DealMemory — Privacy Policy
Effective date: July 12, 2026 · Version v1.5-2026-07-12
This policy describes how Deal Memory Ai LLC ("DealMemory," "we") handles information in connection with the DealMemory application and the dealmemoryai.com website.
The two roles we play
For our customers' business data, we are a service provider. DealMemory is used by real estate businesses ("Customers") who upload their own deal notes and lead information. That material — including names, phone numbers, emails, and deal details of a Customer's own clients — is processed on the Customer's behalf and under their instructions. If you are a client of one of our Customers and have questions or requests about your information, the Customer is the right first contact; we support Customers in honoring such requests, and you can also reach us at privacy@dealmemoryai.com.
For account holders and site visitors, we act for ourselves with respect to the limited data described below.
What we collect
Account data: name, work email, and a password (stored only as a modern salted hash — we cannot see your password), plus sign-in and account-lifecycle timestamps. Payment data: if you purchase a subscription, payment is collected by Stripe on Stripe-hosted pages; we never receive or store card numbers — only Stripe's customer and price identifiers and your subscription status, which control your workspace's features.
Customer Content: the notes and files Customers upload, and the structured records the Service derives from them. Client identities inside Customer Content (names, phone numbers, email addresses) are stored exclusively in an encrypted vault, separated from the rest of the system under a per-customer encryption key; everywhere else — match results, exports, logs — those identities appear only as pseudonymous codes.
Technical data: service logs and error reports that are engineered not to contain client identities or note text (error reporting, when enabled, is configured to exclude request bodies and code-level variable contents), plus operational records such as invitation, signup-code, and deletion-audit entries that contain no client personal data.
We do not collect precise location, biometric data, or advertising identifiers. The application sets only functional cookies needed to keep you signed in; we use no advertising or cross-site tracking cookies.
How we use information
To provide, secure, support, and improve the Service; to communicate with account holders about the Service; and to meet legal obligations. Three commitments in plain terms: we do not sell personal information; we do not use it for advertising; and we do not use Customer Content to train our own or anyone else's AI models. One narrow use of Customer activity keeps extraction quality honest: when a reviewer corrects an extracted field, that example may be added to our internal accuracy test suite — but only after client identities are replaced with synthetic stand-ins (fictional names and phone numbers), and never if the underlying record has been deleted.
AI processing, honestly described
Extraction uses a third-party large-language-model API. Before any text is sent to that provider, telephone numbers and email addresses are replaced with placeholder tokens by deterministic pattern matching, and personal names are replaced using each Customer's known-contact list together with a local recognition model. Name masking is best-effort by nature: an unusual name the local model does not recognize may reach the provider in clear text in that request. Compensating controls: the known-name list grows with each Customer's own data, a human reviews every extraction before it is saved, our provider's API terms do not permit training on API inputs, and stored processing records contain only the masked text. The token-to-identity mapping exists only for the moment of the request and is never stored or transmitted.
Who receives data (subprocessors)
OpenAI (LLM API — masked extraction text only); Neon (managed database hosting — encrypted storage of the categories above); Fly.io (application hosting); Postmark (transactional email delivery — account email addresses and account-lifecycle messages such as verification links only, never Customer Content); Stripe (payment processing — when you purchase a subscription, your payment card details are provided by you directly to Stripe on Stripe-hosted pages and never transit our systems; we store only Stripe's account identifiers and subscription status); Cloudflare (bot defense — when you use the public signup form, a Cloudflare Turnstile challenge runs in your browser, and our server forwards the resulting challenge token and your IP address to Cloudflare to verify it; Cloudflare receives no account data and no Customer Content); Sentry (error reporting — receives error and diagnostic metadata only, such as the error type and where in our code it occurred; request bodies, personal-information fields, and code-level variable contents are excluded by configuration that an automated test verifies on every change). We may also disclose information if required by law, and to professional advisors under confidentiality. We do not otherwise share personal information with third parties.
Security
Customer environments are isolated at the database layer with enforced row-level security; client identities are encrypted at rest under per-customer keys, which are themselves stored only in encrypted (wrapped) form under a master key; passwords are hashed with Argon2id; sessions are signed and expiring; account admission is controlled (self-service signup is protected by a bot-detection challenge and email verification, and workspaces can also be created by owner provisioning, invitations, or single-use signup codes); and an automated test suite exercises these isolation and authentication properties on every change. A detailed technical security exhibit is available to Customers on request. No system is perfectly secure; if a breach affects your information, we will notify affected parties as required by law.
Retention and deletion
Customer Content is retained while the Customer's account is active. Customers can delete individual records in-product (deletion cascades through derived records, match results, and vaulted identities no longer referenced), and full account deletion is available at offboarding, with an export window first. Deletions are recorded in an audit ledger that contains counts and timestamps, not client personal data. Residual copies in database backups expire within the backup retention window, which never exceeds 7 days. Account data is deleted or de-identified within a reasonable period after account closure, except where law requires longer retention.
Your rights and choices
Account holders can access and correct account data in-product and can request deletion at privacy@dealmemoryai.com. For information contained in Customer Content, we act on our Customer's instructions and will route or support requests accordingly. Depending on where you live, you may have specific legal rights regarding personal information (such as access, correction, deletion, and portability); we honor valid requests as required by applicable law and do not discriminate for exercising them. We do not sell or share personal information as those terms are defined under applicable U.S. state privacy laws.
Other things you'd want to know
The Service is for business use and not directed to anyone under 18, and we do not knowingly collect children's information. Our services are operated in the United States; if you access them from elsewhere, your information is processed in the U.S. If we make material changes to this policy, we will post the update with a new effective date and notify account holders in-product or by email.
Contact: Deal Memory Ai LLC · privacy@dealmemoryai.com