1. Organisation and contact
The verified legal operator, registration number, registered address, privacy contact, and Data Protection Officer details have not yet been published. Homa will add them here before this policy becomes effective or any production personal data is collected through the website.
2. Current marketing website
The marketing website can provide Clerk account access and subscription management when the approved production configuration is active. With visitor permission, PostHog measures website use and account-funnel events. The private-beta page remains informational and installer buttons remain clearly labelled release placeholders until an official signed build exists.
3. Website and analytics data
The website may process information you deliberately submit to Clerk or Stripe, consent records, basic security logs, and privacy-limited PostHog analytics. PostHog receives page paths, navigation and call-to-action interactions, referrer and campaign context, browser and device information, sign-up completion, sign-in sessions, billing-funnel status, and—after sign-in—the stable Clerk user ID. Homa does not send names, email addresses, passwords, payment details, form contents, chart data, or desktop-session content to PostHog. Optional analytics stays off until accepted, and session replay is disabled.
4. Intended desktop session data
Depending on your settings, Homa may process the selected platform/window, symbol and timeframe context, voice or text conversation, on-demand chart or region snapshots, technical observations, mistake evidence, non-clinical behavior signals, session reflection, and purposeful mentor memory. Homa should record meaningful events rather than continuous full-motion video.
5. Capture and microphone
Homa is intended to observe only the application window or region you explicitly authorize. Viewing, microphone, capture, analysis, and session states must remain visible. The app should pause if the selected source closes and must never silently switch to another source. A single STOP HOMA control should end microphone, capture, and active analysis.
6. Data-minimization defaults
- Screenshots are transient by default.
- Only key snapshots you approve should be stored.
- Raw audio should normally be discarded after realtime processing or transcription.
- Transcript storage, behavior analysis, session reflection, screenshot storage, and persistent memory are separate controls.
- Continuous full-motion screen streaming to AI is not the intended design.
7. Providers and international processing
Approved hosting, authentication, AI, voice, email, analytics, storage, and payment providers may process data in other countries. Before production, the operator must publish a current vendor register, processing locations, transfer safeguards, provider retention terms, and applicable Singapore PDPA assessments.
8. Retention and deletion
Retention should be purpose-specific and no longer than necessary. Stored session data, screenshots, transcripts, and purposeful mentor memory should be inspectable and deletable where appropriate. Exact retention periods and deletion workflows remain launch requirements and must be published before production.
9. Security
Intended safeguards include server-derived identity, ownership checks, default-deny access, rate limits, private storage, short-lived provider authorization, server-side secrets, audit events, kill switches, signed desktop releases, and security testing. No system can guarantee absolute security.
10. Your choices and rights
Depending on applicable law, you may have rights to notice, access, correction, withdrawal of consent, deletion, portability, restriction, or complaint. The production service must provide a verified request channel and identity-confirmation process.
11. Children
Homa is not directed to children. The proposed minimum age is 18.
12. Contact
Launch contact pending verification.
The legal operator, registered address, privacy email, and verified rights-request channel will be published here before production launch.