Privacy Policy

Last updated: 2026-07-28

Quick summary:

  • We collect account data, the deal content you create, and usage telemetry needed to run the Service.
  • We do not sell your personal information.
  • We do not use your User Content to train general-purpose AI models.
  • Primary application data is hosted in U.S. cloud regions; some subprocessors may route edge traffic globally. We do not knowingly accept EU / UK signups.
  • You can request access, correction, or deletion at privacy@crescope.com.

1. Who This Policy Applies To

This Privacy Policy describes how CREscope LLC, a California limited liability company (“CREscope,” “we,” “us”), handles personal information when you visit our websites or use the Service. It applies to U.S. users. The Service is offered to U.S. business users; see the Terms of Service for the full eligibility scope.

2. What We Collect

We collect the following categories of information:

  • Account data: name, email, hashed password (via our authentication provider), profile preferences, billing metadata (we receive a payment token from our payment processor; we do not see your card number).
  • User Content: deal records, properties, contacts, notes, uploaded files, share-link configurations, and text you enter into the Service.
  • Usage data: page views, feature interactions, performance telemetry, error logs, IP address, user agent, viewport, timestamps.
  • Consent and confirmation records: where a feature asks you to confirm something before it runs, we record that you confirmed, when, and which version of the text you were shown. Today this covers consenting to fetch a listing URL you paste, and confirming a securities-offering notice before generating a report.
  • Share-link access records: when someone opens a share link you created, we record the access time, a one-way hash of the visitor IP address, and the browser user agent, for security and to measure engagement with the links you send.
  • Communications: support emails, in-app messages, and the content of feedback you send us.

3. How We Use Information

We use information to operate, secure, and improve the Service, including to:

  • Provide account access, authentication, and session management.
  • Process payments and prevent fraudulent or abusive use.
  • Host, store, and process your User Content so the Service works.
  • Generate analyses, extractions, and exports you request.
  • Send transactional emails (account, billing, security, support).
  • Send marketing email only where you have opted in or where allowed under applicable law, with unsubscribe in every message.
  • Detect, prevent, and respond to abuse, security incidents, and policy violations.
  • Keep consent and confirmation records so we can show what you agreed to.
  • Comply with legal obligations, including sanctions screening and tax reporting.

No AI-training use of your data. We do not use your User Content to train general-purpose AI or machine-learning models, and the model providers listed in Section 4 are contractually barred from using it to train or improve their own models. Server-side automated processing of your User Content occurs only to generate the outputs you request within the Service.

4. How We Share Information

We share personal information only with subprocessors who help us operate the Service, with parties to whom you direct disclosure (for example via a share link), or as required by law.

We do not sell personal information, and we do not share it for cross-context behavioral advertising. Our product analytics (Section 7) is first-party and used only to operate and improve the Service.

Subprocessors. The following vendors process data on our behalf in the categories noted:

VendorPurposeRegion
VercelApplication hosting, edge computeU.S.
RenderBackend API hostingU.S.
NeonPostgreSQL databaseU.S.
Cloudflare R2Object storage for uploadsU.S. / global edge
ClerkAuthenticationU.S.
StripePayment processingU.S.
ResendTransactional emailU.S.
SentryError monitoringU.S.
SvixAuthentication webhook routingU.S.
Google (Gemini)Automated extraction from uploaded documents and market-narrative synthesisU.S.
GroqAutomated rewriting of extracted content (not currently enabled in production)U.S.
AnthropicInternal knowledge-base authoring (server-side, not per-user runtime)U.S.
PostHogFirst-party product analytics (usage metadata only; no deal content)U.S.
Google Maps PlatformAddress autocomplete, geocoding, and street imagery for property addressesU.S. / global edge
GeocodioAddress geocoding fallbackU.S.
RegridParcel and assessor data lookup by addressU.S.
RentCastProperty and rent data lookup by locationU.S.
Walk ScoreWalkability and transit scoring by addressU.S.
SerperWeb search for market contextU.S.
TavilyWeb search for market contextU.S.

We maintain a current list of subprocessors on this page. Where a new subprocessor will process account data, payment data, or User Content, we will give notice in advance where practicable, and otherwise promptly.

Legal disclosure. We may disclose information if required by valid legal process (subpoena, court order, government request), to enforce our Terms, to protect rights or safety, or in connection with an investigation of suspected fraud, abuse, or security incidents.

5. Retention and Deletion

  • Active account data: retained until account closure or a verified deletion request.
  • User Content (deals, notes, uploads): deleted on account closure unless you export it first.
  • Deals you delete yourself: recoverable for 30 days, after which they become eligible for permanent removal. When a deleted deal is permanently removed, anonymized market figures derived from it (for example sale price and capitalization rate, without your notes or documents) may be retained for comparable-sales analysis within your own team.
  • Usage records: when your team generates a deal package or runs an Excel export, we record that it happened. Each record notes the team, the deal, the time, and the person who ran it where that account still exists. It does not include your deal content. We keep these while the team account is open so we can apply the refund conditions in our Terms. A record stays after you delete the individual deal it refers to, and still identifies that deal. Records are deleted from our active database when the team account closes, subject to the backup window below.
  • Consent and confirmation records: retained while your account is open and for a period afterward so we can evidence what you agreed to, or longer if a litigation hold applies.
  • Operational and error logs: retained no longer than 90 days, except where a log is preserved for a security investigation or a litigation hold.
  • Database backups: our database provider retains point-in-time recovery snapshots on a short rolling window measured in days, not months. Deletions propagate as those snapshots age out.
  • Billing records: retained as required by tax and accounting law.

6. Your Rights

Subject to applicable law, you may have the right to access, correct, delete, or port your personal information, and to opt out of certain processing. To exercise these rights, email privacy@crescope.com from the address associated with your account, and we will verify and respond. Self-serve account-closure controls are not currently available in-app; email is the supported channel.

We aim to respond to verified requests within 45 days. Requests may be denied or limited where the law permits, including where retention is required to defend legal claims, comply with legal obligations, or prevent fraud and abuse.

California residents. If you are a California resident with an account, you have rights under the CCPA / CPRA to know, delete, correct, and opt out of sale or sharing. We do not sell personal information, and we do not share it for cross-context behavioral advertising. Our product analytics is first-party and used only to improve the Service.

7. Cookies and Tracking

We use strictly necessary cookies for authentication, session management, and security. We also set two first-party cookies that last up to 30 days: one that records how you first reached our site (for example, which link or campaign referred you), and one that remembers which share link you arrived from so we can attribute a later signup to it. Neither is used for advertising, and neither is shared with any advertising network.

We also use first-party product analytics, provided by PostHog acting as our processor, to measure product usage, for example sign-ups, deal creation, and feature adoption, so we can improve the Service. This analytics is used only to operate and improve the Service, never for advertising, and we do not sell or share it for cross-context behavioral advertising. It records product-usage events and an account identifier only; it does not receive your deal content, property addresses, recipient details, or document contents. It runs without non-essential persistent browser identifiers (no analytics cookies); we will publish a cookie notice and obtain consent before enabling any persistent non-essential trackers. We honor the Global Privacy Control (GPC) signal where required by state law.

8. Security

We use commercially reasonable administrative, technical, and organizational safeguards. These include TLS 1.2 or higher enforced on all user-facing connections, encryption at rest at our infrastructure providers’ storage layer, multi-factor authentication on administrative accounts, role-based access controls within the application that limit each user to their own team’s data, and automated dependency vulnerability alerting. No system is perfectly secure; you must promptly notify us at security@crescope.com if you suspect unauthorized access to your account.

Breach notice. If a security incident affects your personal information, we will notify you and applicable regulators within the timelines required by applicable state law, generally no later than 30 days after determining notice is required, and as early as is reasonable given investigative needs.

9. Children

The Service is not directed to children under 13. We do not knowingly collect personal information from children under 13. Accounts must be held by users 18 or older. If you believe a minor account exists, report it to legal@crescope.com and we will close it and delete associated data within 30 days.

10. International Use

Primary application data, databases, and uploaded files are hosted in U.S. cloud regions. Some subprocessors (for example, content delivery and edge-storage providers) may route metadata or edge traffic globally in the ordinary course of operating their networks; our subprocessor list above identifies any vendor with a non-U.S. processing footprint.

We do not target or actively market to users in the European Economic Area, the United Kingdom, or Switzerland and we do not knowingly accept signups from those regions. If you reach an account from such a region, contact privacy@crescope.com and we will assist with closure and deletion.

11. Changes to This Policy

We may update this Policy. Material changes (data we collect, how we use or share it, your rights, retention, security) will be noticed through in-app notice or email at least 30 days before they take effect, except where a shorter timeframe is required by law. Non-material updates take effect on posting.

12. Contact

Privacy: privacy@crescope.com. Security: security@crescope.com. The Service is operated by CREscope LLC, a California limited liability company.