What we collect
Account details: your name, email address, and a password. The password is stored only as a hash by our authentication provider; we never see it.
Project details you enter: a project name and, if you add it, the property address.
The bids you upload — PDFs, photos, spreadsheets, or pasted text — and the line items, contractor contact details, and totals we extract from them.
Expenses and tasks you log against a project, including any receipt photos you attach.
Payment records: that a project was paid for, when, and the identifier of the payment. Your card number never reaches us; see Payments below.
Technical records: errors the app hits, and a sample of anonymised session recordings used to reproduce them. See Error reporting below.
We do not run advertising trackers, third-party analytics, or marketing pixels on the site or in the app.
How we use it
To do the one thing the product does: read your bids, line them up by trade, flag what each one leaves out, write the questions to ask, and carry the winning bid forward as a budget.
To keep your account working — signing you in, sending password resets and confirmation emails, and confirming payment.
To answer support requests you send us.
We do not sell your data, rent it, or share it with contractors, other users, or advertisers.
AI processing
To read a bid, RehabRocket sends its text or image to Anthropic's API, which returns the extracted line items. The comparison analysis (gaps, questions, and price hints) is produced the same way from the extracted data.
Anthropic processes this under its commercial API terms. Your bids are not used to train models, are not pooled into a dataset, and are not sold.
Extraction is imperfect. Every extracted line is editable in your account, and the price hints are a rough gauge from general knowledge, not local pricing data.
Who can see your data
You. Your projects, bids, budgets, and tasks are visible only to the account that created them.
Us, when we need to look — to fix a problem you have reported, or to investigate abuse. We do not browse customer projects otherwise.
The service providers listed below, each only for the purpose named.
Service providers
- Supabase — account authentication, the database, and file storage for uploads and receipts.
- Vercel — hosting for the site and the app.
- Anthropic — the AI model that reads bids and produces the analysis.
- Stripe — payment processing. Stripe collects your card details on its own hosted checkout page and handles them under its privacy policy; we receive a payment confirmation and a customer reference, not your card number.
- Resend — sends our email: account confirmations, password resets, and the optional follow-ups described below.
- Sentry — error reporting and session replay, described below.
Each provider is bound by its own terms to use the data only to provide its service to us.
Error reporting and session replay
When something breaks, the app sends an error report to Sentry so we can fix it. Reports do not include personal details by default.
Sentry also records a replay of roughly one in ten sessions, and of every session in which an error occurs. Text and images in replays are masked, so the recording shows the shape of the screen, not the contents of your bids.
Follow-up emails
The free templates on the site can be downloaded without giving us anything. Beside the download there is an optional email field. If you use it, we send two emails: one about a week later asking whether your scope went out to contractors, and one about three weeks later when bids are usually back. That is the whole series.
Every one of those emails has an unsubscribe link, and unsubscribing takes one click and no account. You can also email support@rehabrocket.com. We keep the address only to send that series; it is not added to any other list and not shared.
We do not send marketing email to account holders. Account emails (confirmation, password reset, payment confirmation) are transactional and cannot be unsubscribed from while you hold an account.
How long we keep it, and how to delete it
Your projects stay in your account until you delete them or ask us to. There is no expiry on a paid project; that is part of what you paid for.
To delete a project, an upload, or your whole account, email support@rehabrocket.com from the address on the account. We will delete the data within 30 days and confirm by reply. Payment records are kept as long as tax and accounting rules require.
Backups of the database are retained for a short period after deletion and then cycle out.
Security
Data travels over HTTPS. Uploads are stored in private buckets and served through short-lived signed links. Access to production systems is limited to the people who run the product.
No system is perfectly secure. If we learn of a breach affecting your data, we will tell you by email.
Children
RehabRocket is for adults managing renovation projects. We do not knowingly collect data from anyone under 18.
Changes to this policy
If we change this policy in a way that matters, we will update the date at the top and, for significant changes, email account holders. Continued use after a change means you accept it.
Contact
Integryl LLC, operating RehabRocket. Email support@rehabrocket.com.