Privacy Policy
Effective Date: January 6, 2026
This Privacy Policy explains how OpenHOA ("the Platform," "we," "us") collects, uses, stores, and protects information. The Platform is designed as an observational research system with strong privacy-preserving controls and data-minimization principles.
See also: Public Overview
1. Guiding Privacy Principles
The Platform is built around the following principles:
- Data minimization: Collect only what is necessary to support research and analytics.
- Aggregation by default: Public outputs are aggregated and anonymized.
- Separation of layers: Reports, evidence, analytics, and contributor metadata are stored and accessed separately.
- Harm reduction: Prevent re-identification, doxxing, and misuse of sensitive information.
- Auditability: Administrative access and changes are logged.
2. Information We Collect
2.1 Contributor Account Information
Contributor accounts are required to support auditability, abuse prevention, and fair evaluation of submissions. In connection with account creation and report submission, the platform may collect:
- Username or account handle
- Email address (stored securely for authentication and communication)
- Account holder name (not publicly displayed)
- Account creation date and activity metadata
- Role designation and permission level
This information is used solely for platform operation, security, and integrity purposes. Personally identifiable information is not included in public views, aggregated analyses, or published outputs.
2.2 Report Data (User Submissions)
When a report is submitted, the Platform may collect:
- Selected HOA and general location indicators (e.g., ZIP code–derived lookup)
- Violation category (from a controlled taxonomy)
- Reported date
- Optional free-text summary
- Confidence-related metadata (status, timestamps, history)
Exact street addresses are not stored in the analytics layer. If temporarily processed for deduplication or sequence detection, they are immediately transformed into non-reversible linkage tokens and discarded.
2.3 Uploaded Evidence
Submission of a report requires uploading the associated notice or communication (including PDFs or email files) to provide contextual grounding and support review.
All uploaded evidence is handled as follows:
- Stored in restricted, access-controlled systems
- Processed through automated PII detection and redaction
- Reviewed internally using redacted versions only
- Never displayed publicly or released in raw form
Contributors remain responsible for the legality of submitted materials, including any personal information contained therein. The platform does not verify ownership or authorization of submitted documents and relies on contributors to comply with applicable legal requirements.
2.4 Technical and Security Signals
To protect data integrity and prevent abuse, the Platform collects limited technical signals, including:
- Privacy-preserving device fingerprints
- Hashed IP-related indicators
- Submission timing patterns
- Account age and activity counts
These signals are used only for security, anti-gaming detection, rate limiting, and trust scoring. They are not used for advertising or tracking across other sites.
3. How We Use Information
We use collected information to:
- Generate aggregated research analytics
- Assess confidence levels and issuer plausibility
- Detect corroboration and reduce coordinated manipulation
- Moderate content and resolve disputes
- Maintain platform security and reliability
We do not sell personal data or use it for targeted advertising.
4. Public vs. Restricted Data Access
4.1 Public Access
Unauthenticated users may view:
- Aggregated HOA-level or grid-level analytics
- Normalized and confidence-weighted statistics
- Trends and comparisons that meet minimum sample thresholds
Public views never include:
- Individual reports
- Contributor identities
- Exact locations
- Raw or redacted evidence documents
- Platform-generated interpretations of individual enforcement actions
4.2 Administrative Access
Moderators and administrators may access:
- Individual reports (for moderation and dispute resolution)
- Redacted evidence previews
- Confidence histories and audit trails
All such access is role-restricted and logged.
5. Data Retention
- Account and report metadata may be retained for research continuity.
- Evidence documents may be retained in redacted form for audit and dispute purposes.
- Trust and confidence histories are retained to preserve analytic integrity.
- Data may be deleted or anonymized upon lawful request, subject to technical and research constraints.
- Retention periods may evolve and will be documented if materially changed.
6. Disputes, Corrections, and Deletions
Users, HOAs, and management companies may request:
- Review of specific reports
- Adjustments to confidence levels
- Annotations noting disputed interpretations
- Removal or suppression of content where appropriate
Corrections are handled through documented moderation workflows and do not imply fault or wrongdoing.
7. Data Sharing
We do not share personal data with third parties except:
- When required by law, regulation, or court order
- To trusted service providers strictly necessary for platform operation (e.g., hosting, security), under confidentiality obligations
- Aggregated, anonymized datasets may be used for academic or public-interest research
8. Security Measures
We employ reasonable technical and organizational safeguards, including:
- Access controls and role-based permissions
- Encryption in transit and at rest where appropriate
- Audit logs for sensitive actions
- Rate limiting and abuse detection
No system is completely secure, and users submit information at their own risk.
9. Children's Privacy
The Platform is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from minors.
10. Changes to This Policy
This Privacy Policy may be updated as the Platform evolves. Material changes will be reflected by an updated effective date and, where appropriate, additional notice.
11. Contact
For privacy-related questions, concerns, or requests, contact: