Privacy policy.
Overview
This Privacy Policy describes how Unlevered, Inc. ("Unlevered," "we," "us") collects, uses, discloses, and protects information when you use the Unlevered platform, our website, and related services (collectively, the "Service").
By accessing or using the Service, you agree to the terms of this Privacy Policy. If you do not agree, please do not use the Service.
Information we collect
We collect three categories of information:
Account information
Name, work email, firm name, role, billing address. Provided directly when you sign up or update your firm profile.
Client property data
Property addresses, closing statements, rent rolls, remodel receipts, photographs, and the public records we link to those properties. Uploaded by your firm or the property owner you invite.
Operational data
Authentication events, IP addresses, audit-log entries, and Stripe payment metadata. Collected automatically as you use the Service.
How we use information
We use information to:
- Provide the Service: run cost segregation engine analyses, generate studies, route engineered review.
- Extract facts from uploaded documents and photographs using AI models. Owner identity (names, tax IDs, contact and account details) is redacted or masked before material is sent for processing; property facts and photographs are processed to identify building components. All classifications and dollar calculations are produced by our deterministic engine, never by an AI model.
- Maintain and improve the engine using de-identified, aggregated operational data with personally identifying information removed.
- Prepare anonymized case studies and samples where the client’s engagement letter grants that consent (fictional owner identity and address by construction; opt-out honored per the letter).
- Process payments via Stripe Connect.
- Communicate operationally about your account, studies, and billing.
- Detect and prevent fraud, abuse, and security incidents.
- Comply with legal obligations (tax records, audit trails, subpoenas).
We do not sell your data, your clients’ data, or any property records you upload, and we do not permit AI providers to train models on your identifiable information.
Sharing and disclosure
We share data only with the subprocessors listed in our Data Processing Addendum: Supabase (database), AWS (storage), Vercel (hosting), Stripe (payments), Anthropic (AI document and photo analysis — owner identity redacted before processing; API data is not used to train models), Fly.io (malware scanning of uploaded files), Smarty (address validation), Google Workspace (email delivery, including client-facing notifications), Slack (operational alerting), and Sentry (anonymized error reports). All subprocessors are bound by data processing agreements no less protective than this Policy.
We may disclose data when required by law, valid legal process, or to protect the rights and safety of our users.
Your rights
Depending on jurisdiction, you may have the right to access, correct, delete, port, or restrict processing of your personal data. To exercise any of these rights, write to hello@unlevered.io. We respond within 30 days.
Deletion requests are honored by removing your data from active systems. Engagement records within their documented retention window, append-only audit ledgers, and encrypted backups retain limited records for the periods required for audit defense and legal compliance; those records are not used for any other purpose.
Retention
Active accounts: data retained while the account is active. Engagement records — delivered studies, workpapers, source documents, and the audit trail — are retained for at least seven (7) years from delivery, matching IRS audit windows and our engagement letters; delivered studies may be retained beyond that so your clients keep access. Cancelled accounts: access is disabled immediately and account data is soft-deleted from active systems; engagement records within their retention window and append-only audit ledgers are retained as described above. Encrypted backups age out on our backup schedule.
Security
Encryption at rest (AES-256) and in transit (TLS 1.3). Row-level access controls, default-deny. Audit logging on every material action. See our Security page for the full picture.
International transfers
All data lives in US-East. We do not transfer data outside the United States. If you access the Service from outside the US, your data is transferred to and processed in the US.
Changes to this policy
We’ll notify firm admins by email at least 14 days before material changes take effect. Continued use of the Service after the effective date constitutes acceptance of the updated Policy.
Contact
Privacy questions: hello@unlevered.io. Mailing address: Unlevered, Inc., San Francisco, California.