Privacy Policy

Last updated: March 18, 2026

This Privacy Policy describes how The Real Estate Toolbox ("we," "us," or "our") collects, uses, and shares information about you when you use our website at https://therealestatetoolbox.com (the "Service"). By using the Service, you agree to the collection and use of information in accordance with this policy.

1. Information We Collect

Account Information

When you create an account, we collect your name and email address. This information is used to create and manage your account, authenticate you when you log in, and communicate with you about the Service.

Usage Data

We log which tools you use and when you use them. This data is tied to your user account and is used to enforce usage limits, monitor platform health, and improve the Service. We do not log the full content of your tool inputs unless explicitly stated.

Content You Submit

When you use our tools, you may submit property addresses, listing details, agent information, market data, and other real estate-related content. This content is processed on your behalf to generate outputs (descriptions, flyers, reports, etc.) and is not stored long-term beyond what is necessary to deliver the result.

Automatically Collected Information

We may automatically collect certain technical information when you visit the Service, including your IP address, browser type, operating system, referring URLs, and pages visited. This information is used for security monitoring, debugging, and aggregate analytics. We use session cookies and authentication tokens to keep you logged in.

2. How We Use Your Information

We use the information we collect to:

  • Create and manage your account and authenticate your identity
  • Provide, operate, and maintain the Service and its tools
  • Process your requests and generate AI-powered outputs
  • Enforce usage limits and prevent abuse
  • Send transactional emails (account confirmation, password resets)
  • Send service-related communications (policy updates, important notices)
  • Analyze usage patterns to improve and develop new features
  • Comply with legal obligations and enforce our Terms of Service

We do not use your data for advertising purposes, and we do not sell, rent, or trade your personal information to third parties for their marketing purposes.

3. Third-Party Services

We use the following third-party services to operate the platform. Each service has its own privacy policy governing how they handle data.

Supabase

We use Supabase for user authentication and database storage. Your account credentials, profile information, and usage logs are stored in Supabase. Supabase is SOC 2 Type 2 compliant. Privacy policy: supabase.com/privacy

Anthropic (Claude AI)

We use Anthropic's Claude API to generate listing descriptions, marketing copy, market analysis, and other AI-generated content. Content you submit through our tools is sent to Anthropic's API for processing. Anthropic does not use API inputs to train its models by default. Privacy policy: anthropic.com/privacy

Replicate

We use Replicate to generate AI images for marketing flyers. Property details you submit for flyer generation may be used to construct image prompts sent to Replicate. Privacy policy: replicate.com/privacy

Rentcast

We use the Rentcast API to retrieve property data, market statistics, and comparable sales. Property addresses you submit to our Comp Analyzer, Neighborhood Report, Market Update Email, and Property Record Search tools are sent to Rentcast to retrieve this data. Privacy policy: rentcast.io/privacy

Resend

We use Resend to deliver transactional emails including account confirmation and password reset emails. Your email address is shared with Resend solely for the purpose of delivering these messages. Privacy policy: resend.com/privacy-policy

Stripe (Planned)

We plan to use Stripe to process subscription payments. If and when payment processing is enabled, billing information you provide will be handled by Stripe and subject to their privacy policy. We do not store full credit card numbers on our servers. Privacy policy: stripe.com/privacy

4. Cookies and Tracking

We use cookies and similar technologies to keep you authenticated between sessions. Specifically:

  • Authentication cookies — set by Supabase to maintain your logged-in session
  • Preference cookies — may be used to remember your settings within the Service

We do not use advertising cookies or tracking pixels for marketing purposes. We do not participate in cross-site tracking networks.

You can control cookies through your browser settings. Disabling authentication cookies will prevent you from staying logged in.

5. Data Storage and Security

Your data is stored on servers provided by Supabase, which operates infrastructure in the United States. We implement reasonable technical and organizational security measures to protect your personal information from unauthorized access, disclosure, alteration, or destruction, including:

  • Encrypted connections (HTTPS/TLS) for all data transmitted to and from the Service
  • Row-level security policies in our database to prevent unauthorized data access
  • Hashed and salted password storage (managed by Supabase Auth)
  • API keys stored as environment variables and never exposed to the client

No method of transmission over the internet or electronic storage is 100% secure. While we strive to use commercially acceptable means to protect your data, we cannot guarantee its absolute security.

6. Data Retention

We retain your personal information for as long as your account is active or as needed to provide the Service. Usage logs are retained for up to 12 months for operational and abuse prevention purposes.

If you delete your account, we will delete or anonymize your personal information within 30 days, except where we are required to retain it to comply with legal obligations, resolve disputes, or enforce our agreements.

7. Your Rights

Depending on your location, you may have certain rights regarding your personal information:

For All Users

  • Access — You may request a copy of the personal data we hold about you
  • Correction — You may request that we correct inaccurate data
  • Deletion — You may request that we delete your account and associated data
  • Portability — You may request your data in a structured, machine-readable format

GDPR (European Economic Area & UK)

If you are located in the EEA or UK, you have additional rights under the General Data Protection Regulation, including the right to object to processing, the right to restrict processing, and the right to lodge a complaint with your local supervisory authority. Our legal basis for processing your personal data is your consent (at account creation) and our legitimate interest in providing and improving the Service.

CCPA (California Residents)

If you are a California resident, you have the right to know what personal information we collect and how it is used, the right to delete your personal information, the right to opt out of the sale of your personal information (we do not sell personal information), and the right not to be discriminated against for exercising these rights. To submit a request under the CCPA, contact us at support@therealestatetoolbox.com.

To exercise any of these rights, please contact us at support@therealestatetoolbox.com. We will respond to verified requests within 30 days.

8. We Do Not Sell Your Data

We do not sell, rent, lease, or trade your personal information to any third party for their own marketing or commercial purposes. We share your data only with the service providers listed in Section 3, and only to the extent necessary to operate the Service.

9. Children's Privacy

The Service is not directed to individuals under the age of 18. We do not knowingly collect personal information from children. If you believe we have inadvertently collected information from a minor, please contact us and we will promptly delete it.

10. Changes to This Policy

We may update this Privacy Policy from time to time. When we do, we will update the "Last updated" date at the top of this page. For material changes, we will notify you by email (sent to the address associated with your account) or by a prominent notice on the Service at least 7 days before the change takes effect.

Your continued use of the Service after any changes constitutes your acceptance of the updated Privacy Policy.

11. Contact Us

If you have any questions, concerns, or requests regarding this Privacy Policy or our data practices, please contact us at: