Privacy Policy
Last updated July 31, 2026
The short version
Fenceline is built to hold as little of you as possible. The site needs your reviews, not your identity. You sign in with a one-time link sent to your email; that login identity is kept separate from what you publish and is never shown next to your posts. We never sell data that identifies you, we don’t run advertising or analytics trackers, and the only cookies we set are the ones that keep you signed in and past the prototype gate.
1. Who we are
Fenceline (“Fenceline,” “we,” “us”) is a personal project operated by an individual, not a company, based in the United States. It is a platform where residents share their own experiences of, and opinions about, the homeowners’ associations (HOAs) they live under.
2. What we collect
We collect only what the product needs to work:
Content you submit
The reviews, ratings (the strictness and toxicity sliders), dealbreaker stances, and figures you report — monthly dues, a fine amount, a board response time — plus any free-text notes you write. This is the material Fenceline exists to aggregate and display.
Account information
You sign in with a one-time code or link sent to the email address you provide, or a one-time code sent by text message to a US phone number. There is no password. That email address or phone number is used only to authenticate you. It is never displayed publicly and is never linked to your posts in any way visitors can see. Inside the database the link between your login and what you publish is broken by design: you post under a pseudonym separate from your login, and the separation is enforced by the schema and row-level security, not just by what the interface chooses to show.
Residency verification (if you choose to verify)
To earn a verified-resident badge you photograph a document that shows your address, such as a piece of postmarked mail or a utility bill. To read the address off it, we send the photo to a third-party AI service (Anthropic) that reads it for us under its own terms; we then check the result against the community you claim and discard the photo from our own systems immediately. As part of that check we also send just the address (never the photo) to Google’s geocoding service, in memory, to confirm the city and state it falls in; we keep nothing Google returns.
If you verify inside the mobile app, two optional signals help confirm the check is genuine, and both are used only in the moment. If you allow it, we read your device’s location once at the time of capture and send those coordinates to Google to confirm they fall near the community you claim; the coordinates are used for that check and never stored. The app also runs a device-integrity check with Apple or Google to confirm the submission comes from a real device rather than an automated one. Neither the coordinates nor the device-integrity result is written to your record.
The photo is never written to our database or to any storage. What we keep is a scrambled version of the address that can’t be turned back into it, a yes/no result, and a confidence score. We recommend blacking out anything except your name and address before you photograph it. See how verification works for the full walk-through.
Push notifications (if you turn them on)
In the mobile app you can turn on push notifications. If you do, we store the device token Apple or Google issues for your device so we can deliver the notifications you asked for, such as a reply to one of your posts. The token identifies a device, not what you post, and it is deleted along with your account.
Information collected automatically
Our hosting provider (Netlify) records standard server logs (IP address, browser/user-agent, and request timestamps), which we use for security, debugging, and preventing abuse. Rows in our database carry creation timestamps. We keep short-lived counters that throttle how often a single account or address can post, comment, or vote, to blunt spam and abuse. We do not run advertising or web-analytics trackers. When something on the site breaks, an error report goes to our error-monitoring service (Sentry) with the technical details of the failure. We configure those reports to leave out personal information, they never include what you write or the pseudonym you post under, and there is no session recording.
3. Where your content is stored
The content you submit is written to our hosted Postgres database (Supabase), so it can be shown to your neighbors and folded into a community’s aggregated read. Access to that database is governed by row-level security: the rules that decide who can read or write a given row live in the database itself, not only in the app.
4. How we use what we collect
We use it to:
- operate the site: show communities, feeds, and reviews;
- compute the aggregated reads (the vibe tier, strictness and toxicity meters, dues and fine figures) from resident-submitted content;
- keep the platform safe: moderate content, detect and prevent spam, abuse, harassment, and manipulation, and enforce our rules, including by suspending or banning accounts;
- respond to legal obligations and to takedown or correction requests.
We do not sell your personal information, and we do not use it for third-party advertising.
Separately from that, we may create, license, and sell aggregated and de-identified data we derive from what residents contribute, such as community scores, tiers, stance verdicts, and counts. It is stripped of anything that identifies you or ties a figure back to your account, so it is not personal information. What we will never sell is data that identifies you, meaning your login email, your account, or free-text you wrote that names you.
5. Anonymity, and its limits
Fenceline is built so that what you publish is not linked to your login identity in anything visitors can see. To your neighbors and to the HOA you post about, you are your chosen pseudonym and nothing more: your email and login are never shown, and the link between them and your posts is enforced by the database and row-level security, not just by the interface.
That is anonymity toward other people, not toward us, and it has limits we can’t engineer away:
- It is not anonymity from the Operator. To sign you in we hold the email address or phone number you sign in with, and our host records standard server logs, including IP address, for security and abuse-prevention. Internally we can associate an account with what it posted, which is what makes moderation, bans, and signing out other devices possible.
- We can be legally compelled to disclose what we hold. If valid legal process requires it, we may have to turn over account information (see Section 6).
- Anything you type into a free-text field is published as written. If you put your name, your address, or details that identify you or a neighbor into a review, that information becomes visible. Don’t include what you wouldn’t want read.
6. Who we share it with
We share personal information only in these narrow cases:
- Service providers that run the site for us: our host (Netlify), our database and authentication provider (Supabase), our SMS provider (Twilio), which processes your phone number to deliver sign-in codes if you sign in by phone, and our error-monitoring service (Sentry), which receives technical error reports configured to leave out personal information. They process data on our behalf, under their own terms and privacy policies.
- Anthropic, in three cases. First, moderation: when you publish a post, comment, or review, its text is sent to Anthropic’s AI service for a content-safety read. This happens automatically for everything published, not only for content someone reports, and it is how we catch doxxing, threats, and harassment that nobody flags. Second, residency verification: if you submit a photo to earn a badge, that photo is sent to the same service to read the address for us. Third, translation: if a reader has chosen a different language, the text of a post or comment is sent to the same service to be translated for them. In every case the content is processed transiently under Anthropic’s terms, is not used to train any model, and is sent without your account identity; we store nothing beyond the verification result, the moderation read, and the translated text.
- Google, only during residency verification: the address read from your photo, and, if you verify in the app and allow it, your device’s location coordinates, are sent to Google’s geocoding API to confirm the city and state. Google never receives the photo, and we store nothing it returns.
- Apple and Google, only for the optional device-integrity check when you verify residency in the mobile app: we ask Apple’s or Google’s device-integrity service to confirm the submission comes from a genuine device. The check carries no content you wrote, returns only a pass/fail signal, and nothing it returns is stored on your record.
- Legal compliance: when we reasonably believe disclosure is required by law, legal process, or to protect the rights, safety, or property of users or the public.
We do not sell or rent data that identifies you to anyone. As Section 4 explains, the only data we may license or sell is aggregated and de-identified, and it cannot be traced back to you or any other individual.
7. Cookies and analytics
Fenceline sets only the cookies it needs to work. There is one:
- The session cookie. When you sign in, our authentication provider (Supabase) sets a cookie that keeps you signed in. It clears when you sign out or when the session expires.
It is strictly necessary: without it you could not stay signed in. We do not use cookies for advertising, and we run no third-party web-analytics trackers, so under the ePrivacy rules and comparable laws there is nothing here that requires a consent banner. If we ever add analytics or any non-essential cookie, we will ask for your consent first, and this page and the banner will say so. A cookie named fenceline_gate, set by the first-visit notice screen we retired in July 2026, is no longer set or read and expires on its own.
8. How long we keep things
We keep each kind of data only as long as it is doing a job, and no longer:
- Your content (reviews, posts, comments, ratings, and the figures you report) stays until you delete it or ask us to. Removing one review may leave a community’s aggregated read unchanged, since that read draws on many residents.
- Your account (the login email and its firewalled link to your pseudonyms) is kept while the account is active. Ask us to delete it and we remove the account and that link.
- Residency hashes. The one-way address hash, the yes/no result, and the confidence score are kept to hold your verified badge and to stop the same address being claimed twice. The photo, the raw address, and any device location reading are already gone, discarded the moment the check finished.
- Server logs (IP, user-agent, timestamps) are kept only as long as needed for security and abuse prevention, then discarded.
- Rate-limit counters are short-lived by design: each counts activity inside a fixed time window and expires on its own.
- Moderation records. When content is actioned, we log what was done and why, with no personal information in the note, so decisions stay consistent and auditable.
- Enforcement records. To stop a banned account from simply signing up again, we keep a one-way hash of its email address, which can outlast the account itself after deletion. To stop a reporter blocked for filing bad-faith reports, we keep a one-way digest tied to that account. Neither can be reversed to recover the email or identify the account, and we keep them only as long as enforcement needs them.
You can request access, correction, or deletion of your data by contacting us (see below), and we’ll honor it as applicable law requires. Depending on where you live, you may also have rights to port your data or to object to certain processing. Contact us to exercise them.
9. Children
Fenceline is intended for adults and is not directed to anyone under 18. We don’t knowingly collect personal information from children. If you believe a child has provided us information, contact us and we’ll delete it.
10. Security
Access to our database is restricted with row-level security and standard access controls. Sign-in is by a one-time email link, so there is no password of yours for anyone to steal or reuse. No system is perfectly secure, and we can’t guarantee absolute security, so don’t publish sensitive information in a review that you wouldn’t want read.
11. Changes to this policy
We may update this policy as the product evolves. When we make a material change, one that affects what we collect, how long we keep it, or who can see it, we send a notice to the email on your account with a summary of what changed, and we update the date at the top. Smaller wording and formatting fixes only move the date. If you keep using Fenceline after a change takes effect, that means you accept the revised policy.
12. Contact
Questions about privacy, or a request about your data, can be sent to hello@fenceline.homes.
See also our Terms of Service.