Privacy Policy

Effective date: April 24, 2026

1. Information We Collect

Information you provide directly

  • Account information. Your name, email address, and password when you create an account.
  • Property data. Property addresses, unit details, building characteristics (year built, property type, square footage), and tenant information (names, lease dates, rent amounts) that you enter into the Service.
  • Component data. Information about building systems and components, including type, make, model, install date, condition, and replacement cost estimates.
  • Photos. Images of building components, nameplates, and property interiors or exteriors that you upload for data extraction or record-keeping.
  • Documents. Inspection reports, invoices, and other files you upload for AI-assisted data extraction.
  • Financial inputs. Rent amounts, reserve balances, inflation assumptions, and other inputs used for reserve adequacy calculations. We do not collect bank account numbers, credit card numbers, or investment account details through the Service. Payment processing is handled by Stripe (see Section 5).
  • Communications. Messages you send us through the contact form, email, or support channels.

Information collected automatically

  • Usage data. Pages visited, features used, and actions taken within the Service. We use this to understand how the product is used and to identify issues.
  • Device and browser information. Browser type, operating system, and screen size. We use this to ensure the Service works correctly across devices.
  • Authentication cookies. The Service uses cookies to keep you logged in and to manage your active account session. These are functional cookies required for the Service to work. We do not use advertising cookies, tracking cookies, or third-party analytics cookies.

2. How We Use Your Information

We use your information to:

  • Operate the Service. Store your property and component data, run reserve calculations, and generate reports.
  • Process uploads with AI. Send your photos and documents to our AI provider (Anthropic) for automated data extraction. See Section 4 for details on how this works.
  • Communicate with you. Send account-related emails such as welcome messages, and respond to your support requests.
  • Improve the Service. Understand usage patterns to fix bugs and improve features. We may use aggregated, de-identified data to improve reference data (such as component useful life estimates) across the platform. This aggregated data cannot be traced back to you or your properties.
  • Ensure security. Detect and prevent unauthorized access, fraud, or abuse.

We do not use your information for advertising. We do not sell your data. We do not build advertising profiles based on your property or financial information.

3. How We Store Your Information

Your data is stored on infrastructure provided by Supabase, a cloud database platform. Key details:

  • Location. Your data is stored on servers located in the United States.
  • Database security. Access to your data is controlled through row-level security policies that ensure users can only access data belonging to accounts they are members of. These policies are enforced at the database level, not just the application level.
  • File storage. Photos and documents you upload are stored in Supabase Storage with access controls that verify account membership before granting access.
  • Encryption. Data is encrypted in transit (TLS) and at rest.
  • Backups. Database backups are maintained for disaster recovery purposes.

4. AI Processing of Your Photos and Documents

This is worth explaining clearly because it is central to how the Service works.

When you upload a photo of a building component or an inspection report, we send that file to Anthropic’s API (the company behind the Claude AI model) for processing. The AI analyzes the image or document and extracts structured data, such as the make, model, and serial number from a nameplate photo, or component conditions from an inspection report.

Here is what you should know about this process:

  • What is sent. The photo or document you uploaded, along with a processing prompt that tells the AI what data to look for. We do not send your name, email, account information, or property address to the AI.
  • How Anthropic handles it. Under Anthropic’s API terms, data sent through their API is not used to train their AI models. It is processed for the purpose of generating a response and is subject to Anthropic’s data retention policies.
  • Accuracy. AI extraction is automated and may produce errors. The Service presents extracted data for your review before it becomes part of your records. You are responsible for verifying the accuracy of AI-extracted information.

If you prefer not to use AI extraction, you can enter all component data manually.

5. Third-Party Service Providers

We use a limited number of third-party services to operate CapEx Reserve:

ProviderPurposeData Involved
SupabaseDatabase, authentication, file storageAll account and property data
VercelWeb hosting and application deliveryUsage data, IP addresses
AnthropicAI processing of photos and documentsUploaded photos and documents
StripePayment processing (when applicable)Payment method details
ResendTransactional email deliveryEmail address, email content

These providers process data on our behalf under their own privacy and security policies. We do not share your data with any other third parties, and we do not sell or rent your information to anyone.

6. Data Retention

We retain your data for as long as your account is active or as needed to provide the Service. Specifically:

  • Active accounts. All data is retained and accessible to you.
  • Deleted components or properties. When you delete a property or component, it is soft-deleted (hidden from view but retained in the database) to allow recovery from accidental deletion. Soft-deleted data is permanently purged after a reasonable period.
  • Closed accounts. If you close your account, we will delete your data within a reasonable timeframe after your request, including photos and documents in storage. We may retain anonymized, aggregated data that cannot be linked back to you or your properties.

7. Your Rights and Choices

  • Access. You can view all data you have entered into the Service at any time through the application.
  • Export. You can request a complete export of your data in a portable format (CSV) by contacting us.
  • Correction. You can update or correct your data directly within the Service.
  • Deletion. You can request deletion of your account and all associated data by contacting us at support@capexreserve.com.
  • Opt out of AI processing. You can choose not to upload photos or documents and enter data manually instead.

For California residents

If you are a California resident, you have additional rights under the California Consumer Privacy Act (CCPA), including the right to know what personal information we collect, the right to request deletion, and the right to opt out of the sale of personal information. We do not sell personal information. To exercise your CCPA rights, contact us at support@capexreserve.com.

8. Cookies

The Service uses a small number of cookies, all functional:

  • Authentication cookie. Managed by Supabase Auth. Keeps you logged in across sessions. Set with Secure, HttpOnly, and SameSite attributes.
  • Account session cookie. Identifies which account you are currently viewing (relevant for users who are members of multiple accounts). Set with Secure, HttpOnly, and SameSite attributes.

We do not use cookies for advertising, behavioral tracking, or analytics. Because our cookies are strictly necessary for the Service to function, we do not display a cookie consent banner.

9. Children's Privacy

The Service is not intended for use by anyone under the age of 18. We do not knowingly collect information from children. If we learn that we have collected information from a child under 18, we will delete it promptly.

10. Security

We take reasonable measures to protect your information, including database-level access controls, encrypted connections, secure cookie settings, and access restrictions on API keys and credentials. However, no system is perfectly secure, and we cannot guarantee absolute security. If we become aware of a security breach affecting your data, we will notify you as required by applicable law.

11. Changes to This Policy

We may update this Privacy Policy from time to time. When we make changes, we will update the “Last Updated” date at the top. For material changes, we will notify you by email or through the Service. Your continued use of the Service after changes take effect constitutes acceptance of the updated policy.

12. Contact

If you have questions about this Privacy Policy or your data, contact us at:

Email: support@capexreserve.com