Privacy
Operated by [OPERATOR NAME]. Contact: [CONTACT EMAIL], [MAILING ADDRESS].
What is public and what is private
- Public: review text, stars, facts and tenancy years (only once above the publishing threshold), a “verified” label on visible reviews, and a link to the City’s own code-enforcement case search.
- Never public: your name, account or email, unit numbers, exact dates, exact publish time, and any document.
- Landlord claimants see: what the public sees, plus their own disputes. Never reviewer identity.
- Admins see: your account ID (not your email), pending revisions, rejected reviews, reason counts for flags, and verification evidence while it is being reviewed.
Lease explainer
Lease text you submit is sent to OpenAI for processing. We do not store the text or the result. We try to remove personal information before sending, and reject the input if we cannot. OpenAI’s API may keep the input for up to 30 days for abuse monitoring under OpenAI’s own policy; we cannot delete it earlier.
One-time evidence review
Verification is a one-time check. The document and any real-name metadata are deleted before a verification decision becomes final. If deletion fails, the request stays pending, with no verified label, until cleanup succeeds. As a backstop, the storage bucket deletes evidence after 30 days, and unfinished uploads after 24 hours.
After a decision, we keep only:
- your account’s link to the property and the status (verified, rejected or needs more info);
- the method and the coarse start and end years shown on the document;
- private request and decision times and the deciding admin’s ID.
We never keep your name, ID images or numbers, the original filename, extracted text, notes, or unit numbers in a verification record. Firebase Auth sign-in data (your email or provider profile) is separate from verification data and is held by Firebase while your account exists.
Data retention and deletion
What we keep, and when we delete it
- Verification evidence and any names inside it: deleted before a decision becomes final; unfinalized uploads after 24 hours; 30-day bucket backstop.
- Verified status, property link, evidence years, private times and deciding admin ID: kept while your account exists; deleted on account deletion (an anonymized review may keep its verified flag).
- Rejected or needs-more-info verification record: 30 days after the decision.
- Undecided verification record: deleted when its evidence expires at 30 days. If deletion fails it stays
cleanup_pendinguntil retried. - Firebase Auth email and provider profile: held while your account exists; removed when the Firebase user is deleted, subject to Firebase’s own retention.
- Published reviews: until withdrawn or removed.
- Withdrawn review text: deleted immediately.
- Rejected review text (not resubmitted): 90 days.
- Reviews removed by moderators: deleted 90 days after removal.
- Review revisions: deleted on approval; rejected revisions after 30 days.
- Dispute details: cleared 180 days after the decision.
- Flags: 1 year.
- Reminders (sent or cancelled): 30 days.
- Unmatched public records: 90 days.
- Raw events and job runs: 90 days, except lease explainer events linked to a signed-in account, which are kept 13 months.
- Daily metrics and AI usage counters: 24 months.
- Moderation audit (no content): 3 years.
- Rate-limit buckets: 1 day after the window.
- Application logs (allowlisted, no content): 30 days. Request logs are excluded.
- Backups: 7 days, so deleted data can remain in a backup for up to 7 days.
- Deleted accounts: the identity link is removed immediately.
What we do not keep
- Lease text and explainer results.
- Search terms.
- IP addresses (only hashed rate-limit keys, no raw IPs in our database).
- Your email in our database (it stays in Firebase Auth).
- Real-name metadata, filenames or extracted text from verification.
Processors keep data under their own policies
Our deletion does not control a processor’s retention. OpenAI may keep lease-explainer input for up to 30 days. Firebase, Google Cloud and Neon apply their own retention and backup rules.
Cookies
We set one cookie, __session, to keep you signed in. We use no analytics scripts, pixels or other cookies.
Processors
- Cloudflare Turnstile — bot checks.
- Firebase Auth — sign-in.
- Resend — email.
- Google Cloud — hosting and storage.
- Neon — database.
- OpenAI — lease explainer processing (see above).
Public records
We do not import public records yet. If we add a city open-data feed, records will attach only to exact address matches and come from the source, which can be incomplete or out of date.
Limits of anonymity
We never show your name or account. But we cannot guarantee anonymity: the details of a review can still identify its author, especially to a landlord. Leave out details you would not want linked to you.
Account deletion and contact
Deleting your account (after a recent sign-in) removes the identity link, evidence, reminders, claims and your Firebase user. You choose whether published reviews stay anonymous (no longer editable) or are withdrawn. An anonymized review keeps its “verified” flag, because that weight was earned. Questions: [CONTACT EMAIL], [OPERATOR NAME], [MAILING ADDRESS]. See also Terms.