Privacy Policy
Last updated: 2026-08-03
Broker Intelligence is a productivity platform for real-estate brokers, operated by BIS LLC ("Broker Intelligence", "we", "us"). This policy explains what data the platform collects, why, who it is shared with, how long it is kept, and the choices you have.
This policy covers the Broker Intelligence web application at app.brokerintelligence.ai and the marketing site at www.brokerintelligence.ai.
Two definitions used throughout:
- Broker — the licensed real-estate professional who holds an account.
- Client data — information a broker records about the people they represent. Brokers control this data; we process it on their behalf.
1. Data we collect
1.1 Account information
Provided when you register or update your profile: first and last name, email address, a password hash (Argon2id — we never store or receive your plain password), your role, brokerage name, brokerage city, state and postal code, country, and timezone.
Timezone and country may be pre-filled by a coarse IP-address lookup at signup so the daily briefing arrives at the right local time. This lookup returns country and timezone only. You can override it at any time in your profile, and we record whether the value was detected or set by you.
1.2 Broker-private business data
The core of the product. Created by you, and visible only to you:
- Clients — name, email, phone, notes, and where you record them, a secondary contact such as a spouse or partner (name, email, phone, relationship).
- Buyer and seller intake — budget range, bedroom and bathroom counts, target areas, timeline, prospective property address, asking price, property type, square footage, listing date, and motivation notes.
- Pipeline and opportunities — stage, priority, source, last-contact and next-follow-up dates, and multiple opportunities per client.
- Transactions — property address, transaction type and status, commission figures, key dates, uploaded documents, and transaction notes.
- Tasks, goals, and activities — including the activity timeline that records your interactions with each client.
- Referral partners — contact details and referral history for the people who send you business, including approximate location for the coverage map.
1.3 Connected mailbox and calendar data
Mailbox and calendar sync is optional. Nothing is read until you connect an account and grant consent, and you can disconnect at any time.
When you connect Google or Microsoft, we request read access to your mail, read access to your calendar, permission to create drafts, and read access to your contacts. What we do with each:
- Mail. We scan messages from the last 30 days at first connection, then new messages going forward, to find correspondence involving people in your pipeline. For each match we store an activity record containing the subject line and a short snippet only — we do not store full message bodies, attachments, or messages that do not match a client in your pipeline. Full message text is held transiently in memory during matching and then discarded.
- Calendar. Events for the current day are read at the moment your daily briefing is generated, classified as real-estate or personal, and used to inform that day's coaching. Calendar events are not stored in our database.
- Drafts. When you ask the platform to generate a follow-up email, it creates a draft in your mailbox. It is a draft only — the platform never sends mail from your account on its own.
- Contacts. Read only when you open the contact-import screen, and shown to you so you can choose which to import. Only the contacts you explicitly select are saved.
We store an encrypted OAuth refresh token so sync can continue without repeated sign-ins. See §5 for how it is protected.
1.4 Voice-recorder transcripts
If you use a PLAUD recorder with the platform, transcripts you forward to your dedicated intake address are ingested and stored: the transcript text, any consent statement captured in the recording, an AI-generated summary and suggested next steps, the recording time, and the client the transcript is assigned to.
You are responsible for obtaining any consent that recording law in your jurisdiction requires before recording a conversation. Many US states require all-party consent.
1.5 Transaction-management integrations
If you connect SkySlope, we read your transaction files to create and update matching transactions in Broker Intelligence: property address, transaction type and status, key dates, price and commission figures, and the principal contacts on the file. If you delete a synced record, we record that decision so a later sync does not silently re-import it.
1.6 AI assistant conversations
Prompts you send to the AI coach and assistant, and the responses, are stored so your conversation history persists between sessions.
1.7 Billing information
Subscriptions are processed by Stripe. We store your Stripe customer and subscription identifiers, plan, status, and period dates. We never receive or store full card numbers, CVV codes, or bank credentials — those go directly to Stripe.
1.8 Audit logs and operational telemetry
We write append-only audit records for material events: account lifecycle, billing changes, integration connects and disconnects, and changes to broker-private data. Each record holds the actor, the action, the affected record's type and identifier, the IP address, the browser user-agent, and the time.
Audit metadata captures field names and identifiers only. Message bodies, note contents, and other free-text values are not copied into audit rows or application logs.
We also collect error reports and aggregate performance metrics. Sensitive fields are redacted before an error report leaves the application, and session replay is disabled.
1.9 Public forms
If you join the waitlist or submit a support request, we store what you entered on that form so we can respond.
2. How we use data
- To operate the features you use.
- To generate your daily briefing, coaching suggestions, market context, and drafted follow-ups.
- To send transactional email — account approval, password reset, billing receipts, support replies, waitlist updates.
- To provide brokerage owners with aggregate analytics about their office.
- To keep the service secure, investigate abuse, and satisfy legal obligations.
We do not sell your data or your clients' data. We do not serve advertising. We do not use your data or your clients' data to train third-party AI models.
3. Google user data
This section governs data obtained through Google APIs and takes precedence over anything more general elsewhere in this policy.
Broker Intelligence's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We use Gmail, Google Calendar, and Google Contacts data only to provide and improve the user-facing features described in §1.3.
- We do not transfer this data to others except as necessary to provide those features, to comply with applicable law, or as part of a merger or acquisition with notice to you.
- We do not use this data for advertising, and we do not sell it.
- We do not allow humans to read this data, except: with your explicit consent for a specific issue you have raised with us; where necessary for security purposes such as investigating abuse; to comply with applicable law; or where the data has been aggregated and de-identified.
Persistence is minimised by design. Of the Gmail data we read, only a subject line and short snippet for messages matching a client in your pipeline are retained. Calendar and contact data are read at request time and not stored, except for contacts you explicitly choose to import.
You can revoke our access at any time from within the app (§6) or directly at myaccount.google.com/permissions.
4. Who we share data with
We use the following subprocessors. Each handles a bounded slice of data under its own terms, and we maintain data-processing agreements where applicable.
Infrastructure
- Render — application hosting, PostgreSQL database, and Redis queue.
- Sentry — error monitoring, with sensitive fields redacted at source and session replay disabled.
Integrations you choose to connect
- Google — Gmail, Calendar, and Contacts sync.
- Microsoft — Outlook mail and calendar sync.
- SkySlope — transaction-file sync.
- PLAUD — voice-recorder transcripts, delivered by email.
Product features
- Anthropic — the primary AI provider for briefings, coaching, and drafting.
- OpenAI — fallback AI provider when the primary is unavailable.
- Mapbox — map tiles and geocoding for the referral coverage map.
- RentCast — market data for the market brief.
- IPinfo — coarse country and timezone lookup at signup.
Business operations
- Stripe — subscription billing and payment processing.
- Resend — transactional email delivery.
Both AI providers are used under terms that prohibit training on our data and provide zero or limited retention. Prompts include the client context needed to produce a useful answer; they do not include your credentials, payment details, or OAuth tokens.
This list is the source of truth. We update it before adding or removing a subprocessor.
Beyond these, we disclose data only when legally required, when necessary to protect our rights or someone's safety, or in connection with a merger, acquisition, or sale of assets — in which case we will give you notice.
5. How we protect data
- Passwords are hashed with Argon2id. Plain passwords are never stored.
- OAuth refresh tokens for Google, Microsoft, and SkySlope are encrypted at rest with AES-256-GCM, with versioned keys.
- All traffic is served over TLS.
- Sessions use signed, short-lived tokens with rotating refresh tokens.
- OAuth state parameters are HMAC-signed to prevent request forgery.
- The database is multi-tenant with query-level tenant scoping, so one brokerage's data cannot be reached from another's session.
- Broker-private data is scoped to its owner. A brokerage owner or manager sees aggregate analytics for their office, not another broker's individual clients, notes, or messages.
- Access to production systems is limited to personnel who need it.
No system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your data, we will notify you and any regulator as required by applicable law.
6. Your choices and rights
- Disconnect an integration. Profile → Platforms → Disconnect. We revoke the token with the provider immediately and stop all further syncing. Data already synced into your pipeline remains until you delete it.
- Revoke access at the provider. Google: myaccount.google.com/permissions. Microsoft: myaccount.microsoft.com/privacy.
- Correct or delete individual records. Clients, notes, transactions, transcripts, and activities can be edited or deleted from within the app.
- Reset your password. Use
/forgot-passwordfor a single-use, time-limited link. - Export your data. Email
privacy@brokerintelligence.aiand we will provide a machine-readable export of your account data. - Delete your account. Email
privacy@brokerintelligence.aifrom your account address. We will confirm, then delete your account and associated broker-private data within 30 days, except records we must retain for legal, tax, or fraud-prevention reasons (see §7).
Depending on where you live, you may have additional rights — access, correction, deletion, portability, restriction of processing, objection, and the right not to be discriminated against for exercising them. Residents of California, Colorado, Connecticut, Virginia and other US states with comprehensive privacy laws, and individuals in the UK and EEA, can exercise these rights by emailing privacy@brokerintelligence.ai. We do not sell or share personal information for cross-context behavioural advertising.
Where a broker has recorded information about you as a client, that broker is the controller of that information. We will refer your request to them and support them in fulfilling it.
7. How long we keep data
- Active accounts — data is retained while the account is in good standing.
- Synced mail activity — retained with your pipeline until you delete the client or the activity, or delete your account.
- Deactivated accounts — retained so the account can be restored, then deleted on request or as part of routine cleanup.
- Deleted accounts — broker-private data is deleted within 30 days of a confirmed request.
- Audit logs — retained for security and compliance for up to 24 months.
- Billing records — retained as long as tax and accounting law requires, typically seven years.
- Backups — deleted data may persist in encrypted backups for a short period before those backups age out.
8. International transfers
We operate in the United States, and our subprocessors may process data in the United States and elsewhere. If you access the service from outside the US, you understand that your data will be transferred to and processed in the US, where privacy law may differ from your own. Where required, we rely on Standard Contractual Clauses or an equivalent transfer mechanism.
9. Children
Broker Intelligence is a professional tool for licensed real-estate professionals. It is not directed at anyone under 18, and we do not knowingly collect data from children. If you believe a child has provided us data, email privacy@brokerintelligence.ai and we will delete it.
10. Changes to this policy
We will update this page when our practices change and revise the date at the top. For material changes we will give notice in the application or by email before the change takes effect. Continued use after a change takes effect means you accept the updated policy.
11. Contact
- Privacy questions and rights requests:
privacy@brokerintelligence.ai - Security reports:
security@brokerintelligence.ai - General support: the
/supportpage inside the application
BIS LLC, Portland, Oregon, United States.