Privacy Policy
Effective Β· June 12, 2026
This Privacy Policy explains what data REIzer ("REIzer," "we," "us") collects when you use our service, how we use it, who we share it with, and the rights you have over it. It applies to reizer.io and all related products.
1. What we collect
Account information
When you sign up, we collect your email address and (where you provide it) name and profile photo. If you sign in with Google, we receive your email, name, and profile picture from Google via OAuth. If you sign up with email and password, we store a salted hash of your password β never the plaintext.
Deal and portfolio data
The property addresses, purchase prices, rehab budgets, financing terms, projected rent, projected ADR, occupancy assumptions, deal notes, comparison rubrics, and any other inputs you enter or upload β collectively, "Your Deal Data." This data is yours; we hold it to run the service for you.
Payment information
If you subscribe to a paid plan, payment is handled by Stripe. We receive limited billing metadata from Stripe (your subscription tier, last 4 digits of your card, billing country) but never receive or store your full card number, CVV, or bank credentials.
Usage and diagnostic data
Pages you visit within the app, features you use, browser and device type, IP address, approximate location derived from IP, error messages, and performance metrics. This data is used to operate, debug, and improve the service.
Communications
Messages you send via the contact form or in response to product emails. We retain these for support history and to improve the product.
AI Copilot inputs
The prompts, questions, and follow-ups you send to the AI Copilot, plus any deal context the app sends along with your prompt (described in AI Copilot data).
2. How we use your information
We use the data we collect to:
- Operate the service β authenticate you, save and load your deals, render charts, generate PDF reports, and route comp requests to data providers.
- Process payments and manage subscriptions (via Stripe).
- Send transactional email β sign-in links, password resets, billing receipts, important service notices, plan-limit warnings, and security alerts (via Resend).
- Provide AI Copilot responses (via Anthropic) when you invoke that feature.
- Improve the product β diagnose bugs, measure feature adoption in aggregate, and prioritize roadmap.
- Comply with legal obligations, enforce our Terms of Service, and protect against fraud and abuse.
The legal bases for these uses (where required by applicable law) are: performance of our contract with you, our legitimate business interests in running and improving the service, your consent (for any marketing communications you opt into), and compliance with legal obligations.
3. What we never do
- We never sell your data. Not to brokers, not to list-buyers, not to advertisers, not to anyone.
- We never use your deal data or AI Copilot prompts to train AI models β ours or any third party's. Our agreement with Anthropic prohibits retention of your prompts for training.
- We never send marketing email without your opt-in. Transactional email (sign-in, billing, security) is necessary and is not marketing.
- We never share your deal data with other users, even when they ask. Row-level security policies in our database enforce this at the database layer.
4. Sub-processors
We rely on a small set of vendors to run the service. Each is contractually bound to handle your data only for the purpose it was shared with them. The current list:
- Supabase β Hosts our database (your account, deals, portfolio), file storage (uploaded images, PDFs), authentication, and Edge Functions. U.S. infrastructure on AWS. Data is encrypted in transit (TLS) and at rest. Row-level security policies isolate your data from other users at the database layer.
- Stripe β Processes subscription payments. Handles card data directly; your full card number never touches our servers. PCI-DSS Level 1 certified.
- Anthropic β Runs the AI Copilot (Claude). Receives the prompts you send to the Copilot plus the deal context the app attaches to your prompt. Anthropic does not retain these prompts for model training under our commercial agreement.
- Resend β Delivers transactional email (sign-in links, password resets, billing receipts, plan-limit notices). Receives your email address and the email body.
- RentCast β Source for sale comps, long-term rent comps, and market statistics. When you trigger a comp lookup, we send the target property's address and search parameters; we do not send your account email or other identifying information.
- AirRoi β Source for Airbnb / VRBO short-term-rental comps, ADR, occupancy, and seasonality. When you trigger an STR comp lookup, we send the target market identifier and search parameters only.
- Google β Optional sign-in via Google OAuth. If you choose Google sign-in, Google shares your email, name, and profile picture with us; we do not receive your Google password.
- Amazon Web Services β Underlying cloud infrastructure for Supabase. U.S.-region hosting.
When we add or remove a sub-processor, we will update this list. Material additions for paid customers will be announced via email at least 30 days in advance.
5. AI Copilot data handling
When you use the AI Copilot:
- Your prompt is sent to Anthropic Claude via an authenticated Edge Function. The prompt may be accompanied by a structured
user_contextblock containing a snapshot of your portfolio, recent deals, or the form state of the analyzer you opened the Copilot from β only what is needed to answer your question. - We do not include your full database or other users' data in the prompt β only the slice relevant to your query.
- Prompts are not retained for training by Anthropic under our commercial agreement.
- Conversation history is stored in our database so you can return to past chats. You can delete a conversation from within the Copilot UI; deleted conversations are permanently removed within 30 days.
- We log token and message counts for billing and rate-limiting (not prompt content). Aggregate counts may be surfaced to operators for capacity planning.
- The AI Copilot is metered. Your monthly message and token usage is stored against your account so we can enforce plan limits.
6. Cookies and local storage
We use a small number of essential cookies and browser-storage entries:
- Authentication tokens β keep you signed in across pages. Required for the service to work.
- Theme preference β remembers your light/dark/midnight selection.
- Local cache β preserves form state between page loads so you don't lose work on refresh.
We do not currently use third-party advertising or behavioral-tracking cookies. If we add aggregate, privacy-respecting analytics in the future, we will update this section.
7. Data retention and account deletion
We retain your data for as long as your account is active and as needed to provide the service. When you delete your account:
- Your account, saved deals, portfolio data, comp snapshots, AI Copilot conversations, and uploaded files are permanently removed within 30 days.
- Backups are purged on rolling retention; residual copies expire within 90 days.
- Billing records and transaction history are retained for the period required by tax and accounting law (typically 7 years), separately from your account data.
- Aggregate, anonymized usage statistics (counts, no identifiers) may be retained for product analytics.
You can request account deletion from settings or by contacting us via our contact page.
8. Security
We follow standard industry practices for protecting your data:
- All data is encrypted in transit via TLS 1.2 or higher.
- All data is encrypted at rest by our database provider.
- Database access is gated by row-level security policies that isolate each user's records β meaning we can't accidentally surface another user's deals even via internal queries.
- API keys for third-party providers (RentCast, AirRoi, Anthropic, Stripe) are stored as encrypted Edge Function secrets, never exposed to the browser.
- We follow least-privilege principles for internal access. Routine admin operations are audited.
- SOC 2 Type II certification is on our roadmap as we scale.
No system is perfectly secure. If we become aware of a security incident affecting your data, we will notify affected users without undue delay and in accordance with applicable law.
9. Your rights
Regardless of where you live, you can:
- Access β request a copy of your account data and deals at any time.
- Correct β update or correct profile and deal information from your settings.
- Delete β delete your account and all associated data from settings or by contacting support.
- Export β download your saved deals as PDF (today) or structured export (on roadmap).
- Opt out β unsubscribe from any non-transactional email at any time.
If you are in the European Economic Area, the United Kingdom, or California, you have additional rights under GDPR, UK GDPR, and the CCPA respectively, including the right to object to processing, the right to data portability, and (for California) the right to know what categories of personal information we have shared. We follow GDPR-equivalent practices globally and do not sell personal information as defined under the CCPA. To exercise any of these rights, contact us via the contact page; we'll respond within 30 days.
10. Children
The service is not directed to anyone under 18, and we do not knowingly collect data from anyone under 18. If you believe a child has provided us personal data, please contact us and we will delete it.
11. International users
REIzer is operated from the United States, and all data is stored and processed on U.S. infrastructure. If you access the service from outside the U.S., you understand and consent to the transfer of your data to the U.S., which may have data-protection laws different from those of your jurisdiction. Where required, we rely on Standard Contractual Clauses or equivalent safeguards for cross-border transfers.
12. Changes to this policy
We may update this Privacy Policy from time to time. We will post the updated version with a new "Effective" date at the top. For material changes β for example, adding a new category of data we collect or a new sub-processor β we will provide reasonable advance notice by email or in-app message before the change takes effect.
13. Contact
Privacy questions, data requests, or concerns? Reach out via our contact page and we'll respond within one business day.