Legal

Privacy Policy

Effective date: January 1, 2025

LeasePilot ("LeasePilot," "we," "us," or "our") operates the LeasePilot commercial lease abstraction service (the "Service"). This Privacy Policy explains what information we collect, how we use it, and the choices you have with respect to your data.

LeasePilot is designed for commercial real estate landlords and investors. We take privacy seriously because we understand that the documents you upload — commercial lease agreements — may contain sensitive business and personal information.


1. Information We Collect

Account information

When you create an account, we collect your email address and a password (stored as a one-way cryptographic hash — we never store your plaintext password). If you sign in via Google OAuth, we receive your name and email address from Google.

Document data

When you upload a lease PDF, we store the file and the extracted text content. After AI processing, we store the structured abstraction (extracted fields, dates, and flags) associated with your account.

Personal information in uploaded documents

Commercial lease agreements frequently contain personal information about third parties — including tenant names, personal guarantors' names and contact details, and in some cases financial information. We process this data solely to provide the abstraction service to you. We do not use it for any other purpose, do not sell it, and do not share it with any third party except as described in this policy.

Payment information

Payment is processed by Stripe. LeasePilot never receives, stores, or has access to your credit card number, bank account details, or other payment credentials. We receive confirmation of payment completion and a Stripe customer identifier only.

Usage data

We collect standard server logs and product analytics (page views, feature usage, errors) to operate and improve the Service. This data is aggregated and not linked to specific documents you upload.

2. How We Use Your Information

  • To provide the lease abstraction service — extracting, structuring, and presenting lease data to you.
  • To operate the monitoring dashboard and send deadline alert emails.
  • To process payments via Stripe.
  • To send transactional emails (abstraction completion, alerts, account notifications).
  • To diagnose and fix technical errors.
  • To improve the Service based on aggregated usage patterns.

We do not use your lease documents or their contents for marketing, advertising, data brokerage, or any purpose other than providing the Service to you.


3. AI Processing — How Your Lease Is Analyzed

LeasePilot uses Anthropic's Claude API to extract and structure lease information from the text of your uploaded document. Your document text is transmitted to Anthropic's servers for processing.

Important: Anthropic does not train on API data

Data submitted through Anthropic's API (including via LeasePilot) is governed by Anthropic's API usage policy, which explicitly excludes API inputs and outputs from being used to train or improve Anthropic's models. Your lease content will never be used to train any AI model.

Anthropic acts as a data processor on our behalf and is subject to Anthropic's own privacy and security policies. We encourage you to review Anthropic's Privacy Policy.


4. Data Security

  • Encryption in transit: All data transmitted between your browser and our servers is encrypted via TLS 1.3.
  • Encryption at rest: All stored files and database records are encrypted at rest using AES-256 encryption via Supabase.
  • Access controls: Row-level security (RLS) is enforced at the database level. No user account can access another user's lease documents, abstractions, or account data — including LeasePilot staff in normal operations.
  • Payment security: Payment processing is handled entirely by Stripe, a PCI DSS Level 1 certified payment processor. LeasePilot never handles raw payment credentials.

Despite our security measures, no internet transmission or electronic storage is 100% secure. If we become aware of a security breach affecting your data, we will notify you in accordance with applicable law.


5. Data Retention

We retain your account data, uploaded lease files, and abstraction results for as long as your account remains active. If you delete your account, all associated data — including uploaded files, abstractions, and monitored dates — is permanently deleted within 30 days.

You may delete individual leases or abstractions at any time from your dashboard. Deletion of individual items is immediate and permanent.

We may retain anonymized, aggregated data (for example, average processing time metrics) that cannot be linked back to you or your documents indefinitely.


6. Your Privacy Rights

Depending on your location, you may have certain rights regarding your personal information:

  • Access: Request a copy of the personal information we hold about you.
  • Deletion: Request that we delete your personal information. You can delete your account and all associated data directly from the Service, or contact us to request deletion.
  • Correction: Request that we correct inaccurate personal information.
  • Portability: Request an export of your data in a machine-readable format.
  • Opt-out of sale: LeasePilot does not sell personal information. There is nothing to opt out of.

California residents have additional rights under the CCPA/CPRA. To exercise any of these rights, email us at privacy@leasepilot.com. We will respond within 45 days.


7. Third-Party Services

LeasePilot uses the following third-party services to operate:

Anthropic (Claude API)AI lease text extraction and structuring
SupabaseDatabase, file storage, and authentication infrastructure
StripePayment processing
ResendTransactional email delivery
VercelApplication hosting and infrastructure
SentryError tracking and monitoring

We do not sell, rent, or share your personal information with any third party for their own marketing or advertising purposes.


8. Cookies

LeasePilot uses strictly necessary cookies to maintain your authenticated session. We do not use advertising cookies, behavioral tracking cookies, or third-party analytics cookies that would be shared with advertising networks.


9. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or by displaying a notice in the Service before the change takes effect. Continued use of the Service after a change constitutes acceptance of the updated policy.


10. Contact

For privacy-related inquiries, data deletion requests, or questions about this policy:

Email: privacy@leasepilot.com