Legal
Privacy Policy
Last updated: August 22, 2026
Aptoria records the facts, decisions, approvals, actions, delivery results, verification, outcomes, and evidence needed to run and account for property-management workflows. We also collect limited account, security, support, and optional product-analytics data. We do not sell personal data or use it for cross-customer advertising profiles.
Policy scope and your choices
This policy applies to Aptoria websites, apps, portals, support, and enabled integrations. Some records are required to create an account, secure it, perform a workflow you request, meet a contract, or keep an audit or financial record. Optional analytics is separate: you can reject it without losing core service access.
Policy version: 2026-08-22. We record the version, time, account, and method when an account holder acknowledges this policy. Existing users may be asked to review a materially changed version before continuing. Acknowledgment does not turn optional analytics on and does not waive privacy rights.
Data we collect
•
Account, organization, authority, and security: name, contact details, role, organization, accessible properties, explicit approval/spending/communication/export authority, authentication method, MFA state, sessions, login and permission changes, support access, and acceptance records.
•
Property operations: portfolio, property, building and unit facts; ownership and operating relationships; equipment, inspections, permits, violations, vendors, work orders, access instructions, and operational contacts. Structured facts can carry source, confidence, effective date, verification, and correction history.
•
People, applications, leases, and communications: contact preferences, language, accessibility requests you provide, applications and verification results, leases and extracted terms, tenancy dates, messages, attachments, call or delivery status, consent and opt-out records, support, complaints, and disputes.
•
Payments and accounting: charges, balances, payment and processor status, fees, refunds, disputes, ledger mappings, and reconciliation evidence. Stripe and Plaid handle raw card or bank credentials; Aptoria stores provider references and operational states, not complete payment credentials.
•
Documents and evidence: uploaded files, metadata, hashes, signatures, OCR/extraction results, source references, access classification, retention category, verification state, versions, and legal-hold status.
•
Workflow, AI, and audit records: triggers, facts considered, policy/rule/model/workflow versions, recommendations, confidence and uncertainty, authority checks, approvals, blocked actions, execution attempts, delivery, reversal, escalation, verification, outcome, cost/latency, and tamper-evident audit references.
•
Business and service operations: onboarding and migration quality, feature/workflow use, integrations, reliability, support effort, satisfaction, subscription and contract data, and aggregated customer-value, retention, sales, marketing, pilot, finance, and security measures.
•
Device and diagnostic data: IP-derived request security context, device/browser/app version, timestamps, route templates, error codes, service latency, queue/provider health, and suspicious or unauthorized access attempts.
•
Optional product analytics: bounded feature events and sanitized route templates, collected only after cookie consent and, for signed-in users, an enabled profile preference. Session replay, form text, messages, record identifiers, email, property, tenant, and payment details are excluded from this analytics channel.
Why we use data
•
Provide, authenticate, configure, support, bill, and secure the service; import records; connect providers; and honor user requests.
•
Evaluate facts and policies, generate AI-assisted drafts or recommendations, check authority, perform an enabled action, verify its result, reconcile external systems, and preserve evidence.
•
Detect errors, fraud, duplicate actions, unsafe execution, cross-workspace access, security incidents, and legal or operational exceptions; investigate and correct them.
•
Measure reliability, workflow outcomes, human effort, data quality, customer value, and trust-adjusted automation. We use minimum-necessary, access-controlled records and aggregate or de-identify results where individual detail is unnecessary.
•
Comply with law, enforce agreements, respond to rights requests, retain required business records, and establish or defend legal claims.
Depending on the person and jurisdiction, these uses rest on performing a contract, complying with law, protecting the service and its users, Aptoria’s legitimate interests in safe service operation, or consent where required. Customers must have an appropriate basis and authority for personal data they place in Aptoria.
AI, inferences, and automated workflows
When an AI-assisted feature is enabled, Aptoria may send the minimum relevant content to the configured model provider to classify, extract, summarize, draft, or recommend. We keep source, model/prompt/policy versions, output, review, correction, and outcome references when needed for safety and replay. Aptoria does not opt that API content into provider model training and does not pool one customer’s tenant, pricing, or operating data to train another customer’s experience. Any future enabled AI subprocessors are documented before they receive production content.
AI outputs and derived facts can be wrong. Consequential eligibility, screening, housing, payment, legal-notice, or other restricted decisions must follow the applicable configured workflow, authority, provider, and human-review requirements. Aptoria does not create a secret person-level tenant score from unrelated behavior.
Who we share it with
We disclose the minimum data needed to workspace members and authorized representatives, a recipient or vendor involved in the requested workflow, and enabled service providers. Access depends on role, organization, relationship, and workflow. Providers process data under applicable contracts and their own service terms.
•
Supabase — database, authentication, file storage
•
OpenAI — the model that powers the agent. API traffic is not opted into model training.
•
Resend — transactional email delivery
•
Stripe — payments + Connect onboarding for landlords and owners
•
Plaid — bank account linking for ACH
•
DocuSign — optional e-signature on leases + addenda
•
Twilio — optional SMS delivery (tenant opts in explicitly)
•
PostHog — optional, consent-gated product analytics with autocapture and session replay disabled
•
Sentry — error monitoring with default PII collection disabled and an Aptoria redaction layer for direct identifiers, credentials, and bounded diagnostic context
We may also disclose data for a business transfer, legal process, safety or security response, or to protect rights, but only as permitted by law. We do not sell personal data and do not share it for cross-context behavioral advertising.
Retention and deletion
We keep each category only as long as needed for its stated purpose, the customer relationship, security, dispute resolution, legal holds, or applicable financial, tax, housing, communications, and audit obligations. Retention therefore varies by record and jurisdiction; an account deletion does not erase another party’s lawful business record.
•
Optional analytics follows its configured short retention and can be stopped prospectively by changing the analytics preference.
•
Operational and workflow records remain while the account or related tenancy/workflow is active and for the documented post-service retention period.
•
Security and diagnostic records are retained for a bounded investigation and defense period.
•
Financial, consent, delivery, audit, dispute, legal-hold, and compliance evidence may be retained longer where law or a legitimate claim requires it.
Canonical workflow events snapshot the governing retention-policy version and expiry when collected. Active legal holds suspend expiry. When the period ends, an audited privileged process may delete, anonymize, or cryptographically unlink the record; it cannot silently bypass the append-only control. A purge receipt and an externally anchored checkpoint preserve evidence that the retained chain existed without retaining the expired event itself. Backups age out on their normal protected cycle.
Canonical events use pseudonymous actor keys instead of a permanent profile foreign key. Account deletion destroys the separately protected identity mapping where required, while a lawful non-identifying operational record may remain.
Data we deliberately avoid
Unless a defined workflow and lawful need require it, do not provide protected-class data, unrelated social-media or browsing history, precise location, unrelated contact lists, biometrics, full bank/card credentials, indefinite identity-document copies, or unstructured notes that could become shadow screening criteria. We prohibit unsupported personality, character, and emotion inferences and cross-customer behavioral profiles.
Your rights
You can request access, a portable copy, correction, or deletion from Settings → Account → Data export / Delete account or by emailing privacy@aptoria.ai. Depending on law, you may also object to or restrict processing, withdraw consent prospectively, appeal a response, or complain to a regulator. We verify the requester and explain any legal exception. We do not discriminate for exercising a privacy right.
Cookies + local storage
We store a session token to keep you signed in and a small set of preferences locally (theme, last-viewed tab, dismissed banners). We do not use third-party advertising cookies and we do not track you across other sites. A cookie banner appears for first-time visitors so you can accept or reject optional analytics.
Security
Aptoria uses workspace-scoped access controls, least-privilege service access, encryption in transit and at rest where supported, redaction, monitoring, backups, and audit evidence. No system is risk-free. If an incident requires notice, we will notify affected parties as required by law. For current controls, contact security@aptoria.ai.
Raw canonical metric evidence is limited to defined management and audit-capable roles. Other users receive bounded self-service receipts rather than organization-wide actor, security, commercial, dimension, provenance, or hash data. Daily chain checkpoints are signed and anchored outside the operational database so privileged reconstruction can be detected.
Children
The service is not intended for users under 18 and we don't knowingly collect their data.
Updates
We version this policy. Material changes are announced before they take effect through an appropriate account notice, such as an in-app notice or email. When law or the nature of the change requires renewed acknowledgment or consent, we request it rather than relying only on continued use.
Contact
Privacy questions: privacy@aptoria.ai. Account-specific support: open a ticket at /support.
This policy is accurate to what the product does today. If you're deploying for a regulated market (HIPAA, GDPR multi-region, financial-services compliance), have your attorney review before going live.