Privacy Policy
Last Updated: June 30, 2026
GnomeOwner (“Company,” “we,” “us,” or “our”) is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website, mobile application, and use our services (collectively, the “Services”).
Please read this Privacy Policy carefully. If you do not agree with the terms of this Privacy Policy, please do not access or use the Services.
1. Information We Collect
We may collect information about you in a variety of ways. The information we may collect via the Services includes:
A. Personal Data
Personally identifiable information that you voluntarily give to us when you register for the Services. This may include:
- Name
- Address
- Email address
- Telephone number
- Information required for compliance (e.g., Corporate Transparency Act / BOI reporting, if applicable).
B. Financial and Property Data
Information related to your Homeowners Association (HOA), Condominium Owners Association (COA), or Property Owners Association (POA), including:
- Property addresses and lot numbers
- Dues, assessment records, and payment history
- Ledger data, bank account balances, and budget details
- Vendor information (e.g., W-9 details for independent contractors)
C. Audio Recordings, Transcripts, and Uploaded Documents
When you use our meeting and record-keeping features, we collect and store audio recordings of meetings, the transcripts generated from those recordings, and any bylaws, CC&Rs, administrative documents, or photos (for example, property-condition photos submitted with maintenance or violation reports) you upload. We also collect and store correspondence sent between residents and their association’s board through platform-provided communication channels, which is retained as part of the association’s records.
D. Payment and Banking Information
We use third-party providers (Stripe and Plaid) for financial transactions and account connections. We do not store full credit card numbers or banking credentials on our servers. When you connect your bank account, we access data via Plaid.
E. Resident Portal Account Data
When a unit owner (or a helper the owner authorizes) registers for the resident portal, we collect their email address and sign-in records, their association and unit affiliation, and the portal activity needed to provide the service (such as the payment history displayed for their unit and messages they send to their board). A resident's portal data is visible to that resident and to their association's board; one resident's data is never visible to another resident. Where a resident manages communication preferences through a secure, single-purpose link sent to their email rather than by logging in, that link is a time-limited access token used only for that purpose.
F. Derivative and Technical Data
Information our servers automatically collect when you access the Services, such as IP address, browser type, cookies, and usage metrics.
2. Our AI Pledge: We Never Train on Your Data
GnomeOwner uses artificial intelligence to generate insights, draft documents, and transcribe meetings.
We explicitly pledge that your personal data, uploaded documents, audio recordings, and HOA financial data are NEVER used to train our AI models or the underlying foundation models of our AI providers. Data passed to our AI sub-processors is used exclusively for generating your requested outputs and is not retained by them for model training.
3. How We Use Your Information
We may use information collected about you via the Services to:
- Create and Manage Your Account: Facilitate account creation and logon processes.
- Provide the Services: Process transactions, transcribe meetings, manage ledgers, and facilitate communication — including operating the resident portal (balances, online dues payment, receipts, and resident-to-board messages) and classifying resident-to-board correspondence for storage as part of the association’s records.
- Improve our Platform: Analyze usage and trends to improve user experience.
- Legal Compliance: Assist in your compliance with legal obligations (e.g., tax reporting, state registrations).
4. Disclosure of Your Information & Sub-Processors
We do not sell your personal information. Your information may be disclosed as follows:
A. Authorized HOA Users
We may share your information with authorized users within your HOA (e.g., board members, property managers) as designated by your Subscriber settings.
B. Service Providers & Sub-Processors
We share data with trusted third-party service providers (“sub-processors”) who process it on our behalf, by category and purpose:
- Cloud hosting & infrastructure (database, authentication, file storage, content delivery) — currently Supabase and Vercel.
- AI / large-language-model providers (document search, the board assistant, meeting transcription) — currently including Google (Gemini) and Groq. Data sent to these providers is processed on a per-request basis only and is not used to train AI models. We engage only AI providers whose terms prohibit training on data submitted through their APIs.
- Bank connectivity — Plaid, on a read-only basis solely to reconcile dues (no authority to move funds). Subject to Plaid’s Privacy Policy.
- Payment processing — Stripe. Card data is handled directly by Stripe (PCI-compliant) and is never stored by us.
- Email delivery — Resend.
A current, complete list of our sub-processors — each provider’s purpose and a link to its privacy policy — is maintained at gnomeowner.com/subprocessors. We will post any new sub-processor to that page and notify account holders of material changes (a new category of processing, a new type of data collected, or processing in a new country) by email or in-app notice before the change takes effect.
C. By Law or to Protect Rights
If we believe the release of information about you is necessary to respond to legal process, or to protect the rights, property, and safety of others.
D. SMS / Text Messaging Policy
Text messaging originator opt-in data and consent will NOT be shared with any third parties under any circumstances.
5. Security of Your Information
We take security very seriously and have developed a comprehensive set of practices to help ensure your data is secure.
- Encryption: All communications and processing occur through Secure Socket Layers (SSL) technology. Data is stored in secure databases in an encrypted format.
- Payment Security: We do not touch your credit card data; it is handled entirely by Stripe.
- Disclaimer: While we strive to protect your personal information, no method of transmission over the Internet is 100% secure. We cannot guarantee absolute security.
6. Data Retention and Deletion
6.1 Subscription Cancellation. Cancelling or downgrading a subscription does not delete your association’s data. Your records remain stored so your association can resume service and pick up where it left off.
6.2 Account and Organization Deletion. Deleting your association’s account or organization is a separate, deliberate action, distinct from cancelling a subscription. Before deletion, we offer the ability to export your association’s data. Following a deletion request, your data enters a thirty (30) day recovery window, during which any authorized administrator of your association may reverse the deletion. After the recovery window expires, your data is permanently deleted from our systems, except that financial and tax-related records will be retained in a minimized or anonymized form as required to satisfy applicable record-retention obligations.
6.3 Individual Portal Users. A resident portal user may request deletion of their individual portal account. Correspondence and records belonging to the association will be anonymized rather than destroyed, since such records remain the association’s own governance and financial records.
6.4 No Warranty After Deletion. We make no representation or warranty regarding recovery of data after the recovery window described in Section 6.2 has expired.
7. Children's Privacy (COPPA)
Our Services are not intended for use by children under the age of 13. We do not knowingly collect personally identifiable information from children under 13. If we discover that a child under 13 has provided us with personal information, we will immediately delete such information from our servers.
8. State Privacy Rights
Depending on the privacy laws enacted in your state of residence, you may have specific rights regarding your personal information. For instance, residents of states with comprehensive privacy frameworks (such as California, Virginia, and Colorado) typically have the following rights:
- Right to Know / Access: You may request details about the specific pieces of personal information we have collected.
- Right to Delete: You have the right to request the deletion of your personal information, subject to certain exceptions.
- Right to Correct: You have the right to request correction of inaccurate personal data.
- Right to Opt-Out of Sale: We do not sell your personal information, nor do we share it for cross-context behavioral advertising.
- Right to Non-Discrimination: You will not receive discriminatory treatment from us for exercising your privacy rights.
To exercise these rights, please contact us using the information below.
9. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will alert you about any changes by updating the “Last Updated” date of this Privacy Policy.
Contact Us If you have questions or comments about this Privacy Policy, please contact us at: ReGild LLC (DBA GnomeOwner) 1103 Scott Blvd Decatur, GA 30030 Email: support@gnomeowner.com