Last updated: June 27, 2026
Looking for our security overview? Read about encryption, tenant isolation, and AI boundaries on the Security page.
OwnerLM ("we," "us," or "our") operates the OwnerLM platform, an AI asset management system for apartment owners and real estate investors. This Privacy Policy explains what we collect, how we use it, who else may process it on our behalf, and the controls you have.
When you create an account we collect your name, email, and organization name. Workspaces have roles (owner, admin, manager, member, viewer), and the original creator is recorded as the primary owner. If you invite teammates, we store their email and the role you assign them.
Addresses, unit counts, year built, ownership entities, financials, KPIs, notes, photos, and any other property or deal information you enter or import.
Files you upload to the Data Room or attach to properties, deals, conversations, or audits. Supported formats include PDF, Excel, CSV, Word, images, audio, and video. We extract text, structured data, and embeddings so the AI can search and answer questions over them.
Meeting transcripts, recordings, agendas, and notes that you upload, paste in, or sync from a connected tool. This may include the names and statements of meeting attendees. The AI summarizes these and proposes KPI updates that you confirm before they touch your scorecards.
If you connect a mailbox, use a custom inbound address (such as your-property@in.ownerlm.com), or forward mail to us, we ingest the message body, attachments, and metadata so we can summarize, route, and surface action items.
If you opt in to SMS or install one of our chat bots, we store the messages you exchange with the bot, your opt-in record, and any action tokens we issue to authenticate you in the channel.
If you connect a bank account or a property management system, we receive the data those systems expose (balances, transactions, units, leases, residents) through their secure APIs. We never receive or store login credentials for those systems.
Optional file-storage and calendar connections sync files, sheets, and events you select. Scope is limited to the folders, sheets, and calendars you authorize, and you can disconnect at any time.
You can add or import business contacts (brokers, vendors, lenders, partners). The AI may also suggest contacts based on email and meeting activity. You confirm before any contact is saved.
For every chat message, agent run, skill execution, and orchestrator analysis we store the input, the AI's response, the documents and sources cited, and token and credit counts. This powers your history, citations, and billing.
We retrieve public information to enrich your properties and markets: ratings and reviews, weather, market and economic indicators, and content from competitor websites you ask us to monitor.
Last-seen time, page views, feature usage, error reports, and basic device and session information. We also keep records of support conversations.
We rely on a small set of vetted infrastructure and service providers to operate OwnerLM. We work with them under data-processing agreements that prohibit using your content to train AI models or for any purpose outside operating the service for you. Categories include:
Enterprise customers can request a detailed, current subprocessor list under NDA by emailing security@ownerlm.com.
You can create scoped links to share data outside your workspace: conversation share links, deal share tokens, public report views, property-manager portals, intake upload portals, and broker upload links. Each link is scoped to the data you choose, can expire, and can be revoked. We log every access against the link for your audit trail.
You can issue API keys and connect our MCP server so external AI tools can read tenant data on your behalf. Treat these keys like passwords. You can revoke any key from Settings, and we recommend rotating keys regularly. You are responsible for actions taken by tools you authorize.
We send transactional emails, briefs, and notifications, and optionally SMS and chat messages, based on your settings and your teammates' settings. Every recipient can unsubscribe from non-essential communications. Suppression and unsubscribe lists are honored across the platform.
Your data is retained while your account is active. Deleting a document, conversation, or note also removes its extracted data, embeddings, and citations. Closing your account triggers permanent deletion of associated data within 30 days, subject to short retention windows we are legally or financially required to keep (such as invoice records).
We use essential cookies for authentication and session management. We do not use third-party advertising or cross-site tracking cookies.
OwnerLM is not intended for use by individuals under 18. We do not knowingly collect information from minors.
OwnerLM is operated from the United States and your data is processed and stored there. If you use the platform from outside the US, you consent to that transfer.
We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice. Continued use of OwnerLM after changes constitutes acceptance.
Questions about this Privacy Policy or your data? Email privacy@ownerlm.com.