Privacy Policy
Last updated: July 21, 2026
This Privacy Policy explains what information RentalAnchor (the "Service") collects, how it is used, and the choices you have. RentalAnchor is a private property hub for property owners and operators, currently offered in the United States.
1. Information we collect
- Account information. Your name and email address, collected through our authentication provider (Clerk) when you sign up, plus email addresses used to send and accept workspace invitations.
- Property records. The property, item, expense, reminder, contact, and note data you enter into your workspace.
- Uploaded files. Documents, receipts, manuals, warranties, and photos you upload.
- Billing information. Subscription and payment details processed by Stripe. We store your plan and subscription status, but never your full card number.
- Service logs. Standard technical logs (such as IP address and request metadata) generated by our hosting provider for security and reliability.
- Operational backups. Backups and restore snapshots may contain property records, uploaded-file metadata, and other Service data while they are retained by our infrastructure providers.
2. How we use information
- To provide, maintain, and secure the Service.
- To process subscription payments and manage trials.
- To send reminder emails you have opted into, and essential service emails such as billing notices and workspace invitations.
- To respond to support requests.
- To read receipts and documents you submit to Smart Capture and pre-fill expense details for you to review.
We do not sell your data, and we do not use your property records or files for advertising.
3. Where your data is stored
- Application hosting: Vercel.
- Database: Turso (libSQL), storing your account and property records.
- Files: Cloudflare R2, in a private bucket. Files are never publicly accessible; downloads use short-lived signed URLs issued only after your access is verified.
- Authentication: Clerk.
- Payments: Stripe.
- Email delivery: Resend (reminder, invitation, and other transactional emails).
- AI receipt scanning:Anthropic. When you use Smart Capture, the receipt or document image you submit is sent to Anthropic's API to extract the vendor, amount, date, and other details. Anthropic does not use this content to train its models, and the image is not retained for that purpose.
Each workspace's data is isolated: every record and file is scoped to your workspace, and access checks run on every request. Workspace owners and active contributors can access the content in their shared workspace. Each person controls their own reminder-email preference and timezone.
4. Tenant information
RentalAnchor is intentionally not designed to hold tenant personal information. Our Terms of Service prohibit storing tenant names, contact details, leases, rent payment records, or screening data. Please keep tenant information out of notes, descriptions, and uploaded files.
5. Cookies
We use only the cookies required to keep you signed in and operate the Service (set by our authentication provider). We do not use advertising or cross-site tracking cookies.
6. Retention, export, and deletion
- Your data is retained while your account is active so your workspace remains your operational memory.
- You can export your records as CSV files at any time from Export.
- Deleting a file in the app removes the stored object from file storage.
- Workspace owners can request account and workspace deletion from Settings → Account & data. Active paid subscriptions stop renewing and remain available through the period already paid for; trial and non-paying workspaces begin deletion after confirmation. If you cannot access the app, contact us via the contact page.
- Contributors can request removal of their personal account and workspace access while shared workspace records remain with the owner.
- Once deletion begins, user-facing access is revoked and application records and uploaded files are purged through an idempotent process within 30 days. We may retain the minimum billing, legal, fraud-prevention, and deletion-audit records needed to operate the Service.
Backups, provider logs, and restore snapshots may retain deleted data temporarily according to our providers' operational retention windows. We do not use backups to keep active user-facing copies after deletion, but they may exist for security, reliability, and restore purposes until they expire.
7. Security
We use industry-standard measures including encrypted connections (HTTPS), workspace-scoped authorization on every data access, private file storage with short-lived signed URLs, and verified webhook signatures for billing events. No method of storage or transmission is 100% secure, so please use a strong password and enable multi-factor authentication.
8. Children
The Service is not directed to anyone under 18, and we do not knowingly collect information from children.
9. Changes to this policy
We may update this policy from time to time. If we make material changes, we will provide notice through the Service or by email before the changes take effect.
10. Contact
Questions or privacy requests? Reach us through the contact page.