Privacy Policy
Effective date: August 16, 2026
Leasepal ("Leasepal," "we," "us," or "our") provides a mobile and web application that helps small landlords track properties, tenants, leases, maintenance, and expenses, with optional AI-assisted features. This Privacy Policy explains what data we collect, how we use it, who we share it with, and the choices you have. By creating an account or using Leasepal, you agree to the collection and use of information as described here.
1. Information we collect
Account information
- Email address and password (password is hashed by our authentication provider; we never see or store it in plain text).
Property, tenant, and financial data you enter
- Property addresses, unit counts, and notes.
- Tenant names and contact details.
- Lease terms, rent amounts, and dates.
- Maintenance tickets, descriptions, and status.
- Expense records (vendor, amount, category, date), recurring expenses, and mileage trips you log.
- Rent payment records, security deposits, insurance policies, and vendor contacts you enter.
Files you upload
- Lease PDFs, stored in a private storage bucket keyed to your account.
- Maintenance photos, stored in a private storage bucket keyed to your account.
- Documents you add to the document vault, stored in a private storage bucket keyed to your account.
- Receipt photos you scan are processed transiently to extract the expense fields and are not stored — only the extracted vendor, amount, date, and description are saved.
Uploaded files are only accessible to your account; storage access rules (row-level security) prevent other users from reading them.
Payment information
- We do not collect or store credit card numbers. Subscription billing is handled by Stripe, which collects payment details directly. We receive only subscription status, plan tier, and billing metadata (e.g., trial/active/canceled) from Stripe.
Push notification tokens
- If you enable notifications, we store a device push token so we can send rent-due, lease-ending, and maintenance reminders.
Usage and diagnostic data
- Feature usage events (e.g., which AI action you ran, whether you accepted or edited the result) via PostHog analytics.
- Crash reports and error diagnostics via Sentry.
- AI call metering (which feature, when, and count against your monthly plan limit) so we can enforce plan quotas.
We do not knowingly collect information from children under 13, and Leasepal is not directed at children.
2. How we use your information
- To provide core functionality: storing and displaying your properties, tenants, leases, maintenance tickets, and expenses.
- To run AI-assisted features you explicitly trigger (see Section 3).
- To process subscription billing and enforce plan limits.
- To send optional push notifications you've opted into (rent due, lease ending, stale maintenance tickets).
- To monitor app stability and fix bugs (crash/error diagnostics).
- To understand feature usage in aggregate so we can improve the product.
- To respond to support requests.
We do not sell your personal information, and we do not use your property, tenant, lease, or expense data for advertising.
3. AI features and third-party processors
Leasepal integrates with the following third-party service providers, each acting as a processor of the data described:
| Processor | Purpose | What's shared |
|---|---|---|
| Supabase | Hosting, database, authentication, file storage | All account and application data described in Section 1 |
| Anthropic (Claude) | AI-assisted lease summaries, maintenance photo triage, rent reminder drafts, expense categorization, receipt scanning, tax summaries, and portfolio digests | Only the content the specific AI action needs — the lease PDF, maintenance photo, receipt photo, or expense/rent text you submit, or (for tax summaries and portfolio digests) the expense and property records the report covers — sent directly from our server, never from your device |
| Stripe | Subscription billing and payment processing | Email, plan selection, billing status (Stripe holds your card details; we never see them) |
| PostHog | Product analytics | Anonymized/pseudonymous usage events (feature taps, AI acceptance) |
| Sentry | Error and crash monitoring | Stack traces and technical diagnostics; we configure it to avoid capturing message bodies where possible |
| Expo (push notification service) | Delivering push notifications | Device push token and notification text (rent/lease/ticket reminders) |
Important about AI processing: Content is sent to Anthropic only when you actively trigger an AI action — uploading a lease for summary, attaching a maintenance photo for diagnosis, drafting a rent reminder, categorizing an expense, scanning a receipt, generating a tax summary, or generating a portfolio digest. This content is not used by Anthropic to train its models, per Anthropic's API terms for commercial customers. AI-generated output (summaries, diagnoses, drafts, categorizations, transcriptions, and reports) is written back to your account and is never shown to other users.
AI outputs are drafts and suggestions. You should always verify AI-generated content — especially lease terms and tax-related expense categorization — before relying on it. See our Terms of Service for the full disclaimer.
4. Data retention
We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible (read-only for AI features once outside your plan's usage) until you either resubscribe or delete your account.
5. Your rights
- Access your data at any time within the app (Properties, Tenants, Leases, Maintenance, Expenses, Settings).
- Export your data (CSV export of expenses is available from Settings; additional exports available on request).
- Correct inaccurate data by editing it directly in the app.
- Delete your account and all associated data at any time via Settings → Delete Account. This is a hard delete: your account, properties, tenants, leases, uploaded files, maintenance tickets, expenses, and subscription records are permanently removed. This action cannot be undone.
- Withdraw consent for push notifications at any time via device settings or in-app notification preferences.
Residents of California, the EU/UK, and other jurisdictions with data protection laws (CCPA, GDPR, etc.) may have additional rights, including the right to object to processing and the right to lodge a complaint with a supervisory authority. Contact us using the details below to exercise any of these rights.
6. Data security
We rely on Supabase's Postgres row-level security to ensure your data is only accessible to your account, encrypted storage buckets for uploaded files, and industry-standard transport encryption (TLS) for all network requests. No system is 100% secure, and we cannot guarantee absolute security.
7. International data transfers
Our infrastructure providers (Supabase, Anthropic, Stripe, PostHog, Sentry, Expo) may process data in the United States and other countries. By using Leasepal, you consent to this transfer and processing.
8. Changes to this policy
We may update this Privacy Policy from time to time. We will update the "Effective date" above and, for material changes, notify you via email or an in-app notice.
9. Contact us
Questions about this Privacy Policy or your data? Email leasepal.support@gmail.com or use the contact form.