Who's responsible
Homies is a personal project, run by one person rather than a company. For anything at all about your data, email [email protected] and it comes straight to them.
Under the GDPR that person is the data controller: they decide what's collected and why, and they're the one to come to first if something's wrong. If you're a member, you already know who they are, because someone vouched for you to get in.
What we hold
| What | Why | Legal basis |
|---|---|---|
| Your email address | It's how you sign in. There are no passwords, so we email you a link instead. It's also how other homies reach you, unless you've set a WhatsApp number and picked that instead. | Performance of a contract: you can't have an account without it. |
| Your name | So other members know who's offering a home, and so the trust chain makes sense. | Performance of a contract. |
| Your WhatsApp number, if you give one | An alternative way for homies to reach you. Entirely optional. | Consent: you chose to add it, and you can remove it any time. |
| Who invited you | Homies is invite-only, and the "how many homies away" chain is built from this. It's the core of how the network works. | Performance of a contract. |
| Your homes: city, country, description, available dates | So other members can find somewhere to stay. | Consent: you chose to list a home, and you can remove it any time. |
That's the lot. No photos, no ratings, no location beyond the city you type, no tracking of what you look at.
What's on the public homepage
The Homies homepage, which anyone can see without logging in, shows the city, country and available dates of homes that are currently open.
It never shows your name, your description, your contact details, or anything that ties a home to a person. Someone reading it sees "Amsterdam, Netherlands, 18 to 20 September" and nothing more.
If you'd rather your home wasn't counted in that at all, remove its dates in the app and it disappears from the homepage while staying visible to you. Or email us and we'll sort it.
Cookies and tracking
Homies sets no tracking cookies and runs no analytics that identify you. There's no cookie banner because there's nothing to consent to.
The app keeps your sign-in session in your browser's local storage, so you don't have to click a link from your inbox on every visit. Signing out clears it. While you're joining, it also holds your invite code and the details you typed, just long enough to finish signing you up, and then deletes them.
We used Google Analytics until 6 August 2026 and removed it, because it set cookies and sent data abroad before anyone had agreed to it.
Who else touches your data
- Supabase stores the database. Your data sits on servers in Ireland, inside the EU.
- Cloudflare serves the website.
- Resend sends your sign-in emails. They're in the United States, so your email address goes there to be delivered. That transfer relies on the EU Standard Contractual Clauses.
- Google Forms runs the waitlist, if you signed up that way before joining. Also in the United States, on the same basis.
Nobody is sold your data, and it isn't used for advertising. There's nothing to sell and no advertising to do.
How long we keep it
For as long as you have an account. Delete your account and it goes immediately, along with your homes and their dates.
One thing survives, in a stripped-down form: the invite codes you handed out stay in the system with your name removed, so the people you vouched for don't lose their place in the network. They can't be traced back to you.
What you can do
The two that usually matter are built into the app, on the Profile screen, so you don't have to ask anyone:
- Download my data gives you a file with everything Homies holds about you.
- Delete my account removes you and your homes on the spot. Anyone you vouched for stays in the network, attached to whoever vouched for you.
You can also correct your name and contact details yourself on that same screen.
Beyond that, the GDPR gives you the right to object to how we use your data, to ask us to restrict it, and to receive it in a portable format. Email us and we'll deal with it inside a month.
If you think we've handled your data badly, tell us first and we'll try to fix it. You also have the right to complain to your national data protection authority. In the Netherlands that's the Autoriteit Persoonsgegevens.
Security, honestly
Access to the database is locked down per member, so signed-in members can read other members' names and contact details, which is the point of the network, but nobody outside can read anything at all. Sign-in is by emailed link, so there's no password to leak.
Worth being straight with you: Homies is a personal project, not a company with a security team. It's built carefully, but treat it as what it is. Don't put anything in a home description you wouldn't want another member to read.
Changes
If this changes in a way that matters, we'll email members rather than quietly editing the page.