Privacy policy
What this site collects
- Contact details you type into a form (name, email, phone), what you asked about, the page you were on, your language, and whether you agreed to text messages, with the date and the version of the consent wording you saw.
- For a home value estimate: the address and home details you enter.
- For saved-search alerts: your email, your search criteria and how often you want emails. Saved homes ("hearts") stay in your own browser and are never sent to us unless you email the list.
- Messages you type into the chat assistant, sent to Anthropic to generate replies. Chat messages are not stored on our server unless you choose "Leave your contact info", in which case the conversation is attached to your inquiry.
- Reviews you submit, with the IP address the review came from (kept for moderation).
Who else processes your data
- Resend (email delivery) and Twilio (text messages to Mariela about new inquiries).
- Anthropic (the AI model behind the chat assistant).
- Our hosting provider, which stores the data above.
- Listing photos load from the MLS's photo servers; your browser requests them directly.
- Google Fonts serves the site's fonts.
How long we keep it
Inquiries are kept while we are helping you and for the record-keeping period our brokerages and state law require. Saved-search alerts are kept until you unsubscribe. Ask us to delete your information at any time.
Texts and emails
We text you only if you checked the separate text-message box. Reply STOP to any text to opt out. Every alert email has an unsubscribe link that works immediately.
Last updated: 2026-09-29
What we collect
- the IP address of anyone who tries to log in to your admin area, held in memory only for a few minutes to throttle password guessing (node/admin-auth.js)
- a signed session token issued to an administrator after a successful login, valid for eight hours (node/admin-auth.js)
- a provider API key that a customer of yours supplies, stored by node/vault.js as ciphertext in the store YOU pass it (a database table in production). It is kept until you call revoke(), which deletes the record; how long you keep it and what you tell customers about it is yours to disclose
- the email address or phone number you send a notification to is handed to Resend or Twilio so they can deliver it; this block keeps no copy of its own (node/notify.js)
- whatever your application chooses to keep in the visitor's own browser (localStorage): this block is the storage and the migration ladder, never the decision about what goes in it (vanilla/store.js)
- the name, email address and message a visitor types into your contact form — where it goes afterwards is your own onSubmit, which this block never decides, so the destination is yours to declare (its DD run names exactly this)
- the IP address of a submission, in memory only, so that one address cannot flood the form (node/submit-handler.js)
- the reviewer's name, rating and review text, which are published on your site once you approve them
- the submitter's IP address, kept for moderation and never serialised to the public endpoint — its DD run names this as personal data under GDPR and says the block cannot decide your retention policy
Why
To answer your enquiry and provide the service you asked for. We do not sell your data.
Who else processes your data
- the AI provider you point it at: callApi() sends the request body your application hands it, under your key or the key that customer stored, to the URL you configure. This block names no provider and keeps no copy of the exchange (node/byok.js)
- Resend receives the recipient's email address and the body of the message you send (node/notify.js)
- Twilio receives the recipient's phone number and the text of the message you send (node/notify.js)
Your choices
Ask us to show, correct, or delete the data we hold about you and we will.
Cookies
We use only what the site needs to work. If we ever add analytics or advertising, we will say so here first.
Questions? Contact Mariela Lovo Ol at [email protected].
