Privacy

This page explains what happens to the documents you upload and the information we hold about you. It is written to be read, not to be survived — if anything here is unclear, ask us and we’ll fix the wording.

Home Decoded is operated by Winlex (ABN 25910096373), in New South Wales, Australia. We handle personal information in accordance with the Privacy Act 1988 (Cth) and the Australian Privacy Principles.

Your documents

We never keep your documents. They're deleted the moment your report is ready. Your report quotes short excerpts from them and is stored until you delete it — we mask personal names where detected, and we never store the full text.

Concretely, here is the whole lifecycle:

  • Your browser uploads each PDF directly to private storage using a short-lived signed link. The files do not pass through our website at any point.
  • The analysis job downloads them, extracts the text and renders scanned pages as images, and sends that content to Anthropic for analysis.
  • When your report is ready, the uploaded files are deleted. If a job fails or is abandoned, an automatic sweep deletes them anyway — nothing is left behind because something went wrong.
  • The extracted full text is never written to a database or a log. It exists in memory during the run and nowhere else.

What your report keeps

Your report contains short verbatim quotes from your documents, with page numbers. That is the entire point of the product — a finding without its quote is just an assertion — so we cannot store your report without storing those excerpts. It also holds the property address, because a report that does not say which property it is about is not much use.

Where we detect personal names in extracted content, we mask them before the report is stored. This is best-effort detection, which is why we say “where detected” rather than promising it catches everything. Your report is kept until you delete it, and you can delete it at any time.

Who else touches your information

We use other companies to run the service. The important distinction is which of them can see your documents and which only see an account:

WhoWhat they doSees documents?
AnthropicDocument analysis (the AI model)Receives extracted text and page images for the duration of the analysis.Yes
SupabaseAccounts, database, and temporary document storageHolds your uploaded PDFs in a private bucket until your report is ready.Yes
Trigger.devRuns the analysis jobHolds document content in memory while the analysis runs. Nothing is retained.Yes
VercelWebsite hostingYour documents upload straight to storage and never pass through our web host.No
StripePaymentsReceives your payment details directly. We never see or store your card number.No

Some of these providers process data outside Australia, including in the United States. By uploading documents you consent to that transfer. Payment card details go straight to Stripe and never reach us — we never see or store a card number.

Your documents are not used to train AI models

Anthropic analyses your documents and does not use them to train its models. We do not keep a copy to train anything of our own either — there would be nothing to train on, because we delete them.

What else we hold

  • Your account — email address and sign-in records.
  • Your credit balance and purchase history, so we can tell you what you have and reconcile a payment if something goes wrong.
  • Usage records — how many tokens an analysis used, what it cost us, how long it took. Numbers only. No document content can appear here by design.
  • Messages you send us through the contact form, so we can reply.

Your rights

You can access the personal information we hold about you, ask us to correct it, delete any report from your history yourself, or ask us to close your account and remove your data entirely. Email contact@homedecoded.com.au and we’ll action it.

If you think we’ve mishandled your information, tell us first — we’d rather fix it. If you’re not satisfied with our response, you can complain to the Office of the Australian Information Commissioner at oaic.gov.au.

Security

Documents are held in a private bucket that is not publicly readable, reachable only through short-lived signed links. Database access is restricted per-user at the database level, so one customer’s reports are not reachable from another customer’s session. No system is perfectly secure, and we will tell you promptly if a breach affects you.

Changes

If we change this page in a way that affects what happens to your documents, we’ll say so rather than quietly updating the date.

Last updated 20 August 2026.