Privacy Policy
Last updated: August 13, 2026
This Privacy Policy explains how Housora handles personal data when you visit the website, create an account, upload content, generate design concepts, buy a plan, or contact support.
1. Controller and contact
Housora is operated by Ismail Abelouas, trading as Housora, who is the controller of the personal data described in this Policy. For privacy requests, legal notices, or questions, email support@housora.app.
2. Personal data we handle
- Account data: name, email address, profile image, authentication identifiers, account status, and plan information supplied by you or our authentication provider.
- Your content: room photographs, floor plans, prompts, project names, selected design options, generated images, and related file metadata.
- Payments and subscriptions: plan, billing period, transaction and subscription identifiers, payment status, and limited receipt information supplied by Whop. Housora does not receive or store your full payment-card number.
- Technical and security data: IP address, timestamps, browser and device information, request metadata, security events, rate-limit records, and error logs.
- Optional analytics data: page paths and selected product events described in section 6, but only after analytics consent.
- Communications: support messages, refund requests, feedback, and any information you choose to include.
We receive this data from you, your device, Clerk, Whop, and the infrastructure providers involved in delivering the Service.
3. Why we use data and our legal bases
- Contract: to create and secure your account, provide requested design features, store projects, process subscriptions, and provide support.
- Legitimate interests: to secure the Service, prevent fraud and abuse, diagnose faults, maintain reliable operations, and establish or defend legal claims. We balance these interests against your rights.
- Consent: for optional PostHog analytics and any optional marketing communication. You can withdraw consent at any time without affecting earlier lawful processing.
- Legal obligations: for tax, accounting, consumer-protection, payment-dispute, and lawful-authority requirements.
Account, upload, prompt, and payment information is required when you ask us to provide the corresponding feature. If you do not provide it, that feature may not work. You are not required by law to create an account or provide optional analytics consent.
4. Images, prompts, and AI processing
You keep your rights in content you upload. You authorize Housora and its processors to host, transmit, and process that content to provide the feature you requested, secure the Service, and support your account. Uploaded content is not used for advertising. Housora will not use your private uploads to train a general-purpose AI model unless we first provide a separate notice and obtain any consent required by law.
Room images can reveal private information about a home. Do not upload images you do not have permission to use, confidential documents, precise security details, or identifiable people who have not agreed to the processing.
5. Providers and recipients
We use service providers only for the functions described here. They may include Clerk for authentication, Convex for application data and file storage, Cloudflare for hosting, delivery, security, and media storage, Whop for checkout and subscriptions, PostHog for consent-based product analytics, and the configured image-generation provider for processing the image and prompt submitted for a generation request. Professional advisers and authorities may receive limited data where legally required.
We do not sell personal data. We do not use uploaded room images or prompts for third-party advertising.
6. PostHog analytics
PostHog analytics is optional and remains off until you choose Allow analytics. When enabled, Housora may record page paths without query strings and explicit product events such as tool selected, upload type and size range, generation status and duration range, checkout state, and project actions. Events can also include event time, browser or device category, and approximate location derived from network data. For signed-in users, events may be associated with a pseudonymous Clerk user identifier and plan name.
Housora configures PostHog without session replay, form or click autocapture, marketing profiling, or the contents of uploaded images and prompts. Query strings are removed from analytics page URLs. You can withdraw consent at any time through Cookie settings in the footer; withdrawal stops future browser and consent-gated server analytics on that device.
7. International transfers
Some providers may process data outside your country or the European Economic Area. Where required, transfers rely on an adequacy decision, the European Commission's Standard Contractual Clauses, or another lawful safeguard. Contact us to request information about the safeguard relevant to a particular provider.
8. Retention and deletion
We keep account, project, upload, and generation data while your account is active and for the period reasonably needed to provide the Service, complete deletion, resolve disputes, prevent fraud, or meet legal duties. Security logs and rate-limit records are kept only for the operational period for which they are needed. Payment and transaction records may be kept for the tax, accounting, chargeback, and consumer-law periods that apply. Optional analytics data follows the retention configured for the Housora PostHog project; contact us for the current setting.
You can start account deletion from the signed-in account controls or email support@housora.app. Deletion requests cover Housora account data, projects, generations, and Housora-controlled uploads, subject to legal retention exceptions and limited provider backup cycles.
9. Your rights
Depending on where you live, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of your personal data. You may withdraw consent and object to processing based on legitimate interests. You may also complain to the data-protection authority where you live, work, or believe an infringement occurred.
To exercise a right, email support@housora.app. We may ask for information needed to verify that the request concerns your account. We will respond within the period required by applicable law.
10. Security and automated decisions
We use access controls, authentication, request validation, encryption in transit, and provider security controls intended to protect data. No internet service can guarantee absolute security. Housora does not make legal or similarly significant decisions about you using solely automated processing.
11. Children
The Service is not directed to children under 16. If local law permits a lower age for independent consent, the local rule applies. If you believe a child has provided personal data without valid authorization, contact us so we can investigate and delete it where appropriate.
12. Changes
We may update this Policy when the Service, providers, or law changes. We will change the date above and provide additional notice when a material change requires it.