any time — revocation takes effect immediately. If you believe a link has reached someone it should not have, tell the agent who sent it and tell us at jon@renovisions.ai.
7. Your rights and choices
Depending on where you live — including under the California Consumer Privacy Act as amended, and comparable laws in other US states — you may have the right to know what we hold about you, to get a copy, to correct it, to delete it, to limit certain uses, and not to be discriminated against for exercising these rights.
We have not sold personal information and have not shared it for cross-context behavioural advertising. We do not knowingly collect information from anyone under 18.
To make a request, email jon@renovisions.ai. We will verify the request before acting — usually by confirming control of the email address involved — and respond within the time the applicable law allows. An authorized agent may act for you with written permission. There is no charge unless a request is excessive.
If you are a homeowner, note the shape of the arrangement: property information was entered by an agent's organization, which is the controller of it. We will forward your request to that organization and support them in answering it, and we will act directly on anything we control — for example a contact request you sent us. If a link is open that should not be, we can disable it.
Marketing email. We send few marketing emails and every one has an unsubscribe link. Transactional email — receipts, notifications about your account — is part of the service and cannot be unsubscribed from while you have an account.
8. Cookies and similar technologies
We use:
- Strictly necessary storage to keep you signed in and to keep the application working. These cannot be turned off without breaking the service.
- Analytics storage (PostHog), to count page views and the named product events listed in section 2.9. Session recording and autocapture are off, and private link tokens are removed before anything is transmitted.
We use no advertising cookies and no cross-site tracking.
Analytics are opt-in. A banner asks before anything analytics-related runs, and the PostHog SDK does not load until you have given consent. If you decline, nothing analytics-related loads at all. If you consent and later change your mind, withdrawing stops collection and clears the identifier the SDK stored in your browser.
9. Changes
We may update this policy. Material changes will be notified by email to operational users and by updating the effective date and the version history below. The current version is always at /info/privacy.
10. Contact
Privacy questions and requests: jon@renovisions.ai General support and abuse reports: jon@renovisions.ai Postal: LLastMile, LLC, 100 Saint Paul St, Apt 101, Brookline, MA 02446
Version history
| Version | Date | Change |
|---|---|---|
| 1.1 | 2026-09-01 | Section 2.9 lists the eight named product events analytics may record and the once-per-purchase account identification (a random account id and the account type, never an email); section 8 says the same. Sections 1, 2.1 and 2.2 catch up with the homeowner pack: a pack buyer has an account, and a pack purchase is recorded with its amount and Stripe identifiers. |
| 1.0 | 2026-08-31 | First published version. Subscription billing and Stripe added; the agent waitlist removed; the stale voice-assistant note replaced with what dictation actually does; retention stated in principle rather than as a schedule no job enforces. |
| 1.0-draft | 2026-08-04 | Initial draft for legal review. Not published. |