Privacy policy
This describes what HOA Power Tools actually does with the text you paste and the account details you give us. It is written to match the system as built, not as an aspiration.
Last updated: [publication date to be set before launch]
Who this is from
HOA Power Tools is a weXare product, built by the team behind Rodri. The operator responsible for the data described here is [operator legal entity to be configured], and privacy questions go to [operator contact to be configured].
What we collect
We collect what a tool needs to do its job, and what an account needs to exist. Nothing else is asked for.
- What you type into a tool. The message, thread or budget figures you submit, and the result produced from them. People paste real resident wording here, so treat it as you would in any other system: include what the tool needs and leave out what it does not.
- Account details. Your verified email address, name, role, business or association where that applies, country, and any optional profile details you choose to add.
- Your consent choices. Which option you selected, the wording you were shown, and when.
- Usage accounting. A count of operations against your allowance. For guests this is keyed to a hash of a random cookie token, never to your IP address or anything your browser reports about you.
- Product events. Which tool was viewed, run, copied or exported, plus sanitised campaign values and the origin and path of a referring link. Arbitrary query strings from a URL are not stored.
What never reaches analytics or logs
Tool inputs, resident text, budget figures, names inside a pasted message, and email addresses are excluded from analytics payloads and from application logs. We do not run session replay on forms or on private results. There are no public sharing links: a result is reachable only by the account or the guest browser that made it.
Internal sales and administration views show account details and aggregate usage counts. They do not show the contents of resident conversations or budgets.
How long each thing is kept
- Unsubmitted draft in your browser
- Stored by the tab you are working in for at most 24 hours. Cleared when you reset the form or sign out.
- Raw submitted text and inputs
- Deleted within 24 hours after the run finishes, or sooner if you delete the result yourself.
- Guest outputs
- Up to 24 hours, reachable only from the browser holding the guest cookie that produced them.
- Outputs saved to an account
- 30 days, measured from when the original run completed — not from the last time you viewed or edited the result. Deleting sooner is always available.
- Guest allowance metadata
- Up to 180 days, so the free-trial limit survives the deletion of the content it was spent on.
- Registered usage accounting
- A minimal ledger of how much of an allowance has been spent, kept for 90 days. Deleting content does not reset your current allowance.
- Identifiable funnel events
- 90 days. Reporting beyond that uses aggregated figures only.
- Profile and consent records
- For as long as the account exists. Removed through account deletion, described below.
Claiming a guest result into an account applies the 30-day deadline from the time the original run completed. It does not extend how long the raw input is kept. Once the input has expired, a saved result stays readable and usable, but a rerun asks you for fresh input rather than prefilling the old one. A calculator result keeps the validated scenario its explanation depends on, so the figures still make sense after the submitted payload is gone.
A result can still contain resident wording
This is the part most easily got wrong, so we will state it plainly. Deleting the raw input after 24 hours does not remove every trace of resident text from the system.
An action list quotes the conversation it came from. Those source snippets are part of the derived output, not part of the raw input, and they can contain resident wording and personal detail. They are kept for as long as the output is kept: up to 24 hours for a guest result, and 30 days for a result saved to an account. A drafted reply can quote or paraphrase the message it answers in the same way.
So: we do not claim that all resident text disappears after 24 hours. The full source you pasted does. The snippets carried into the result remain until that result expires or you delete it. Once the original input has expired, the product shows the saved snippets without suggesting the full conversation is still available.
Deleting things
- Deleting a result. It leaves your active access immediately, and its stored payload is queued for deletion within 24 hours. Because usage accounting is separate from content, deleting a result does not return a use to your allowance.
- Deleting your account. Active profile and result data are removed within seven days and your sessions are revoked.
- Backups. Deletion applies to live systems first. Backup copies expire on the documented schedule of the infrastructure this service runs on — [backup expiry schedule to be documented for the chosen infrastructure] — and are not edited individually. We do not promise immediate erasure from backups, because that is not something this deployment can honestly guarantee.
AI processing
The AI-backed tools send your submitted text to a third-party model provider in order to produce a result. Every model call happens on our server; your browser never talks to a provider directly. The model is given no tools: it cannot browse, fetch a URL or take any action outside producing text, so instructions that happen to appear inside a pasted resident message are treated as inert data.
The provider, the model, and the business or API processing arrangement under which they run are set in this deployment’s configuration, together with that provider’s retention and training terms: [AI provider, model and its published retention and training terms to be recorded here from the deployment configuration]. Where the configured arrangement excludes your content from provider-side training or long-term retention, that exclusion is what applies. We do not publish an unconditional zero-retention or no-training promise here, because that claim is only true of a specific verified configuration and would be misleading stated in the abstract.
The dues calculator is deterministic. Calculating a scenario runs no model call at all, and its figures never leave our systems for a provider unless you separately ask for the explanation to be polished with AI.
How this is protected
Traffic is encrypted in transit and stored in a protected database. Submitted inputs and outputs live in a restricted content table separate from profiles and accounting. Result routes are checked against the signed-in account or the guest cookie on every request, so one user’s result cannot be read by another. Model-generated text is escaped where it is displayed, and exports are sanitised before download.
Administrative access is granted through server-managed roles. No field you can edit on your own profile grants it.
Email and marketing
Sign-in codes and other transactional messages are separate from marketing. Agreeing to the terms is not agreement to marketing: product news is a separate, unchecked option you can decline and later change. Registering is not a request for a sales call. Forwarding your details to any external system stays disabled unless the operator explicitly configures and authorises it.
Your choices
From your account you can see what you have made, export it, delete an individual result, change your marketing preference, and delete your account. For anything else, including a copy of what is held about you, write to [operator contact to be configured]. If you used the tools without an account, we cannot identify you from an email address: clearing your browser cookie ends the guest identity, and the associated result expires within 24 hours anyway.
Changes to this policy
If retention periods or processing arrangements change, this page changes with them and the date at the top is updated. Read this alongside the terms of use and the plain-language summary on how it works.