The short version
This page explains what Homio does with your data. If you only read one section, read this one — everything below is the same thing in detail.
- We never ask for your name, email address, phone number or a password. Your account is created from a random identifier generated on your device.
- The photos you upload are sent to an external AI provider, kie.ai, to create your redesign. That is how the product works, and it is described in full in section 5. The app tells you this before your first photo leaves the device and asks you to confirm.
- We keep the photos you used and the designs made from them until you delete them or delete your account. A photo you uploaded but never used in a design is removed automatically after about eight days.
- We use a small number of service providers: Cloudflare (the network in front of our servers, and the storage your images are served from), Adapty (subscriptions), PostHog (product analytics, including session recordings inside the app), Sentry (error reports) and Google Firebase (crash reports and push messaging).
- You can erase everything from the app: Settings → Delete account.
- We do not sell your personal information and we do not run advertising.
Who we are
Homio is a mobile app that turns a photo of a room, a garden or a building façade into an AI-generated redesign.
The controller of the personal data described here is Individual Entrepreneur Dzmitry Matatau, a sole proprietor registered in Georgia under identification number 300435330, with the registered address Building 54a, Apt. 46, III Quarter, XI Micro-District, Zvezsubani Settlement, Nadzaladevi District, Tbilisi, Georgia (“Homio”, “we”, “us”).
You can reach us at [email protected] about anything on this page.
What we collect
Your account
When you first open the app it generates a random identifier (we call it the install ID) and stores it in your device’s Keychain or Keystore. The app sends it to us to create or recover your account. We store only a one-way hash of it, so the identifier itself never sits in our database. Alongside it we store the platform (iOS or Android), the app version, your device language, and the times the account was created and last seen.
That is your entire account. There is no email address, no name, no password, and nothing that identifies you as a person unless you put it in a photo or a prompt yourself.
Photos and designs
The photos you upload, the prompts and styles you choose, the images the AI produces, and the history of your generations, including their status and any error the provider returned.
Chat with the design assistant
The messages you write to the in-app assistant, the photos you attach to them, and the assistant’s replies, kept as conversation history so you can come back to them.
Purchases
Your subscription status and entitlements, the store you bought from (Apple or Google), the product identifiers, transaction events, and the profile identifier assigned by our subscription provider Adapty. We never see or store your card details — see section 6.
Usage and diagnostics
Product analytics events (which screens you open, which features you use), the app version, platform, device language and region, feature-flag assignments, and — while you use the app — session recordings of the app’s own screens. We also collect crash reports and error diagnostics, which include the device model, OS version and a technical stack trace.
Technical logs
Our servers receive your IP address and standard request metadata whenever the app talks to us. We use this to operate the service, enforce rate limits and investigate abuse.
What we do not collect
We do not collect your name, email address, postal address, phone number, contacts, calendar, precise location, health data, or payment card data. We do not scan your photo library — the app only receives the specific photos you pick or take.
Why we use it, and our legal bases
If you are in the EEA or the UK, the GDPR and UK GDPR require us to name a legal basis for each purpose. Ours are:
- Providing the app — creating your account, storing your photos, generating designs, keeping your history. Basis: performance of a contract with you.
- Purchases and credits — unlocking subscriptions, granting and deducting in-app tokens, restoring purchases. Basis: performance of a contract with you.
- Security and abuse prevention — rate limits, fraud and abuse checks, technical logs. Basis: our legitimate interest in keeping the service working and affordable.
- Crash and error diagnostics — finding and fixing defects. Basis: our legitimate interest in a stable product.
- Product analytics and session recordings — understanding how the app is used and where it fails. Basis: our legitimate interest in improving the product, or your consent where local law requires it.
- Answering a refund request you make to Apple — telling Apple how you used the purchase you are asking it to refund. Basis: our legitimate interest in defending a payment against a request we believe is unfounded, and the permission you give us in our Terms of Use, which you may withdraw at any time.
- Legal and accounting records — keeping transaction records. Basis: compliance with a legal obligation.
Your photos and how AI generation works
This is the part of the service that involves the most sensitive data, so it is worth being precise about it.
The upload
When you pick a photo, the app asks our server for a short-lived upload link and then uploads the file straight from your device to our object storage. The photo does not pass through our API. The link expires after a few minutes.
The notice before the first photo
Before the first photo leaves your device, the app shows a short notice saying that the photo will be processed by an AI provider, that it is kept for you and not used for training, and that Homio is for pictures of spaces rather than people. Nothing is uploaded until you confirm. The confirmation is remembered on the device; deleting the app forgets it.
The generation
To produce a redesign we send a request to kie.ai, an external AI generation platform. That request contains a link to your photo, your prompt and your style and format settings. kie.ai downloads the photo from that link and runs it through the image model it hosts on our behalf — currently Google’s Nano Banana Pro. The finished image is returned to us and copied into our own storage so it stays available in your history.
The design assistant
The in-app chat works the same way: the messages you write and links to the photos you attach are sent to a language model hosted by kie.ai, which drafts the reply and, when you ask for a design, starts the generation described above.
We do not send your account identifier, your install ID, your IP address or any purchase data to kie.ai. kie.ai processes your photo as our service provider, for the sole purpose of fulfilling your generation request. It operates outside the EEA — see section 7 — and handles data under its own terms as well.
We do not use your photos to train AI models, and we do not publish them or use them in marketing.
How your images are stored
Your uploads and generated images live in our object storage (Cloudflare R2, in Western Europe) under long, randomly generated addresses, and are served to the app through Cloudflare’s content delivery network, which keeps temporary copies at its edge locations so images load quickly. Those addresses are not listed anywhere and cannot be guessed, but anyone who has the exact link can open the image — so treat a link you share the way you would treat the photo itself.
Sensitive content
Please do not upload photos of other people without their agreement, and do not upload photos of children, identity documents, or anything you would not want processed by an external provider. Homio is built for photos of spaces, not of people.
International transfers
Some of the providers above are located outside the European Economic Area and the United Kingdom, including in the United States. This applies in particular to kie.ai and the image model it runs, and to our analytics, error-monitoring and messaging providers.
Where we transfer personal data out of the EEA or UK, we rely on the European Commission’s Standard Contractual Clauses (and the UK Addendum where relevant), or on an adequacy decision where one exists for the destination country.
Our own servers and database run in Germany (Hetzner Online), and our object storage sits in Western Europe(Cloudflare R2). Cloudflare’s network keeps temporary copies of your images at edge locations around the world so they load quickly wherever you are.
How long we keep things
- Photos you uploaded but never used — deleted automatically about 8 days after upload.
- Photos used in a design, and the generated images — kept until you delete the design or your account. There is no automatic time limit; the images are your history and we do not expire them behind your back. Deleting a design deletes its images, including the original photo, unless that same photo is still the input of another design you have kept.
- Your account and device record — kept until you delete your account.
- Purchase, subscription and token records — retained after account deletion as an accounting and anti-abuse record. These rows contain no images and no contact details.
- Analytics, session recordings and crash reports — retained according to the retention settings of each provider, typically for a limited period measured in months.
- Server logs — kept for a short operational period and then rotated out.
Your rights
If you are in the EEA or the UK you have the right to access your data, to have it corrected, to have it erased, to restrict or object to how we use it, to receive it in a portable format, and to withdraw consent where we rely on it. You can also complain to your local data protection authority.
The fastest way to exercise the right to erasure is inside the app: Settings → Delete account. See section 10 for exactly what that removes.
For anything else, write to [email protected]. Because Homio accounts are anonymous, we usually cannot connect an email address to an account. To help us find your data, write from the device that has Homio installed and tell us what you can about the account — roughly when you started using it, and the store receipt for any purchase you made. If we cannot identify you, we may have to decline the request; the law allows this, and it exists to stop us handing your data to a stranger.
Deleting your data
Open the app and go to Settings → Delete account. You can also email [email protected] and we will do it for you.
When you delete your account:
- your account is closed immediately and your sessions are revoked;
- every photo you uploaded and every image generated for you is deleted from our storage;
- your design history is removed from the app;
- a minimal accounting record of your purchases and token usage is retained, containing no images and no contact details.
Deleting your account does not cancel a subscription. Subscriptions are managed by Apple or Google and must be cancelled in the App Store or Google Play — see section 9 of the Terms of Use.
Copies may persist for a short period in encrypted backups and in our providers’ systems until their own retention windows expire.
California privacy rights
If you are a California resident, the CCPA as amended by the CPRA gives you specific rights. In the last 12 months we have collected the categories of personal information described in section 3: identifiers (a random account identifier and a hashed device identifier), internet and app activity, approximate region derived from your device settings, commercial information about your purchases, and visual information — the photos you choose to upload. We collect them from you and from your device, for the business purposes listed in section 4, and we disclose them to the service providers listed in section 6.
We do not sell personal information and we do not share it for cross-context behavioural advertising, including the personal information of anyone under 16.
You have the right to know what we collect, to delete it, to correct it, to opt out of sale or sharing (which does not apply, since we do neither), to limit the use of sensitive personal information, and not to be discriminated against for exercising any of these rights. Use Settings → Delete account, or write to [email protected]. An authorised agent may submit a request on your behalf with proof of authorisation.
Children
Homio is not for children. You must be at least 16 years old to use it. We do not knowingly collect personal data from anyone under 16.
If you believe a child has used Homio, write to [email protected] and we will delete the account and its content.
How we protect your data
Traffic between the app and our servers is encrypted in transit. Your device secret is stored in the platform Keychain or Keystore and reaches us only as a one-way hash. Upload links are short-lived and scoped to a single file. Access to production systems is limited to the people who need it.
No service is perfectly secure. If we ever suffer a breach that puts your rights at risk, we will notify the relevant authority and, where required, you.
This website
homiolabs.com serves our marketing pages and these legal documents. It does not set advertising or analytics cookies and does not track you across sites. The site is served through Cloudflare, which — together with our own server — records standard web server logs, including IP addresses, to serve and protect the site.
Changes to this policy
We update this policy when the product changes. The date at the top always reflects the current version. If a change materially affects how we use your data, we will tell you in the app before it takes effect.
Contact us
Questions, requests or complaints about privacy: [email protected].
Postal address: Individual Entrepreneur Dzmitry Matatau, Building 54a, Apt. 46, III Quarter, XI Micro-District, Zvezsubani Settlement, Nadzaladevi District, Tbilisi, Georgia.
We are established in Georgia and have not appointed a representative in the EU or the UK. Requests from EU and UK residents are handled directly at the address above.