Draft under legal review. It describes how we intend to operate and is not yet in effect.
Privacy Policy
This policy explains what information OpenPermits (HomeReceipt) handles: about you as a customer, and about people who appear in the public records we publish.
Customers and visitors
- Account details: your name, email, organization name, password (stored only as a salted hash) and, if you turn it on, your two-factor secret (encrypted).
- Billing: Stripe processes payments. We keep your Stripe customer and subscription identifiers and plan status, never your card number.
- Usage: API and app requests (time, path, status, records returned, the key used). The per-request log is deleted after 14 days; daily totals are kept for billing and support.
- What you save: saved searches, webhook URLs (signing secrets are encrypted) and delivery history, kept while your account is active.
- Cookies: one session cookie that keeps you signed in and a short-lived one during two-factor sign-in. No advertising or cross-site tracking cookies.
We use this information to run the Service, bill for it, keep it secure, answer support requests and tell you about changes to your account. We don't sell it. We share it only with processors who run parts of the Service for us (hosting, payments, email delivery), under contracts that limit their use, or when the law requires.
People in public records
Permits, licenses, parcels and zoning decisions are public records published by governments. We republish property and business details from them. We deliberately leave out owner and applicant names and residents' phone numbers, even where the source includes them. Contractor business names, licenses and business addresses stay, because they identify licensed businesses.
If a record we publish contains your personal information, or is wrong, you can ask us to correct or remove it: see record correction and removal.
Your choices and rights
You can update your account details in the app and ask us to delete your account by emailing data@openpermits.ai. Depending on where you live (for example, California), you may have rights to know, correct or delete personal information we hold about you and to not be discriminated against for using them. We'll verify requests before acting on them and answer within the time the law requires.
Security
Passwords and API keys are stored as hashes, secrets we need to use are encrypted, connections use HTTPS, and staff access is limited and requires two-factor authentication. No system is perfectly secure; if we learn of a breach affecting your information we'll tell you as the law requires.
Changes and contact
We'll post changes here and email account owners about material ones. Questions: data@openpermits.ai.
Last updated Sep 25, 2026.