1. Homele
  2. Privacy Policy

PRIVACY POLICY

Effective date: 2026-08-27

1. Introduction

Homele (“we”, “us”, or “our”) is a real estate platform based in Erbil, Kurdistan Region, Iraq. We are the data controller responsible for the personal data described in this policy. You can reach us about anything in this document at [email protected].

This Privacy Policy explains what personal data we collect, why we collect it, who we share it with, how long we keep it, and the choices you have. It applies to all three places you can use Homele (together, the “Service”):

  • the Homele website at homele.com;
  • the Homele mobile apps for iOS and Android;
  • Homele for ChatGPT, our read-only connector published in the ChatGPT app directory. Section 4 describes that connector in full, including exactly what each of its tools receives and returns.

By using the Service you agree to the collection and use of information in accordance with this policy. Together with our Terms and Conditions, it forms your agreement with us.

2. Definitions

  • SERVICE means the Homele website, the Homele mobile apps, and Homele for ChatGPT.
  • PERSONAL DATA means data about a living individual who can be identified from that data, or from that data together with other information we hold or are likely to hold.
  • PROCESSOR (or SERVICE PROVIDER) means a company that processes personal data on our behalf and under our instructions. Section 6 names the ones we use.
  • COOKIES are small files stored on your computer or mobile device.
  • LISTING PARTNER means a real estate agency, developer, or agent that publishes listings on Homele.
  • CONNECTOR means Homele for ChatGPT, and TOOL means one of the individual search or lookup functions it exposes.

3. Data We Collect

3.1 Data you give us

  • Account data. If you create an account: your name, email address, and a password, which we store only as a cryptographic hash and never in readable form. If you sign in to the mobile app with Google or Apple, we receive only the profile information you authorise them to release — typically your name, email address, and profile picture.
  • Enquiry data. If you use “Request a call” or a WhatsApp contact button on a listing, project, or agency page: your name, your phone number, and which listing or agency you enquired about. We record the IP address and browser user-agent alongside the enquiry to detect duplicate and abusive submissions.
  • Correspondence. Anything you send us by email or through support channels, including the content of your message.

3.2 Data collected automatically

  • Usage data. The listings and projects you view, the searches and filters you run, and the contact buttons you click. Each recorded event carries the listing identifier, title, property type, city, area, listing agency, and price, together with your chosen language and currency.
  • Device and technical data. IP address, approximate city-level location derived from that IP address, browser and device type, operating system, referring page, and the date, time, and URL of each request.
  • Error diagnostics. When something breaks, an automated report containing the failing URL, technical stack trace, and IP address.
  • Precise location (mobile apps only, with your permission). On listing and project detail screens the app can use your device location to show distance and directions to a property. You are asked for permission first, and you can refuse or later revoke it in your device settings; the rest of the app continues to work.
  • Push notification token (mobile apps only). A device token issued by Firebase Cloud Messaging so we can send you notifications. Turn notifications off in your device settings to stop this.

3.3 Cookies and similar technologies

On the website we use cookies and local storage to keep you signed in, to remember your language and currency, and to hold the pseudonymous identifiers our analytics providers use to distinguish one visit from another. Beacons, tags, and scripts are used for the same analytics purposes.

You can instruct your browser to refuse all cookies or to warn you when one is being set. The site will still work, but your session, language, and currency preferences will not persist.

3.4 Data we do not collect

  • We do not collect payment card or bank details. No payment is taken on Homele.
  • We do not collect government identification documents or biometric data.
  • We do not buy personal data from data brokers.
  • We do not knowingly collect special category data such as health, religion, or political opinions, and we ask you not to send it to us.

4. Homele for ChatGPT

Homele for ChatGPT is a read-only connector that lets ChatGPT search our public property catalogue on your behalf. It is served from https://homele.com/mcp using the Model Context Protocol. It can only look things up: nothing can be created, changed, purchased, booked, or contacted through it, and it never sends a message to an agency on your behalf.

4.1 What the connector receives

The connector requires no sign-in. There is no OAuth flow, no account linking, and no way for it to identify you. We do not receive your ChatGPT account, your name, your email address, your conversation, or any message you did not turn into a search. What reaches our servers is limited to the tool arguments ChatGPT constructs from your request, plus the network metadata any web request carries.

The connector exposes five tools. These are the only inputs any of them accept:

  • search-properties — whether you want to buy or rent, city, area, property type, number of bedrooms and bathrooms, minimum and maximum price, currency, rental frequency, sort order, page number, results per page, and display language.
  • search-projects — city, property type, minimum and maximum price, page number, results per page.
  • list-plot-areas — an optional city name.
  • search-agencies — a full or partial agency name, an optional city, and a result limit.
  • list-locations — an optional city name.

These are structured property search filters, not free-form text, and none of them is intended to carry personal data. Because ChatGPT decides what to put in them, please do not type personal details such as your phone number, address, or identification into a Homele search: we neither need nor want them.

4.2 What the connector returns

The connector returns search results only, never a full listing record. The tools return only information already published on homele.com: listing id, title, whether it is for sale or rent, formatted price and rental frequency, bedrooms, bathrooms, size, property type, city and area, the name of the listing agency, listing photos, and the listing URL. Project results add the price range, construction status, and developer name. Agency results return the agency name, its public profile URL, and how many active listings it has. Location tools return the names of cities, areas, and property categories, together with how many listings each currently holds.

No contact details are returned. The connector does not expose agent or agency phone numbers, WhatsApp numbers, or email addresses, and it returns no personal data about any Homele user. Search results may be displayed inside ChatGPT in an inline widget; that widget renders the same public listing fields listed above.

4.3 What we log, and why

To answer your search we process the arguments in section 4.1 in memory and return the results. We do not write them to a search history, we do not attach them to any profile, and because the connector cannot identify you there is no profile to attach them to.

Our servers and our content delivery network record the standard request metadata that every web request produces — the originating IP address, the time, and the endpoint called. We use it for one purpose only: keeping the connector working and safe, by enforcing the limit of 60 requests per minute, detecting abuse, and investigating faults. Our own application logs are rotated and deleted after 14 days. If a request fails, an automated error report may capture the technical details of that request; our error monitoring is configured not to collect personal identifiers.

We do not build user profiles from connector activity, we do not use it for advertising, and we do not use it to train artificial intelligence models.

4.4 OpenAI's role

ChatGPT is operated by OpenAI, not by us. When you use the connector, OpenAI sends your search to us and displays our results back to you. What OpenAI collects, how it uses your conversations, and the controls you have over them are governed by OpenAI's own privacy policy, not this one. If you want to stop sharing searches with Homele altogether, disable or remove the Homele app in your ChatGPT settings.

5. Why We Use Your Data

We use each category of data only for the purposes set out below.

  • To run the Service — to answer your searches, show listings and projects, and render results in the website, the mobile apps, and ChatGPT.
  • To pass your enquiry to the listing partner — when you request a call or send a WhatsApp enquiry, your name and phone number are delivered to the agency or developer behind that listing so they can call you back. This is the entire purpose of submitting an enquiry, and we tell you so at the point you submit it.
  • To create and manage your account — to register you, sign you in, verify your email address, and let you reset your password.
  • To remember your preferences — your language and currency.
  • To send notifications you asked for — push notifications in the mobile apps and service emails such as email verification and password resets.
  • To measure and improve the Service — to understand which listings are viewed, which searches return nothing useful, and where people get stuck, so we can fix it.
  • To keep the Service secure — rate limiting, duplicate and spam detection, and fraud and abuse prevention.
  • To diagnose and fix faults — through automated error reporting.
  • To respond to you — support questions and the privacy requests described in section 9.
  • To comply with the law — where we are legally required to retain or disclose information.

We do not sell your personal data. We do not use it for cross-site behavioural advertising. We do not use it to train artificial intelligence models. And we do not make decisions about you by automated means that produce legal or similarly significant effects.

6. Who We Share Data With

We do not sell, trade, or rent your personal information. We share it only with the recipients named below, and only for the purposes described.

  • Listing partners (agencies, developers, and their agents). When you submit a call request or WhatsApp enquiry, the agency or developer that published that listing receives your name, phone number, and the listing you asked about, delivered through the Homele agency CRM. That partner then handles your enquiry as an independent controller under its own privacy practices and retention rules, which we do not control. Browsing and searching alone never sends anything to a listing partner.
  • OpenAI, L.L.C. — operator of ChatGPT, when you use Homele for ChatGPT. See section 4.
  • Google LLC — Google Analytics for website and app usage measurement, and Firebase for push notifications and mobile analytics. Receives usage events, pseudonymous identifiers, and IP address.
  • Hotjar Ltd — behavioural analytics and heatmaps on the website. Receives page interaction data and IP address.
  • Functional Software, Inc. (Sentry) — application error monitoring. Receives error reports that may include the failing URL and IP address.
  • Cloudflare, Inc. — content delivery, DNS, TLS termination, and protection against denial-of-service attacks. Processes IP address and request metadata for every request.
  • Apple Inc. — where you choose Sign in with Apple, and for delivery of iOS push notifications.
  • Our hosting and infrastructure providers — the providers that run our servers, databases, and backups under contract with us.
  • Legal and regulatory recipients — courts, regulators, or public authorities where we are required by law to disclose information, and our professional advisers where necessary to establish or defend legal claims.
  • A successor entity — if we are involved in a merger, acquisition, or sale of assets, your data may transfer as part of that transaction. We will post notice on this page before it takes effect.

Google user data. If you sign in with Google, we use the profile information you authorise solely to create and authenticate your Homele account. We do not transfer Google user data to third parties except the processors named above, and we do not use it for advertising.

7. International Transfers

Homele operates from Iraq, but several of the providers named in section 6 process data on servers in the European Union and the United States. Where your data is transferred outside your country, we rely on the contractual data protection terms those providers offer, including standard contractual clauses where applicable, and we share only the minimum each provider needs to perform its function.

8. How Long We Keep Data

We keep personal data only as long as it serves the purpose it was collected for, then delete it. Our retention periods are:

  • Account data — for as long as your account exists. After you delete your account, it is removed from our live systems within 30 days and from backups within 90 days.
  • Call requests and WhatsApp enquiries — 24 months from submission, then deleted. The copy held by the listing partner you contacted is subject to that partner's own retention period.
  • Usage and analytics events, both our own and those held in Google Analytics — 26 months.
  • Hotjar behavioural data — up to 12 months, per Hotjar's retention settings.
  • Homele for ChatGPT request metadata — 14 days in our application logs. Our content delivery network applies its own retention to the request metadata it holds.
  • Web server and application logs — 14 days.
  • Automated error reports — up to 90 days at our error monitoring provider, then deleted.
  • Support and privacy correspondence — 24 months after the matter is closed.
  • Records we are legally required to keep — for the period the applicable law requires, after which they are deleted.

9. Your Rights and Choices

You can ask us to give you a copy of the personal data we hold about you, correct it if it is wrong, delete it, restrict how we use it, object to our using it, or receive it in a portable format. Where we rely on your consent — for example device location or push notifications — you can withdraw it at any time without affecting what we did before you withdrew it.

To exercise any of these rights, email [email protected]. We respond within 30 days. We may ask you for information to confirm your identity before we act, so that we do not disclose your data to somebody else. Exercising these rights is free.

You also have these direct controls:

  • Delete your account in the mobile app. Open Profile, then Edit profile, then Delete account. You will receive a confirmation email; once you confirm, your account and the personal data attached to it are deleted. If you use only the website, email [email protected] and we will do the same for you.
  • Withdraw an enquiry. Email [email protected] and we will delete the call request or WhatsApp enquiry from our systems. Because the listing partner already holds its own copy, ask them directly to stop contacting you as well, and tell us if they do not.
  • Opt out of analytics. Refuse cookies in your browser settings, or install the Google Analytics opt-out browser add-on, or use Hotjar's do-not-track opt-out. The Service continues to work.
  • Turn off location and notifications. Both are device permissions you can revoke at any time in your iOS or Android settings.
  • Stop using Homele for ChatGPT. Disable or remove the Homele app in your ChatGPT settings and no further searches reach us.

If you are unhappy with how we handled your request, please tell us first at [email protected] so we can put it right. You may also complain to the data protection authority competent for your country.

10. Data Security

We implement technical and organisational measures to protect your personal information against unauthorised access, alteration, disclosure, or destruction:

  • Encryption in transit. All traffic between your device and our servers is encrypted with TLS (HTTPS).
  • Password hashing. Passwords are stored as one-way hashes; nobody at Homele can read them.
  • Access controls. Personal data sits on servers with restricted access, and staff access is limited to those who need it for their job.
  • Abuse protection. Rate limiting and duplicate detection on enquiry submissions and on the ChatGPT connector.

No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If a breach affects your personal data and is likely to put you at risk, we will notify you and the relevant authority without undue delay.

11. Children's Privacy

The Service is not intended for children under 18, and we do not knowingly collect personal data from them. If you believe a child has given us personal data, contact [email protected] and we will delete it.

12. Changes to This Privacy Policy

We may update this Privacy Policy from time to time. We will post the new version on this page and update the effective date at the top. Where the change materially affects how we use your data, we will give notice by email or a prominent notice in the Service before it takes effect. We keep this policy aligned with what Homele for ChatGPT actually does, and update section 4 whenever a connector tool's inputs or outputs change.

13. Contact Us

Homele is the controller of the personal data described in this policy.

logo-white

ev satın alın, kiralayın, yatırım yapın veya konut veya ticari mülk satın

Telif Hakkı © 2026 Tüm hakları saklıdır.