Privacy Policy
Last updated: June 8, 2026
1. Introduction
AIpraisal ("Company," "we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our website, applications, and services (collectively, the "Service").
Please read this Privacy Policy carefully. By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with our policies and practices, do not use the Service.
This Privacy Policy may change from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date.
2. Information We Collect
2.1 Information You Provide to Us
We collect information you voluntarily provide when using the Service:
- Account Information: When you create an account, we collect your email address, password (encrypted), and optional profile information such as your full name.
- Project and Item Data: Information you enter about appraisal projects and items, including item names, descriptions, categories, and notes.
- Images: Photographs you upload for item identification and analysis.
- Search Queries: Keywords and search terms you enter when researching comparable items.
- Payment Information: If you subscribe to a paid subscription, payment details are collected and processed by our third-party payment processor. We do not store complete credit card numbers on our servers.
- Communications: Information you provide when you contact us for support or feedback.
2.2 Information Collected Automatically
When you access the Service, we automatically collect certain information:
- Device Information: Browser type, operating system, device type, and unique device identifiers.
- Usage Data: Pages visited, features used, time spent on the Service, and interaction patterns.
- Log Data: IP address, access times, referring URLs, and error logs.
- Cookies and Similar Technologies: We use cookies, local storage, and similar technologies to enhance your experience and collect usage information (see Section 8).
2.3 Information from Third Parties
We may receive information from third-party services integrated with AIpraisal:
- Marketplace Data: Product listings, prices, and seller information from various online marketplaces and sales databases.
- AI Services: Analysis results and generated content from configured AI routing and optional direct model providers, including OpenRouter-routed models, Anthropic, and Google Gemini where configured.
- Search and Visual Search: Marketplace data, semantic web search results, image recognition results, and similar item matches from services such as SerpAPI and Exa.
3. How We Use Your Information
We use the information we collect for the following purposes:
3.1 Providing and Improving the Service
- Create and manage your account
- Process your uploaded images for AI analysis and item identification
- Search for comparable items across marketplaces
- Generate AI-assisted item analysis, comparable research, support notes, and exports
- Store and organize your projects and items
- Generate reports and documentation
- Process payments and manage subscriptions
- Improve and optimize the Service based on usage patterns
3.2 Communications
- Send account-related notifications (verification, password reset, security alerts)
- Respond to your inquiries and support requests
- Send service updates and important notices
- With your consent, send marketing communications about new features or services
3.3 Security and Compliance
- Detect, prevent, and address fraud, abuse, or security issues
- Enforce our Terms of Service and other policies
- Comply with legal obligations and respond to lawful requests
- Protect the rights, property, and safety of AIpraisal and our users
4. How We Share Your Information
We do not sell your personal information. We may share your information in the following circumstances:
4.1 Service Providers
We share information with third-party service providers who perform services on our behalf:
- Supabase: Database hosting, authentication, and file storage
- AI and Model Routing Providers: Item analysis, generated content, and gated research workflows where enabled
- Search APIs: Marketplace search, semantic search, and visual search services
- Stripe: Payment processing, subscription billing, and fraud prevention
- Analytics and Error Monitoring: Product usage analytics, performance telemetry, and production error diagnostics
- Hosting Providers: Cloud infrastructure, content delivery, and request logging
These providers are contractually obligated to use your information only to provide services to us and to maintain appropriate security measures.
4.2 AI Processing
Important: When you use AI features, your uploaded images and item descriptions may be sent to AI routing providers, model providers, and search providers listed in Section 11, including OpenRouter, Anthropic, Google Gemini, Exa, and SerpAPI where configured. This data is used to provide item analysis, comparable search, visual search, and gated research features where enabled. We recommend not uploading images containing sensitive personal information.
4.3 Payment Processing
Stripe Payment Processing: When you subscribe to a paid subscription, your payment information is collected and processed directly by Stripe, Inc. We do not store complete credit card numbers on our servers.
Information shared with Stripe includes:
- Payment card details (processed directly by Stripe)
- Billing address and contact information
- Transaction amounts and subscription details
- Device and browser information for fraud prevention
Stripe's privacy policy is available at: stripe.com/privacy
4.4 Legal Requirements
We may disclose your information if required to do so by law or in response to valid requests by public authorities (e.g., a court or government agency), including to:
- Comply with a legal obligation
- Protect and defend the rights or property of AIpraisal
- Prevent or investigate possible wrongdoing in connection with the Service
- Protect the personal safety of users or the public
4.5 Team and Organization Data Sharing
If you are part of a team or organization account:
- Organization administrators can view all projects, items, and activity within the organization
- Data you create within an organization account is owned by and shared with that organization
- Your name and email may be visible to other members of your organization
- If you leave an organization, your access to organization data will be revoked, but the data itself remains with the organization
- Organization administrators may export or delete organization data, including your contributions
4.6 Business Transfers
If AIpraisal is involved in a merger, acquisition, or sale of assets, your information may be transferred as part of that transaction. We will provide notice before your information becomes subject to a different privacy policy.
5. Data Storage and Security
5.1 Data Storage
Your data is stored on secure servers provided by our hosting partners. We use industry-standard cloud infrastructure with data centers located in the United States.
5.2 Security Measures
We implement appropriate technical and organizational security measures to protect your information, including:
- Encryption of data in transit (TLS/SSL) and at rest
- Secure password hashing using industry-standard algorithms
- Row-level security policies in our database
- Regular security assessments and monitoring
- Access controls limiting employee access to personal data
- Secure authentication mechanisms
5.3 Security Limitations
While we strive to protect your information, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security and are not responsible for the actions of third parties who may gain unauthorized access.
6. Data Retention
6.1 Active Accounts
We retain your information for as long as your account is active or as needed to provide you with the Service. This includes your account information, projects, items, and uploaded images.
6.2 Account Deletion
When you delete your account, we will delete or anonymize your personal information within 90 days, except where we are required to retain certain information for legal, accounting, or business purposes.
6.3 AI Processing Data Retention
AI-connected workflows may pass item photos, image URLs, item descriptions, categories, search queries, prompts, and generated results to the providers listed in Section 11 under their own retention and processing policies:
- AI model providers: OpenRouter, Anthropic, and Google Gemini may process prompts, item descriptions, image URLs or image content, and generated responses for AI analysis and research workflows.
- Search APIs: SerpAPI and Exa may process search queries, item descriptions, categories, image references, result URLs, and related search metadata.
- Provider retention: Retention, abuse monitoring, and model-training commitments are governed by each provider's published terms and data processing policies. We use these providers to deliver the Service and do not sell your data.
6.4 Retention for Legal Purposes
We may retain certain information for longer periods if required by law, to resolve disputes, enforce our agreements, or protect our legal rights. This may include transaction records, communication logs, and security-related data.
7. Your Rights and Choices
7.1 Access and Portability
You have the right to access the personal information we hold about you. You can view and download your data through the Service settings, or contact us to request a copy of your data in a portable format.
7.2 Correction
You can update or correct your account information at any time through your account settings. If you believe any information we hold about you is inaccurate, please contact us.
7.3 Deletion
You can request account deletion by contacting support@aipraisal.io. Upon deletion, we will remove your personal information as described in Section 6. You can also request deletion of specific data by contacting us.
7.4 Marketing Communications
You can opt out of marketing communications at any time by clicking the "unsubscribe" link in our emails or by updating your communication preferences in your account settings. Note that you may still receive transactional or account-related communications.
7.5 California Residents
If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA):
- Right to know what personal information is collected, used, shared, or sold
- Right to delete personal information held by us
- Right to opt-out of sale of personal information (we do not sell personal information)
- Right to non-discrimination for exercising your privacy rights
7.6 European Residents
If you are a resident of the European Economic Area (EEA) or United Kingdom, you have additional rights under GDPR:
- Right to access your personal data
- Right to rectification of inaccurate data
- Right to erasure ("right to be forgotten")
- Right to restrict processing
- Right to data portability
- Right to object to processing
- Right to withdraw consent at any time
- Right to lodge a complaint with a supervisory authority
8. Cookies and Tracking Technologies
8.1 What Are Cookies
Cookies are small data files stored on your device when you visit a website. We use cookies and similar technologies (local storage, session storage) to operate and improve the Service.
8.2 Types of Cookies We Use
- Essential Cookies: Required for the Service to function, including authentication and security cookies. These cannot be disabled.
- Functional Cookies: Remember your preferences and settings to enhance your experience.
- Analytics Cookies: Help us understand how users interact with the Service so we can improve it.
8.3 Managing Cookies
Most web browsers allow you to control cookies through their settings. You can set your browser to refuse all cookies or to indicate when a cookie is being sent. However, some features of the Service may not function properly if you disable cookies.
9. Children's Privacy
The Service is not intended for children under the age of 13. We do not knowingly collect personal information from children under 13. If you are a parent or guardian and believe your child has provided us with personal information, please contact us immediately.
If we discover that we have collected personal information from a child under 13, we will take steps to delete that information as quickly as possible.
10. International Data Transfers
Your information may be transferred to and processed in countries other than your country of residence. These countries may have data protection laws that are different from the laws of your country.
If you are located in the EEA or UK, we ensure that transfers of personal data to countries outside the EEA/UK are protected by appropriate safeguards, such as standard contractual clauses approved by the European Commission.
By using the Service, you consent to the transfer of your information to the United States and other countries where we and our service providers operate.
11. Third-Party Services and Subprocessors
The Service integrates with various third-party services (subprocessors) that help us provide, maintain, and improve the Service. Each third-party service has its own privacy policy governing the use of your information.
11.1 Subprocessor List
The following is a list of our current subprocessors:
| Provider | Purpose | Data Processed | Location |
|---|---|---|---|
| Supabase | Database, authentication, and file storage | Account data, user profiles, organizations, projects, items, and images | United States |
| Vercel | Application hosting, edge delivery, and request routing | IP addresses, request metadata, usage logs, and application telemetry | Global edge network |
| Stripe | Payment processing, subscription billing, invoices, and fraud prevention | Billing contact data, payment details, subscription status, and transaction data | United States |
| OpenRouter | AI model routing for item analysis, fallback models, and gated research workflows where enabled | Prompts, item descriptions, image URLs or image content, and generated analysis | United States |
| Anthropic | Claude model processing for AI item analysis where configured | Prompts, item descriptions, image URLs or image content, and generated analysis | United States |
| Google Gemini | Fallback vision and language model processing through configured AI routing | Prompts, item descriptions, image URLs or image content, and generated analysis | United States |
| Exa | Semantic web search for comparable-item discovery | Search queries, item descriptions, categories, result URLs, and search metadata | United States |
| SerpAPI | Marketplace, shopping, and visual search result retrieval | Search queries, image URLs or image content, result URLs, and search metadata | United States |
| PostHog | Product analytics, usage events, and feature behavior measurement | User identifiers, organization identifiers, device data, usage events, and page views | United States |
| Sentry | Error monitoring, performance telemetry, and session replay diagnostics | Error traces, request metadata, device data, logs, and masked replay diagnostics | United States |
11.2 Privacy Policy Links
- Supabase: supabase.com/privacy
- Vercel: vercel.com/legal/privacy-policy
- Stripe: stripe.com/privacy
- OpenRouter: openrouter.ai/privacy
- Anthropic: anthropic.com/privacy
- Google Gemini: policies.google.com/privacy
- Exa: exa.ai/privacy
- SerpAPI: serpapi.com/privacy
- PostHog: posthog.com/privacy
- Sentry: sentry.io/privacy
11.3 Third-Party Links
When you click on links to third-party websites or marketplaces from within the Service, you are subject to their privacy policies. We are not responsible for the privacy practices of third-party websites.
12. Do Not Track Signals
Some browsers include a "Do Not Track" (DNT) feature that signals to websites that you do not want your online activity tracked. Because there is no universally accepted standard for how to respond to DNT signals, we do not currently respond to DNT browser signals. However, you can manage your cookie preferences as described in Section 8.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any material changes by:
- Posting the new Privacy Policy on this page
- Updating the "Last updated" date at the top of this page
- Sending you an email notification for significant changes
- Displaying a prominent notice within the Service
You are advised to review this Privacy Policy periodically for any changes. Changes are effective when posted on this page. Your continued use of the Service after any changes indicates your acceptance of the updated Privacy Policy.
14. Contact Us
If you have any questions about this Privacy Policy, your personal data, or would like to exercise your privacy rights, please contact us:
AIpraisal - Privacy Inquiries
Email: support@aipraisal.io
Please include "Privacy Request" in the subject line for faster processing.
15. Privacy Policy Summary
Key Points:
- We collect information you provide and information generated through your use of the Service
- Your images and data are processed by AI services to provide analysis features
- We do not sell your personal information
- We use industry-standard security measures to protect your data
- You can access, correct, or delete your data at any time
- We delete or anonymize account data within 90 days after account deletion, except where retention is legally or operationally required
- You can contact us at support@aipraisal.io for any privacy concerns