1. Scope and roles
HomeCraft OS (“HomeCraft,” “we,” “us,” or “our”) provides a multi-tenant business operating platform. A subscribing business controls its tenant and determines which people may use it. That business is responsible for the business records it enters and the access it grants. This notice applies to HomeCraft’s website, application, support, and connected services.
2. Information we process
- Website requests: your contact details, company, requested help and permission to contact you. We keep requests in a private platform inbox to respond and, when you proceed, prepare onboarding. A keyed network fingerprint helps limit spam. Submitting a request does not start a trial or enroll you in marketing.
- Account and tenant information: names, email addresses, authentication identifiers, company membership, roles, permissions, and settings.
- Business records: customer, project, schedule, communication, document, estimate, contract, invoice, cost, payment, reporting, and audit information entered or generated through authorized workflows.
- Connected-service data: data received from Google or another provider only after an authorized person connects a capability and grants the requested permission.
- Security and service data: device, browser, network, diagnostic, usage, and audit information needed to operate, secure, support, and improve the service.
3. Google user data
HomeCraft requests Google permissions incrementally and in context. Current capabilities use identity information needed to connect the authorized account, narrowly scoped Calendar access for calendars HomeCraft created, per-file Drive access, exact-user Gmail send access, and—only when separately owner-enabled and consented—bounded exact-user Gmail read access for on-demand project-mail review.
- For an activated project, HomeCraft creates a separate secondary calendar named for that job. It does not publish all jobs into a user’s primary calendar.
- HomeCraft publishes only the authorized project-schedule projection. Internal notes, private subcontractor details, costs, and financial information are excluded from that Calendar projection.
- Drive access is limited to files HomeCraft creates or an authorized user explicitly selects through the per-file workflow; it does not grant broad Drive browsing.
- Gmail sending is authorized separately for the exact connected user. HomeCraft sends only an explicitly approved HomeCraft project-mail version and stores its controlled draft, audit state, and provider message identifiers. This permission does not authorize HomeCraft to read, search, watch, modify, label, or delete Gmail messages.
- Optional mailbox review requires a separate restricted
gmail.readonlygrant from the exact connected user. When enabled, HomeCraft performs only the user's bounded search, requests metadata headers for at most 10 matching threads, shows those results transiently, and stores no search text, subject, sender, recipient, body, attachment, or result copy. HomeCraft stores only content-free access audit and any exact thread-to-project link the user explicitly confirms. - Mailbox review does not enable background watch, history ingestion, company-wide mailbox access, Gmail-native drafts, labels, modification, or deletion.
- Each Google capability requires a separate product action, an explanation of the additional permission, and additional consent where required. A Calendar permission does not silently authorize Drive or Gmail, and Gmail send permission does not authorize mailbox reading.
HomeCraft’s use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements.
HomeCraft does not use raw or derived Google Workspace API data to develop, improve, or train generalized or non-personalized artificial intelligence or machine-learning models. The bounded Gmail mailbox-review capability does not send its search text or returned mailbox results to an AI model and does not make them available to a HomeCraft support or administrator viewer.
4. How we use information
We use information to provide and maintain HomeCraft; authenticate users; enforce tenant, project, and role permissions; complete authorized workflows; synchronize deliberately enabled connected services; produce requested AI assistance; secure and troubleshoot the platform; provide support; maintain auditability; comply with law; and improve reliability and usability.
We use Google user data only to provide or improve the user-facing Google capability the user authorized, to protect that capability, or as otherwise permitted by the Google User Data Policy. We do not sell Google user data or use it for advertising, ad targeting, advertising profiles, credit-worthiness, lending, or generalized/non-personalized AI or machine-learning training.
5. AI processing
When an authorized user invokes an AI feature, HomeCraft may provide the minimum relevant, permission-allowed context needed to answer or perform the requested task. AI assistance does not replace HomeCraft permissions, approvals, canonical records, or audit controls. Users should review AI-generated content before relying on it for business, legal, safety, tax, or financial decisions.
6. Sharing and service providers
We may share information with infrastructure, authentication, database, hosting, communication, AI, and other service providers when needed to operate HomeCraft. Providers receive only the access needed for their role and are subject to applicable contractual and security obligations. We may also disclose information when required by law, to protect rights or safety, or as part of a business transaction subject to appropriate safeguards.
7. Storage, security, and tenant separation
HomeCraft uses technical and organizational safeguards designed to protect information, including tenant-scoped authorization, access controls, audit records, transport security, and protected credential storage. No system is completely secure, so customers should also protect their accounts, devices, recovery methods, and administrator access.
8. Retention, disconnection, and deletion
We retain information for as long as needed to provide the service, maintain required business and audit records, resolve disputes, enforce agreements, and meet legal obligations. Retention may vary by record type and tenant settings.
An authorized tenant administrator may disconnect a Google capability from HomeCraft. Disconnection stops future provider access after the authorization is revoked or expires, while HomeCraft business records and audit history may remain as required for continuity and accountability. Users may also revoke access through their Google Account. Requests concerning access, correction, export, or deletion should be directed first to the tenant administrator or to HomeCraft using the contact below.
See Google data access, disconnection, and deletion for step-by-step instructions and an explanation of what HomeCraft deletes, what remains in Google, and which canonical business or audit records may need to be retained.
9. Choices and rights
Depending on location, a person may have rights to request access, correction, deletion, restriction, objection, or portability. We may need to verify identity and the requesting person’s relationship to the relevant tenant. Some information cannot be deleted immediately when retention is required for security, legal, financial, or audit purposes.
10. Changes and contact
We may update this notice as HomeCraft changes. We will revise the effective date and provide additional notice when required. Questions or privacy requests may be sent to privacy@homecraftos.com.
For product terms, see the HomeCraft Terms of Service.
