Last updated: April 7, 2026
1. Introduction
Petal ("we," "us," or "our") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered real-estate intelligence platform (the "Service").
By using Petal, you consent to the data practices described in this policy. If you do not agree with the terms of this privacy policy, please do not access or use our service.
2. Information We Collect
Account Information
- Email address and name (via WorkOS AuthKit with Google or Microsoft OAuth)
- WorkOS user ID and authentication tokens
- Company affiliation and role (when provided during onboarding)
- Onboarding completion status and preferences
Usage and Interaction Data
- Chat conversations and queries submitted to our AI assistant
- Property addresses and locations you research
- Vault content: files, pro formas, workflows, reports, sites, memories, and folders you create
- Generated reports and analysis results
- Feature usage patterns and preferences
- Session duration and frequency of access
Technical Data
- IP address and device information
- Browser type and version
- Operating system and platform details
- Pages visited and time spent on each page
- Referral sources and navigation paths
3. How We Use Your Information
We use your information for the following purposes:
- Service Provision: To provide and maintain our real-estate intelligence service
- AI Processing: To power our AI assistant and analysis capabilities
- Account Management: To authenticate users and manage access controls
- Service Improvement: To analyze usage patterns and enhance our service features
- Security: To detect and prevent fraudulent activities and ensure platform security
- Communication: To send service updates, security alerts, and support communications
- Compliance: To comply with legal obligations and regulatory requirements
4. Data Storage and Security
We employ robust security measures to protect your information. Our data infrastructure includes:
Data Storage Locations:
- Convex: User accounts, chat conversations, vault content (files, pro formas, workflows, reports, sites, memories), and usage statistics
- Convex Storage: File attachments, PDF reports, and other user-uploaded content
- Vercel: Application hosting and serverless functions
All data transmission uses industry-standard encryption (TLS 1.2+). We implement access controls, regular security audits, and monitoring systems to protect against unauthorized access. User data is stored in US-based data centers.
5. AI Processing and Third-Party Services
Our AI services process your queries and data to generate insights and reports. This involves:
- AI Model Providers: We use Anthropic Claude as our primary AI service for chat, pro forma generation, and workflow automation
- Data Enrichment: We integrate with multiple real-estate data providers to enhance analysis, including ReGrid (parcel data), ATTOM Data (property history & AVM), Zoneomics (zoning data), US Census Bureau (demographics), and others
- Geocoding & Maps: Google Maps API and Mapbox for address geocoding and map visualization
- Search: Tavily for real-time web search capabilities
- Memory Storage: Pinecone and SuperMemory for long-term memory and vector embeddings
We carefully select our AI and data service providers and ensure they maintain appropriate security and privacy standards. These services are bound by contractual obligations to protect your data and use it only for providing services to us.
6. Data Sharing and Disclosure
We may share your information in the following circumstances:
Service Providers
- AI Services: Anthropic Claude for processing user queries, pro forma generation, and workflow automation
- Cloud Infrastructure: Vercel for hosting and computing services
- Database: Convex for backend database, real-time sync, and file storage
- Real-Estate Data: ReGrid (parcel data), ATTOM Data (property history, AVM), Zoneomics (zoning), US Census Bureau (demographics), and other data providers
- Geocoding & Maps: Google Maps API for geocoding and Mapbox for map visualization
- Authentication: WorkOS AuthKit for user authentication (Google, Microsoft OAuth)
- Search: Tavily for real-time web search
Legal Requirements
We may disclose your information when required by law, court order, or government request, or to protect our rights, property, or safety, or that of our users or the public.
7. Data Retention
We retain your information for different periods based on the type of data and purpose:
- Chat History: Retained in Convex for the duration of your account unless manually deleted
- Vault Content: Files, pro formas, workflows, reports, sites, and memories stored in your vault for the duration of your account
- Account Data: Retained while your account remains active and for a period after account termination
- Analytics Data: Aggregated and anonymized after a reasonable period for service improvement
You can request deletion of your data at any time, subject to legal and operational constraints. Some data may be retained in anonymized or aggregated form for service improvement.
8. Your Rights and Choices
Depending on your location, you may have the following rights:
Access and Portability
- Request a copy of your personal data
- Request your data in a structured, machine-readable format
- Export your chat history and generated reports
Correction and Deletion
- Correct inaccurate or incomplete personal information
- Request deletion of your account and associated data
- Delete specific conversations or reports from your account
Control and Preferences
- Manage your account settings and preferences
- Control email notification preferences
- Opt out of marketing communications (though not essential service communications)
9. Cookies and Tracking
We use cookies and similar technologies to enhance your experience, maintain your session, analyze usage patterns, and provide personalized features. Our cookie practices include:
- Essential Cookies: Required for basic site functionality and security
- Authentication Cookies: Keep you logged in and maintain your session
- Analytics Cookies: Help us understand how our service is used
- Preference Cookies: Remember your settings and customization choices
You can control cookies through your browser settings, though disabling certain cookies may affect the functionality of our service.
10. International Data Transfers
Petal operates globally and may transfer your data across international borders. When we transfer data outside your country, we ensure appropriate safeguards are in place, including:
- Standard contractual clauses with our service providers
- Adequacy decisions where available
- Other legally recognized transfer mechanisms
Our application is hosted on Vercel with data stored in Convex's US-based data centers. We store data primarily in regions that align with our user base and comply with applicable data protection regulations.
11. Children's Privacy
Petal is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children under 18. If we become aware that we have collected personal information from a child under 18, we will take steps to delete such information immediately. If you believe we have collected information from a child under 18, please contact us.
12. Data Breach Notification
In the event of a data breach that may affect your personal information, we will notify affected users and relevant authorities in accordance with applicable legal requirements. Our notification will include details about the breach, the types of information affected, and steps we recommend you take to protect yourself.
13. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify users of any material changes by posting the updated policy on our website and sending email notifications to affected users. Your continued use of our service after such changes constitutes acceptance of the updated policy.
14. Contact Information
If you have any questions about this Privacy Policy or want to exercise your data rights, please contact us at:
Email: support@petal.fyi
Website: petal.fyi
For data subject requests from the EU, please include "GDPR Request" in your email subject. For requests from California, please include "CCPA Request" in your email subject. We will respond to your request within the timeframe required by applicable law.