Privacy policy
Use public guidance without an account; sync projects only if you choose.
This policy describes the current public version of HomeRulebook. Last updated August 6, 2026.
01 · Information you enter
Street addresses are used for a temporary geography match.
When you choose address verification, the street address is sent to the U.S. Census Geocoder to match an incorporated place and county. HomeRulebook does not place the street address in the Permit Brief URL or save it to a user account.
A short-lived, HTTP-only browser cookie stores only the matched jurisdiction details so the next result page can label the match. Project and scope selections remain in the result-page URL. Avoid entering private notes or sensitive personal information.
02 · Approximate location
An IP-based city suggestion is optional and starts only when requested.
HomeRulebook does not contact GeoJS automatically. If you select “Use my approximate area,” the browser requests an approximate country, state and city so the site can suggest a relevant local starting point. GeoJS receives the network request needed to estimate the visitor location; HomeRulebook ignores the returned IP address, coordinates, network owner and other unnecessary fields.
Before confirmation, HomeRulebook keeps only the approximate city and state in session storage. If you confirm or manually choose an area, that coarse preference is stored on your device so later pages can prioritize useful links. It never proves a street address, residence, parcel boundary or permitting jurisdiction, and it can be changed or cleared from the location control.
03 · Operational data
Hosting systems may process standard request data.
The hosting provider may maintain routine server logs such as IP address, browser information, requested pages, timestamps and security events. These logs support delivery, troubleshooting and abuse prevention.
04 · Privacy-conscious analytics
Optional external analytics are consent-gated and avoid private workflows.
HomeRulebook records a small allowlist of first-party operational events, such as a Permit Brief being created, a location suggestion being accepted or an answer being copied. An event may include a covered city slug, two-letter state, coverage outcome, project slug and page path; the event endpoint rejects query strings and does not accept the entered street address.
If you select Allow analytics, HomeRulebook loads Google Analytics 4 on public information pages. It receives the sanitized page path without query strings, basic browser and device information, approximate geography derived by Google, and limited product events. Advertising storage, Google Signals and ad personalization are disabled. Google Analytics is not loaded before consent and is disabled on address checks, result pages, account areas, project workspaces, contractor checks, review intake and review-status pages.
Creating a Project Center account is optional. Account identity, street addresses, form contents, recovery codes, project notes and encrypted project data are kept outside Google Analytics and the first-party product-event payload. HomeRulebook does not build a personalized advertising profile. Choose Essential only to use the site without Google Analytics, or reopen Privacy choices in the footer at any time. Standard server logs may still contain the request information described above.
05 · Free human-review pilot
Private pilot fields are encrypted and kept out of analytics.
The free pilot collects an email address, project property address, selected jurisdiction and project, optional clarification and consent. These fields are sent in the encrypted request body, encrypted again at rest, excluded from page URLs and product analytics, and used only to prepare and deliver the requested review.
The requester receives a reference number and a one-time recovery code. The code is not placed in the URL or stored in plaintext. A signed, HTTP-only cookie keeps the current device authorized. Keep the recovery code private because it can restore access to the request status and report.
Delivered pilot records are removed after the configured retention period, currently 30 days. Pending work is retained long enough to complete the request. Contact privacy@homerulebook.com to request earlier deletion and include only the reference number, not the street address or recovery code.
06 · Optional project account
The Home Project Center separates identity, sessions and encrypted project details.
Google sign-in requests only the OpenID identifier, primary email address and basic profile name needed to create or match a HomeRulebook account. HomeRulebook stores the Google subject identifier, the email observed when the identity was linked, the link and last-sign-in timestamps, revocable session records, and the projects you choose to create or import. It does not request Gmail, Drive, contacts, calendar or advertising data. Google account data is used only for authentication and account security and is not sold or used for advertising.
Existing password accounts keep a salted scrypt password hash and an HMAC of the one-time recovery code. A password is transmitted over TLS for registration or sign-in, but is not logged or retained in plaintext. New password registration stays disabled while verified Google sign-in is the public registration path. Project notes, permit numbers, contractor contacts, checklist details and final-record metadata are encrypted at rest. HomeRulebook does not store uploaded project documents.
Account projects remain until you delete a project or the account. Expired and revoked sessions are removed by scheduled retention, and account security audit events are retained for up to 365 days. Account deletion removes the account, its Google identity link, synced projects, sessions and related account audit records through database cascades. Device-local workspace copies are separate and remain in that browser until you remove them.
Offline recovery remains available only to password accounts that received a one-time recovery code. Google-only accounts recover access through Google. Keep credentials private, and do not place government credentials, identity documents, payment data or highly sensitive personal information in project notes.
07 · External services
Identity, analytics, location and government services have their own policies.
Google provides optional account authentication and, only after an analytics choice, public-page measurement through Google Analytics. Approximate location suggestions use GeoJS, and address matching uses the public U.S. Census Geocoder. Links to government departments and application portals leave HomeRulebook. Their privacy, accessibility and security practices are controlled by those organizations.
The free pilot does not request card information or use a payment processor. Do not enter payment data in any HomeRulebook form.
08 · Privacy contact
Send privacy questions by email.
Contact privacy@homerulebook.com with a privacy question. Do not email sensitive permit documents or account credentials.
Questions about these policies? Use the corrections and contact page.