Homeful logo Homeful
Features How it works FAQ Contact
Get the app
‹ Back to home

Privacy Policy

Last updated · July 2026

§1. Data Controller

  1. The controller of the personal data of the users of the Homeful mobile application (available on the App Store and Google Play, hereinafter: the "Application") and of the marketing website available at gethomeful.com (hereinafter: the "Website") is Windify Digital Services, with its registered office at ul. Płocka 127/16, 87-800 Włocławek, Poland, NIP: 8943145650, REGON: 384382857 (hereinafter: the "Controller").
  2. The Controller may be contacted on matters concerning personal data at: hello@gethomeful.com.
  3. The Controller processes personal data in accordance with Regulation (EU) 2016/679 of the European Parliament and of the Council of 27 April 2016 (the General Data Protection Regulation, hereinafter: the "GDPR"), the Polish Personal Data Protection Act of 10 May 2018 (ustawa o ochronie danych osobowych), the Polish Act of 18 July 2002 on the provision of electronic services (ustawa o świadczeniu usług drogą elektroniczną), and the Polish Telecommunications Law Act of 16 July 2004 (Prawo telekomunikacyjne) (as regards Articles 173 and 174 concerning cookies).

§2. Scope of Data Collected

The Controller collects and processes the following categories of personal data:

Account Data

  • Email address, required to create an Account, log in, verify identity, communicate, and send purchase confirmations.
  • First name (optional), provided by the user to personalise correspondence and the Application interface.
  • Authentication identifier, where a user logs in with an Apple ID or Google account: the identifier returned by the sign-in provider (Sign in with Apple, Google Sign-In). A password, used solely for email login, is stored in encrypted form (bcrypt hash). The Controller has no access to the password in plain text.

Content Uploaded by the User

  • Photos of a room, a home exterior, or a floor plan, uploaded to the Application in order to perform a Generation. The photos are sent to the AI model provider, which returns the Generation result. Location and other metadata (EXIF) are stripped on upload.
  • Generated Content, images produced by the Application's AI models on the basis of the user's Content. Stored in the Account "Archive" until the user deletes them or deletes the Account. User photos and results are never public: they are served only through an authenticated endpoint and are not accessible without the user's session.

Technical and Diagnostic Data

  • IP address, collected in server logs and security systems for the purpose of detecting abuse.
  • Device data, device model, operating system and its version, Application version, interface language.
  • Application installation identifier, an internal identifier generated by the Application. The Controller does not use advertising device identifiers (IDFA on iOS, GAID on Android) for marketing purposes, nor does it share them with third parties for that purpose.
  • Application activity data, the type of Generations performed, technical errors, diagnostic logs (processed in order to improve stability).
  • Push notification token, for sending notifications via Apple Push Notifications (APNs) or Firebase Cloud Messaging (FCM).
  • Cookies and similar technologies, on the Website only (gethomeful.com). The Application does not use cookies in the traditional sense. Detailed information is set out in the Cookie Policy.

Transaction Data

  • Subscription and purchase history, date, amount, plan selected, transaction identifier (App Store / Google Play).
  • Generation balance and history, accruals, deductions, renewals.
  • The Controller does not store payment card details. All payments within the Application are handled exclusively by the Apple App Store and Google Play, in accordance with their terms and payment mechanisms.

§3. Purposes and Legal Bases of Processing

Purpose of processingLegal basis (GDPR)
Creating and maintaining an Account in the ApplicationArt. 6(1)(b), performance of a contract
Provision of the Services (receiving photos, performing Generations, archiving Generated Content)Art. 6(1)(b), performance of a contract
Handling payments and settlementsArt. 6(1)(b), performance of a contract
Sending push notifications and emails (transactional, account-related)Art. 6(1)(b), performance of a contract / Art. 6(1)(f), legitimate interest
Ensuring security, detecting abuse, protecting the ApplicationArt. 6(1)(f), legitimate interest
Handling complaints and contact with the user (including the Website contact form)Art. 6(1)(b), performance of a contract / Art. 6(1)(f), legitimate interest
Fulfilling legal obligations (accounting, taxes, invoicing)Art. 6(1)(c), legal obligation
Improving the Application on the basis of anonymised ContentArt. 6(1)(f), legitimate interest; with the option to withdraw consent in the Application settings
Establishment, exercise or defence of legal claimsArt. 6(1)(f), legitimate interest

§4. Recipients of Data

Users' personal data may be transferred to the following categories of recipients (processors and separate controllers):

  1. Cloudflare, Inc. (USA), provider of the hosting and backend infrastructure for Homeful (Cloudflare Workers), the database (D1), object storage for photos and Generated Content (R2), content delivery network (CDN), bot and DDoS attack protection, and email routing for addresses in the gethomeful.com domain. The data stored in object storage is encrypted at rest and in transit.
  2. OpenRouter, Inc. (USA), provider of a proxy service that routes generation requests to AI model providers. The Controller configures OpenRouter with the Zero Data Retention (ZDR) setting enabled; this means that requests are routed exclusively to downstream providers that do not retain the submitted data after inference is performed and do not use it to train their models.
  3. Google LLC and Google Ireland Limited, provider of the Google Gemini image model API used to produce the visualisations, and provider of Google Play (in-app purchases) and Google Sign-In. In accordance with the Google Gemini API terms (paid, production tier), content submitted via the API is not used to train Google's models.
  4. Apple Inc., in connection with the sale of Subscriptions within the Application via the App Store, Sign in with Apple, and the sending of push notifications (Apple Push Notifications).
  5. Resend (email delivery provider), used to deliver transactional emails and to forward messages submitted through the Website contact form (name, email address, subject, message) to the Controller. The contact form is processed by the Controller's own Cloudflare Worker; there is no third-party form-forwarding service.
  6. Public authorities, at the request of authorised bodies, on the basis of applicable law.
  7. Legal and tax advisers, to the extent necessary for the establishment, exercise or defence of legal claims.

The Controller does not sell users' personal data to third parties. Users' Content (photos of rooms, exteriors and floor plans) is not shared with data brokers or advertising networks, nor is it used by the AI model providers to train their models.

Nature of the Use of AI Models

  1. The Generation of a visualisation is performed by AI models in a probabilistic manner; the result is not deterministic and may differ with each generation, even from the same input data. Complaints concerning defective results are governed by the Terms of Service (a Generation refund in the case of manifest defects).
  2. The user's Content is transmitted to the AI model providers solely for the purpose of performing the given Generation. The AI model providers do not use the submitted Content to train or fine-tune their models; the Controller relies on the Zero Data Retention configuration and the applicable production-tier API terms to that effect.
  3. A Generation does not constitute automated decision-making within the meaning of Art. 22 GDPR; the Generation result is graphic content delivered to the user for any use, and not a decision producing legal effects concerning them or significantly affecting their situation.
  4. The full list of the Controller's subprocessors is made available to the user upon a written request sent to hello@gethomeful.com.

§5. Transfers of Data Outside the EEA

  1. Some of the entities to which the Controller entrusts the processing of data have their registered office outside the European Economic Area (EEA), in particular in the United States. This applies in particular to: Cloudflare, Inc., OpenRouter, Inc., Google LLC (Gemini API, Google Play, Google Sign-In), Apple Inc., and the email delivery provider (Resend).
  2. Transfers of data to the USA take place on the basis of the EU-US Data Privacy Framework (European Commission implementing decision of 10 July 2023) or Standard Contractual Clauses (SCC) approved by the European Commission, in accordance with Art. 46 GDPR.
  3. The Controller uses only providers that ensure an adequate level of personal data protection in accordance with the requirements of the GDPR.
  4. In the event that a data transfer mechanism is invalidated or changed, the Controller will promptly take steps to ensure that the transfer complies with applicable law.

§6. Data Retention Period

Category of dataRetention period
Account data (email, first name)Until the Account is deleted by the user or the Controller + 30 days (for possible restoration)
Photos uploaded for a GenerationUntil deleted by the user or, at the latest, until the Account is deleted
Generated Content (Archive)Until the specific Generation is deleted by the user or the Account is deleted
Transaction history (Subscriptions, invoices)5 years from the end of the tax year (accounting obligation)
Contact-form data / complaint correspondenceUntil the request has been dealt with + 12 months
Server logs (IP addresses, technical data)Up to 90 days
Data for the establishment/defence of claimsUntil the expiry of the limitation period (up to 6 years)
  1. Once the retention period has expired, the data is permanently deleted or anonymised.
  2. Where an Account is deleted, the user's data, including photos and Generated Content in object storage, is deleted promptly (with a 30-day restoration window), with the exception of data the retention of which is required by law (e.g. transaction data, 5 years).

§7. Rights of the User

Under the GDPR, the user has the following rights:

  • Right of access (Art. 15), to obtain information about the data processed, including a copy of the data.
  • Right to rectification (Art. 16), to correct inaccurate data or complete incomplete data.
  • Right to erasure (Art. 17), to request deletion of the data (the "right to be forgotten"). The user may delete their Account themselves in the Application settings. This right does not apply to data the retention of which is required by law.
  • Right to restriction (Art. 18), to restrict the processing of data in certain cases.
  • Right to data portability (Art. 20), to receive the data in a structured, commonly used and machine-readable format.
  • Right to object (Art. 21), to object to processing based on the Controller's legitimate interest, including objection to the use of anonymised Content for improving the Application.
  • Right to withdraw consent (Art. 7(3)), at any time, without affecting the lawfulness of processing carried out beforehand.
  • Right to lodge a complaint, with the supervisory authority: the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych), ul. Stawki 2, 00-193 Warsaw, Poland (uodo.gov.pl).

To exercise the above rights, please contact the Controller at hello@gethomeful.com. The Controller will deal with the request within 30 days. In the case of complex or numerous requests, this period may be extended by a further 60 days, of which the Controller will inform the user.

§8. Data Security

  1. The Controller applies appropriate technical and organisational measures to protect personal data, including:

    • SSL/TLS encryption, all communication with the Application and the Website takes place over an encrypted HTTPS connection.
    • Encryption of data at rest, photos and Generated Content are stored in encrypted object storage.
    • Private media, user photos and results are never public; they are served only through an authenticated endpoint.
    • EXIF stripping, location and other metadata are removed from photos on upload.
    • Password hashing, passwords (for email login) are stored solely as a bcrypt hash.
    • Token-based authentication, Application sessions are based on signed tokens, which can be revoked.
    • No storage of card details, payment data is processed exclusively by the Apple App Store / Google Play.
    • Access control, access to data is limited to authorised persons, with an access log.
  2. Notwithstanding the above safeguards, the Controller is unable to guarantee the complete security of data transmitted over the Internet. The user is responsible for securing their own device and login credentials.

§9. Personal Data Breach

  1. In the event of a personal data breach that may result in a risk to the rights or freedoms of natural persons, the Controller will report such breach to the President of the Personal Data Protection Office (Prezes Urzędu Ochrony Danych Osobowych) without undue delay, and no later than 72 hours after becoming aware of the breach (Art. 33 GDPR).
  2. Where a personal data breach may result in a high risk to the rights or freedoms of natural persons, the Controller will promptly inform the affected users (Art. 34 GDPR), including of the nature of the breach, the possible consequences, and the remedial measures.

§10. Profiling and Automated Decision-Making

  1. The Application uses AI models to generate images. This is carried out solely at the user's request and does not constitute automated decision-making within the meaning of Art. 22 GDPR, as it produces no legal effects and does not significantly affect the user's situation.
  2. The Controller does not use the Website for behavioural profiling and does not run analytics or marketing trackers on it; details are set out in the Cookie Policy.

§11. Children's Personal Data

  1. The Application and the Website are not intended for persons under 16 years of age. The Controller does not knowingly collect children's personal data.
  2. Uploading photos depicting minors to the Application is prohibited (in accordance with §5 of the Terms of Service). If the Controller becomes aware that the Content contains the likeness of a child or that an Account belongs to a person under 16 years of age, it will promptly delete the relevant data and block the Account.

§12. Obligation to Provide Data

  1. Providing Account data (email address) is voluntary but necessary to create an Account and use the Application.
  2. Uploading photos is voluntary and necessary to perform a Generation.
  3. Providing data in the Website contact form is voluntary and necessary in order for the Controller to respond to the message.

§13. Changes to the Privacy Policy

  1. The Controller reserves the right to amend this Privacy Policy at any time, in particular in order to adapt it to changes in the law, technological changes or changes in the scope of data processing.
  2. The Controller will inform users who hold an Account of material changes by email or by notification within the Application, at least 14 days in advance.
  3. We recommend reviewing the content of this Policy regularly; it is available at gethomeful.com/privacy.

§14. Controller's Details

Windify Digital Services
ul. Płocka 127/16, 87-800 Włocławek
NIP: 8943145650 · REGON: 384382857
Contact: hello@gethomeful.com

Homeful logo Homeful

See it before you buy it. AI home visualization for iOS & Android.

App Store · soon Google Play · soon
Product
FeaturesHow it worksFAQDownload
Company
Contact
Legal
Privacy PolicyTerms of ServiceCookie PolicyReturns & ComplaintsImpressum
© 2026 Homeful. All rights reserved.
Privacy Terms Cookies Contact

We use cookies

Homeful uses only essential cookies to keep the site working. No analytics, no tracking. See our Cookie Policy and Privacy Policy.