Your data.
Safe. To the highest standards.

EU hosting. AES-256 encryption. GDPR compliant. So you don't have to worry.

Security starts before the first click inside.

Houselinc is built for sensitive and important information — from personal profile data and insurance records to property documents, financial details and invoices. Secure login and two-factor authentication help protect access from the very beginning.

Create your account, verify your identity, enable two-factor authentication and enter a platform built around privacy-aware organization.

Two-factor authentication

Secure every login with a second verification step.

Encrypted data storage

Your information is stored with strong encryption at rest and in transit.

Private by design

Your data is never sold, shared or used for advertising.

Access control

You decide who sees what — full control over sharing and permissions.

01

Where is my data stored?

Your data is held in Frankfurt, Germany, in the Google Cloud region europe-west3. The processing server functions run there too. In regular operation your content does not leave the EU.

Our infrastructure is Google Cloud and Firebase. Where individual services process outside the EU — such as sign-in via Firebase Authentication — we rely on the EU-US Data Privacy Framework and the standard contractual clauses.

02

Can Houselinc staff read my content?

Technically yes, and we say so plainly: Houselinc GmbH and the developers we commission can access stored content, including uploaded receipts and documents.

We only do so for a specific reason — when you ask us for support, for error analysis, to prevent misuse and security incidents, or where we are legally obliged to. We do not analyse your content for advertising, build no usage profiles and do not sell your data.

03

How is my data protected against attacks?

  • In transit: TLS 1.3 on every connection.
  • At rest: AES-256, with key management by Google.
  • Sign-in: optional two-factor authentication via TOTP, plus an app lock using Face ID, Touch ID or a passcode.
  • Access control: server-side security rules that confine every access to your own account, plus App Check against tampered clients.
04

Can Houselinc access my bank account?

No. Houselinc has no access to your bank account, and account aggregation is not active. Bank details you enter yourself in the financial profile are plain text entries in your account.

05

What happens to my data when I delete my account?

Your profile, properties, assets, folders, receipts, trips, reports and uploaded files as well as your login account are deleted immediately and permanently. Recovery is not possible afterwards — so export whatever you want to keep beforehand.

Independently of this, the following remain: your subscription record with the respective app store or RevenueCat under their own retention rules, crash reports for 90 days, and payment records from web purchases, which we must retain for ten years.

06

Is my data sold to third parties?

No. There is no profiling, no advertising and no sale of data at Houselinc. The service providers we use are purely technical processors under Art. 28 GDPR — cloud infrastructure, subscription management, payment processing, website hosting and newsletter delivery. Our privacy policy names each of them.

07

How are particularly sensitive documents protected (tax ID, marriage contract, IBAN)?

They are stored encrypted in Frankfurt like all other content: TLS in transit, AES-256 at rest. There is no separate per-field encryption with a key only you hold — we do have technical access and use it strictly when there is a specific reason.

What protects you additionally: the app lock via Face ID, Touch ID or passcode, and two-factor sign-in.

08

Where is my content processed by AI, and is it used for training?

We use AI for receipt recognition and document matching — from the Investor plan onwards and only if you switch the feature on. Text recognition runs locally on your device first; your photo or PDF does not leave it. Only the recognised text is transmitted, to a server function in Frankfurt and from there to the Gemini 2.5 Flash language model via Vertex AI in the Frankfurt region.

Under the applicable terms, Google does not use this data to train its models. Only metadata is stored — model, prompt version, timestamp and your confirmation — not the transmitted text itself. You review and confirm every suggestion before it is saved.

09

Will I be informed if there is a security incident?

Yes. Art. 33 and 34 GDPR apply: notification of the supervisory authority within 72 hours, and notification of affected users without undue delay where the risk is high. The authority responsible for us is the Bavarian Data Protection Authority (BayLDA), Promenade 18, 91522 Ansbach, Germany.

As of 27 August 2026 · For questions, reach us at info@houselinc.com

Your data stays in Europe.

All data is stored in the Google Cloud region europe-west3 in Frankfurt, Germany — database, file storage and server functions. In regular operation your content does not leave the EU.

Encrypted like a bank.

Transmission over TLS 1.3, stored data encrypted with AES-256; the keys are managed by Google. We access your content only when there is a specific reason.

Your data belongs to you.

Export at any time. If you delete your account, your content is removed immediately and permanently.

carry the moments with you. not the documents.