Last updated: September 10, 2026
YardRule exists to keep records, so we take what goes into those records seriously. This policy explains what we collect, why, who processes it, and the choices communities and owners have. For most resident data, the condominium corporation or association decides what is collected and why, and YardRule processes it on the community's instructions.
Name, email address, and optional phone number for board members and invited owners; authentication credentials are handled by Supabase Auth and we never see passwords in plain text.
Property addresses, issue reports, notices, owner responses, and the append-only audit trail — entered by your board in the course of its compliance work.
Issue photos may carry embedded EXIF metadata, including GPS coordinates and capture time. YardRule preserves this metadata deliberately — it records where and when a photo was taken — and displays it to the board alongside the photo. Boards should photograph only what their compliance work requires.
Audio recorded by the board, its transcript, and any email threads the board imports. These are visible to board members only — never to owners — and recordings require an explicit all-party consent confirmation before they start. Imported emails support redaction before export.
Payment is processed by Stripe; we store only the Stripe customer reference and subscription status.
We record a small number of first-party product events — for example that the public demo was opened, a sample PDF was downloaded, or a signup was started (with the page it came from and any pilot code used) — to understand how the service is used. These events use no cookies and are not shared with advertisers.
The sample PDFs on the public demo are free. Your browser keeps a count of how many you have taken, and after the second one we ask for an email address before the next download. We store that address, which sample prompted it, the page you asked from, and any pilot code in the link — so we know which of our letters or posts a reader came from. We only send you anything beyond the file you asked for if you tick the box saying so, and every such email carries an unsubscribe. Ask us at support@yardrule.app and we will delete the address.
We use only what the product needs to function: an authentication session, a theme preference, and the sample-download count described above, all stored in your browser rather than sent to us. No advertising trackers, no third-party analytics cookies.
To provide the service: maintaining records, delivering notices by email, generating PDFs, and, where those features are enabled, transcribing recordings and drafting AI-assisted documents. We do not sell personal information, and we do not use community records to train AI models. Content sent to an AI subprocessor is used only to produce the requested draft.
These providers process data on our behalf, each limited to the purpose listed. Providers marked “not currently enabled” receive no data until that feature is switched on, and features tied to an optional provider stay off if the community never uses them.
| Provider | Purpose | Data involved |
|---|---|---|
| Supabase | Database, authentication, and file storage | All community records, account credentials, uploaded files |
| Render | Application hosting | Request data in transit |
| Stripe | Subscription billing | Billing contact and payment details (card numbers never touch our servers) |
| Resend | Transactional email delivery | Recipient email addresses and notice contents |
| Twilio | SMS notice notifications (not currently enabled) | Recipient phone numbers and short notice alerts |
| Deepgram | Meeting audio transcription (not currently enabled) | Meeting recordings submitted for processing |
| Anthropic | AI drafting: summaries, minutes, email cleanup (not currently enabled) | Transcripts and imported email text submitted for processing |
| Mapbox | Address verification and geocoding (not currently enabled) | Property addresses entered by the board |
Where data is stored. These providers store and process data primarily in the United States, so community data may be stored or processed outside Canada. Wherever it is processed, it remains protected by our contracts with these providers and the safeguards described in this policy, but it may be subject to the laws of the jurisdiction where it is held.
Records are kept for as long as the community account exists — durable history is the product. A board admin can export the community’s complete data from Settings at any time, and can permanently delete the community, which removes its database records, stored files, and member sign-ins. Owners seeking correction or deletion of their information should contact their condominium corporation or association; we assist communities in honoring such requests, and you can also reach us at support@yardrule.app.
Data is encrypted in transit and at rest by our hosting providers. Every database table carries row-level security policies scoped to the community; sensitive files live in private buckets accessible only through expiring signed URLs; the audit trail is append-only so history cannot be silently rewritten from inside the product. No system is perfectly secure — if we learn of a breach affecting your data we will notify affected communities without undue delay.
Depending on where you live (including under PIPEDA in Canada), you may have rights to access, correct, or receive a copy of your personal information. Owners can view their records in the portal and update their contact details directly; for anything else, contact your condominium corporation or association and we will support its response. We have designated a privacy officer accountable for compliance with this policy; reach them (and us) at support@yardrule.app.
YardRule is not directed at children and we do not knowingly collect information from anyone under 16. We may update this policy; material changes will be announced in the product with reasonable notice.