Directory

Effective 4 September 2026

Privacy

What this site collects, why it collects it, who can see it and how long it is kept. It is written from the code that does the collecting: every claim below names the file and line it was read from, in the page’s own HTML source, so you can check it against the software rather than take it on trust.

Who runs this site

Hoam is an independent site run by homeowners. It is not published by any association, board or management company, and no association funds pay for it.

One person operates it, from their own Amazon Web Services account. There is no company behind it, no investor, and nobody is paid to look at what you do here. Nothing you write on this site is reported to a board or to a management company, and nothing on this site is the Association speaking.

What is collected, and why

Signing in

Signing in with Google asks Google for three things: that you are signed in, your email address, and your basic profile. Nothing more is requested, and no Google service is called again afterwards.

Of what Google sends back, four fields are kept: Google’s own stable identifier for your account, your email address, whether Google says that address is verified, and your first name (or your full name, if Google gives no first name). Not your picture, not your contacts, not anything else.

That becomes an account: a random identifier, your email address, a display name and the date it was created. The display name starts as “A verified owner” — the anonymous byline, not your real name — because the safe choice should be the one nobody has to think about.

Two lookups point at that account: one keyed on Google’s identifier, and one keyed on a one-way hash of your email address rather than on the address itself.

You can sign in with an emailed link instead. The link works once and expires in thirty minutes, and what is stored is a hash of it, never the link. Sign-in mail is the one kind of message that is never withheld for any reason — there is no way back into an account for somebody whose sign-in mail is suppressed.

A copy of that sign-in message, your address included, is written to a queue. Amazon’s mail service is still restricted for this account, so the queue is how a link can be delivered by hand if the send fails. It is the only place a sign-in message is kept, and — unlike almost everything else here — it has no expiry on it: it stays until the operator clears it out.

Signed in, your browser holds a signed token that carries your account identifier, your display name and two timestamps. Nothing else is in it. It lasts thirty days and lives in your browser’s local storage, not in a cookie. Two things live in that local storage and no more: the token, and — if you have used Ask — the identifier of your current thread, so a reload does not lose it.

There are three cookies, and they do one job: they admit your browser to your own association’s files for seven days. They carry an expiry and a signature, not your identity; they are scoped to that one association’s path; and no script can read them. There are no other cookies on this site.

Verifying a home

A home is verified by post, because receiving mail somewhere is the one thing that cannot be faked from a keyboard. A card to the property proves you are there; a card to the owner’s mailing address, as the association itself holds it, is what a vote depends on.

The code on the card is stored as a salted one-way hash, never in the clear. The readable code exists in one place, the row that tells the operator what to print, and it is cleared when the card is sent.

A code is good for forty-five days and five attempts, and one home can be sent at most three cards in a week however many people ask.

A verified home is one row: an identifier for the membership, your account, the association, the lot — keyed on its assessor’s parcel number, never on a house number — the property address, which tier you hold, and the date. That row is what every permission on the site is decided against.

The address a card goes to is chosen by the server from the county’s parcel list, never from anything you type.

Taking part

A posting or a reply stores two separate things: which household wrote it, and the byline your neighbours see. Hoam therefore knows one home wrote one post, while the page says “A verified owner”. The link between them is never sent to anybody’s browser. Losing it would lose one home, one vote; publishing it would lose the reason anyone posts honestly.

A sign-up sheet resolves to a list of bylines, because putting your name down is choosing to be listed. An RSVP resolves to a count, because saying you cannot come is not.

Reporting a posting stores the reason and which household reported it, and neither is ever returned to anybody. You are not told how many others have reported it, or whether anything happened — every report gets the same answer, because a different one would let somebody find the threshold. Three separate households hide an item until a steward looks.

Elections, recalls, amendments and assessment votes are not run here at all — California requires an independent inspector of elections, and no ballot of that kind passes through this site. The polls here are advisory, say so, and are a separate mechanism.

An advisory poll is not a posting, and it is not stored like one. It records one choice per home, against the lot and against the account that cast it, which is what makes one household one vote and lets you see your own answer change when somebody else in the house changes it. Your neighbours are sent the totals and never the rows.

Asking a question

Ask searches the association’s own documents, takes the ten passages that match, and sends those and your question to a model running on Amazon Bedrock inside this AWS account. There is no API key and no other company in the path.

Three things are kept afterwards. Your thread — your questions and a trimmed copy of each answer — is kept against your account for seven days, so a reload does not lose the conversation.

An opening question and its answer are cached for the whole association for thirty days, under a hash of the question, so the second neighbour to ask the same thing waits for nothing. That cached row carries the question and the answer and no account, so it cannot be traced back to whoever asked first.

And two counters: how many questions your account and your network address have asked today, kept for three days, and what the association has spent this month. They exist to stop a script spending an association’s budget. Your network address is used for that, for the same kind of counter on the city form, and in the web access logs below. Nowhere else, and never against anything you wrote.

Proposing a document, or mailing one

A document proposed with the form goes from your browser straight to a private bucket. The record beside it holds the file’s name, size, type and fingerprint, which household proposed it, and the byline. The household is never returned to anyone.

Your filename is shown to you and to the stewards, and to nobody else. A filename routinely names a home — and a per-home matter is exactly what does not belong on a page every member can read.

The note beside it is shown the same way, and for the same reason. The form asks for anything a steward should know, so a steward is who it goes to — you, and them, and nobody else. The same is true of the note on a correction you raise.

When a document is published, the record the site is built from carries what kind of document it is, what it is dated, and the byline. Not the filename, not the note, not who proposed it.

A document mailed to the address this site gives your association is matched to a member by the email address it came from, and that address is then not written down: the proposal carries the same byline a form proposal would, and the fact that it arrived by mail. Your filename is discarded and replaced with a plain one. The subject line is never taken anywhere at all.

A photograph mailed in has its embedded metadata — the camera, the timestamp, any location the phone wrote into it — removed before it is stored. A photograph uploaded with the form does not: that is a known gap, it is written down as one in the repository, and until it is closed a photograph added that way keeps whatever its camera put in it.

One receipt is written per message so the operator can see that the address is working: what happened, and never who it happened to — no address, no subject, no account, no filename. It expires after thirty days. The raw email itself is deleted as the last act of handling it, and anything that somehow survives is expired after two days.

Once a steward confirms a proposal, the file is read by Amazon Textract so that it can be searched — and if it is a budget, an audit, a reserve study or a governing document, its pages are then read by a model to pull out its figures. See who else is involved for what both of those mean.

Asking for a city

The directory asks whether your city is covered, and if it is not, you can say which city and state you are in and name your association. That is all the form can send. There is a field for an email address in the code and it is switched off at both ends — the form does not draw it and the store would discard it — so today no address is collected there at all. There is one more field, a short note, which the form does not draw either; unlike the address it has no switch in front of it, so a note can only reach the queue in a request somebody made by hand rather than by using the site.

That form answers the same way whatever happens, so nobody can learn from it whether anyone else has asked about their city, and nothing on the page claims anything was stored. A row expires by itself after four hundred days.

What is never collected

  • No analytics, and no advertising. There is no analytics product, no tag manager, no advertising identifier and no tracking pixel on any of the three surfaces. There is no third-party script on this site at all.
  • Nothing is sold, rented or shared for anybody else’s purposes. There is nobody to sell it to and no business here that would want to.
  • Nothing goes to the Association, the Board or the management company. They have no account here, no export and no view. If a board member lives in the association they see what every other verified household sees, and nothing more.
  • No per-home standing, ever. What a particular home owes, or has been cited for, is a record the law keeps between the association and that member. It is not collected here and it is never shown to a neighbour. You see your own; everyone sees totals.
  • No photographs on postings. Every kind of posting is text; the picture upload does not exist.
  • Nothing personal in the public directory. It is built from county parcel records and recorded subdivision maps. There is no account, no login, and nothing about a person in it.
  • No record, against your account, of what you read — and no record at all of what you searched for. An association’s documents are static files. Opening the budget asks a content network for a page; it tells the participation service nothing, because it never speaks to it. What the content network keeps is its own delivery log — the address that asked, which page, and the browser — for ninety days; it records the page, never a document and never an account, and nothing joins it to who you are. The search box is different again: the index is downloaded with the page and searched inside your browser, so there is nothing to log what you typed. Ask is the exception, and it is described above, because a question does have to be sent somewhere to be answered.

Who can see what

Your neighbours

Other verified households in your association see your byline, what you post, when you posted it, and your name on a sign-up sheet if you put it there. They do not see your account, your email address, your lot, your street unless your byline names it, or which home anything came from.

Stewards

A steward is a neighbour who volunteered to keep the records straight. They see the queue of proposed documents, including filenames and notes, and they see the trail of what has been done — which carries bylines and never identities. A steward can add a document, date a thing and correct a figure. They cannot delete anything, rank anything, or write a summary, and that is enforced in the software rather than asked for in a guideline. Nothing per-home reaches them either.

The operator

The person who runs this site holds the keys to the account it runs in, so they can read the database and the buckets. That is true of anybody who runs any website, and it is written here rather than left to be assumed. What they do not do is read for curiosity: the operator’s own working rule is that a flow needing a real member is tested by asking that member to try it, not by reading their rows.

One store is closed even to the software that writes it: the coverage queue can be written by the API and not read back by it, because no route should ever be able to hand somebody else’s request over.

Who else is involved

Two companies run this site, and they are named below. Writing to the support address involves one more — the mail provider the operator reads their own mail at — and that is below too.

Google

Google does two things here and only these two. It is one way to sign in, if you choose it — Google knows you signed in to Hoam, the way it knows every place you sign in to with it — and its font service serves two typefaces to the public pages.

This page and the other public pages load those typefaces from Google Fonts, so Google’s font service sees the request for a font file. It is the only thing on this site fetched from anywhere but this site. Inside an association’s portal the same two typefaces are served from this site itself.

Amazon Web Services

Everything else runs on Amazon Web Services in one account, in the United States: the pages, the participation service, the database, the mail, the reading of documents and the model that reads their figures and answers Ask.

Reading a document. A confirmed document is read by Amazon Textract. By default AWS may keep what its AI services process in order to improve them; this account is opted out of that, by a policy attached at the organisation root that names every such service. Textract is covered by it.

Reading the figures out of a document. After Textract has read a budget, an audit, a reserve study or a governing document — those four kinds and no others — the text of its pages is sent to a Claude Haiku model on Bedrock, in this same account, to pull out the figures and passages that are then checked against the totals the document itself prints. It is the text of the pages that is sent, never the scan. This happens once a steward has confirmed the document and before anybody has published it, so it is the one place in this product where a record that is not yet public is read by a model. The request is reached through the same profile and may be served in any of the same three US regions, and the two statements below hold for it exactly as they hold for Ask.

Answering a question. Ask sends your question and the passages it found to Amazon Bedrock, in this same account. The model is reached through a profile that may route the request to any of three US regions. Nothing is sent to the board, to a neighbour or to any other company; there is no model provider being called directly and no prompt leaves this account.

Two things worth stating precisely rather than comfortably. Bedrock does not keep prompts or use them to train models, under its own default terms and the account’s default retention setting — that, and not the opt-out policy above, is what protects a question, and a page sent to have its figures read: the opt-out reaches the AWS services whose terms would otherwise let content be used to improve them — Textract among about thirty — and Bedrock is not one of them, because its terms never allow it in the first place. And the one switch that would put a second copy of every question, answer and page somewhere this site does not govern — Bedrock’s own invocation logging — is off in all three regions, and was checked rather than assumed.

The mailbox support mail goes to

Writing to the support address puts your message in the operator’s own mailbox, which is at a commercial mail provider like anybody else’s and sits outside the account everything above runs in. That is one message reaching one person because you wrote to them, rather than a company this site is built on, and it is the only thing on this page that goes anywhere but the two above. What the message passes through on the way is under Contact.

How long things are kept

Session token
30 days, in your browser.
Member cookies
7 days, then your browser is asked to sign in again.
Sign-in link
30 minutes, and one use. The row that checks it is swept a day after it stops working.
Sign-in message
No expiry. The copy in the queue stays until the operator clears it.
Postal code
45 days, and five attempts. The claim row — your account against a lot — is swept a fortnight after that, used or not.
Postcard queue
No expiry. The row that tells the operator what to print holds the property address and the lot; the readable code is cleared the moment the card is marked sent.
Ask thread
7 days.
Cached answer
30 days, so it is re-read after a document changes.
Daily counters
3 days, and 14 for the one that caps a home to three postcards a week.
Monthly spend
400 days. What Ask cost this association in a month, with nobody’s account on it.
Mail receipt
30 days, and it names nobody.
A mailed message
Deleted as soon as it is handled, whether it came to the document address or the support one; 2 days if that ever fails.
Coverage request
400 days.
Service logs
30 days.
Web access logs
90 days. They record the request — address, page, browser — and are configured to exclude cookies.
Backups
The database can be restored to any point in the last 35 days, so a deleted row is recoverable for that long.

Postings, replies, sign-ups, poll responses, memberships and the record of what stewards have done have no expiry. They are the record of the place. Removing one is an act somebody takes, not a timer running out.

Your choices

Sign out

Signing out drops the token in your browser and asks the server to expire the member cookie — in every association you hold a home in, not only the one you are looking at.

Stop the email

The only unsolicited mail this site sends is a deadline notice, at most two per deadline: one when it opens and one three days before it closes. Turn them off with one tap in the app, or from the unsubscribe link in any of them — that link works without signing in, because somebody who wants mail to stop should not have to log in to stop it. Sign-in mail is unaffected, and there is nothing else to unsubscribe from.

Have your account and postings removed

Write to support@go-hoam.com and ask. There is no button for it today and it would be dishonest to imply otherwise: the operator does it by hand, and will write back to say when it is done. Ask for the whole account or for particular postings; both are possible. That message leaves this account and lands in the operator’s own mailbox — Contact says what it passes through, which matters here because a removal request is the message most likely to name a home.

Two things are worth knowing about removal. Removing your own posting in the app hides it from everyone, you included, but the row itself stays marked as removed rather than being erased — otherwise a report filed against it would stop meaning anything to whoever reviews it. Its replies go with it. And the trail of what a steward confirmed stays, under its byline, because that trail is what makes every document on this site checkable.

Correct something

If a figure or a fact on this site is wrong, say so and it will be corrected in public. That is the whole point of the site. The same address works.

Children

This site is not for anyone under 18. An account is only useful once a home is verified, verification runs on a card posted to a property, and membership of an association runs with the deed. No account is knowingly created for a child, and nothing here is aimed at one. If you believe a child has an account, write to the address below and it will be removed.

Changes to this policy

The date at the top is the date this version took effect. This page lives in the same repository as the software it describes, so a change to what is collected is a change to the code that collects it, made in the same place and visible in the same history. There are no silent edits; if what is collected changes materially, this page says so and the date changes with it.

Contact

support@go-hoam.com

A person reads it. Write about anything on this page — a question, a removal, a correction, or a claim here that does not match what the site actually does.

What happens to it. Amazon’s mail service receives it at this domain and writes it to a private bucket; it is checked for viruses; a function rewrites the header block and relays the whole message to the operator’s own mailbox, outside this account. The copy in the bucket is deleted as soon as it has been relayed, and one that could not be relayed expires in two days. No address, no subject and no filename reaches a log line, and nothing about the message is written to the database.

Two things about that are different from a document mailed in. Your address travels: it is put in the reply field, because it is what the operator hits reply on — so the promise above that a sender’s address is not written down is about documents and does not carry across to here. And nothing is ever sent back to you automatically: there is no bounce and no acknowledgement, only a person writing back.