Privacy Policy
Last updated: September 27, 2026
Information We Collect
When you create a CREagentic account, we collect your name, email address, and company name. We also collect usage data such as pages visited, features used, analysis runs performed, and valuation models created.
When you upload documents (leases, operating memoranda, rent rolls, etc.) for AI analysis, we process the contents to deliver results. Payment information is collected and processed by Stripe. We never store credit card numbers on our servers.
We automatically collect device information, IP address, browser type, and referring URLs through standard server logs.
How We Use Your Information
We use your information to:
- Provide, maintain, and improve CREagentic services
- Process your documents through our AI analysis pipeline
- Process payments and manage your subscription
- Send transactional emails (welcome, billing, usage alerts)
- Analyze aggregate usage patterns to improve the platform
- Enforce our Terms of Service and prevent abuse
We do not sell your personal data to third parties.
AI Data Processing
When you use CREagentic's AI features, your document content, prompts and chat messages are sent to Anthropic's Claude API for processing. Anthropic is the only AI provider that receives customer document content. Under Anthropic's commercial API terms, inputs and outputs are not used to train Anthropic's models; retention is governed by Anthropic's published API data policy.
CREagentic also uses OpenAI and Google AI models for internal operator tooling only (for example, transcribing the operator's own voice notes and drafting internal reports). Those services do not receive your uploaded documents, analysis outputs or chat content.
CREagentic does not use your uploaded documents or analysis results to train any AI models. Your data is used solely to deliver the analysis you requested. Outputs produced by AI are labeled as such in the product and in exports.
Data Sharing
We share data with the following categories of service providers, solely to operate and deliver CREagentic:
- Payment processing (billing, invoicing, subscription management)
- Cloud infrastructure (database hosting, application hosting, content delivery)
- AI processing (document analysis, natural language processing)
- Transactional email (account notifications, billing alerts)
- Rate limiting and caching (abuse prevention)
We do not share your data with advertisers or data brokers. We may disclose data if required by law or to protect our legal rights.
Data Retention and Deletion
We retain your account data for as long as your account is active. Analysis results and valuation models are retained until you delete them. Server logs are retained for 90 days.
You may delete your account at any time from the Settings page. Upon account deletion, all personal data, uploaded documents, analysis results, and valuation models are permanently removed within 30 days. Some data may persist in encrypted backups for up to 90 days before being purged.
Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate personal data
- Request deletion of your personal data
- Export your data in a portable format
- Opt out of non-essential communications
- Withdraw consent for data processing
To exercise any of these rights, contact privacy@creagentic.ai or use the account settings page.
CCPA Specific Rights
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, and shared
- Right to delete personal information
- Right to opt out of the sale of personal information
- Right to non-discrimination for exercising your rights
CREagentic does not sell personal information. To exercise your CCPA rights, contact privacy@creagentic.ai with the subject line "CCPA Request."
Security Measures
We implement appropriate technical and organizational measures to protect your data, including:
- Encryption at rest (AES-256) and in transit (TLS 1.3)
- Row-Level Security (RLS) ensuring data isolation between users
- Role-based access controls for internal systems
- Regular security reviews and vulnerability assessments
- API key hashing (SHA-256) with one-time display of plaintext keys
No system is 100% secure. If you discover a vulnerability, please report it to security@creagentic.ai.
Subprocessors
CREagentic uses the following subprocessors to deliver our services:
- Anthropic (AI processing of customer documents, prompts and chat) - United States
- Stripe (payment processing) - United States
- Supabase (database, authentication and file storage) - United States
- Vercel (application hosting, edge functions and analytics) - United States
- Resend (transactional email) - United States
- Upstash / Vercel KV (rate limiting and short-lived support chat state) - United States
- Sentry (error monitoring) - United States
- PostHog (product analytics) - United States
- Cloudflare (CDN, bot protection) - United States
- Google Fonts (web font delivery; receives visitor IP addresses only) - United States
- OpenAI (internal operator tooling only; no customer document content) - United States
- Google AI (internal operator tooling only; no customer document content) - United States
- Telegram (internal operator alerts; receives masked email addresses, partially masked IP addresses and support conversation summaries) - United Kingdom / United Arab Emirates
- GitHub (source code hosting for the platform; no customer data) - United States
The current list is also published in our repository at docs/compliance/SUBPROCESSORS.md. We will update this list when subprocessors change and notify affected users.
Contact Information
For privacy-related inquiries, contact privacy@creagentic.ai.
For general support, contact support@creagentic.ai.
CREagentic