Account information: your name, email, organization name, an optional phone number (used to ring you for click-to-call), and a hashed (never plaintext) password.
Content you provide: messages you send to any desk, files you upload (listing photos, PDFs of contracts/disclosures, etc.), any optional context notes you save in Settings, and the records you keep here — contacts, listings, transactions, follow-ups, commissions, goals and recruiting notes. This includes information about your clients and leads: names, phone numbers, email addresses, messages they send you, whether they have agreed to be texted or called, and whether they have opted out.
Usage data: which desks you use, how often, and token counts per request (used to show you your own usage/cost estimate in Settings — see the AI Use Disclosure).
We do not sell your information, and we do not use your content to train AI models beyond what's necessary to generate your own responses (see the next section for how the underlying AI provider handles this).
These are the outside services that handle your data or your contacts' data to run the Service, and what each one receives. A service marked “when enabled” receives nothing until it is configured for the Service.
Conversation history, uploaded-file placeholders (not the raw file itself — see the AI Use Disclosure), records and account information are stored in our database for as long as your account is active.
Deleting your account. You can delete your account from Settings › Profile. For a team member, that removes your login, your desk conversations, your weekly coaching check-ins and your saved chat preferences. The team's shared records stay with the team, including the calls you logged and the usage your requests generated, which move to the workspace owner. For the owner of a workspace with no other members, it removes the entire workspace — every record, conversation, setting and usage entry. An owner whose workspace still has other members is asked to have them remove their own accounts first.
When one of your contacts asks to be deleted. An owner or admin can delete that person's data from their contact page: the contact and their follow-ups, calls, messages, documents and consent history, and optionally the desk chats linked to them. To keep honoring their request not to be contacted, a one-way scrambled form of their phone number and email can be kept so they are never texted or auto-emailed again; it cannot be turned back into the number or address. Mentions of them you typed into other records (a transaction's notes, for example) are not searched out automatically.
Deletion takes effect in our database immediately. Copies can persist for a limited time in our database provider's point-in-time recovery history, and in the processors' own logs (for example, message logs at Twilio or Resend) under their retention policies.
Passwords are hashed (never stored in plaintext). Access to your organization's data is restricted to authenticated users within that organization — see the multi-tenant isolation note in our engineering documentation for how this boundary is enforced at the database query level. [Placeholder — add specifics on encryption at rest/in transit once finalized for production infrastructure.]
You can review and correct your account information from Settings, and delete your account from Settings › Profile as described in section 4. If you are a client or lead of someone who uses the Service, ask that agent to delete your data; they can do it from your contact record.
The Service is intended for licensed real estate professionals and is not directed at or intended for use by children.
[Placeholder — to be completed based on actual hosting location and user base once deployed.]
This policy may be updated from time to time. Material changes will be noted with an updated "last updated" date on this page.
Questions about this policy can be sent to the account owner directly.