Flatre ("Flatre," "we," "our") provides an AI-native real estate transaction management platform (the "Service"). This Privacy Notice describes what information we collect when you or the people you work with use the Service, how we use it, and the choices you have.
This notice applies to real estate professionals who sign up for Flatre, members of their workspace, and the clients, leads, and counterparties whose information flows through the Service. If you are a client or lead of a Flatre customer, that customer is the controller of your information and may have its own privacy notice that also applies.
1. Information we collect
Information you provide
- Account details. Name, email address, password, brokerage name, profile photo, phone number, and license information.
- Workspace content. Contacts, leads, properties, listings, offers, transactions, tasks, calendar events, notes, uploaded documents, and photos you add to Flatre.
- Other financial information. Offer, listing, and transaction amounts; earnest money and other deposit amounts; commissions and commission splits; transaction expenses; and net-sheet calculations that you or another workspace member add to Flatre. These are first-party real estate workspace records and are distinct from subscription payment-method details processed by Stripe.
- Communications. Email deliberately sent or copied to a Flatre intake address, messages Flatre sends after you or another authorized workspace member writes or approves them, related attachments, and in-app communication records.
- Voice calls. Call participants, phone numbers, timestamps, routing and status metadata, and, only after the participating Flatre member has expressly enabled recording, call audio. Recording consent and consent to AI processing are separate choices. When recording is enabled without AI consent, Flatre does not create a transcript, AI summary, embedding, or other AI-derived call content. Before any recording begins, a notice is played to the other participant, explains that remaining connected indicates consent, and gives the participant an opportunity to disconnect. On shared lines, the current consent of the member who places or answers the call controls recording; a line-level setting alone is not consent.
- Payment details. If you subscribe to a paid plan, our payment processor collects billing contact information and payment method details. Flatre does not store full card numbers.
- Support requests. Messages, screenshots, and related metadata you send when contacting us.
Information from integrations
- Email sending accounts. Gmail and Outlook connections are used only to identify the connected account and send messages the connection owner writes or approves. Every outbound message requires human approval, including when a deal uses Trusted auto. Connecting an account does not authorize a message to be sent. Flatre does not request permission to read, list, search, modify, delete, backfill, or synchronize those provider inboxes. Yahoo connections are not supported.
- Calendar connections. For Google Calendar, Flatre checks selected ranges on your primary calendar using FreeBusy. Google returns only busy start and end times; Flatre never receives the event titles, descriptions, locations, or attendees and does not persist those busy intervals. Flatre also creates a user-owned secondary calendar named Flatre Bookings, where it reads, stores, creates, updates, and deletes booking details and sync identifiers. Events created directly in Flatre Bookings can sync into Flatre.
- MLS data. Listing, property, and market data retrieved from brokerage MLS providers configured for your workspace or searched through Flatre after setup.
- Lead sources. Lead records imported from Follow Up Boss, Meta, and other lead integrations you connect.
- e-Signature. Documents, envelopes, recipient information, and status events from DocuSign or other e-signature providers you connect.
- Sign-in providers. Basic profile information (name, email, avatar where available) and authorization identifiers from Apple, Google, or Microsoft when you use provider sign-in. Provider tokens are encrypted at rest and used only to maintain or revoke the connection you requested.
Information collected automatically
- Device and log data. IP address, browser and device type, operating system, referring URLs, pages viewed, timestamps, app version, and device-level notification tokens used to deliver account, transaction, and incoming-call notifications.
- Product interaction data. On selected authenticated web and iOS cohorts, Flatre records allowlisted screen paths, app version, an ephemeral analytics-session identifier, and bounded active-use heartbeats. These events are linked to the signed-in workspace and member so we can measure whether product features are useful. They exclude record identifiers, search terms, message or document contents, contact details, and precise device identifiers.
- Cookies and similar technologies. Session cookies for authentication and user preference cookies. If you allow optional analytics cookies, our public marketing pages load Google Analytics, which sets first-party analytics cookies (such as
_ga) to measure aggregate visits; Google acts as our analytics processor for those pages. Authenticated product analytics is processed by Flatre as described above; it does not use Google Analytics cookies. We do not deploy advertising or session-replay technologies. - Public portal interactions. When a client, buyer, seller, or counterparty opens a Flatre portal link (e.g., offer, CMA, net sheet, onboarding), we record view and action events to keep the originating agent informed.
Information we generate
- AI outputs and derived content. Draft messages, call and communication summaries, extracted fields, classifications, and other content produced by AI features acting on your workspace data.
- Search and similarity indexes. To power in-app search and AI features, we generate vector embeddings of selected workspace content, including contact records, message threads, transaction summaries, and document text. These embeddings are derived from your content and are processed by the AI providers identified in Section 3.
- Audit and model-call logs. Internal records of administrative actions, security events, and AI model calls (with sensitive values redacted before storage).
2. How we use information
- Provide, maintain, and improve the Service and its features.
- Authenticate users, secure accounts, and prevent abuse or fraud.
- Power AI features such as drafting messages, summarizing communications, extracting transaction data, and recommending next steps using large language model providers acting as our processors.
- Provide Voice calling and, when the participating Flatre member has opted in, record calls. Transcription, summarization, embeddings, and other Voice AI processing occur only when that member has also separately consented to AI processing. The member can revoke either choice and can stop recording for an individual call.
- Send transactional emails (magic links, receipts, status alerts) and service announcements.
- Send messages through a connected Gmail or Outlook account when the connection owner writes or approves them. Flatre does not send an outbound message without human approval.
- Send opted-in, one-way workspace alerts and requested account or verification messages to members.
- Analyze aggregate product usage to prioritize improvements.
- Comply with law and enforce our Terms of Use.
We do not sell your personal information, and we do not use customer or client content to train third-party AI models.
If you opt in to Flatre SMS messages, we use your mobile phone number to send action-required workspace alerts. Client and vendor text conversations are not supported. Message frequency varies based on workspace activity. Message and data rates may apply. You can reply STOP to opt out or HELP for help.
3. AI processing
Flatre's AI features are powered by third-party large language model and document intelligence providers acting as our processors. We currently use:
- OpenAI for chat completion, drafting, summarization, classification, and vector embeddings used by search and AI features.
- Microsoft Azure AI Document Intelligence for optical character recognition on uploaded documents where text extraction is required.
To return a useful response, AI features transmit the relevant inputs to the provider. Depending on the feature, these inputs can include contact details (names, email addresses, phone numbers), property and listing addresses, the bodies of communications you exchange in Flatre (including emails received from clients and counterparties when inbound triage is enabled), uploaded document content, transaction metadata, prior AI conversation history, and consented call transcripts or audio when a Voice summary is requested.
Content sent to these providers is governed by the providers' commercial terms. Under those terms our customer content is not used to train their generally available models and is retained by the provider only for the limited periods required to deliver, debug, and secure the service (commonly up to 30 days for OpenAI's standard API). Where supported by the provider, we may enable zero-retention processing for specific features.
We require each AI provider that receives personal data to provide the same or equal protection described in this Privacy Notice and required by applicable privacy rules. One current workspace choice, managed by a workspace owner, controls provider-backed AI features for all workspace members and configured background automations. The choice remains with the workspace if its members or owners change. An active owner can turn it off at any time. A changed policy version or disclosure blocks new provider requests until an owner reviews the current choice.
Workspace AI is separate from Voice recording and Voice AI. A call may be recorded without AI processing, but Flatre will not create its transcript, summary, embedding, or other AI-derived call content unless the participating member has also made a current personal Voice AI choice. Workspace owners can manage Fai in Settings > AI Controls; each member manages their own Voice choices.
Google Workspace API data and Limited Use
Flatre uses the Gmail API only to send messages from a Gmail account that its owner connected to Flatre. Every message must be written or individually approved by an authorized person in Flatre. Trusted auto does not bypass that approval. Connecting Gmail does not authorize a message to be sent.
Gmail access. Flatre requests your stable Google account identifier and email address, plus the gmail.send permission. It does not request your profile name. Flatre calls users.messages.send to deliver outgoing messages and does not request or use permission to read, list, search, modify, delete, backfill, or synchronize Gmail messages, threads, attachments, labels, or inbox activity.
Gmail use and storage. Flatre encrypts Google OAuth credentials and stores the outgoing messages and attachments created in Flatre, selected recipient information, provider delivery identifiers, and delivery and audit records needed to provide, secure, and troubleshoot sending. Flatre does not import or store messages or attachments from the connected Gmail mailbox.
Gmail sharing. Flatre transmits the outgoing content to Google for delivery and to the recipients selected or authorized through Flatre. We do not sell Gmail-derived data, use it for advertising or credit decisions, or use or transfer it to train generalized or foundational AI models.
Gmail controls. The connection owner can disconnect Gmail at any time. Disconnecting immediately prevents new sends through that connection, cancels confirmed-unsent deliveries, removes the stored live credential from Flatre, and starts Google authorization revocation. An attempt already in provider transfer is preserved for reconciliation rather than falsely reported as cancelled. If Google is temporarily unavailable, Flatre retries revocation using encrypted, access-restricted custody and destroys that custody after revocation reaches a final result. Flatre-created outgoing records remain subject to the retention and deletion terms in Section 6.
For step-by-step access, disconnect, retention, export, and deletion instructions, see the public Gmail connection guide.
Flatre uses the Google Calendar FreeBusy API to check selected ranges on your primary calendar. It receives only busy start and end intervals, never event titles, descriptions, locations, or attendees, and does not persist those intervals. With the calendar.app.created permission, Flatre creates a user-owned secondary calendar named Flatre Bookings. Flatre reads and stores event titles, descriptions, locations, start and end times, and sync identifiers only for that calendar, and can create, update, or delete events there. Events created directly in Flatre Bookings can sync into Flatre.
The use of information received from Google Workspace APIs will adhere to the Google Workspace API User Data and Developer Policy, including the Limited Use requirements. Flatre does not use or transfer raw or derived Google Workspace API data to create, train, or improve generalized or foundational machine learning or artificial intelligence models.
Google-derived Calendar content, including events synchronized from Flatre Bookings, is excluded from Fai features, model inputs, embeddings, and AI retrieval. Flatre uses it only for the visible Calendar and synchronization features you authorized. We do not sell it, use it for advertising or credit decisions, or permit human access except with your explicit support consent, for security, or when required by law.
For auditability, Flatre stores its own copy of each AI request and response in our database. Before storage we apply automated redaction to mask email addresses, phone numbers, postal addresses, and recognizable secrets from these internal records. Redaction is applied to the stored copy and does not alter the content already transmitted to the AI provider.
AI outputs are generated by probabilistic models and may be inaccurate, incomplete, or fabricated. Do not rely on AI output as legal, tax, financial, or fair-housing advice without human review.
4. AI assistant connectors
If you authorize an AI assistant connector such as Claude, ChatGPT, or Codex, Flatre returns scoped workspace evidence and, if enabled by workspace policy and OAuth scopes, governed Automation write outcomes for that assistant to process in your assistant session. Current connector responses may include transactions, contacts, properties, tasks, approvals awaiting review, safe message previews, document details, transaction financial summaries, integration status, workspace activity, and Flatre Automation outcomes.
AI assistant connectors do not return raw email bodies, document contents, attachments, storage keys, credentials, Fai model output, embeddings, direct Gmail or Outlook mutations, direct approval mutations, or web search results. A connector cannot access a provider mailbox or bypass Flatre Automation. An authorized connector request may ask Flatre Automation to prepare a message, but the connector cannot approve or send it. Any delivery still requires an authorized person to approve the message and pass the same recipient and safety checks as an in-product request. Connectors do not use the workspace's metered AI or automation balance.
Workspace owners and admins can disable or restrict connector scopes, and authorized users can revoke active connector grants from Settings > Integrations.
5. How we share information
- Service providers. We rely on third parties that process data on our behalf under written agreements: Vercel and Render (web and API hosting), our managed Postgres database and object-storage providers, Resend (transactional email delivery),Stripe (billing), Twilio (phone numbers, call routing, call audio, and transcription), OpenAI and Microsoft Azure (AI processing; see Section 3),DocuSign and Dropbox Sign (e-signature), and the MLS, lead, and sign-in partners you enable. We maintain an internal subprocessor register and will provide the current list on request to privacy@flatre.ai.
- Workspace members. Information you add to a Flatre workspace is visible to other members of that workspace according to their permissions.
- Integration partners. When you connect an integration (configured brokerage MLS, email sending, e-signature, lead source), data flows to and from that provider as directed by the connection settings. For Gmail and Outlook sending, Flatre sends the outgoing message and attachments to the provider for delivery to the selected or separately authorized recipients; Flatre does not retrieve provider inbox content.
- Portal recipients. Information you intentionally share through a public portal link is accessible to whoever has that link.
- Legal and safety. We may disclose information to comply with legal process, protect rights and safety, or during a corporate transaction (with notice where required).
We do not sell, rent, or share mobile phone numbers with third parties for their own marketing or promotional purposes. We may share mobile phone numbers with messaging providers and other service providers only as needed to deliver, secure, support, and comply with opt-in, opt-out, and legal obligations for Flatre communications.
6. Data retention
We retain workspace content for as long as your account is active and for a reasonable period afterward to support recovery, dispute resolution, security, and legal obligations. Consented Voice recordings and any related raw transcripts, summaries, embeddings, unapproved suggestions or extracted fields, and pending AI job payloads are deleted no later than 365 days after the call, or earlier when an authorized user deletes the call data. Deletion removes the source recording from Twilio and removes those source and unapproved draft artifacts from Flatre. Tasks, notes, communications, and other workspace business records that a user explicitly approved remain under their applicable workspace and legal retention rules. Flatre may retain a content-free audit tombstone showing that deletion occurred without retaining the deleted call content.
Support case messages and their activity history are retained with your account so Flatre can preserve case context and audit sensitive actions. Raw support email files and attachments are deleted no later than 365 days after receipt; the case message and delivery record remain after those files are removed.
Disconnect a calendar from Settings > Integrations > Calendar. Flatre revokes its Calendar authorization and removes its tokens, watch channel, and sync state. Existing Flatre workspace records and the Google-owned Flatre Bookings calendar remain by default so disconnecting does not silently delete your work. The connection owner can instead explicitly choose to remove that secondary calendar and its synced provider-side events during disconnect, or delete Flatre Bookings in Google Calendar afterward. See the public Calendar connection guide or email privacy@flatre.ai for help.
Disconnect a Gmail or Outlook sending account from Settings > Integrations > Email sending accounts. Disconnecting immediately prevents new sends, cancels confirmed-unsent deliveries, removes the stored live credential, and revokes sending access for that account. An attempt already in provider transfer is preserved for reconciliation rather than falsely reported as cancelled. For Gmail, Flatre requests Google authorization revocation and retries temporary failures without restoring the connection. Microsoft does not provide a token-revocation endpoint for this connection, so an Outlook user can also remove Flatre from Microsoft account permissions. Historical outgoing Flatre records remain after disconnect. Full outgoing message bodies in bounded mailbox storage follow the configured retention schedule, which is 365 days by default; deployment configuration may differ, and legal holds may postpone deletion. Recipients, provider delivery identifiers and status, consent evidence, security records, and audit metadata remain until an authorized deletion or permanent workspace purge, and may be retained longer for a documented legal, brokerage, security, or compliance requirement. Attachments and other workspace-owned business records follow their applicable workspace and legal retention. Disconnecting does not delete messages already delivered to recipients or stored by the email provider. See the public Gmail connection guide for access, export, and deletion instructions.
You can delete many individual records in the Service and can initiate account deletion in the iOS app. Account deletion removes or anonymizes the account data governed by Flatre, revokes connected Sign in with Apple authorization when available, retires provider grants owned by that member, and schedules applicable provider-backed data for deletion. Workspace-owned records may remain under workspace authority. Records we must retain by law or legitimate security/compliance needs can also remain (for example tax, audit, or real estate transaction records).
The accountable owner can request permanent workspace deletion. Workspace access ends and integrations are retired at the verified deletion boundary; permanent purge runs 30 days later, subject to legal holds. This does not delete messages or other copies already held by an integration provider or recipient.
To make deletion retry-safe and prevent a deleted identity from silently recovering old data, Flatre retains a permanent one-way identity fence after deletion. The fence is derived from the sign-in email and, when applicable, the Apple account identifier; it does not keep either value in readable form and cannot be used to restore the deleted account. It lets Flatre require a new identity proof and explicit confirmation before creating a separate, empty account. If Apple revocation cannot finish immediately, the refresh credential remains encrypted only until revocation succeeds or an authorized operator completes the documented manual resolution; it is then destroyed.
AI and document-intelligence providers process the inputs we send them subject to their own retention windows, which are independent of the retention period for your account in Flatre. See Section 3 for the current provider terms we rely on.
7. Security
We use encryption in transit (TLS) and at rest, hashed passwords, least-privilege access controls, OAuth with short-lived tokens, and audit logging. No system is perfectly secure; notify us promptly of suspected compromise at the address below.
8. Your choices and rights
Depending on where you live, you may have rights to access, correct, export, or delete the personal information we hold about you, and to object to or restrict certain processing. California residents have rights under the CCPA/CPRA including the right to know and to delete, and to opt out of "sharing" for cross-context behavioral advertising (Flatre does not engage in such sharing). EEA/UK residents have rights under the GDPR/UK GDPR. To exercise rights, email us at the address below.
If you are a client or lead of a Flatre customer, please contact that customer first because they control your data inside Flatre. We will assist them in fulfilling requests.
9. International transfers
Flatre is operated from the United States. If you access the Service from outside the U.S., your information is transferred to and processed in the U.S. and other jurisdictions where our service providers operate. We rely on appropriate safeguards (including Standard Contractual Clauses where applicable) for cross-border transfers.
10. Children
The Service is not directed to children under 16, and we do not knowingly collect personal information from them. If you believe a child has provided information, contact us so we can delete it.
11. Changes to this notice
We may update this notice to reflect product or legal changes. Material changes will be announced in the Service or by email. The "Last updated" date below indicates when the current version took effect.
12. Contact
Questions, requests, or complaints about this notice: privacy@flatre.ai.
Last updated August 4, 2026