Legal
Privacy Policy
1. The short version
JasmoFlo collects only what we need to read deals for you and run the service. We don’t sell your data. We use third- party data providers for the math (RentCast, FRED, HUD, US Census, FEMA, Walk Score, Azure Maps); their privacy posture is documented below. You can export or delete your data at any time from Settings.
2. What we collect
- Addresses you evaluate. Stored, hashed, cached for up to 24 hours so a re-read doesn’t hit paid upstreams twice. Plaintext addresses are deleted after 90 days unless you save them as a watched property.
- Your captured philosophy. Target market, price ceiling, return floor, strategy lens. Stored versioned so we can show how your thinking evolves.
- Account info. Email, name, ZIP code, optional agent/lender contact details.
- Usage telemetry. Pages visited, features used, evaluation outcomes (decided/skipped). Used for product improvement and abuse detection. Not sold.
- Operational logs. IP address, user agent, correlation IDs, request timing, error stacks. Kept 30 days.
3. Third-party data providers
To return a deal read, we send the address you submit to one or more of the following sources:
- RentCast (property + AVM + rent comps)
- Federal Reserve Economic Data (mortgage rate baseline)
- HUD Fair Market Rent (county/metro rent ceilings)
- US Census American Community Survey (tract demographics)
- FEMA National Flood Hazard Layer (flood zone)
- Walk Score (walk/transit/bike scores)
- Azure Maps (POI within 1 mile)
- Azure OpenAI (narrator voice — never sees your account identity, only the deterministic deal data)
Each call is logged with its capture timestamp; you can see the full provenance trail inside any deal-read.
4. How we use your data
- Deliver the service (read deals, save deals, run pipeline).
- Improve the math (calibrate RACI scores against outcomes).
- Detect abuse (rate-limit + cost-cap by IP).
- Communicate with you (transactional emails, optional market alerts).
5. Your rights
Wherever you live, you can:
- Access a copy of all data we hold about you (Settings → Account → Download my data).
- Delete your account and all associated data (Settings → Account → Delete account). Some compliance-mandated audit logs are retained for 12 months after deletion.
- Correct inaccurate data via Settings.
- Object or restrict processing — write to privacy@jasmoflo.com.
- Opt out of marketing emails via the one-click unsubscribe link in any marketing message (transactional emails always send).
California residents have additional rights under CCPA/CPRA; EU/UK residents have additional rights under GDPR. We honor both.
6. Cookies
We use a single first-party cookie (anonymous_user_id, scoped to .jasmoflo.com) to attribute the marketing page handoff to the workspace. No third-party analytics or ad trackers. See our cookies page for the full list.
7. Data security
All traffic is HTTPS with HSTS preload. Secrets are stored in Azure Key Vault with managed-identity access. Database is encrypted at rest (AES-256) and in transit. Audit logs are append-only.
8. Retention
- Account data: until you delete the account.
- Saved deals + pipeline: until you delete them.
- Evaluation history (incl. plaintext address): 90 days unless saved.
- Usage telemetry: 24 months, aggregated after 90 days.
- Operational logs: 30 days.
- Audit logs: 12 months after deletion (required for regulatory auditability).
9. Children
JasmoFlo is not directed at children under 18 and we do not knowingly collect data from them. If you believe we have, write to privacy@jasmoflo.com and we will delete it.
10. Changes to this policy
Material changes are announced at least 14 days in advance via the email on file and an in-app banner. The effective date at the top of this page reflects the current version.
11. Contact
Privacy questions or rights requests: privacy@jasmoflo.com.