Privacy Policy

Last updated: April 7, 2026

Applies to revealestate.xyz and broker.revealestate.xyz

MVP Disclaimer — Early Access Platform

Reveal Estate is in its Minimum Viable Product (MVP) stage and is under active development. All features, data, scoring models, and reports may change, break, or be removed at any time. Data may be incomplete, inaccurate, or outdated. Nothing on this platform constitutes financial, legal, real estate, investment, or professional advice of any kind. Reveal Estate is a framework to help you understand generally where you stand — not a definitive authority. Always consult qualified professionals before making any real estate decision. Use of this platform is at your sole risk.

1. Who We Are

Reveal Estate ("we," "us," or "our") is a real estate intelligence platform operated by Castor & Pollux LLC, a Florida limited liability company. This Privacy Policy explains how we collect, use, store, and protect personal information when you use our platform at revealestate.xyz and broker.revealestate.xyz (collectively, the "Platform").

By using the Platform, you agree to the collection and use of information in accordance with this Privacy Policy. This Policy applies to all users: residential consumers, licensed real estate brokers and agents, and visitors.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name (optional), email address, and password (stored as a bcrypt hash — we never store your password in plaintext).
  • Broker/agent information: Real estate license number and license state (broker portal users only). This information is required to access the broker portal and may be verified.
  • Payment information: When you purchase a report or subscription, payment processing is handled entirely by Stripe. We do not receive or store credit card numbers, CVVs, or full card details. We store Stripe customer IDs and subscription IDs for billing management.

2.2 Information Collected Automatically

  • Usage and search data: Property searches you perform, addresses you look up, reports you generate, pages you visit, and features you use.
  • Security data: IP address and user-agent string associated with login attempts (successful and failed). This data is used exclusively for security, rate limiting, and abuse prevention.
  • Session data: Session tokens stored in HttpOnly cookies to keep you logged in. Session tokens expire after 30 days.
  • Password reset tokens: Temporary tokens stored when you request a password reset. These expire after use or within a short time window.
  • Behavioral analytics: With your consent, we collect page views, click patterns, scroll depth, mouse movements, and session recordings via Microsoft Clarity and Vercel Analytics. See Section 4 (Cookies) for details.

2.3 Information We Do NOT Collect

  • We do not collect Social Security numbers, government ID numbers, or financial account numbers.
  • We do not collect sensitive personal information beyond what is listed above.
  • We do not collect information from children under 18.

3. How We Use Your Information

  • Provide, operate, and maintain the Platform and its features
  • Authenticate your identity and maintain secure sessions
  • Process transactions and deliver property reports you purchase
  • Prevent unauthorized access, fraud, and abuse (login rate limiting)
  • Send transactional emails: purchase receipts, password resets
  • Analyze usage patterns to improve the Platform (with your consent for analytics cookies)
  • Comply with legal obligations, including tax and financial record-keeping
  • Enforce our Terms of Service

We do not use your information to send marketing emails without your explicit opt-in, and we do not sell, rent, or trade your personal information to any third party for their marketing purposes.

4. Cookies & Tracking Technologies

4.1 Strictly Necessary Cookies

These cookies are required for the Platform to function. You cannot opt out of them while using the Platform. No consent is required to set these.

CookiePurposeExpiry
urb-sessionConsumer account authentication (HttpOnly)30 days
hfx_authConsumer login state indicator30 days
broker_sessionBroker portal authentication (HttpOnly)30 days
broker_authBroker login state indicator30 days
demo_sessionDemo mode authentication (if applicable)Session

4.2 Analytics Cookies (Consent Required)

These cookies are only placed if you accept analytics via our cookie consent banner. You may change your preference at any time via the "Cookie Settings" link.

  • Microsoft Clarity sets cookies including_clck,_clsk,MUID to record mouse movements, clicks, and scroll behavior. Sessions are retained for 13 months. Clarity does not capture passwords or sensitive form inputs.
  • Vercel Analytics collects anonymized page view and performance data. No personally identifiable information is associated with these events.

Microsoft Clarity will not load unless you accept analytics cookies. You can manage your cookie preference at any time by clicking "Cookie Settings" at the bottom of any page.

5. Third-Party Services & Data Sharing

We share data with the following third parties only to the extent necessary to operate the Platform. We do not sell your information to any of these parties for their own marketing.

Stripe

Payment processing. Your email and payment method are shared with Stripe to process transactions. Stripe stores card data on our behalf under PCI DSS compliance. We store your Stripe customer ID and subscription ID. Stripe may retain payment records per their own data retention policy.

Stripe Privacy Policy

Vercel Analytics

Usage analytics and performance monitoring. Anonymized page view data and Core Web Vitals are sent to Vercel. No PII is included in these events.

Vercel Privacy Policy

Microsoft Clarity

Session recording and behavioral analytics (consent required). Clarity records mouse movements, clicks, and page interactions to help us improve the product. Clarity automatically masks sensitive inputs. Data is retained for 13 months. Clarity is not loaded unless you have accepted analytics cookies.

Microsoft Privacy Statement

Auth0 (by Okta)

Authentication services for social login (Google, Apple, Yahoo). If you use a social login method, your email and profile information are passed from Auth0 to create or update your Reveal Estate account. Auth0 stores authentication tokens and logs on our behalf.

Auth0 Privacy Policy

Apify

Property data enrichment. We send property addresses to Apify to retrieve publicly available real estate data. No user personal information (name, email, payment data) is shared with Apify.

Apify Privacy Policy

Railway

Database and infrastructure hosting. All platform data, including user accounts, is stored on Railway's PostgreSQL infrastructure. Data is encrypted at rest and in transit. Railway is our data processor and does not access your data independently.

Railway Privacy Policy

6. Data Retention

Data TypeRetention PeriodReason
Account profile (name, email)Life of accountAccount operation
Password hashLife of accountAuthentication
Session tokens30 days (auto-expire)Authentication; purged on expiry
Login attempts (IP + email)90 daysSecurity & rate limiting
Property search historyLife of accountUser features; deleted on account deletion
Report purchase records7 years (anonymized after deletion)Tax & legal compliance (IRS requirements)
Stripe payment recordsPer Stripe's retention policyFinancial compliance; Stripe-controlled
Analytics data (Clarity)13 months (Clarity-controlled)Product analytics
Password reset tokensUntil used or expired (hours)Security

7. Your Rights & Choices

7.1 Access & Export

You may export your personal data at any time from your Account Settings page. Your export includes your profile information, subscription status, property search history, and report purchase history. It does not include raw parcel data, scoring algorithms, third-party property records, or any proprietary Platform data — those are Castor & Pollux LLC trade secrets and are not exportable under any plan.

7.2 Deletion

You may delete your account from your Account Settings page. Upon deletion, your profile, session tokens, and search history are permanently deleted. Financial records (report purchases) are anonymized but retained for 7 years for legal compliance. See Section 9 for full details on what is deleted vs. anonymized.

7.3 Cookie Preferences

You may update your analytics cookie preference at any time. Strictly necessary cookies cannot be disabled while using the Platform.

7.4 CCPA Rights (California Residents)

California residents have the right to: (a) know what personal information is collected and how it is used; (b) delete personal information; (c) opt-out of the sale of personal information (we do not sell personal information); (d) non-discrimination for exercising these rights. To exercise your rights, use the Account Settings page or contact us through the Platform. We will respond to verified requests within 45 days.

7.5 Do Not Sell

We do not sell, rent, or trade your personal information to third parties for their own commercial purposes. Period.

8. Proprietary Platform Data

Reveal Estate aggregates data from public records, government databases, and licensed third-party sources. The following constitute proprietary trade secrets and confidential information of Castor & Pollux LLC, regardless of your subscription tier:

  • Aggregated parcel records and our curated property database
  • Opportunity scoring algorithms, weights, and component calculations
  • Component lifespan models and HouseFax grading logic
  • Deed classification and title analysis models
  • Bulk property records, even those derived from public sources

Users may not export, scrape, reverse-engineer, redistribute, or attempt to reconstruct any proprietary Platform data. The data export feature (Section 7.1) provides only data that you created or that was specifically created about you as a user.

9. Account Deletion & Data Removal

When you delete your account, the following actions are taken immediately:

Hard Deleted (permanent, immediate)

  • Your user profile (name, email, password hash)
  • All active session tokens
  • Your subscription record
  • Your property search history (TitleSearchLog records)

Anonymized (retained for legal compliance)

  • Report purchase records: your user ID and session identifiers are nulled out. The financial record (amount, date, property) is retained for 7 years for IRS compliance. You cannot be identified from an anonymized record.
  • Login attempt records: your email address is nulled out. The IP address and timestamp are retained for 90 days for security audit purposes.

Third-Party Data (outside our control)

  • Stripe retains payment records per their own data retention policy. You may contact Stripe directly to request deletion of Stripe-held records.
  • Microsoft Clarity session recordings that have already been captured are governed by Clarity's 13-month retention policy. We cannot retroactively delete third-party analytics data.
  • Vercel Analytics data is anonymized and aggregated; individual records cannot be identified or deleted.

10. Data Security

We take reasonable measures to protect your information, including:

  • Passwords hashed with bcrypt (12 salt rounds) — never stored in plaintext
  • Session tokens are 32-byte cryptographically random values
  • All cookies are HttpOnly and SameSite=Lax; Secure flag in production
  • HTTPS enforced across all Platform domains
  • Login rate limiting (5 failed attempts per 15 minutes per IP)
  • Database encrypted at rest via Railway infrastructure

MVP caveat: We are an early-stage platform. Security practices are continuously being improved. No system is 100% secure, and we cannot guarantee absolute security of data transmitted over the internet. You acknowledge this risk by using the Platform.

11. Children's Privacy

The Platform is intended for users who are 18 years of age or older. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal information, please contact us through the Platform and we will delete it.

12. Changes to This Policy

We may update this Privacy Policy at any time. The "Last updated" date at the top of this page will reflect any changes. Your continued use of the Platform after changes are posted constitutes acceptance of the updated Policy. We recommend reviewing this page periodically. For material changes, we will make reasonable efforts to notify active users via the Platform.

13. Governing Law

This Privacy Policy shall be governed by and construed in accordance with the laws of the State of Florida, without regard to conflict of law principles. Any disputes arising under this Policy are subject to the exclusive jurisdiction of state and federal courts in Pinellas County, Florida, consistent with our Terms of Service.

13b. Additional Terms for Broker & Agent Users

This section applies specifically to users of the broker portal at broker.revealestate.xyz.
  • License information: Your real estate license number and license state are collected and stored. This information may be verified against state licensing databases. Providing a fraudulent license number is a material breach of the Broker Terms of Service.
  • Report activity: All property reports you generate, including the property address and any client delivery details (email, name), are logged and associated with your account and your brokerage company for billing purposes.
  • Company data: Brokerage-level data (report counts, billing records, invoices) is associated with your company account and is accessible to your company's admin users.
  • Client information: If you enter a client's name or email when sending a report, that information is stored in your report history. You are responsible for ensuring you have appropriate authorization to share client information with us.
  • Export & deletion: Broker account deletion removes your personal profile and sessions. Your report history records are anonymized (your user ID is disassociated) but retained for your company's billing records. Company accounts are not deleted when an individual user account is deleted.

14. Contact Us

For privacy-related questions, data export requests, or to exercise your CCPA rights, please contact us through the Platform. We will respond to verified requests within 45 days.

© 2026 Castor & Pollux LLC. All Rights Reserved.