Privacy policy
DealKept ("we", "us") is an assistant for real estate agents and their teams. This policy explains what we collect, why, who we share it with, and how you control and delete it. It applies to the DealKept app and to dealkept.com.
Google user data
DealKept's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
What we access
When you choose to connect a Google account, we ask for these permissions and no others:
| Permission | Why we need it |
|---|---|
Read your Gmail (gmail.readonly) | To find conversations with your clients, remember what was said and promised, and learn your mailbox address. |
Send email as you (gmail.send) | To send a reply or follow-up only after you approve it in DealKept. |
Manage calendar events (calendar.events) | To read your schedule for prioritising follow-ups, and to create or update showings and appointments you approve. |
Signing in with Google gives us only your verified email address and name. We do not keep Google sign-in tokens.
How we use it
- We use Google user data only to provide and improve the features you see in DealKept: your client memory, commitments, follow-ups, drafts and approved actions.
- We do not use Google user data for advertising, and we do not sell it.
- We do not use Google user data to develop, improve or train generalised or non-personalised AI or machine-learning models.
- We transfer Google user data to others only as needed to run DealKept (see service providers), to comply with law, or as part of a merger or acquisition with notice to you.
- No person at DealKept reads your email or calendar content unless you ask us to (for example, for support), it is needed for security (such as investigating abuse), or the law requires it. Every such access is recorded in an audit log.
What we collect
- Account data: your name, email address, team, and role.
- Connected content: email, calendar events, and, where your team uses our phone integration, call recordings, transcripts and text messages with clients. Calls always play a recording notice.
- What DealKept learns from it: contacts, facts about clients and properties, commitments, follow-ups and drafts. Each fact records where it came from.
- Pilot sign-ups: if you request pilot access on dealkept.com, the email address you enter, which form you used and when. We use it only to contact you about the pilot, never share or sell it, and delete it when you ask. The form sets no cookies and runs no trackers.
- Usage and diagnostics: which features you use, and error and performance logs. Logs carry IDs, not message content.
Who can see your data
- Your connected mailbox and raw messages are private to you. Teammates never see your messages.
- Your team shares the facts, commitments and follow-ups DealKept derives, marked as coming from a private source.
Service providers
We use these providers to run DealKept. They process data on our behalf and only for that purpose:
- Cloudflare: hosting, storage, databases and our AI gateway.
- AI model providers, reached through Cloudflare AI Gateway or OpenRouter: to extract facts, classify messages and write drafts. We send only what a task needs, and our gateway does not log prompts or responses.
- Quo: phone numbers, calls and text messages, if your team uses them.
- RealEstateAPI: public property records for addresses you work on.
- PostHog: feature flags and product usage. Axiom: operational logs without message content. Stripe: billing.
Security
- Everything is encrypted in transit. Message content, recordings and connection tokens are encrypted at rest with a key unique to your team.
- Google tokens are stored only in encrypted form, in storage private to the agent who connected them, and are never written to logs.
- Nothing is sent to a client on your behalf without your approval.
Retention and deletion
- Raw message bodies, email content and call audio are deleted 90 days after we receive them. Facts and commitments derived from them are kept while your account is active, and show "source expired" once the original is gone.
- Disconnecting Google (in Settings → Connections) stops access immediately, deletes your stored tokens and revokes DealKept's access at Google. You can also remove access from your Google account.
- Deleting a team destroys its encryption key, which makes all of its encrypted data permanently unreadable.
- To delete your account or get a copy of your data, email privacy@dealkept.com. We respond within 30 days.
Your rights
Depending on where you live, you may have the right to access, correct, delete or export your personal data, and to object to or restrict how we use it. Email privacy@dealkept.com to exercise these rights. Clients of our users whose conversations DealKept processes can also contact us there.
Children
DealKept is for real estate professionals and is not directed at anyone under 18.
Changes
If we change this policy, we will update the date above and, for material changes, tell you in the app or by email before they take effect.
Contact
Questions about privacy: privacy@dealkept.com.