Legal

Privacy Policy

Last updated: September 18, 2026

On this page

1. Introduction

Ratifyly (“Ratifyly,” “we,” “us,” or “our”) provides an AI-assisted service that orchestrates residential real-estate transactions for real estate agents and brokerages. This Privacy Policy explains what information we collect, how we use and process it (including with artificial intelligence), how we store and protect it, and the choices you have. Ratifyly is currently offered as an invite-only early-access service.

By creating an account or using the service, you agree to the practices described here and in our Terms of Service.

2. Information We Collect

We collect the following categories of information:

  • Account information. Your name, email address, brokerage or company name, password (stored only as a salted hash), and account settings.
  • Transaction and document content. Real-estate contracts, addenda, disclosures, and related documents you upload, along with the structured data extracted from them (parties, dates, addresses, prices, contingencies, tasks, and similar transaction details) and, where closing paperwork contains them, financial details such as loan terms and payment instructions.
  • Usage and technical data. Log data such as IP address, browser type, pages visited, actions taken, and timestamps, collected to operate and secure the service.
  • Communications. Messages you send us for support or feedback.
  • Connected Google accounts. If you choose to connect your Gmail inbox, we read only the messages under the one Gmail label you pick, and we keep the facts we draw from them rather than the messages themselves. If you connect Google Contacts, we import contact names and email addresses. What we read, what we never do, how long we keep it, and how to disconnect are set out in Connected Google Accounts below.
  • Connected social accounts. If you choose to connect an Instagram professional account, a Facebook Page, or a LinkedIn profile, we receive its name and identifier, the text of your own recent posts and bio, and an access token we store encrypted. We use these to learn how you write, and, where you enable posting, to publish a post to your own account only after you review and approve it. What we read, what we never do, and how to disconnect or delete that data are set out in Connected Social Accounts & Data Deletion, which forms part of this policy.

3. How AI Processing Works

A core part of the service uses artificial intelligence to read uploaded documents and produce structured output. When you upload a contract or document, its contents may be sent to third-party large-language-model providers that we use as sub-processors to perform extraction, classification, and compliance review. The AI returns structured fields and flagged issues, which we store alongside your transaction.

  • Our large-language-model provider is Anthropic. We instruct our AI providers not to use your content to train their general-purpose models, consistent with their enterprise/API terms.
  • AI output can be incomplete or incorrect. It is decision support, not legal, financial, or professional advice, and should be reviewed by a qualified person before you act on it.
  • We do not use your uploaded documents to sell advertising or build profiles about you for third parties.

4. How We Use Information

We use the information we collect to:

  • Provide, operate, maintain, and improve the transaction-compliance features;
  • Process and analyze the documents and data you submit;
  • Authenticate you, secure accounts, and prevent fraud or abuse;
  • Respond to your requests and provide support;
  • Communicate service-related notices (for example, security or account updates);
  • Comply with legal obligations and enforce our Terms.

5. Storage & Security

Your data is stored on infrastructure we control or contract for, and each account’s data is logically isolated so that other customers cannot access it. We use reasonable administrative, technical, and physical safeguards (including encryption in transit and at rest, access controls, and hashed passwords) designed to protect your information.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for keeping your login credentials confidential.

6. Third Parties We Share With

We do not sell your personal information. We share information only with service providers that help us operate Ratifyly, under agreements that limit their use of the data, including:

  • AI / large-language-model providers used to process documents;
  • Cloud hosting and storage providers;
  • Email delivery providers used for transactional and account notifications;
  • Text-message (SMS) delivery providers used to send the transaction updates and reminders you opt in to and to carry your replies. Mobile phone numbers and text-messaging opt-in consent are never shared with or sold to third parties or affiliates for marketing or promotional purposes;
  • A log-monitoring provider used for error alerting and reliability. When a contact-form delivery fails, the log entry forwarded to this provider includes the details you submitted (including your email) so we can recover and answer your message.
  • A privacy-preserving website-analytics provider, which receives only anonymous public-website traffic data and never receives account or document data (see Website Analytics below).
  • The social platforms you connect (Meta for Instagram and Facebook, LinkedIn), which receive a post only when you approve it for your own account, under their own terms. We do not share your documents or transaction data with them (see Connected Social Accounts).

We may also disclose information if required by law, to protect our rights or the safety of others, or in connection with a merger, acquisition, or sale of assets (in which case we will notify affected users).

7. Connected Google Accounts (Gmail and Contacts)

Ratifyly’s use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

If you connect your own Gmail inbox. This is optional, it is yours to turn on, and it works like this:

  • We ask for read-only access. We request permission to read your mail and to see your email address, and nothing else. We cannot send, reply, label, archive, or delete anything in your mailbox, because we never ask for the permission that would let us.
  • You pick one label, and we read only what is under it. Google grants access to a whole mailbox, so we narrow it ourselves: you choose a single Gmail label, and every request we make asks Google for that label alone. Until you choose one, a connected inbox reads nothing at all. You decide what goes under that label, and you can change or remove it whenever you like.
  • We do not keep your messages. A message is read into memory, used to work out what changed on your transaction, and then discarded. What we keep is the record, not the correspondence: the message’s Google identifier, its subject, who it was from and to, when it arrived, whether it carried an attachment, and a one-line summary of what we concluded, with bank account and routing numbers masked out of that line. We do not store the message body, or any part of it.
  • We do keep the documents. Paperwork is the exception, and it is deliberate: if a message we matched to one of your transactions carries a PDF, we download that PDF and file it onto the transaction, because filing the paperwork is what connecting a mailbox is for. Those documents are kept as part of that deal’s records, the same as one you upload or forward to us. We download nothing from a message that does not match one of your transactions, and we download only PDFs.
  • Opening the original goes back to Google. Where we show a fact drawn from your mail, you can open the message it came from. We fetch it from Google at that moment using your own connection, show it to you, and keep nothing. If you disconnect, that link stops working, because there was never a copy behind it.
  • Your mailbox is yours alone. Your brokerage sees the transaction facts drawn from your mail, because those are the brokerage’s records. It does not see your mailbox, your messages, or the link back to them, and neither does anyone else at your brokerage.

Mail you forward or copy to your Ratifyly intake address. This is deliberately different, because you are handing us a document on purpose. Mail sent to an intake address is stored, including its body, and PDF attachments are downloaded and filed onto the matching transaction. If you would rather we did not hold the message itself, connect your inbox instead of forwarding to us.

If you connect Google Contacts. We read your contacts once you connect them, and we import names and email addresses so the product can recognize the people on your deals. We do not write anything back to your Google Contacts.

What reaches an AI model, and what it is never used for. To work out what a message means for your transaction, its text is sent to our large-language-model provider, Anthropic, which processes it and returns the result to us. We do not use Google user data to develop, improve, or train generalized or non-personalized artificial-intelligence or machine-learning models, and our provider does not train its general-purpose models on it. Google user data is never used for advertising, never sold, and never transferred to anyone except as needed to provide the feature you asked for, as required by law, or with your explicit consent. Other providers that help us run the service, such as hosting, storage, and error monitoring, are described in Third Parties We Share With.

Who reads it. No one at Ratifyly reads the contents of your Google data, except in the narrow cases Google’s policy allows: with your explicit consent for specific messages, where it is necessary for security purposes such as investigating abuse, to comply with applicable law, or as part of internal operations where the data has been aggregated and anonymized.

How long we keep it. We keep the records described above for as long as your account is active. We do not set an expiry on them, because they are part of your transaction history. They are deleted when you delete your workspace, or when you ask us to delete them.

Disconnecting, and deletion. You can disconnect a connected Google account at any time from your settings in the app. Disconnecting revokes our access at Google and deletes the credential we hold, so we can no longer read anything. Transaction facts already recorded stay, because they are your brokerage’s records of the deal, and the links back to the original messages stop working. You may also revoke our access directly from your Google Account permissions page. To have the stored records themselves deleted, email us at hello@ratifyly.com and we will delete them.

8. Requests from Public Authorities

A government agency, court, or other public authority may ask us for information about a user. Every such request is handled the same way:

  • Legal review first. No request is answered until it has been reviewed for legal validity: that it comes from an authority with jurisdiction, cites a lawful basis, and is properly served on Ratifyly, Inc.
  • We challenge requests we believe are unlawful. A request that appears to lack legal basis, is overbroad, or seeks more than the law allows is refused, narrowed, or challenged through the available legal process before any data is produced.
  • Minimum necessary. When a request is valid, we disclose only the specific information it lawfully requires and nothing more.
  • A record of every request. We keep a log of each request we receive, our response, the legal reasoning behind it, and the people involved on both sides.
  • Notice where permitted. Unless we are legally prohibited from doing so, or an emergency involving a risk of serious harm makes it unreasonable, we notify the affected user before disclosing their information so they may seek protection.

This applies to all personal information we hold, including information received from platforms you connect to Ratifyly. Emergency disclosures are limited to what is needed to prevent imminent harm and are logged the same way.

9. Website Analytics & Cookies

We do not use advertising or cross-site tracking cookies, and we do not run advertising networks’ tracking pixels. We do not build advertising profiles about you, and we do not sell or share your information with data brokers.

On our public marketing website (the pages you can browse without signing in), we use a privacy-preserving analytics tool to understand aggregate traffic: for example, how many people visited a page, which page they arrived from, and roughly what country they are in. This tool is cookieless: it does not store identifiers on your device, does not track you across other websites, and does not collect information that identifies you personally.

This does not apply to the signed-in product. The application, the client portal, and any page where your transactions or documents appear carry no analytics of any kind. Uploaded documents, transaction data, and account information are never sent to an analytics provider.

We also record when someone submits our contact or early-access form, so we can tell how many inquiries we receive. That record is a count of the event only; it does not include your name, email address, or anything else you typed into the form. The details you submit reach us by email, as described in Information We Collect.

For visitors outside the EU and UK, we set one first-party cookie: an attribution token (rf_ref), described below. It is not used for advertising or cross-site tracking, is never shared, and lasts about 13 months. You can delete it in your browser at any time with no effect on your ability to use the site or reach us. We set no other cookies, and none at all for EU or UK visitors. If your browser sends a “Do Not Track” or Global Privacy Control signal, our marketing analytics still collects no personal information about you.

When you submit our contact or early-access form, the details you enter (your name, email, company, role, state, product interests, and message) are emailed to our team inbox (hello@ratifyly.com) so we can reply, and are also written to our application logs as a delivery backstop. If a delivery fails, that log entry (which includes your email) may be forwarded to our log-monitoring provider so we can recover and answer your message. We retain these details for no longer than 24 months, after which we delete them; we do not keep them in the product database that holds customer accounts and documents.

Separately, we keep a small record of the submission itself for funnel analytics: the page you submitted from, the role, state, and interests you selected, a timestamp, and a random token. This record does not contain your name, email, company, or message. It is pseudonymous rather than anonymous: for visitors outside the EU and UK, the random token is stored in the rf_ref cookie so that, if you later create an account from the same browser, we can connect that account to your original inquiry and record that it converted, which also links the role, state, and interests you selected to your account. You can delete the rf_ref cookie at any time; doing so only disables that conversion match. None of this form or funnel data is ever used to train or fine-tune any AI model.

10. Data Retention

We retain your account, transaction, and document data for as long as your account is active or as needed to provide the service. You may request deletion of your account and associated data by contacting us; we will delete or de-identify it within a reasonable period, except where we are required or permitted by law to retain it (for example, for security, dispute resolution, or legal compliance).

11. Your Choices & Rights

You may access and update most account information within the app. Depending on your jurisdiction, you may have rights to access, correct, export, or delete your personal information, or to object to certain processing. To exercise these rights, contact us using the details below and we will respond consistent with applicable law.

12. Changes to This Policy

We may update this Privacy Policy from time to time. When we make material changes, we will update the “Last updated” date above and, where appropriate, notify you. Your continued use of the service after changes take effect constitutes acceptance of the revised policy.

13. Contact Us

If you have questions about this Privacy Policy or your data, contact us at hello@ratifyly.com.