← CasaCaddy
Privacy Policy
Last updated July 29, 2026
The short version
CasaCaddy has no account or sign-in and does not ask for your name, email, or street address. Your editable home inventory, maintenance schedule, saved photos, history, and three-digit ZIP prefix live on your device. Appliance scans send photos for AI processing and create the limited server records described below.
What we process
- Transient appliance photos. The unit photo and any optional model-plate photo are sent over an encrypted connection to our API and an AI model provider to perform recognition. CasaCaddy processes those image bytes in request memory and does not persist the photos in its database or server file storage after the request. The original photo you choose to save remains on your device. We retain a cryptographic hash of the primary image so an identical re-upload can reuse a result without another AI call.
- Recognition content. We retain the complete result returned for a scan: category, item name, brand, model, serial number, confidence, specifications, estimated age, and suggested maintenance tasks. The record also includes the image hash, AI model used, request cost/token counts, timestamp, and anonymous installation ID.
- An anonymous installation identifier and app version.The app stores a server-issued random device ID and credential in Keychain. Our server stores only a hash of the credential. These values connect recognition records, daily usage, generated guides, and purchase status for that installation; they are not linked by CasaCaddy to a name, email address, Apple ID, or advertising identifier.
- Product interaction and usage. We retain per-day AI recognition and fresh-guide counts for quota enforcement. A generated guide cache contains the guide, model used, hit count, timestamps, a hashed cache key derived from the request, and the anonymous device that created it. A lifetime free-scan count is kept only in Keychain on your device for abuse prevention.
- StoreKit purchase status.Apple processes payment. We process Apple's signed product, transaction and original transaction IDs, Production/Sandbox environment, purchase/signing dates, expiration, and revocation status to determine Pro access. We retain those current entitlement facts and tier on the anonymous device record, but not the signed transaction itself, payment-card details, or Apple ID. A separate entitlement-lifecycle record uses keyed HMAC-SHA-256 pseudonyms of the Production/Sandbox transaction scope and transaction ID. It retains the product, purchase/signing/event dates, effective expiration, revocation/refund-reversal status, and active/grace/inactive state so a saved pre-refund transaction cannot restore access after device deletion. It is stored separately and contains no raw transaction or device identifier. While an anonymous device record exists, CasaCaddy can associate the two by pseudonymizing that record's transaction scope with the service-held key. Verified App Store server notifications are recorded in a minimal 400-day retry ledger. It contains cryptographic hashes of the notification UUID and signed event facts, plus keyed HMAC pseudonyms for the transaction scope and ID; the environment, notification type/subtype and signed date; processing outcome and attempt count; and receipt/processing times. It does not contain the raw notification payload, notification UUID, or transaction identifiers.
- Your three-digit ZIP prefix. ZIP entry is required during setup so the app can choose a climate schedule. Only the first three digits are saved, and they stay on your device. CasaCaddy does not upload them to its API or put them in contractor-search links.
What we never collect
Through the app and CasaCaddy API, we do not collect your name, email, phone number, street address, precise location, contacts, advertising identifier, or analytics profile. We do not sell data or use it for cross-app tracking. There are no third-party ads or analytics SDKs in the app. If you email support or follow a contractor-search link, your email provider or the destination service handles the information you choose to provide under its own policy.
Service providers
Vercel hosts the API, Neon hosts the database, and OpenRouter routes recognition and guide requests to AI model providers. They receive data needed to provide, secure, and operate those services, and their own terms and retention policies apply. Apple handles StoreKit purchases. CasaCaddy does not make a broader promise about a provider's training or log retention than that provider's current terms support.
Retention and deletion
CasaCaddy does not persist raw scan photos on its servers after a recognition request finishes. Server device, recognition, daily-usage, purchase-status, and guide-cache records linked to your installation are retained until you delete them in Settings. The pseudonymous entitlement lifecycle high-water is retained for the operating life of the purchase service for replay/fraud prevention. After attributed device rows are deleted, no stored installation link remains; if an Apple transaction is presented later, the service can still compare its pseudonym with that record to prevent replay. The record cannot recreate deleted content. “Delete home and server data” first authenticates and atomically deletes those attributed server rows; only after success does it remove the anonymous identity and local home data. If a step fails, the app says what was and was not removed and lets you retry. If server deletion committed but its response or later local cleanup failed, the same server-signed credential can confirm the row is already absent during its bounded recovery window; CasaCaddy does not retain a deletion tombstone or treat a generic unauthorized response as proof of deletion. On each verified notification delivery, the processor removes retry-ledger rows older than 400 days. The ledger cannot recreate a deleted anonymous device or its attributed content when Apple retries a notification. Hosting, network, and AI providers may retain operational or security records under their own policies.
Your data, your exit
Your local inventory is exportable from Settings as JSON plus photos on every tier. Deleting the app removes its app-container data, but Keychain values and server records may survive an uninstall. Use “Delete home and server data” before uninstalling to erase attributed server content and the anonymous identity. The local lifetime AI-scan count remains in Keychain after that action and reinstall solely to prevent repeated free-tier resets. Deleting data does not cancel an active Apple subscription; use Manage Subscription in CasaCaddy Settings or Apple billing support. For deletion help, contact john@soxoa.com.
Contact
Questions: john@soxoa.com. CasaCaddy is a Soxoa product.