← Back

Privacy Policy

Draft — last updated September 13, 2026. Not yet reviewed by an attorney.

This is a draft. It has not been reviewed by a licensed attorney and should not be relied on as a binding privacy commitment until it has been — particularly around specific legal frameworks (CCPA, GDPR, state privacy laws) that may apply depending on where your users and their clients are located.

1. What information we collect

Account information: your name, email, organization name, an optional phone number (used to ring you for click-to-call), and a hashed (never plaintext) password.

Content you provide: messages you send to any desk, files you upload (listing photos, PDFs of contracts/disclosures, etc.), any optional context notes you save in Settings, and the records you keep here — contacts, listings, transactions, follow-ups, commissions, goals and recruiting notes. This includes information about your clients and leads: names, phone numbers, email addresses, messages they send you, whether they have agreed to be texted or called, and whether they have opted out.

Usage data: which desks you use, how often, and token counts per request (used to show you your own usage/cost estimate in Settings — see the AI Use Disclosure).

2. How we use your information

  • To provide and operate the Service — generating responses, maintaining conversation history, and applying any context notes you've saved.
  • To send the texts, calls and emails you or your configured automations initiate, and to honor opt-outs.
  • To detect and prevent abuse (e.g. rate-limiting login attempts).
  • To show you your own usage and estimated cost.

We do not sell your information, and we do not use your content to train AI models beyond what's necessary to generate your own responses (see the next section for how the underlying AI provider handles this).

3. Third-party processors

These are the outside services that handle your data or your contacts' data to run the Service, and what each one receives. A service marked “when enabled” receives nothing until it is configured for the Service.

  • Anthropic (AI processing). Each desk and Delilah (the Executive Assistant) send your message, the conversation so far, and — when a chat is linked to a contact, listing or transaction — that record's details to Anthropic's Claude API to generate a response; an attached image or PDF is sent for that request only. When a contact messages you, their message is also sent to Claude to pick which of your approved scripts fits. Per Anthropic's terms, API content is not used to train their models by default. See the AI Use Disclosure for what is and isn't retained.
  • Twilio (calls and texts, when enabled). Receives the phone number and message text of each text the Service sends, and, for click-to-call, your phone number and your contact's number so it can connect the call; it reports back call status and duration. The Service does not ask Twilio to record calls.
  • Resend (email, when enabled). Delivers account emails (welcome, team invites, password resets), deadline reminder digests and escalation notices to you and your teammates, and automatic email replies to your contacts — so it receives each recipient's address and the email's content.
  • Neon (database). Stores all account data, records and conversation history in a managed Postgres database hosted in AWS's US East (Ohio) region.
  • Vercel (hosting). Runs the application, so every request passes through Vercel's servers and their operational logs. Vercel Web Analytics counts page views and visits without cookies; it is not used for advertising.
  • Stripe (billing, when enabled). Billing is not live yet. When it is, card and payment details are entered with Stripe and never stored by the Service, which keeps only a Stripe customer and subscription reference and the subscription's status. Stripe receives no client, lead or conversation data.
  • Sentry (error monitoring, when enabled). Receives error and crash reports — the error, a stack trace and basic request details — so problems can be fixed. It does not receive normal content: request bodies, cookies and authorization headers are removed before a report is sent, and personal-data collection is turned off.

4. Data storage, retention and deletion

Conversation history, uploaded-file placeholders (not the raw file itself — see the AI Use Disclosure), records and account information are stored in our database for as long as your account is active.

Deleting your account. You can delete your account from Settings › Profile. For a team member, that removes your login, your desk conversations, your weekly coaching check-ins and your saved chat preferences. The team's shared records stay with the team, including the calls you logged and the usage your requests generated, which move to the workspace owner. For the owner of a workspace with no other members, it removes the entire workspace — every record, conversation, setting and usage entry. An owner whose workspace still has other members is asked to have them remove their own accounts first.

When one of your contacts asks to be deleted. An owner or admin can delete that person's data from their contact page: the contact and their follow-ups, calls, messages, documents and consent history, and optionally the desk chats linked to them. To keep honoring their request not to be contacted, a one-way scrambled form of their phone number and email can be kept so they are never texted or auto-emailed again; it cannot be turned back into the number or address. Mentions of them you typed into other records (a transaction's notes, for example) are not searched out automatically.

Deletion takes effect in our database immediately. Copies can persist for a limited time in our database provider's point-in-time recovery history, and in the processors' own logs (for example, message logs at Twilio or Resend) under their retention policies.

5. Security

Passwords are hashed (never stored in plaintext). Access to your organization's data is restricted to authenticated users within that organization — see the multi-tenant isolation note in our engineering documentation for how this boundary is enforced at the database query level. [Placeholder — add specifics on encryption at rest/in transit once finalized for production infrastructure.]

6. Your rights

You can review and correct your account information from Settings, and delete your account from Settings › Profile as described in section 4. If you are a client or lead of someone who uses the Service, ask that agent to delete your data; they can do it from your contact record.

7. Children's privacy

The Service is intended for licensed real estate professionals and is not directed at or intended for use by children.

8. International data transfers

[Placeholder — to be completed based on actual hosting location and user base once deployed.]

9. Changes to this policy

This policy may be updated from time to time. Material changes will be noted with an updated "last updated" date on this page.

10. Contact

Questions about this policy can be sent to the account owner directly.