Privacy
What we keep, and where.
What we store
Your email address and password hash, so you can sign in. A TOTP secret, because two-factor authentication is required on every account.
Every search you run: the budget, yield target, location, strategy and preferences you entered, and the report that came back.
Your API key
If you choose to save your Anthropic API key, it is encrypted with AES-256-GCM before it is written to our database. It is decrypted only inside the server function that calls Anthropic on your behalf, and is never returned to the browser — the interface only ever shows the last few characters.
You can remove a stored key at any time from the search screen. Removing it deletes the stored record.
Who can see your reports
Completed reports are shared with everyone signed in to this deployment, so the team can reuse research instead of paying to repeat it. Reports are shown without the email or user id of whoever ran them.
Administrators can see which account ran a search, for billing and support.
Caching
An identical brief run within three days returns the stored report instead of researching again. This costs nothing and calls no external service.
Third parties
Searches call the Anthropic API, including its web search tool, to do the research. Property listings link out to realestate.com.au and Domain; following those links is a visit to their sites, under their terms and their tracking.