Aptoria
Features
Product
Resources
Company
Tools
Log in
See the demo
Legal
Privacy Policy
Last updated: May 25, 2026
We collect data used to operate, secure, support, and improve the service. We do not sell personal data as that term is defined by applicable privacy law. The sections below explain — in plain English — what we collect, why, and who else sees it.
What we collect
Account info: email, name, role (landlord / tenant / owner / staff).
Property and lease data you enter (addresses, unit details, rent amounts).
Application data tenants submit (employment, income, prior address, references).
Payment records (amounts, dates, statuses). Card and bank account numbers are stored by Stripe, not us.
Conversations with the AI agent and threaded messages with your landlord / tenant.
Documents you upload (signed leases, receipts, ID copies, insurance declarations).
Product analytics: pages visited and features used. We use this information to understand and improve the service; we do not sell it.
How we use it
To operate the service: route messages, generate AI proposals, execute approved actions, send notifications, and build the audit history you can review at any time. We use aggregate, de-identified analytics to improve the product (find slow pages, find broken flows). We do not sell personal data as that term is defined by applicable privacy law.
Who we share it with
We share the minimum data needed for each integration. Each provider is bound by their own data-processing agreement.
Supabase — database, authentication, file storage
OpenAI — the model that powers the agent. API traffic is not opted into model training.
Resend — transactional email delivery
Stripe — payments + Connect onboarding for landlords and owners
Plaid — bank account linking for ACH
DocuSign — optional e-signature on leases + addenda
Twilio — optional SMS delivery (tenant opts in explicitly)
Sentry — error monitoring (no PII in error reports by default)
AI training
When the OpenAI-powered agent is enabled, relevant conversation content is sent through the configured API integration to generate a response. Aptoria does not opt that API content into provider model training. Provider terms, retention, data controls, and any future enabled AI subprocessors are documented in the applicable agreement and subprocessor materials.
Your rights
You can request a copy of your data, ask us to correct it, or delete your account at any time from Settings → Account → Data export / Delete account. Deletion removes your profile and all user-scoped data within 30 days. We retain only what's required by law (e.g., tax records of past payments). EU and California residents have additional rights under GDPR and CCPA; reach out to privacy@aptoria.ai to exercise them.
Cookies + local storage
We store a session token to keep you signed in and a small set of preferences locally (theme, last-viewed tab, dismissed banners). We do not use third-party advertising cookies and we do not track you across other sites. A minimal cookie banner appears for first-time visitors so you can confirm.
Security
Supported database access paths use workspace-scoped access controls. Aptoria shares data with configured subprocessors as described in our Privacy Policy and DPA; access and data handling depend on the enabled workflow. For security questions or current controls, contact security@aptoria.ai.
Children
The service is not intended for users under 18 and we don't knowingly collect their data.
Updates
Material changes to this policy will be announced via in-app banner + email at least 30 days before they take effect. Continued use after the effective date constitutes acceptance.
Contact
Privacy questions: privacy@aptoria.ai. Account-specific support: open a ticket at /support.
This policy is accurate to what the product does today. If you're deploying for a regulated market (HIPAA, GDPR multi-region, financial-services compliance), have your attorney review before going live.