Anthoam
Loading...
Anthoam
Sign In
Back to Home

Privacy Policy & User Agreement

Last Updated: June 10, 2026Version 1.3

1. Introduction

HOAM App, LLC dba Anthoam ("Anthoam," "we," "us," or "our") is committed to protecting your privacy. This Privacy Policy & User Agreement ("Policy") describes how we collect, use, disclose, and safeguard your information when you use the Anthoam platform ("Platform"). Please read this Policy carefully. By using the Platform, you agree to the collection and use of information in accordance with this Policy.

2. Information We Collect

2.1 Information You Provide

  • Account Information: Name, email address, password, phone number, and role within your HOA community
  • Profile Information: Unit number, residency type (owner-occupant, tenant, non-resident owner), mailing address, and emergency contact details
  • Financial Information: Payment method details (processed by Stripe; we do not store full credit card numbers), dues payment history, and financial product enrollment data
  • Communication Data: Messages sent through the Platform's direct messaging system, maintenance requests, announcements, and community communications
  • Documents: Files uploaded to the Platform such as HOA governing documents, meeting minutes, financial reports, and community records
  • Voting Data: Votes cast in community polls and elections, including vote selections and timestamps
  • Amenity Booking Data: Reservation details, booking dates, times, and facility preferences
  • Vendor Information: Vendor contact details, service records, contract information, and performance notes submitted by property managers
  • Move-In/Move-Out Data: Inspection records, deposit tracking information, key management records, and related workflow data
  • Beta/Lead Request Information: Property details, community information, and notes submitted through our access request forms

2.2 Information Collected Automatically

  • Usage Data: Pages visited, features used, timestamps, and interaction patterns
  • Device Information: Browser type, operating system, device identifiers, and screen resolution
  • Log Data: IP addresses, access times, referring URLs, and error logs
  • Notification Preferences: Your email notification settings and communication preferences

2.3 AI-Generated Content

When you use AI-powered features (such as Ask Anthoam or document analysis), your inputs may be processed by third-party AI services. The responses generated by these services are stored on the Platform as part of your interaction history. We minimize personally identifiable information sent to AI providers and use data processing provisions available under their business terms.

3. How We Use Your Information

We use the information we collect to:

  • Provide, maintain, and improve the Platform and its features
  • Process payments and manage financial transactions
  • Facilitate communication between community members, managers, and board members through direct messaging and announcements
  • Send notifications about community events, maintenance updates, voting deadlines, amenity bookings, and account activity
  • Conduct and tally community votes and polls
  • Manage amenity reservations and booking schedules
  • Facilitate document storage, organization, and sharing within communities
  • Support vendor management and service tracking
  • Process move-in/move-out workflows and capital project tracking
  • Respond to your inquiries and support requests
  • Generate financial reports, analytics, and community insights
  • Detect, prevent, and address technical issues and security threats
  • Comply with legal obligations and enforce our Terms of Service
  • Power AI-assisted features such as Ask Anthoam responses, document analysis, and intelligent search (using anonymized or aggregated data where possible)

4. Third-Party Services

We share information with the following third-party service providers to operate the Platform:

Google Cloud

Hosting and storage. The Platform runs on Google Cloud, and uploaded files and photos are stored in Google Cloud Storage with encryption at rest.

Stripe

Payment processing. When you make a payment, your payment information is transmitted directly to Stripe (a PCI DSS Level 1 certified provider). We receive transaction confirmations but do not store full payment card details. Stripe's privacy policy governs their handling of your data.

Resend

Email delivery. We use Resend to send transactional emails including account verification, password resets, payment receipts, and community notifications. Your email address and message content are shared with Resend for delivery purposes.

OpenAI

AI-powered features. Certain features (such as Ask Anthoam, intelligent document analysis, and smart search) use OpenAI's API. We minimize personally identifiable information sent to OpenAI and use the data processing provisions available under OpenAI's business terms. AI-generated responses are for informational purposes only.

Twilio

SMS delivery. For members who opt in to text notifications, we share the mobile number and message content with Twilio for delivery. We do not share mobile numbers for third-party marketing.

Sentry

Error monitoring. We use Sentry to detect and diagnose technical errors so we can fix them quickly. Diagnostic data may include limited technical context about the request that failed.

5. Data Sharing & Disclosure

We may share your information in the following circumstances:

  • Within Your Community: Your name, unit number, and community role are visible to other members of your HOA as needed for community management. Your votes in community polls may be visible to managers and board members depending on poll configuration.
  • Property Managers & Board Members: Authorized managers and board members can access resident information, payment records, messaging logs, voting data, amenity bookings, and community data for management purposes
  • Financial Product Partners: If you enroll in third-party financial products (e.g., home warranties, insurance), your contact and relevant information may be shared with the product provider
  • Legal Requirements: We may disclose your information if required by law, legal process, or governmental request
  • Business Transfers: In connection with a merger, acquisition, or sale of assets, your information may be transferred to the acquiring entity
  • With Your Consent: We may share your information for any other purpose with your explicit consent

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide you services. Financial transaction records are retained for a minimum of seven (7) years to comply with accounting and tax requirements. Community records, documents, and voting data are retained for the duration of the HOA's use of the Platform. Direct messages are retained as long as your account is active and for a reasonable period afterward. Upon account termination, we will delete or anonymize your personal information within ninety (90) days, except where retention is required by law or for legitimate business purposes. You may request deletion of your data by contacting us at support@anthoam.com.

Canceled communities. When a community's subscription is canceled, we retain the community's data and uploaded files for ninety (90) days so the community can reactivate it or export its data during that window. At the end of the 90-day window, the community's data and uploaded files are permanently deleted and cannot be recovered, except where longer retention is required by law (for example, the financial transaction records described above). If a community pauses its subscription instead of canceling, its data and uploaded files are preserved for the duration of the pause.

7. Data Security

We implement appropriate technical and organizational measures to protect your personal information, including:

  • Encryption: data is encrypted in transit (HTTPS/TLS) and at rest, meaning stored data is scrambled on disk and unreadable from the raw storage files alone.
  • Trusted infrastructure: the Platform is hosted on Google Cloud, and payments are processed by Stripe so card data never touches our servers.
  • Role-scoped access: managers, board members, and residents can only access the data their role permits, enforced server-side.
  • Authentication: secure authentication with optional two-factor authentication (2FA).
  • Request protection: CSRF protection on state-changing requests to block forged actions from other sites.
  • Auditing: audit logging on sensitive administrative actions, plus ongoing error monitoring and security review.

However, no method of transmission over the Internet or method of electronic storage is 100% secure, and we cannot guarantee absolute security.

Reporting a vulnerability: if you believe you've found a security issue, please report it responsibly to security@anthoam.com and give us a reasonable opportunity to address it before public disclosure. We aim to acknowledge reports within five (5) business days.

8. Your Rights & How to Exercise Them

Depending on your location, you may have the following rights:

  • Access: Request a copy of the personal information we hold about you
  • Correction: Request correction of inaccurate or incomplete personal information
  • Deletion: Request deletion of your personal information, subject to legal retention requirements
  • Portability: Request a copy of your data in a structured, machine-readable format
  • Opt-Out: Opt out of certain data processing activities, including marketing communications

How to submit a request: If you have a Anthoam account, you can submit data export and account deletion requests directly from your Settings > Data & Privacy page. Alternatively, you can email us at support@anthoam.com. We will respond to your request within thirty (30) days.

9. California Privacy Rights (CCPA) & Do Not Sell

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):

  • Right to Know: You have the right to request that we disclose the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purpose for collecting it, and the categories of third parties with whom we share it
  • Right to Delete: You have the right to request deletion of your personal information, subject to certain exceptions
  • Right to Non-Discrimination: We will not discriminate against you for exercising any of your CCPA rights
  • Do Not Sell: We do not sell your personal information to third parties. You can formally opt out using the control below

To submit a CCPA request, contact us at support@anthoam.com or use the data request tools available in your account settings. We may need to verify your identity before processing your request.

Do Not Sell My Personal Information

Under the California Consumer Privacy Act (CCPA), you have the right to opt out of the sale of your personal information. While Anthoam does not sell your personal data to third parties, we provide this control so you can formally express your preference.

No opt-out preference set

You are not currently logged in. Your preference is saved in this browser. Log in to save it to your account.

10. Cookies & Tracking

The Platform uses session cookies and local storage to maintain your authentication state and preferences. We use essential cookies necessary for the Platform to function properly. We do not use advertising or third-party tracking cookies. You can configure your browser to reject cookies, but this may limit your ability to use certain features of the Platform.

When you first visit the Platform, a cookie consent banner will appear allowing you to accept or decline the use of cookies. Your choice is stored locally and the banner will not reappear once you have made a selection. If you decline, essential session cookies required for authentication may still be used as they are necessary for the Platform to function.

11. GDPR — European Data Protection Rights

If you are located in the European Economic Area (EEA), the United Kingdom, or Switzerland, you have additional rights under the General Data Protection Regulation (GDPR) and equivalent local legislation. This section supplements the rest of our Privacy Policy.

Lawful Basis for Processing

We process your personal data on the following legal bases:

  • Contract Performance: Processing necessary to fulfill our obligations under your service agreement (e.g., account management, payment processing, community features)
  • Legitimate Interests: Processing for our legitimate business interests, such as improving the Platform, preventing fraud, and ensuring security, where those interests are not overridden by your data protection rights
  • Consent: Processing based on your freely given consent, such as marketing communications or optional AI features. You may withdraw consent at any time
  • Legal Obligation: Processing necessary to comply with applicable laws and regulations

Data Subject Rights

Under the GDPR, you have the following rights:

  • Right of Access: Obtain confirmation of whether we process your data and request a copy of it
  • Right to Rectification: Request correction of inaccurate or incomplete personal data
  • Right to Erasure ("Right to Be Forgotten"): Request deletion of your personal data, subject to legal retention obligations
  • Right to Data Portability: Receive your personal data in a structured, commonly used, machine-readable format and transmit it to another controller
  • Right to Object: Object to processing based on legitimate interests, including profiling and direct marketing
  • Right to Restrict Processing: Request restriction of processing under certain circumstances while we verify or resolve concerns

To exercise any of these rights, please contact our Data Protection Officer at the email below. We will respond within thirty (30) days. You also have the right to lodge a complaint with your local data protection supervisory authority.

Cross-Border Data Transfers

Your personal data may be transferred to, stored, and processed in the United States or other countries outside the EEA. When we transfer personal data outside the EEA, we ensure appropriate safeguards are in place, including Standard Contractual Clauses approved by the European Commission, adequacy decisions, or other legally recognized transfer mechanisms. You may request a copy of the applicable safeguards by contacting us.

Data Protection Officer

Anthoam — Data Protection Officer

Email: support@anthoam.com

12. Children's Privacy (COPPA)

The Platform is not directed at children under the age of 13 and is not intended for use by children. In compliance with the Children's Online Privacy Protection Act (COPPA), we do not knowingly collect, use, or disclose personal information from children under 13. If we become aware that we have inadvertently collected personal information from a child under 13, we will take steps to delete such information promptly. If you believe a child under 13 has provided us with personal information, please contact us at support@anthoam.com.

13. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Policy on the Platform and updating the "Last Updated" date. Your continued use of the Platform after any changes indicates your acceptance of the updated Policy.

14. SMS / Mobile Messaging

If you opt in to receive SMS text messages from Anthoam, this section describes the messages we send, how often, the costs you may incur, and how we handle your mobile phone number. By providing your mobile phone number and checking the consent box on the SMS opt-in surface in your account, you agree to the terms in this section.

Message Types

All Anthoam text messages are operational and transactional, including: account verification codes, maintenance and work-order updates, payment and billing reminders, operational community notices from your manager or board, including emergency alerts, governance notices (voting, board meetings), and (for vendors) quote invitations. "Community notices" are operational messages a community's manager or board sends to its own residents through Anthoam; they are not Anthoam marketing. Anthoam does not send promotional or marketing text messages, and we do not request consent for marketing.

Message Frequency

Message frequency varies based on community activity and the events you are subscribed to. You may receive multiple messages per week during periods of active community business and few or none during quiet periods.

Message & Data Rates

Msg & data rates may apply. Standard message and data rates from your mobile carrier may apply to messages you send to or receive from Anthoam, depending on your mobile service plan. Anthoam does not charge a fee for receiving SMS messages.

HELP and STOP

Reply HELP to any Anthoam text message for help, or email support@anthoam.com. Reply STOP to any Anthoam text message to opt out at any time. After opting out, you will receive a confirmation message and no further SMS from Anthoam. You may also remove your mobile number from your account at Settings → Notifications.

Non-Sharing of Mobile Numbers

Mobile phone numbers and SMS opt-in consent records are used solely to deliver the messages described above and to support account security. We do not sell, rent, or share mobile phone numbers or SMS opt-in data with third parties or affiliates for marketing or promotional purposes. The only third parties that receive your mobile number are the telecommunications providers necessary to deliver your messages (e.g., Twilio and downstream carriers).

Consent Records

When you opt in, we record the timestamp, IP address, user agent, and the exact consent text you agreed to. These records are retained as long as your account is active and for a reasonable period afterward to demonstrate compliance with applicable law and carrier requirements.

The public mirror of the SMS opt-in disclosure is available at /sms-opt-in.

15. Contact Us

If you have questions or concerns about this Privacy Policy or our data practices, please contact us at support@anthoam.com.

DISCLAIMER: This Privacy Policy & User Agreement is provided as template language for the Anthoam platform. It has not been reviewed by legal counsel and should not be considered legal advice. Anthoam recommends consulting with a qualified attorney to review and customize this policy for your specific needs and to ensure compliance with applicable laws.