
Your data.
Safe. To the highest standards.
EU hosting. AES-256 encryption. GDPR compliant. So you don't have to worry.
Security starts before the first click inside.
Houselinc is built for sensitive and important information — from personal profile data and insurance records to property documents, financial details and invoices. Secure login and two-factor authentication help protect access from the very beginning.
Create your account, verify your identity, enable two-factor authentication and enter a platform built around privacy-aware organization.
Secure every login with a second verification step.
Your information is stored with strong encryption at rest and in transit.
Your data is never sold, shared or used for advertising.
You decide who sees what — full control over sharing and permissions.
01Where is my data stored?
Where is my data stored?
Your data is held in Frankfurt, Germany, in the Google Cloud region europe-west3. The processing server functions run there too. In regular operation your content does not leave the EU.
Our infrastructure is Google Cloud and Firebase. Where individual services process outside the EU — such as sign-in via Firebase Authentication — we rely on the EU-US Data Privacy Framework and the standard contractual clauses.
Where is my data stored?
Your data is held in Frankfurt, Germany, in the Google Cloud region europe-west3. The processing server functions run there too. In regular operation your content does not leave the EU.
Our infrastructure is Google Cloud and Firebase. Where individual services process outside the EU — such as sign-in via Firebase Authentication — we rely on the EU-US Data Privacy Framework and the standard contractual clauses.
02Can Houselinc staff read my content?
Can Houselinc staff read my content?
Only when it is necessary. Access to your content is limited to authorised persons — for example when you ask us for support, to resolve technical issues, to prevent misuse and security incidents, or to comply with legal obligations.
We do not analyse your content for advertising, build no usage profiles and do not sell your data.
Can Houselinc staff read my content?
Only when it is necessary. Access to your content is limited to authorised persons — for example when you ask us for support, to resolve technical issues, to prevent misuse and security incidents, or to comply with legal obligations.
We do not analyse your content for advertising, build no usage profiles and do not sell your data.
03How is my data protected against attacks?
How is my data protected against attacks?
- In transit: TLS 1.3 on every connection.
- At rest: AES-256, with key management by Google.
- Sign-in: optional two-factor authentication via TOTP, plus an app lock using Face ID, Touch ID or a passcode.
- Access control: server-side security rules that confine every access to your own account, plus App Check against tampered clients.
How is my data protected against attacks?
- In transit: TLS 1.3 on every connection.
- At rest: AES-256, with key management by Google.
- Sign-in: optional two-factor authentication via TOTP, plus an app lock using Face ID, Touch ID or a passcode.
- Access control: server-side security rules that confine every access to your own account, plus App Check against tampered clients.
04Can Houselinc access my bank account?
Can Houselinc access my bank account?
No. Houselinc has no access to your bank account. Bank details you enter yourself in the financial profile are plain text entries in your account.
Can Houselinc access my bank account?
No. Houselinc has no access to your bank account. Bank details you enter yourself in the financial profile are plain text entries in your account.
05What happens to my data when I delete my account?
What happens to my data when I delete my account?
Your profile, properties, assets, folders, receipts, trips, reports and uploaded files as well as your login account are deleted immediately. Any data contained in backups is removed in the course of the respective backup cycle; uploaded files are permanently deleted when the account is deleted. So export whatever you want to keep beforehand.
Independently of this, the following remain: your subscription record with the respective app store or RevenueCat under their own retention rules, crash reports for 90 days, technical log data for 30 days, and payment records from web purchases, which we must retain for ten years.
What happens to my data when I delete my account?
Your profile, properties, assets, folders, receipts, trips, reports and uploaded files as well as your login account are deleted immediately. Any data contained in backups is removed in the course of the respective backup cycle; uploaded files are permanently deleted when the account is deleted. So export whatever you want to keep beforehand.
Independently of this, the following remain: your subscription record with the respective app store or RevenueCat under their own retention rules, crash reports for 90 days, technical log data for 30 days, and payment records from web purchases, which we must retain for ten years.
06Is my data sold to third parties?
Is my data sold to third parties?
No. There is no profiling, no advertising and no sale of data at Houselinc. The service providers we use are purely technical processors under Art. 28 GDPR — cloud infrastructure, subscription management, payment processing, website hosting and newsletter delivery. Our privacy policy names each of them.
Is my data sold to third parties?
No. There is no profiling, no advertising and no sale of data at Houselinc. The service providers we use are purely technical processors under Art. 28 GDPR — cloud infrastructure, subscription management, payment processing, website hosting and newsletter delivery. Our privacy policy names each of them.
07How are particularly sensitive documents protected (tax ID, marriage contract, IBAN)?
How are particularly sensitive documents protected (tax ID, marriage contract, IBAN)?
They are stored encrypted in Frankfurt like all other content: TLS in transit, AES-256 at rest. What protects you additionally: the app lock via Face ID, Touch ID or passcode, and two-factor sign-in.
How are particularly sensitive documents protected (tax ID, marriage contract, IBAN)?
They are stored encrypted in Frankfurt like all other content: TLS in transit, AES-256 at rest. What protects you additionally: the app lock via Face ID, Touch ID or passcode, and two-factor sign-in.
08Where is my content processed by AI, and is it used for training?
Where is my content processed by AI, and is it used for training?
We use AI for receipt recognition and document matching — in every plan within its AI allowance, and only if you switch the feature on. Text recognition runs locally on your device first. The recognised text is transmitted to a server function in Frankfurt, and for receipt scanning additionally an image of the first receipt page so that handwritten details can be recognised; for document matching only the recognised text. It is evaluated with the Gemini 2.5 Flash language model via Vertex AI in the Frankfurt region.
The image is neither stored nor logged, and the transmitted text is not stored permanently. Under the applicable terms, Google does not use this data to train its models. You review and confirm every suggestion before it is saved.
Where is my content processed by AI, and is it used for training?
We use AI for receipt recognition and document matching — in every plan within its AI allowance, and only if you switch the feature on. Text recognition runs locally on your device first. The recognised text is transmitted to a server function in Frankfurt, and for receipt scanning additionally an image of the first receipt page so that handwritten details can be recognised; for document matching only the recognised text. It is evaluated with the Gemini 2.5 Flash language model via Vertex AI in the Frankfurt region.
The image is neither stored nor logged, and the transmitted text is not stored permanently. Under the applicable terms, Google does not use this data to train its models. You review and confirm every suggestion before it is saved.
09Will I be informed if there is a security incident?
Will I be informed if there is a security incident?
Yes. Art. 33 and 34 GDPR apply: notification of the supervisory authority within 72 hours, and notification of affected users without undue delay where the risk is high. The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.
Will I be informed if there is a security incident?
Yes. Art. 33 and 34 GDPR apply: notification of the supervisory authority within 72 hours, and notification of affected users without undue delay where the risk is high. The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.
As of 27 August 2026 · For questions, reach us at info@houselinc.com
Your data stays in Europe.
All data is stored in the Google Cloud region europe-west3 in Frankfurt, Germany — database, file storage and server functions. In regular operation your content does not leave the EU.
Encrypted like a bank.
Transmission over TLS 1.3, stored data encrypted with AES-256; the keys are managed by Google. We access your content only when there is a specific reason.
Your data belongs to you.
Export at any time. If you delete your account, your content is deleted immediately.
carry the moments with you. not the documents.

