Scope
This Policy applies to HomeStroke.com (the Website) and the HomeStroke mobile application (the Mobile App), both provided by Stroke Technology, Inc. It covers Website visitors and Mobile App users acting as survivors, caregivers, clinicians, or contractors.
The Website and Mobile App do not collect the same data. The Website does not request camera access, device location, room photos, or AI room analysis. Those features apply only to the Mobile App.
Information collected on the Website
The Website may collect:
- an email address and selected products when a visitor joins a waitlist;
- referral and campaign information, including referrer URL, landing page, and UTM parameters;
- a randomly generated first-party visitor identifier stored in the browser;
- pages visited, browser user agent, IP address, host, and country code supplied by the hosting network; and
- information sent by email or through a support request.
This information is used to operate the waitlist, measure Website performance and attribution, prevent abuse, and respond to requests. Website visit records are first-party analytics stored in Supabase.
Information collected in the Mobile App
Depending on the features used, the Mobile App may collect:
- Account data: name, email address, authentication provider, and selected role.
- Health-related Home Plan data: stroke timing, mobility, transfers, falls, one-sided weakness, cognition or vision flags, and caregiver availability.
- Home and safety data: home type, ownership or rental status, rooms, stairs, flooring, drill permission, budget, recommendations, task status, reviews, and progress.
- Room scans: photos a user chooses to capture or upload, room name, hazards, confidence values, and recommended actions.
- Sharing data: care-team membership, invitations, permissions, clinician decisions, contractor profiles, work orders, and messages.
- Foreground location: coordinates used with permission to find nearby installers or fill a contractor location. Saved contractor profiles may include an address and coordinates; temporary installer-search coordinates are not saved to a user's Home Plan.
- Device-local data: preferences, notification read status, learning progress, consent status, and the Supabase session.
- Operational data: request logs, timestamps, and security diagnostics made available to infrastructure providers.
Sensitive health-related data
Home Plan fields about stroke recovery, disability, mobility, falls, cognition, and vision may be sensitive personal or consumer health data. We use this data only to provide features requested by the user, maintain security, and comply with law. We do not sell it, use it for targeted advertising, or share it with data brokers.
HomeStroke is not a covered entity or business associate under HIPAA unless a separate written arrangement makes HIPAA applicable. HomeStroke data is not an official medical record. Where applicable law requires a separate consent, the Mobile App presents one before collecting the relevant data.
Mobile App photos and AI room analysis
Room photos are stored in a private Supabase Storage bucket and accessed using time-limited signed URLs. When a Mobile App user requests analysis, the photo and necessary context are processed by a Supabase Edge Function and the configured AI provider. The current default integration uses OpenRouter with an OpenAI-compatible vision model.
HomeStroke does not use room scans for facial recognition and does not intentionally create biometric identifiers. Avoid including other people, documents, screens, or private belongings. AI output may be wrong and is not a diagnosis, professional inspection, or substitute for qualified review.
How information is used
- create and secure accounts;
- provide Home Plans, scans, recommendations, tasks, progress, and user-requested sharing;
- locate nearby contractors when location permission is granted;
- operate contractor, clinician, caregiver, support, and local-notification workflows;
- operate the Website waitlist and first-party analytics;
- prevent fraud, abuse, and security incidents; and
- troubleshoot, improve the services, enforce Terms, and comply with law.
Retention
- Mobile App account data and content are retained while the account is active and removed from active HomeStroke systems when deletion completes.
- A verified web deletion request is normally completed within 30 days, subject to verification and lawful holds.
- Device-local HomeStroke data is cleared by the in-app deletion flow.
- Website waitlist data is retained until unsubscribe, deletion request, or the waitlist purpose ends.
- First-party Website visit records are reviewed at least annually and retained only while reasonably needed for measurement, security, and abuse prevention.
- Backups and provider logs may persist for a limited routine rotation period or as law requires.
Account and data deletion
Signed-in Mobile App users can open Profile → Privacy & Security → Delete account. The flow removes the user's scan images, HomeStroke records, Supabase Auth account, and HomeStroke data stored locally on the device.
Anyone without the Mobile App can use the public account-deletion page or email privacy@homestroke.com. We may verify identity before acting.
Choices and privacy rights
Depending on location, a person may have rights to access, correct, obtain a copy of, delete, or restrict uses of personal information; withdraw consent; opt out of certain sale, sharing, or targeted advertising; or appeal a denied request. Submit requests to privacy@homestroke.com. We may verify identity and authority before responding.
Security
Safeguards include encrypted network transport, Supabase authentication, row-level access controls, private storage buckets, signed image URLs, least-privilege service access, and access logging. No system is completely secure. Use a strong, unique password and report suspected unauthorized access promptly.
International processing and children
Stroke Technology is based in the United States. Information may be processed in the United States and other locations where providers operate, using an applicable transfer mechanism where required.
HomeStroke is intended for adults and is not directed to children under 13, or a higher minimum age where required. Contact us if you believe a child submitted information.
Changes and contact
Material changes will be communicated through the Website, Mobile App, or email when appropriate.
Stroke Technology, Inc.
2810 N Church St
Wilmington, DE 19802, United States
- Privacy: privacy@homestroke.com
- Support: support@homestroke.com
- Deletion: homestroke.com/account-deletion