How Real Estate OS handles your data and the systems you connect to it.
This policy covers the Real Estate OS website, applications, connectors, and the MCP server at mcp.realestateos.com (together, the "Service"). It applies to information about you as a customer and to information we process on your behalf from systems you connect.
Two different roles matter here. For information about you as a customer — account details, billing, support — we act as a controller. For the data inside the systems you connect (your CRM records, contacts, calls, documents), we act as a processor handling it on your instructions. You remain responsible for that data and for having the right to share it with us.
When you authorize a connector, we store the credentials needed to keep it working: OAuth access and refresh tokens, or API keys you provide. These are stored encrypted and used only to make requests you or your instructions initiate.
Depending on which connectors you enable, the Service reads and may write:
We read from your source systems at request time rather than maintaining a full duplicate copy. We do store operational records: identifier mappings between systems, synchronization logs, and call recordings where you have enabled recording.
Standard technical logs — IP address, browser type, timestamps, and pages or endpoints accessed — used for security, debugging, and reliability.
We do not sell your data. We do not use the contents of your connected systems to train AI models, and we do not share that content for advertising.
The Service can be connected to an AI assistant, such as Claude, through the Model Context Protocol. When you connect one:
Where you enable recording, audio files are stored in private object storage and served through links that expire. Recordings are retained per your account's retention setting and deleted on request.
We use the following categories of subprocessor. Each receives only what it needs:
| Purpose | What they process |
|---|---|
| Cloud infrastructure and storage | Application hosting, encrypted data at rest, call recordings |
| Database | Account records, connection credentials, sync logs, identifier mappings |
| Payment processing | Billing details and subscription status |
| Email and SMS delivery | Notifications and alerts you configure |
| AI assistant providers | Only the data returned in response to your requests |
A current list of named subprocessors is available on request. We will make reasonable efforts to notify customers of material changes.
We share information only:
Data in your connected systems remains in those systems and is governed by their providers' policies, not this one.
No system is perfectly secure. If a breach affects your data, we will notify you as required by applicable law.
Depending on where you live, you may have additional rights under laws such as the California Consumer Privacy Act or the GDPR. Contact us at [PRIVACY EMAIL] and we will respond within the period required by law. For data we process on a customer's behalf, we will refer your request to that customer.
If you are a homebuyer, seller, or other consumer whose information appears in a Real Estate OS customer's system, that customer — not Real Estate OS — controls your information. Contact them directly. If you contact us, we will forward your request to them.
The Service is for business use and is not directed to anyone under 18. We do not knowingly collect information from children.
The Service is operated from the United States. If you access it from elsewhere, your information will be transferred to and processed in the United States.
We may update this policy. Material changes will be announced through the Service or by email, and the "last updated" date above will change. Continuing to use the Service after a change means you accept the updated policy.
Questions about this policy or your data:
[PRIVACY EMAIL]
[BUSINESS NAME]
[BUSINESS ADDRESS]