Legal
Privacy Policy
Last updated: May 12, 2026
1. Who we are
CompPilot is the controller of personal data described in this policy. Questions, requests, or complaints can be sent to support@comppilot.ai.
2. What we collect
- Account data: the email address and password hash you provide at signup, plus any optional brand name or accent color you save for report customization.
- Report inputs: property addresses, bed/bath/sqft, and optional purchase / financing details you submit to generate a CMA.
- Usage data: a row per CMA lookup with the normalized address, timestamp, and a cache-hit flag — used to enforce per-plan limits.
- Billing data: if you upgrade, your payment method is held by our payment processor; CompPilot stores only the resulting subscription state (plan, status, period dates) and a customer ID.
- Operational telemetry: server logs, error reports, and performance traces. We do not log full request bodies and we redact identifiers wherever possible.
3. How we use it
- To deliver the service you signed up for — generating reports, saving portfolios, sending receipts.
- To enforce per-plan usage limits and prevent abuse.
- To debug failures and improve product quality.
- To send transactional email related to your account (receipts, password resets, plan changes). We do not sell your data and we do not run marketing or behavioral-advertising trackers.
4. Third-party processors
CompPilot uses the following processors to deliver the service. Each receives only the data needed for its purpose, under a contract requiring confidentiality and equivalent privacy practices:
- Cloud hosting: Microsoft Azure (data center region: United States) — application hosting, database, cache.
- Rental comp data: a third-party rental-data API receives the property address you submit so it can return market comps.
- Narrative generation: a large-language-model provider receives the property facts and comp data so it can generate the analyst narrative for your report.
- Payments: Stripe — processes your payment method and stores billing details. CompPilot never sees full card numbers.
- Transactional email: a transactional email provider — sends receipts, password resets, account notifications.
- Error monitoring: Sentry — receives error stack traces and request metadata for debugging.
5. Cookies and local storage
CompPilot uses a small amount of browser local storage to remember your session (your access token and basic profile). We do not use third-party analytics or advertising cookies.
6. How long we keep your data
- Account data is retained while your account is active and for up to 30 days after deletion.
- Report history is retained for the life of your account so you can revisit prior CMAs.
- Usage and audit logs are retained for 13 months for fraud and abuse review.
- Billing records are retained as required by tax and accounting law (typically 7 years in the US).
7. Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal data, or to object to certain processing. Email support@comppilot.ai with your request and we will respond within 30 days. You can delete your account at any time from your account settings, which triggers the retention timeline above.
8. Security
Data is encrypted in transit (TLS 1.2+) and at rest. Passwords are stored as salted hashes. Access to production systems is restricted and audited. No system is perfectly secure; if you believe you've found a vulnerability, please email support@comppilot.ai.
9. Children
CompPilot is a B2B tool for real estate investors and is not directed to anyone under 16. We do not knowingly collect data from children.
10. Changes
If we make material changes to this policy we will notify active users by email at least 14 days before the change takes effect. Minor updates will be reflected in the "Last updated" date above.
11. Contact
Questions or requests: support@comppilot.ai.