Privacy Policy
This page says what we collect, who can see it, how long we keep it, and how to have it deleted. It is written to describe what the product actually does today, not what we intend it to do. Effective August 24, 2026.
First, what this product is
It matters here too: we hold documents about your purchase because that is what a coordination tool does. We are not the official record of it. See the Terms.
What we collect from an agent
An agent creates their own account, so they choose what to put in it. That is: their name, their email address, an optional phone number, their time zone, and — because agents sign in with a password — a scrambled, one-way version of that password. The scrambling only runs one way: we cannot turn it back into your password and neither can anyone who steals the file. Agents can also add a photo, a brokerage name and an accent colour, which is what their buyers see at the top of the screen.
What we collect about a buyer
If you are buying a home, you did not sign up here — your agent invited you. So most of what we hold about you was entered by them, on your behalf, and you can see almost all of it on your own screen.
- You never create a password. There is no password to forget, reuse or have stolen, because you do not have one. You get in by clicking a link we email you. That link works for a short time, once, and only ever goes to the email address your agent invited — never to an address typed into a form by whoever is holding the link.
- Your name, email address and an optional phone number — normally typed in by your agent when they invited you.
- The purchase itself — the property address, the purchase price and closing date if your agent enters them, the key dates, the to-do items and their due dates, and the contact details your agent adds for the lender, title company, inspector and so on. Those contact details are other people's names, phone numbers and email addresses, and sometimes a licence number.
- Documents you or your agent upload — including, realistically, financial ones: pre-approval letters, proof of funds, inspection reports, the agreement of sale.
We do not ask for and do not want your Social Security number, your bank account or routing numbers, or your card details. Nothing in this app should ever be used to send money. If someone emails you asking you to wire funds because of something you saw here, stop and call your agent or the title company on a number you already had.
What we record while you use it
- Activity — who did what and when inside a purchase: a to-do marked done, a document uploaded, a buyer invited or removed. This is how both sides can see the purchase moved, and it is also our record if anyone ever disputes what happened when.
- Product usage — sign-ins, screen opens, and which emailed link brought you here, kept in our own database. We use it to work out whether this product is worth continuing to build. There are no advertising or tracking scripts on any page — we checked the whole codebase, and there is no analytics company involved at all.
- Security records — a count of recent sign-in attempts per email address, so nobody can hammer the sign-in form or ask for endless sign-in links. It stores the address and the time, nothing else.
- A note of which emails we sent — enough to be sure the same reminder does not go out twice.
One thing worth knowing, because it is not obvious from the screen: your agent can put their photo on your view of the purchase, and that photo is loaded from wherever they host it. When your browser fetches it, that other website sees your internet address and the time you looked. We do not choose that host and we do not receive anything from it.
Who can see it
- Your agent sees everything in the purchases they own, and nothing in any other agent's purchases.
- You, as a buyer, see only the purchases you were invited to, and within them only the items your agent marked shared. Agents can mark a to-do, a document, a document slot or an activity entry “internal” — their own working notes. Internal items are filtered out on our server, before anything is sent to your browser. They are not hidden with styling and they are not sent and then covered up: they never leave our server. We test this by planting internal items on a real purchase and searching the raw data the browser receives for any trace of them.
- A co-buyer on the same purchase sees the same shared items you do.
- Us — the small team running the service. Being precise, because the honest version is more useful than the reassuring one: there is no admin screen and no support login inside the app. Nobody can browse your purchase from a control panel, because no such panel exists. What a person on our side does have is direct access to the database and the file storage, the way any small team does, and that is how a support question or a deletion request gets handled.
We do not sell personal information, we do not share it for advertising of any kind, and we would hand anything to a government or into litigation only where the law actually requires it.
The companies that help us run this
Running a service means other companies hold pieces of it. These are all of them. Each one processes data on our behalf, under its own contract, and is not permitted to use it for its own purposes. There are no others, and none of them is an advertising or analytics company.
- Vercel — runs the website itself and stores every uploaded document. Documents are held in a private store, encrypted while stored.
- Neon — runs our database: accounts, purchases, dates, to-dos, contacts, activity. Encrypted while stored.
- Resend — sends our email. Worth reading twice, because it is the one that surprises people: Resend keeps the contents of each message, and the record of what happened to it, for 30 days before deleting it. Our emails include things like the property address, a closing date or a to-do title, so for those 30 days Resend holds a small slice of your purchase. Documents are never attached to email — they stay in storage and the email links to them.
- GitHub — stores the software's source code. No account, purchase or document data is kept there.
How documents are stored, and how they are handed out
- A document is never a public link. There is no address you could paste to a friend that would open one, and there is no address that keeps working. Each time somebody who is allowed to see a file clicks it, we mint a one-off link for that one person and that one file, and it stops working 15 minutes later.
- Before a file is accepted we check what it actually is, on our server, by reading its contents — not by trusting its name. Only PDFs, common photo formats and Word documents are stored, up to 25 MB. A web page renamed to look like a PDF is refused and never written anywhere.
- Every download is recorded — who, which file, when — so there is an answer if it is ever asked.
- Our storage and database providers encrypt what they hold. We do not add a second layer of our own encryption on top of theirs, which means a person on our side with database and storage access can open a document. If that matters for a particular file, don't upload it.
- Traffic between your browser and the site runs over HTTPS, which our hosting platform provides and enforces. Nothing moves in the clear.
No system is perfectly secure, and anyone who tells you otherwise is selling something. If we ever have a breach that affects your personal information, we will tell the people affected and any regulator we are required to tell.
Cookies, and staying signed in
We use cookies for exactly one thing: remembering that you are signed in between clicks. There are no advertising cookies, no tracking cookies and no third-party cookies, so there is no consent banner to click through — there is nothing to consent to.
- If you are a buyer, your cookie is a long random number and nothing else. It means nothing on its own; it matches a row in our database that says which purchase you are signed in to. Your agent can end that session, and it lapses on its own after 30 days of not visiting.
- If you are an agent, your cookie is a signed token that carries your account's internal id. It does not carry your name, your email or anything about your purchases, but it is not simply a meaningless number either, and we would rather say so than round it off.
Both are set so that other websites cannot read them, and so that they are only sent over an encrypted connection.
How long we keep it
- A purchase that closes stays, indefinitely, on purpose. Keeping the record of your home after closing — the documents, the dates, everyone who helped — is the point of the product, not an oversight. It stays until somebody asks us to delete it.
- A purchase that does not complete stays open to the buyer for 30 days after the agent marks it that way, so there is time to download everything. After 30 days the buyer's access ends — really ends: the session stops working, no new sign-in link will be issued, and the documents can no longer be fetched. The agent keeps their own record of the transaction.
- Agent accounts and everything in them are kept while the account is open.
- Activity, product usage, security and email-sending records are kept indefinitely today. There is no automatic clear-out yet. Saying so is more useful than inventing a schedule we have not built.
How the 30-day cut-off and the keep-forever promise fit together: they are about different things. The 30 days is about access — who can still open the file. Keeping a closed purchase is about storage — the data still exists either way. Ending access is not deletion, and a purchase that did not complete is not deleted at the 30-day mark; the buyer simply can no longer reach it. If you want it actually deleted, ask, using the section below.
Deleting your data, correcting it, or seeing what we hold
Being straight with you about the mechanism, because it changes what you should expect: there is no “delete my account” button in the app. Deletion is a person on our side following a written procedure across the database and the file storage. That is why the window is 30 days rather than instant, and why we confirm in writing what was removed rather than just showing you a spinner. When we automate it, this section gets shorter and faster, and we will move the effective date at the top when it does.
None of this costs anything, and asking will not get you a worse version of the product.
The one thing deletion cannot do: a purchase has two sides. If you are an agent and you ask us to delete your account, we remove your personal information, but the buyer's own record of their own purchase — their documents, their dates, their home — survives, with your details removed. If you are a buyer asking for deletion, your side goes and the agent keeps their record of the transaction with your personal details removed. We will not destroy one person's copy of a transaction to satisfy a request from the other party to it. Tell us which you want and we will confirm exactly what we did.
The only reasons we would keep something after you asked us to delete it
Most privacy pages put a line here saying the company may keep data “for legal reasons”. That sentence is a blank cheque: it lets a company keep anything, for as long as it likes, without ever naming what or why. So instead, here is the list. It is the whole list. Anything not named on it is deleted when you ask.
- A legal demand, or a dispute somebody has told us about. If we are served with a subpoena or a court order, or told in writing that there is a lawsuit, an insurance claim or a complaint to a state real-estate commission about a particular purchase, we hold the records for that purchase — not your other purchases, and nothing about you beyond it. We hold them until the matter is finished. Then we delete them within the same 30 days, without you having to ask a second time. We tell you when a hold starts, why, and when it lifts.
- A short receipt proving we did it. Your email address, the date you asked, the date we finished, and one line saying what was removed. It exists so we can show you — or a regulator — that the deletion really happened, and so an old invitation cannot quietly pull your information back in later. No documents, no property address, no purchase details: those four things and nothing else. We keep it for as long as we run the service.
- Backups, briefly, by their nature. Our database provider keeps automatic snapshots so the service can be brought back after a failure. A deletion clears the live data straight away, and then ages out of those snapshots as they are replaced. We never restore a snapshot to bring back something you asked us to delete, and if we ever have to restore one after a real failure, we re-run your deletion against it.
- Email that already went out. As described above, the company that sends our email holds sent messages for 30 days before deleting them. Deleting your information here cannot reach back into a message that has already been sent.
What about your agent's record-keeping? Agents and their brokers are required to keep their own file on a transaction for a number of years. That is a rule about their records, kept in their system — and, as the top of this page and the Terms both say, we are not that system. The brokerage keeps its own compliance file. So their record-keeping duty is not a reason for us to hold on to our copy: when you ask, we delete ours. That is our reading, and we are having it confirmed by a real-estate attorney rather than assuming it. If it turns out that some specific record does have to be kept, this page will name that record, name the rule that requires it, say for how long, and say what happens to it afterwards — and the effective date at the top will move so you can see it changed. It will not turn into a general “legal reasons” clause. That is a promise about the shape of this page, and it is the one we would most like you to hold us to.
If you are an agent closing your account: your own record-keeping duty to your broker is yours, and deleting your account here neither satisfies it nor excuses it. Download what you need first. Deletion is not reversible and we will not have a copy to give you afterwards.
Email about your own purchase — your invitation, your sign-in link, a document shared with you, a to-do coming due — is part of the service, and we will keep sending it while you have access. There is no opt-out for those, and there should not be: switching them off would lock you out of your own purchase.
The daily summary an agent receives is different. It is a recurring digest, so every one of them carries an opt-out with an address on it. Being precise about how that opt-out works today, because the wording in the email is friendlier than the machinery behind it: a person reads that mailbox and switches the summary off by hand. We do it within 10 business days, and it does not affect anything else — every other message keeps working. There is no self-service unsubscribe link yet.
Every email we send identifies who sent it, carries a postal mailing address, and can be replied to.
Children
This is a tool for people buying a house. It is not for anyone under 18, we do not knowingly collect anything from a child, and there is nothing in it aimed at children. If we learn we have collected something from one, we delete it. Nobody under 18 can be invited to a purchase except by an agent typing their address in, and if that happens, tell us and we will remove it.
When this page changes
The effective date at the top is the honest signal — it moves whenever anything on this page substantively changes, so you can always tell which version you agreed to. If a change matters to you (what we collect, who can see it, how long we keep it, or how deletion works) we will also email account holders about it rather than quietly swapping the text.
Reaching us
For anything on this page — a question, a request for a copy of your data, a correction, a deletion, or a complaint: nabilrezqui@gmail.com.