Privacy Policy
Last updated: 19 August 2026
Homescreen (“we”, “us”) is the app-building service at gethomescreen.com, operated by Thorpe Software Ltd, a company registered in England and Wales, company number 17382863. We are the data controller for everything described in this policy, except where we say we're acting on a creator's behalf. This policy explains what we collect, why, and the choices you have. Questions any time: axel@gethomescreen.com.
What we collect
- Account details. Your email address and sign-in identity, handled by our authentication provider, Clerk. We never see or store your password.
- Your content. The app descriptions you write, the content and branding you add to your apps, and the apps we generate for you.
- Your published posts. When you connect a source — your Instagram profile, your Substack, or an export you upload — we collect what you published there: the posts and captions, the dates and links, the images, engagement counts, and a sample of the comment replies underneath. We keep our own copy, because that copy is what your app is built from.
- Payment details. Processed by Stripe. We never store card numbers; we keep records of your plan, invoices, and payouts.
- Usage data. How the builder and your published apps are used (pages viewed, features used, build events), collected through PostHog and our own logs, tied to a random identifier where possible.
- Push subscriptions. If a fan enables notifications for a creator's app, we store the push subscription needed to deliver them.
Creators we haven't met yet
Homescreen can build a preview app from a creator's public posts before that creator signs up — usually because they asked to see one, or because we're showing someone what the product does with their own work. To do that we collect what is already public on their profile: their posts and captions, the dates, the images, engagement counts, and a sample of the comment replies underneath. Creators often continue a recipe in their own reply, so we read the replies to find the rest of it.
We rely on our legitimate interest in demonstrating the product to the creator it's for, and we keep that interest narrow on purpose:
- We delete it after 45 days. If the creator claims the app, the preview becomes their account data and the rest of this policy applies. If they don't, we delete all of it — the text, the images, and everything we worked out from it.
- We don't publish it anywhere they haven't asked us to, we don't sell it, and we never use one creator's posts to build anyone else's app.
- They can stop us at any time. Email axel@gethomescreen.com and we'll delete the preview immediately, or not build one at all. We won't ask for a reason.
If you're a creator and you'd rather we hadn't, tell us and it's gone.
Comments from other people
Where we read the comments under a creator's posts, we store the comment text and the public username that wrote it. We need the username because it's how we tell the creator's own replies apart from everyone else's — that's the only thing we use it for. We don't build a profile of anyone who comments, we don't contact them, and we don't use their comments for anything except understanding the creator's own content.
Comments are deleted with the creator's data, and — unlike the creator's own posts — they are deleted when the creator deletes their account, not kept afterwards. If you commented on a creator's post and want your comment removed from our copy, email us and we'll remove it.
Your fans' data
When fans sign up, subscribe, or save progress inside a creator's app, we process that data on the creator's behalf: the creator is the controller of their audience; we are their processor. We never sell fan data or use one creator's audience to benefit anyone else. Fans can contact the creator or us to exercise their rights.
How we use it
- To build, host, and run your apps — including sending your app descriptions and content to our AI providers to generate your app. Our AI providers do not train on this data.
- To work out the structure of your content — which posts belong to a recurring series, what a recipe's ingredients and steps are, what an image shows — so your app can present it as something better than a feed.
- To operate subscriptions, billing, and creator payouts.
- To understand what's working and fix what isn't.
- To email you about the product — marketing email only with your consent, and every message has an unsubscribe link.
Who we share it with
Only the services that run Homescreen: Clerk (authentication), Stripe (payments and payouts), MongoDB Atlas (database), Fly.io and Cloudflare (hosting and image delivery), PostHog (analytics), Apify (collecting public posts from Instagram), Meta (reading a connected creator’s own account through Instagram’s official API), and our AI model providers — Anthropic, Google, and Replicate — for generating apps and understanding content and images. Each processes data under its own agreement with us. We don't sell personal data. Some providers process data in the United States under standard contractual clauses.
Keeping and deleting data
We keep your account details and billing records while your account is active. If you delete your account, we delete or anonymise your account details and usage data within 30 days, except records we're required to keep, like invoices.
One thing survives account deletion. We keep the library we built from your published content — your posts, captions, images, and the structure we worked out from them — for up to 24 months, and then we delete it automatically. We do this so that if you come back your app is still there rather than starting from nothing, and so we can keep improving how the product understands content like yours. We rely on our legitimate interest, weighed against your privacy. Comments written by other people are deleted at account deletion regardless.
You can override this at any time. Ask us to erase your data and we erase all of it, including that library, within 30 days. “Delete my account” and “erase my data” are two different things here, and you can have either: email axel@gethomescreen.com and say which.
How we protect it
We keep the safeguards you would expect of a service holding a creator's account access and their audience's details.
- Encrypted in transit. Every connection to Homescreen and between our services uses TLS.
- Encrypted at rest. Our database encrypts stored data with AES-256, and uploaded images are held in encrypted object storage.
- Access tokens are held only as long as they are needed. When you disconnect an account, we stop using its token and remove it. Tokens are never shown in our interface, returned by our API, or written to logs.
- Least access. Only the people who need it can reach production systems, and access is tied to individual accounts rather than shared credentials.
- Separation between creators. Every record is scoped to the creator it belongs to, so one creator's content cannot be read while serving another.
No system is perfect. If something goes wrong that affects your data, we will tell you and the relevant regulator where the law requires it. To report a security problem, email axel@gethomescreen.com.
Your rights
Under UK and EU data-protection law you can access, correct, export, restrict, object to, or delete your personal data, and withdraw consent at any time. Where we rely on legitimate interest — the preview apps above, and the library we keep after account deletion — you have the right to object, and you don't have to explain why. Email axel@gethomescreen.com and we'll respond within a month. You can also complain to the ICO (UK) or your local authority.
Cookies
We use the cookies needed to keep you signed in (Clerk) and a first-party analytics identifier. No advertising cookies, no cross-site tracking.
Changes
If this policy changes in a way that matters, we'll say so on this page and, for significant changes, by email.