Back to Home

    Privacy Policy

    Last updated: June 27, 2026

    Looking for our security overview? Read about encryption, tenant isolation, and AI boundaries on the Security page.

    Your data is yours.
    • You own everything you upload. We do not sell it, share it across customers, or use it to train public AI models.
    • Each workspace is logically isolated and access-controlled at the database level.
    • Data is encrypted in transit and at rest.
    • Every third-party connection is opt-in and revocable from Settings.
    • You can export your data or request deletion at any time.

    OwnerLM ("we," "us," or "our") operates the OwnerLM platform, an AI asset management system for apartment owners and real estate investors. This Privacy Policy explains what we collect, how we use it, who else may process it on our behalf, and the controls you have.

    1. Information We Collect

    Account and workspace

    When you create an account we collect your name, email, and organization name. Workspaces have roles (owner, admin, manager, member, viewer), and the original creator is recorded as the primary owner. If you invite teammates, we store their email and the role you assign them.

    Property, portfolio, and deal data

    Addresses, unit counts, year built, ownership entities, financials, KPIs, notes, photos, and any other property or deal information you enter or import.

    Uploaded documents

    Files you upload to the Data Room or attach to properties, deals, conversations, or audits. Supported formats include PDF, Excel, CSV, Word, images, audio, and video. We extract text, structured data, and embeddings so the AI can search and answer questions over them.

    Conversations and meeting content

    Meeting transcripts, recordings, agendas, and notes that you upload, paste in, or sync from a connected tool. This may include the names and statements of meeting attendees. The AI summarizes these and proposes KPI updates that you confirm before they touch your scorecards.

    Email content

    If you connect a mailbox, use a custom inbound address (such as your-property@in.ownerlm.com), or forward mail to us, we ingest the message body, attachments, and metadata so we can summarize, route, and surface action items.

    SMS and chat

    If you opt in to SMS or install one of our chat bots, we store the messages you exchange with the bot, your opt-in record, and any action tokens we issue to authenticate you in the channel.

    Bank and PMS data

    If you connect a bank account or a property management system, we receive the data those systems expose (balances, transactions, units, leases, residents) through their secure APIs. We never receive or store login credentials for those systems.

    File-storage and calendar integrations

    Optional file-storage and calendar connections sync files, sheets, and events you select. Scope is limited to the folders, sheets, and calendars you authorize, and you can disconnect at any time.

    Contacts

    You can add or import business contacts (brokers, vendors, lenders, partners). The AI may also suggest contacts based on email and meeting activity. You confirm before any contact is saved.

    AI usage

    For every chat message, agent run, skill execution, and orchestrator analysis we store the input, the AI's response, the documents and sources cited, and token and credit counts. This powers your history, citations, and billing.

    Enrichment data we fetch on your behalf

    We retrieve public information to enrich your properties and markets: ratings and reviews, weather, market and economic indicators, and content from competitor websites you ask us to monitor.

    Usage and device telemetry

    Last-seen time, page views, feature usage, error reports, and basic device and session information. We also keep records of support conversations.

    2. How We Use Your Information

    • Run the product. Process documents, answer chat questions, run agents and skills, generate the Daily Morning Brief, monitor competitors, send notifications, and produce audits and reports.
    • Account and billing. Manage your subscription, meter credits, and process payments.
    • Team collaboration. Route notifications, scope access by role, and power shared workspaces and shared deals.
    • Sharing on your instruction. When you create a magic link or invite an external party, we use the linked data to render the shared view.
    • Developer access on your instruction. When you issue a REST API key or connect our MCP server, an external tool you authorize can read tenant data scoped to that key.
    • Product improvement. Aggregated and anonymized usage patterns help us improve features. Your individual financial, property, or conversation data is never used to train AI models, ours or anyone else's.

    3. Subprocessors

    We rely on a small set of vetted infrastructure and service providers to operate OwnerLM. We work with them under data-processing agreements that prohibit using your content to train AI models or for any purpose outside operating the service for you. Categories include:

    • Cloud infrastructure. Managed database, object storage, serverless compute, and hosting.
    • AI processing. Large language model providers operating under enterprise no-training terms.
    • Document parsing. Services that convert PDFs and spreadsheets into structured text.
    • Transactional email, SMS, and voice. Delivery of notifications you have opted in to.
    • Payments. A PCI-compliant payment processor. We do not store card numbers.
    • Optional user-connected integrations. Productivity, file storage, banking, property management, and calendar services that you explicitly authorize from Settings, plus public web and licensed market data sources used to enrich your portfolio.

    Enterprise customers can request a detailed, current subprocessor list under NDA by emailing security@ownerlm.com.

    4. Sharing and Public Surfaces

    You can create scoped links to share data outside your workspace: conversation share links, deal share tokens, public report views, property-manager portals, intake upload portals, and broker upload links. Each link is scoped to the data you choose, can expire, and can be revoked. We log every access against the link for your audit trail.

    5. Developer API and MCP

    You can issue API keys and connect our MCP server so external AI tools can read tenant data on your behalf. Treat these keys like passwords. You can revoke any key from Settings, and we recommend rotating keys regularly. You are responsible for actions taken by tools you authorize.

    6. Outbound Communications

    We send transactional emails, briefs, and notifications, and optionally SMS and chat messages, based on your settings and your teammates' settings. Every recipient can unsubscribe from non-essential communications. Suppression and unsubscribe lists are honored across the platform.

    7. Data Security

    • Encryption. TLS 1.2+ in transit, AES-256 at rest.
    • Tenant isolation. Row-level security policies enforce that workspaces cannot see each other's data. Storage paths are scoped by tenant.
    • Role scoping. Manager and member roles can be restricted to specific portfolios or properties. Admins and owners inherit full workspace access.
    • Password protection. Passwords are checked against a known-breached-password database at signup and change.
    • Service credentials. Privileged keys are never exposed to client code.
    • Audit logs. Sensitive actions and share-link views are recorded.
    • No data selling. We do not sell, rent, or share your personal or financial data with third parties for their marketing.

    8. Data Retention and Deletion

    Your data is retained while your account is active. Deleting a document, conversation, or note also removes its extracted data, embeddings, and citations. Closing your account triggers permanent deletion of associated data within 30 days, subject to short retention windows we are legally or financially required to keep (such as invoice records).

    9. Your Rights

    • Access and export. View your data in-app at any time, and export structured bundles where available.
    • Correction. Update profile, organization, property, and contact details from Settings.
    • Deletion. Delete individual items or your full account.
    • Disconnect. Unlink any third-party integration in one click. Sync stops immediately.
    • Opt out. Unsubscribe from non-essential email or SMS at any time.

    10. Cookies

    We use essential cookies for authentication and session management. We do not use third-party advertising or cross-site tracking cookies.

    11. Children's Privacy

    OwnerLM is not intended for use by individuals under 18. We do not knowingly collect information from minors.

    12. International Users

    OwnerLM is operated from the United States and your data is processed and stored there. If you use the platform from outside the US, you consent to that transfer.

    13. Changes to This Policy

    We may update this Privacy Policy from time to time. We will notify you of material changes by email or in-app notice. Continued use of OwnerLM after changes constitutes acceptance.

    14. Contact Us

    Questions about this Privacy Policy or your data? Email privacy@ownerlm.com.