Haushaus

Last updated October 6, 2026

Privacy policy

What Haus collects, why, and who it is shared with — for the companies that run on Haus and for the homeowners, agents and crew who deal with them through it.

Who we are

Haus is made and operated by rlty.ai (“we”, “us”). It is a back-office platform for home-staging companies: intake forms, quotes, contracts and e-signatures, invoices and payments, a job tracker, inventory, messaging and an AI assistant. You can reach us at hello@rlty.ai.

Two kinds of people use Haus

Companies are the staging businesses that subscribe to Haus and sign in to run their work. Clients are the homeowners, real-estate agents, movers, photographers and other people a company deals with through Haus: someone who fills in a company’s intake form, signs a contract, pays an invoice, follows a job tracker or signs in to a company’s portal.

A company decides what client information goes into Haus and why; we store and process it on that company’s behalf. If you are a client, the company you are dealing with is responsible for how it uses your information, and its own privacy practices apply alongside this policy. Client-facing pages and emails carry that company’s name and logo for the same reason.

What we collect

  • Account details. For each company seat: name, email address, role and a password, which we store only as a hash.
  • Job and client records. Whatever a company or a client enters: names, email addresses, phone numbers, property addresses and listing details, room and package selections, quotes, invoices, notes, tasks, planning boards, messages and uploaded photos, floor plans and documents.
  • Contracts and signatures. The contract as sent, the signature as typed or drawn, and an audit trail of each signing step with its time, IP address and browser identifier. These are kept as legal records of the agreement.
  • Payments. Card and bank payments are processed by Stripe under a company’s own Stripe account. Card and bank numbers are entered on Stripe’s pages and never reach Haus. We keep the amount, the status and Stripe’s reference for each payment, and, when a client saves a payment method, Stripe’s customer and payment-method identifiers so it can be charged again. To act on the company’s behalf we hold the Stripe API key and webhook secret the company gives us, encrypted.
  • Connected accounts. A company may connect its Facebook or Instagram pages and a Google account so its messages, comments and email arrive in one inbox. We store the access tokens (encrypted) and a copy of the messages, comments and email content needed to show and answer those conversations. Google Voice texts and voicemails reach Haus only as the notification emails Google Voice sends to the connected Gmail account.
  • Phone calls. A company may switch on an AI receptionist for its phone number. Calls to that number are answered by an AI agent and recorded and transcribed by our voice provider. The first thing the caller hears says that they are speaking to an AI and that the call is recorded, before anything else is said; a company that writes its own greeting must keep that notice in it. We keep the transcript, a summary, the caller’s number and a log of what the agent looked up or did on the call. The audio recording stays with the voice provider and is not copied into Haus.
  • Live call coaching. A company’s team member can turn on the microphone on the Phone page during a call they’re on. The words are turned into text by the team member’s own browser (Chrome, Edge and Safari use their maker’s speech service to do this), shown on screen, and the transcript so far is sent to our language-model provider to suggest what to say next and to sum up the call when it ends. When the call ends, Haus keeps its transcript, the suggestions shown during it and the summary in the company’s account, where its team can name, read and delete it. Haus does not keep the audio. The screen reminds the team member to ask the other person for consent before recording.
  • Assistant conversations. Questions a company’s team asks the Haus assistant and the assistant’s replies. To answer, the assistant reads the company’s job and client records: leads and contacts, quotes, invoices, tasks, inventory, calendar entries, activity notes, file names and the status of contracts. It does not read connected-account messages or email, team chat, the text of contracts, or phone-call transcripts.
  • Technical data. Standard server logs (IP address, browser, pages requested, timestamps), the cookies described below, and a push-notification subscription (the browser’s push endpoint and keys) if someone turns notifications on.

How we use it

  • To run the service: pricing quotes, producing contracts, collecting signatures, issuing invoices, tracking jobs and inventory.
  • To send the emails and notifications the service is built around: a quote, a contract to sign, an invoice, a tracker link, a payment receipt, a reminder. Companies can also send outreach emails to their own contacts; every one of those carries an unsubscribe link.
  • To show a job’s progress page to anyone who enters its property address on the Status page, once the job has been paid for. That page shows the address, the client’s name and the job’s dates and steps — never prices or access details. As an address is typed, the Status page suggests matching job addresses (street and city only), including jobs not yet paid for, which are shown as not active and lead nowhere.
  • To calculate travel distances and place addresses on a map.
  • To answer questions asked of the assistant and the phone receptionist.
  • To keep the service secure, fix problems and prevent abuse.

We do not sell personal information, and we do not use it for advertising.

Who we share it with

We use these providers to run Haus. Each receives only what its job needs.

  • Vercel hosts the application. Supabase stores the database and uploaded files.
  • Resend delivers email.
  • Stripe processes payments.
  • Google (Maps) and Mapbox receive property addresses for distances and geocoding.
  • Meta and Google (Gmail) exchange messages with Haus when a company connects those accounts.
  • Twilio carries phone calls and ElevenLabs runs the AI receptionist and holds the call audio, when a company turns it on.
  • DeepSeek is the language-model provider behind the assistant. Each question, the recent turns of that conversation, and the job and client records the assistant looks up to answer it (listed under “Assistant conversations” above) are sent to DeepSeek to generate the reply. When a team member uses live call coaching, the transcript of that call so far is sent too. Nothing from connected-account messages, email or the AI receptionist’s calls is sent. DeepSeek processes that data under its own privacy policy, which states that it stores data in the People’s Republic of China.

We also share information when a company asks us to, when the law requires it, or to protect the rights and safety of the people who use Haus.

Google user data

When a company connects a Google account, Haus’s use of information received from Google APIs follows the Google API Services User Data Policy, including its Limited Use requirements. Haus asks for permission to read and send Gmail. That data is used only to show the company’s own conversations inside Haus and to send its replies. It is not used for advertising, not sold, not passed to the assistant or to any AI or language-model provider, and not read by people at rlty.ai except to fix a problem with the company’s consent or as the law requires. A company can disconnect Google at any time from its settings. Disconnecting deletes the stored tokens and stops new mail arriving; the messages already copied into the Inbox stay until the company deletes them or asks us to.

Cookies

Haus sets up to three cookies, none of them for tracking. One keeps a company user signed in and one keeps a client signed in to a company’s portal; each lasts up to 14 days. The third is set only if you turn push notifications on: a random identifier for this browser, kept for a year, so the notification subscription can be found again. There are no advertising or analytics cookies and no third-party analytics scripts. Blocking cookies means you cannot sign in.

How long we keep it

Job and client records stay for as long as the company’s account is active, so it can look back at past work. Signed contracts and their audit trails are kept as records of the agreement, including after the account closes, for as long as the law requires us to keep contract records. Disconnecting a connected account removes its tokens but not the messages already copied into the Inbox; a company can delete those itself or ask us to. A company’s team can delete a saved live call at any time. A company can ask us to delete call transcripts and summaries and assistant conversations at any time. When an account closes, we delete its data within 30 days of the request, apart from the contract records above and anything else we must keep by law. Copies in our database provider’s routine backups expire on their own rolling schedule after that.

Security

Everything travels over HTTPS. Passwords are stored only as salted hashes. Connected-account tokens, the Stripe key and webhook secret a company gives us, and any Maps API key it gives us are encrypted at rest (AES-256-GCM) under a key held outside the database. Every record carries the company it belongs to, and every query the application makes is limited to the signed-in company. No system is perfectly secure; tell us at hello@rlty.ai if you think something is wrong.

Your choices

  • If you are a client, ask the company you dealt with to see, correct or delete your information. We will help them do it.
  • If you are a company, you can edit or delete most records yourself, disconnect any connected account, and ask us to close the account and delete its data.
  • Every outreach email has an unsubscribe link. Using it stops all further outreach from that company.
  • Turn push notifications off from the bell in the app, or from your device’s settings. Turning them off removes the subscription from our records.

Children

Haus is a business tool and is not intended for anyone under 18. We do not knowingly collect information from children.

Changes

When this policy changes we will update the date at the top and, for meaningful changes, tell companies by email. Continuing to use Haus after a change means you accept the updated policy.

Contact

Write to hello@rlty.ai with any question about this policy or your information.