This Privacy Policy explains what iKEY collects, why, and how you can control it.
What we collect
- Account info: email, name, brokerage details, brand color, logo.
- CRM data: leads, transactions, deadlines, documents, notes, activity you record.
- Client portal data: clients you invite, magic-link tokens (hashed), messages and documents they upload.
- Usage: standard server logs (IP, timestamp, route). No third-party analytics.
- Billing: Stripe handles payment info. We store a Stripe customer id, never a card number.
How we use it
Data is used to operate the Service — scoring your leads, generating deadlines, sending emails and push notifications you configure. We do not sell your data.
AI processing
When you use AI features (message drafting, portal Ask, model compare), the minimum context needed is sent to our LLM provider (Emergent's managed integration wrapping Anthropic / OpenAI / Gemini). Providers do not train models on your workspace data.
Where it lives
Storage runs on Supabase (US-West). Row-Level Security ensures your workspace is only readable by you (and by teammates in your brokerage, if you have one). Files uploaded to the client portal live in Supabase Storage with signed-URL access.
Sub-processors
- Supabase — database, auth, file storage
- Stripe — payment processing & Stripe Tax
- DocuSign — e-signature envelopes on paid tiers (envelope status, signer email, audit trail)
- Resend — transactional email
- Emergent LLM (Anthropic, OpenAI, Gemini) — AI message drafting and portal Q&A
- Expo Push — mobile notifications
- Google Analytics 4 — anonymised product analytics (page views, conversions)
Your controls
- Export any lead / transaction from the app UI (CSV download).
- Delete your workspace via Settings → Account. This removes all your data within 30 days.
- Revoke a client portal magic link at any time.
Contact
Privacy questions: reach us via the in-app support link.