RenoAlly
Example DashboardPricing
Sign InRequest Beta Access

Legal

Privacy Policy

Effective and last updated: August 22, 2026

RenoAlly LLC ("RenoAlly," "we," "us," or "our") provides informational analysis of homeowner renovation documents. This Privacy Policy explains the personal information we collect, why we use it, when we disclose it, and the choices available to you.

Information we collect

Information you provide

  • Account and contact information: email address, name when provided, authentication details supplied by our sign-in provider, and communications with support.
  • Renovation documents and project information:uploaded quotes, estimates, contracts, change orders, payment requests, and related files. These documents may contain names, addresses, contractor information, prices, project details, signatures, and contract terms.
  • Analysis and feedback: extracted document data, generated findings, questions, comparisons, project updates, ratings, and feedback you choose to submit.
  • Transaction information: purchase amount, discounts, currency, payment status, refund status, and processor transaction identifiers. Stripe processes payment-card details; RenoAlly does not receive or store full card numbers.

Information collected automatically

  • Security and service logs, such as IP address, device and browser information, timestamps, requested pages, and diagnostic events.
  • Essential browser storage used for authentication, security, site access, and maintaining an upload or checkout session.
  • If you allow optional analytics, Google Tag Manager and Google Analytics may receive page and event information, approximate location, device/browser information, campaign parameters, and a pseudonymous visitor or session identifier. We do not intentionally send those analytics services or advertising-measurement services document content, filenames, names, addresses, email addresses, payment-card data, AI prompts or outputs, or analysis findings. This limitation applies to measurement services; the document processing needed to provide RenoAlly is described below under AI processing and automated file-security checks.
  • If you separately allow advertising measurement, campaign and ad click identifiers and the Google Analytics client/session identifiers may also be stored and used to connect a later server-confirmed purchase or refund to the consented visit. RenoAlly configures its Google analytics and advertising-measurement services to deny ad personalization.
  • Privacy-limited service events, such as upload, checkout, payment, project-access, and analysis status. These events do not include document content, filenames, names, addresses, email addresses, payment-card data, or analysis findings.

How we use information

  • Provide, secure, troubleshoot, and improve the service.
  • Upload, scan, extract, analyze, and compare renovation documents.
  • Process purchases, discounts, refunds, and prevent fraud.
  • Authenticate users and control project access and sharing.
  • Send service, receipt, access, and support communications.
  • Understand service use and performance through privacy-limited operational events.
  • Comply with law and protect users, RenoAlly, and others.

AI processing

RenoAlly uses automated systems to extract and analyze document content. Project documents and relevant instructions are sent to approved AI model providers through Vercel AI Gateway. The specific model and provider may vary based on the analysis task and configured routing. We do not use customer documents for marketing or public examples, and we do not intentionally use them to train RenoAlly models without separate, explicit permission.

Automated analysis can be incomplete or incorrect. See our Terms of Service for important limits on the service.

Automated file-security checks

RenoAlly always performs local file-type, signature, size, page-count, parseability, fingerprint, and processing-eligibility checks. When malware scanning is enabled, RenoAlly also transmits the PDF payload over HTTPS to a RenoAlly-operated ClamAV scanner hosted on Google Cloud Run for malware detection before analysis.

RenoAlly sends only the PDF bytes and does not send the customer-provided filename to the scanner. The scanner does not write a durable document copy to application storage. Processing occurs in a short-lived Cloud Run instance whose memory and local filesystem are ephemeral. RenoAlly retains only bounded verification facts needed for eligibility, audit, retry, and support: file size, page count, SHA-256 fingerprint, provider, status, timestamps, and a normalized rejection or failure code.

Remote malware scanning is a conditional configuration and may be disabled. Local checks remain mandatory. A passed check does not guarantee that a document is safe or virus-free.

Provider and scanner information: Google Cloud privacy and security · ClamAV documentation

When we disclose information

We may disclose information to:

  • Service providers: Supabase for database, authentication, and private document storage; Vercel for hosting and AI Gateway; OpenAI, Google Gemini, Anthropic Claude, and other approved AI model providers for document analysis; Stripe for payments; Google Tag Manager and Google Analytics for optional analytics; Google Ads for separately consented conversion measurement; Google Cloud for the conditionally enabled RenoAlly ClamAV file-security service; Resend for service email; Inngest for background work orchestration; Cloudflare for DNS and related edge services; and configured authentication providers.
  • People you authorize: project viewers or collaborators you choose to invite.
  • Legal and safety recipients: when reasonably necessary to comply with law, respond to valid legal process, prevent fraud or harm, or protect legal rights.
  • Business transaction recipients: in connection with a merger, financing, acquisition, reorganization, or sale of assets, subject to applicable law and appropriate confidentiality protections.

Sale, sharing, and targeted advertising

We do not sell personal information or use personal information for targeted advertising. Some privacy laws may treat disclosure of online identifiers for cross-context advertising measurement as "sharing," a "sale," or targeted advertising. RenoAlly keeps advertising measurement off unless you separately allow it, honors supported Global Privacy Control signals as an opt-out, and configures its Google measurement services to deny ad personalization.

When optional analytics is allowed, Stripe-confirmed paid purchases and refunds may be sent from RenoAlly's server to Google Analytics using a pseudonymous analytics transaction identifier, amount, currency, and consented Google client/session identifiers. Browser purchase events are diagnostic only. If Google Ads is enabled, the server-exported Google Analytics purchase is the only event RenoAlly designates as a Primary advertising conversion. Upload, checkout, claim, and browser purchase events are not Primary conversions.

Advertising storage and advertising user-data consent remain denied on project, admin, authentication, and payment routes even if you previously allowed advertising measurement. Global Privacy Control keeps advertising measurement off. You can withdraw either optional choice at any time with Privacy choices; withdrawal stops future optional collection and clears RenoAlly's locally stored attribution identifiers, but does not require deletion of aggregate or transaction records already lawfully retained.

Retention and deletion

We use the following retention periods unless a longer period is required by law, needed to resolve a dispute or security incident, or subject to a legal hold:

  • Incomplete uploads and unpaid intake records: up to 30 days after the upload or checkout session expires.
  • Project documents, extracted text, and analyses: while the project remains available to the account holder and until a verified deletion request is executed, subject to any applicable legal or financial hold.
  • Account and support information: while the account is active. Support communications may be retained for up to two years after the last interaction.
  • Security, diagnostic, and operational records: up to 12 months, unless a record is needed longer to investigate an incident, prevent fraud, or protect the service.
  • Optional analytics and attribution information: browser-stored attribution identifiers expire after 90 days and are removed sooner if you withdraw the relevant choice or clear browser storage. Attribution attached to an intake or transaction follows the applicable incomplete-intake or transaction period above. Provider analytics and measurement records follow RenoAlly's configured provider-retention settings.
  • Transaction, tax, refund, and legal-acceptance records: up to seven years to meet accounting, tax, dispute, and legal obligations. These records may remain after project content is deleted.

Backup copies may remain until overwritten through our service providers' normal backup cycles. We do not use backup copies for ordinary business purposes after a deletion request has been completed.

Verified deletion requests are handled through a restricted, subject-scoped support workflow. An operator must first run a dry run, use a case ID, and enter the exact execution confirmation. The workflow deletes the subject's Storage objects, projects, account, extracted document text, and derived analysis data while detaching transaction and legal-acceptance records that must be retained. It is designed so a retry does not delete another customer's data or repeat completed work. Requests may be sent to support@renoally.com. We do not promise a fixed 30-day completion period; applicable law and any verified legal or financial hold govern timing.

Your choices and privacy requests

Depending on where you live, you may have rights to request access, correction, deletion, or a copy of personal information; to opt out of certain advertising disclosures; and to appeal a denied request. We will honor applicable rights and may honor the same requests more broadly. We may need to verify your identity and authority before completing a request. Legal exceptions may permit or require us to retain certain information.

Submit a request to support@renoally.com. We will not discriminate against you for exercising an applicable privacy right.

Security

We use administrative, technical, and organizational safeguards designed to protect personal information. No security measure or internet transmission is guaranteed to be completely secure. Keep account links and credentials private and contact us if you suspect unauthorized access.

If we identify a security incident involving personal information, we will investigate and provide notices to affected people and authorities when required by applicable law.

Data location and international transfers

RenoAlly is based in the United States. We and our service providers may process information in the United States and other countries where providers or subprocessors operate. Those locations may have different privacy laws. Where required, we rely on contractual or other legally recognized safeguards for international transfers.

Children

RenoAlly is not directed to children under 18, and we do not knowingly collect personal information from children. Contact us if you believe a child provided information to the service.

Changes to this policy

We may update this policy as the service and applicable requirements change. We will post the updated policy here and revise the effective date above. If a change materially affects how we collect, use, or disclose personal information, we will provide additional notice through the service, by email, or through another legally permitted method before the change takes effect. We will obtain consent where required by law.

Contact us

RenoAlly LLC, Ohio, USA
Email: support@renoally.com

© 2026 RenoAlly LLC

Private BetaContactPrivacyTermsRefunds

Informational analysis only. RenoAlly does not provide legal, financial, engineering, architectural, or construction advice.