Privacy Policy

Last updated: September 27, 2026 · Oliver Labs LLC
SMS Messaging Privacy: Eidice does NOT share your phone number or your leads' phone numbers with third parties for marketing purposes. Phone numbers are used solely to deliver messages you explicitly create, approve, and send through the Service. We never sell, rent, or license phone numbers to advertisers, data brokers, or any other third party.

Gave your details to a real estate agent on one of their pages? Section 11.7 explains what happens to them and how to exercise your rights.

1. Information We Collect

Account Information: name, email, phone, real estate license number, brokerage, service area cities — provided by you during registration. Lead & Contact Data: You import or enter lead information including names, phone numbers, emails, property preferences, status, notes, and communication history. You are the data controller — Eidice processes it on your behalf. Communication Data: When you send SMS (via Twilio) or email (via your connected Gmail or Outlook mailbox, or via SendGrid), we store message content, timestamps, delivery status, channel, and associated lead info. Inbound replies you log are also stored. Email Reply Routing & Storage: Emails sent through Eidice use the agent sender identity configured for your account. If you use a Eidice-provided sending handle, replies route through that handle's reply-routing address so the response can appear in your Eidice Inbox. If you configure a verified custom domain or direct agent reply address, replies route through that configured address. Older email threads sent before the current routing system may still be received through a legacy Eidice reply alias for continuity. Inbound email replies are received by Eidice's email infrastructure, stored in your account's communication history, and displayed in your Eidice Inbox tab. The content of inbound email replies is stored in Supabase, encrypted at rest, accessible only by your account, and subject to the same retention policy as other communication data (Section 15). You may optionally enable "Forward email replies to my inbox" in Settings → Integrations to also receive a copy in your personal email. You may disable this at any time. Usage Analytics: Usage analytics tied to your account — feature and screen usage counts, AI generation counts, message send counts, reply rates, session activity, and the device type, app version, and subscription tier attached to each event. Each event is stored against your account so we can support it and show you your own activity; we report on it only in aggregate. We do NOT collect message content or your leads' personal information in these analytics, and we use NO third-party advertising or web-analytics trackers (no Google Analytics, no Meta / Facebook pixel) — analytics are processed only through our own infrastructure (Supabase). We also capture limited diagnostic and error telemetry (crash reports, cloud-sync failures) to keep the Service working; email addresses, phone numbers, and access tokens are scrubbed before it is stored. You can opt out of usage analytics at any time in Settings → Privacy & Legal. When you opt out, behavioral and usage analytics stop; essential crash/error diagnostics and any reports you submit through the in-app bug/feedback tool keep running so we can keep your account working. Some aggregate counts that are an inherent byproduct of operating the Service — such as message-send logs retained for TCPA / CAN-SPAM compliance and quota counts retained for billing — are retained regardless of this setting (see Sections on data storage and retention). Email Open and Click Tracking (optional, off by default): If you turn on “Measure opens and clicks” in your email settings, emails Eidice sends on your behalf carry an invisible image and, where your sending domain supports it, rewritten links. When a recipient opens one of those emails or clicks one of its links, our email provider (SendGrid) tells us, and we record which email it was and who it was sent to, when it happened, which link was clicked, and the browser or device description the recipient’s email app reports. We do not keep the recipient’s IP address. We use these records to show you engagement with your emails inside Eidice and to detect abuse of the Service; we do not sell them or use or share them for advertising. Tracking does not apply to email you send through your own connected Gmail or Outlook mailbox, which leaves your account directly. You can turn tracking off at any time; emails sent after that carry no tracking image or rewritten links. Some email apps open images automatically or block them, so an “opened” record is an indication, not proof, that a person read the email. Referral Program Records: If you share a referral link or sign up through one, we keep who referred whom, each reward's status and amount, and a record of every reward decision. To stop fraud we compare accounts' sign-in email addresses, verified phone numbers and verified license numbers, stored for this purpose only as one-way hashes, and the payment-card fingerprint our payment processor (Stripe) provides; we never see or store full card numbers. We use these records only to run the referral program and to prevent fraud, and we do not sell or share them. They are kept for 3 years after a reward's final decision, including after you delete your account, because they are needed to detect repeat fraud; after that they are deleted. Email We Send You About Eidice: We use the email address on your account to send you service and account messages you cannot opt out of while your account is open — billing receipts, security alerts, password resets, and notices about changes to the Service or to these policies. We also send occasional product news about Eidice. You can stop the product news at any time using the unsubscribe link in any of those emails, or by emailing support@eidice.com, without affecting your account or the service messages above.

2. AI-Generated & AI-Inferred Data

Eidice's AI generates and stores the following data types from your interactions with leads. ALL items below are algorithmic inferences — NOT verified facts:

3. How We Use Your Data

We use your data to provide the Eidice CRM - Real Estate service including AI message generation, lead management, and analytics; classify emotional states and communication patterns to improve personalization; detect potential life events to surface relevant opportunities (never for discriminatory purposes); calculate conversion probabilities and referral readiness; schedule and deliver messages you approve via SMS and email; process auto-fire sequence messages you have explicitly activated; sync data across devices; create, update, and delete Google Calendar / Outlook Calendar events when you manage appointments in Eidice; improve the Service through aggregated analytics. We do NOT: train AI models on your data, sell or share lead data with third parties, target advertising, make discriminatory decisions based on protected characteristics, or contact your leads without your explicit approval.

4. Phone Numbers and SMS — Explicit Disclosure

Phone numbers collected by Eidice (both the agent's phone number and the phone numbers of your imported leads) are used exclusively for the following purposes:

Eidice does NOT: sell phone numbers to advertisers, share phone numbers with third parties for marketing purposes, use your leads' phone numbers for any marketing outside of the messages you (the agent) personally approve, or permit any other party (including Oliver Labs LLC, our employees, contractors, or service providers) to contact your leads via phone or SMS for any purpose other than service operation.

Phone numbers are never shared with third parties except as strictly necessary to deliver SMS messages you have approved (e.g., to Twilio as the carrier-routing service), and only for the single purpose of routing that message.

No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.

4.1 Call Recording and Transcription

If your agent turns on call recording, California law requires every party to consent before the call is recorded (Cal. Penal Code §632 and §632.7). In the announced mode, Eidice plays an automated announcement to the parties before the call connects, and keeps a recording only when it holds provider-attested proof that the announcement was delivered and that the party stayed on the line after it. A call whose consent Eidice cannot prove is not stored: the audio is deleted at the carrier and nothing reaches your agent's account. In the manual mode, your agent is responsible for announcing the recording themselves, and Eidice holds no proof that they did.

Recordings are held in your account for 90 days and are then deleted automatically. A recording may be transcribed by OpenAI's transcription service and summarised by an AI model; the transcript and the summary are stored in the lead's record inside your agent's account. A copy of each recording is also held by our telephony provider, Twilio, under their retention terms. The record of which announcement was played, to whom, and when is kept indefinitely as evidence of lawful recording, and is not deleted when an account is closed.

5. Sleep-Window Guardrail

Eidice does NOT auto-send during your sleep window. By default, no automated messages are sent between 10 PM and 7 AM in your configured agent timezone. The window is per-agent configurable in Settings → Profile → Working Hours. Messages you initiate manually from within the app (tap-to-send, click-to-send) are exempt and send immediately when you trigger them. Auto-fire sequences, scheduled sends, speed-to-lead replies, and Zero Work Mode auto-replies are all subject to the sleep-window check and queue (rather than fire) until the next allowed send time. The window is yours to change or to switch off entirely, and if you have not set a timezone we use Pacific time — so set yours in Settings if you work elsewhere.

6. Fair Housing Compliance

Eidice incorporates Fair Housing Act (42 U.S.C. §§ 3601-3619) and California FEHA guardrails into every AI generation. AI-generated content is designed to never reference, imply preference for, or steer based on protected characteristics. Life event detection is provided as informational context ONLY and must NEVER be used to discriminate in housing recommendations or any housing-related decision. You are responsible for ensuring all communications comply with Fair Housing laws.

7. DRE §10140.6 First-Contact Disclosure

California Business & Professions Code §10140.6 requires licensed real estate agents to identify themselves and their license number on first written solicitation to consumers. Eidice adds the agent's name and DRE license number to first-contact marketing email and to public agent pages, and refuses to send or publish those when the information is missing from the agent's profile. For text messages, Eidice adds the disclosure when the agent's profile records a California license; agents are responsible for confirming that their first-contact texts carry it. The disclosure is required on the first written solicitation only — it does not need to repeat on every CRM message in an ongoing conversation. Agents are responsible for verifying their first-contact templates contain the required disclosure for their license type and jurisdiction.

Service operator: Oliver Labs LLC (Zachary Oliver, principal licensee).

8. Microsoft / Outlook User Data

If you connect a Microsoft account (personal or work / school), Eidice requests OAuth access to a limited set of Microsoft identity and Microsoft Graph scopes. The same no-sell, no-share, no-AI-training commitments apply.

Scopes requested

Scopes we do NOT request: Eidice does not request Mail.ReadWrite.Shared, Calendars.ReadWrite.Shared, Files.Read, Files.ReadWrite, or Microsoft application permissions. If you see a Microsoft consent screen for Eidice requesting a scope outside identity, your own profile, offline access, Mail.Send, Mail.ReadWrite, Calendars.ReadWrite, or Contacts.Read, do not approve it and contact support immediately.

How we use Microsoft data

Microsoft user data is used solely to perform user-initiated actions inside Eidice. Microsoft user data is NEVER used to train AI models, NEVER shared with third parties for marketing, and NEVER sold.

Email signature import. Microsoft does not let apps read an Outlook signature. When you press Import from my email in your email branding, Eidice reads the text of up to 12 of your most recent Sent Items, once, to find the closing lines they share. The result appears in your signature box. Only the signature text is kept, and only if you choose Save; the messages it read are not stored, not sent to an AI provider, and not used for anything else.

Retention & revocation

OAuth tokens are stored server-side in our managed database (Supabase / PostgreSQL), encrypted at rest by the infrastructure layer, and additionally encrypted by Eidice before storage using application-layer token encryption; all transmission uses TLS. When you disconnect Microsoft in Settings → Integrations, all tokens are deleted within 24 hours. You can also revoke access at any time from your Microsoft account permissions page.

9. Landing Page Analytics

We do not load third-party session-recording scripts on the Eidice web origin. Our public marketing pages carry no session replay, no heatmap or click-map recorder, and no third-party analytics tag — on the marketing pages and inside the signed-in application alike.

Marketing-page measurement is limited to the usage analytics described in Section 1, processed only through our own infrastructure. There is no third-party recording to opt out of; the analytics opt-out in Settings → Privacy & Legal still governs our own usage analytics.

Do Not Track. Some browsers send a "Do Not Track" signal. There is no common standard for honoring it, so Eidice does not respond to it — but the answer it asks for is already true here: we run no third-party advertising or analytics trackers on any Eidice page, and no third party collects information about your browsing across other sites through us. The analytics opt-out in Settings → Privacy & Legal governs our own usage analytics.

10. Google User Data

If you connect your Google account, Eidice requests OAuth access to a limited set of scopes. We follow Google API Services User Data Policy and the Limited Use requirements.

Scopes requested

How we use Google data

Gmail Inbox renders mailbox content on demand through a live server proxy and stores none of it. Separately, an inbound message whose sender matches exactly one existing lead is stored durably as that lead's Eidice communication history; an unmatched or ambiguous sender is not stored by Gmail Inbox and never creates a lead. Features you explicitly enable may use that lead conversation for reply capture, cancellation of pending follow-ups, facts capture, notifications, and an opted-in automated reply. When Gmail Inbox is on, Eidice also notices when you send an email from Gmail to one of your existing leads, using only the recipient address and send time from that message, so it can pause that lead's automatic replies as your "after I reply myself" setting says; the message itself is not stored. Inbox Organizer, described below, works differently and does store the mail you select.

Inbox Organizer (optional, and off unless you turn it on)

Inbox Organizer is a separate feature from Gmail Inbox. It is off by default, it only ever runs if you switch it on yourself, and switching it off stops it. When you turn it on you choose which labels or folders it covers and an explicit date range. It never covers your whole mailbox unless you select that.

What it stores, and how this differs from Gmail Inbox. Gmail Inbox only displays mail and stores nothing. Inbox Organizer is different: to read your selected mail it keeps a durable copy of it in your Eidice account — the subject, the message text, and attachments where you allow files to be retained. This includes messages from senders who are not one of your leads. Those are kept and marked “needs review” so you can decide who they belong to. Nothing outside the coverage you selected is stored.

Where it is analysed. Text from your selected messages is sent to OpenAI so Eidice can extract facts, requests and commitments from it. Under OpenAI’s API terms, data sent through their API is not used to train their models; OpenAI may retain it for up to 30 days for abuse monitoring before deleting it. Eidice does not use your mail to train any model, does not share it for marketing, and does not sell it.

Turning it off and deleting. Switching Inbox Organizer off stops all further capture and analysis. Stored messages and files are deleted when you delete the lead they belong to or your account, and you can delete them sooner from your data controls.

Email signature import. When you press Import from my email in your email branding, Eidice reads the signature saved in your Gmail settings. If none is set, it reads the text of up to 12 of your most recently sent messages, once, to find the closing lines they share. The result appears in your signature box. Only the signature text is kept, and only if you choose Save; the messages it read are not stored, not sent to an AI provider, and not used for anything else.

Google user data is used only to provide capabilities you turn on, such as sending an email, displaying your live mailbox, capturing an existing lead's reply, pausing a lead's automatic replies when you reply from Gmail, importing a contact you selected, importing your email signature when you ask, or managing a calendar event. Google user data is never used to train Eidice's or any provider's AI models, never shared with third parties for marketing, and never sold. Where a feature you enabled sends content to an AI provider for analysis, that is stated in the section for that feature.

Retention & revocation

OAuth tokens are stored server-side in our managed database (Supabase / PostgreSQL), encrypted at rest by the infrastructure layer, and additionally encrypted by Eidice before storage using application-layer token encryption; all transmission uses TLS. Tokens are tied to your Eidice account and only readable by server processes serving the Google capabilities you enabled.

Gmail Inbox off stops Gmail's live mailbox view, watch, and lead-reply capture while leaving the shared Google grant available for Google Calendar and Contacts. Disconnect Google removes Eidice's local token and sync authority for the shared grant, so Gmail, Calendar, and Contacts all disconnect; Eidice also attempts to revoke the grant at Google and reports if that upstream confirmation is unavailable. You can revoke it directly from your Google account permissions page.

Messages already captured for an existing lead remain in Eidice as CRM communication history after Gmail Inbox off or Google disconnect and are deleted with the associated lead or account. Imported contacts and calendar records you created in Eidice also remain after disconnect. Messages sent through Gmail remain in your Gmail Sent folder under Google's normal retention.

Eidice's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to other parties except as necessary to provide the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with your prior notice.

11. CCPA — Your California Privacy Rights

California residents have the following rights under the California Consumer Privacy Act (CCPA), as amended by CPRA, and the California Generative AI Training Data Transparency Act (AB-2255):

To exercise these rights, use the in-app features in Settings → Data, visit Eidice Account Deletion, or contact zacholiver@oliverlabsllc.com. We will respond within 45 days. We will verify your identity before processing requests.

11.1 Categories of personal information collected (CCPA §1798.110(c))

In the prior twelve months, Eidice has collected the following categories of personal information about California consumers. The list maps to the categories enumerated in CCPA §1798.140:

Eidice does NOT collect: biometric identifiers (no fingerprints, retina, facial recognition, or voiceprint identifiers), precise geolocation, race, religion, sexual orientation, immigration status, or union membership.

11.2 Sources of personal information (CCPA §1798.100(b))

Personal information is collected from: (a) you directly, when you sign up, enter agent profile data, import leads, send messages, configure integrations, or interact with Eidice features; (b) lead-source integrations you authorize (CRM imports from FUB / kvCORE / BoldTrail / Lofty / CINC / Real Geeks / BoomTown / Sierra / Chime / Zapier / Make / n8n / lead-gen vendors); (c) OAuth providers you connect (Google for Gmail/Contacts/Calendar; Microsoft for Contacts); (d) public real estate data feeds (CRMLS Trestle Member resource for license/office verification; CoreLogic Trestle MLS listings); (e) browser-derived data (IP for geolocation, cookies for session continuity).

11.3 Business and commercial purposes for collection (CCPA §1798.100(b))

Personal information is collected and used for the following purposes: (a) providing the Eidice Service (lead management, AI-assisted messaging, MLS integration, Chrome extension); (b) account creation, authentication, billing, and subscription management; (c) sending transactional emails (receipts, password resets, system notifications) and approved outbound messages (SMS / email / voice / browser-call) to your leads; (d) AI-driven personalization of drafts, summaries, and recommendations; (e) security, fraud prevention, abuse detection, and rate-limiting; (f) compliance with TCPA (SMS consent + opt-out tracking), CCPA (data subject request fulfillment), DRE §10140.6 (license disclosure on first contact), Fair Housing (protected-class proxy scrubbing); (g) product analytics and quality improvement (aggregate or de-identified where feasible); (h) communicating with you about service changes, Eidice updates, and product offerings (you may opt out of non-transactional emails).

11.4 Right to opt-out of sale or sharing — clarification (CCPA §1798.120)

Eidice does NOT sell personal information to third parties for monetary or other valuable consideration. Eidice does NOT share personal information for cross-context behavioral advertising. We do not display third-party advertising in the Eidice app, and we do not provide data to ad networks. The "Do Not Sell or Share My Personal Information" right under §1798.120 is structurally preserved: because no sale or sharing occurs, there is no opt-out mechanism to expose, but you may still confirm this posture by emailing zacholiver@oliverlabsllc.com.

11.5 Verifiable consumer request methods (CCPA §1798.130(a)(1))

You may submit a verifiable consumer request by either of two designated methods:

We confirm we have received your request within ten business days and tell you how we will handle it. We then respond substantively within 45 days, extendable by 45 more if reasonably necessary, with notice to you.

We verify your identity before processing any request that returns or alters data. For account-holders, verification is satisfied by requesting from the account-of-record email; non-account-holders may need to provide additional identifying information. We will not discriminate against you for exercising any CCPA right.

11.6 Authorized agents

You may name someone to submit a request for you. Send the request from your own account-of-record email confirming who is acting for you, or have your agent send us written permission signed by you. We will still verify your identity directly before we return or delete anything, and we may ask you to confirm with us that you gave the permission.

11.7 If you gave your details to a real estate agent

Real estate agents use Eidice to run their public pages and forms, such as an open-house sign-in, a home-value estimate or a market report. If you filled one in, this section is for you.

12. CRMLS & MLS Data Redistribution

Eidice integrates MLS data through CoreLogic Trestle and similar approved syndication APIs under MLS-data-display licenses. MLS listing content (photos, descriptions, prices, status, agent attribution) is shown only to authenticated Eidice users who have a verified MLS membership for the originating MLS. We do not redistribute MLS data to non-members or to third parties.

MLS listing data is NEVER used to train AI models. AI features that summarize or surface MLS data operate on the data only at request time and do not persist a derivative training corpus.

Per CRMLS Photo Policy effective 2026-02-18, listing photos are filtered by status: Active and Pending listings show full photo sets; Sold, Withdrawn, Expired, and Closed listings show a status-conditional reduced set per the policy. Coming Soon listings respect the syndication windows defined by each MLS.

13. Third-Party Services & Vendor Data Processors

Eidice uses the following processors. We share only the minimum data necessary for each processor to function. None of these processors is permitted to use your data for marketing.

13.1 AI Assistant Connections You Turn On (Anthropic / Claude)

Eidice offers an optional connection that lets you use your own AI assistant account — currently Anthropic's Claude — to work your pipeline. This connection is off unless you turn it on, and turning it on requires you to approve, on a consent screen, exactly what the assistant may do.

When you connect it, your CRM information — including your leads' names, phone numbers, email addresses, notes, and your message and call history with them — becomes readable by the AI assistant provider you connected, under your own account and your own agreement with that provider. Their privacy policy and terms govern what they do with it; ours do not. Oliver Labs LLC does not pay for, read, or store what your assistant does with that information, and is not a party to your account with that provider. You choose the permissions separately — reading your CRM, and writing drafts that wait for your approval — and you can approve one without the other.

A connected assistant can never send a text message, an email, or place a call; never book, move, or cancel an appointment; never delete anything; and never reach any account other than yours. Every draft it writes waits in your approval queue for you to send.

We keep a record of every request your assistant makes on your behalf — which tool it used, when, and how many records were returned. We do not store the contents of those requests. You can read this record, and disconnect the assistant, at any time in Settings > Integrations; disconnecting stops all access immediately. If you are a California resident, this record is part of what you may request under Section 11.

14. Data Storage & Security

Lead data stored in Supabase (PostgreSQL) with row-level security policies. Local device caching via localStorage. API keys and credentials stored server-side only. HTTPS / TLS encryption on all data transmission. Rate limiting on sensitive endpoints. 30-day session timeout. Prompt injection sanitization on all user-provided data before AI processing. A baseline Content Security Policy is enforced for frame-ancestors, object-src, base-uri, and per-route source allowlists for scripts, styles, fonts, images, connections, media, and frames; a stricter site-wide policy is being validated through Report-Only telemetry before enforcement, and CSP violation reporting remains wired for monitoring.

If there is a breach. If we discover that unencrypted personal information has been acquired by an unauthorized person, we will notify the affected users without unreasonable delay, in the form and with the contents required by California Civil Code §1798.82. Where a single incident affects more than 500 California residents, we will also submit a sample notice to the California Attorney General. We will tell you what was taken, when it happened, what we have done about it, and how to reach us.

15. Data Retention & Deletion

We keep each category of information for the period below, or for as long as we need it for the purpose it was collected, whichever is shorter. Where a category has no fixed period, we keep it while your account is active and delete it when your account is deleted.

CCPA deletion requests follow the 45-day response period described in Section 11. After a verified account-deletion request is approved, active account and lead data is purged within 30 days unless a legal-retention exception applies. Deleting a lead permanently removes it, its communication history and the AI-generated data about it, except the do-not-contact and consent records described below, which we keep so that deleting a lead never lets anyone contact a person who asked us to stop.

TCPA Consent Records: Each permission to text a phone number that is recorded by hand on a lead, given by replying to a text, or given on a texting opt-in page (the phone number, when and how permission was given, and the evidence recorded with it, including the opt-in language for written permission), and each opt-out Eidice records (a STOP reply, an unsubscribe, or a request to stop in a reply), are retained for a minimum of 7 years, even after the lead is deleted and even after account deletion, as required for TCPA compliance and potential litigation defense. We also retain, for at least 7 years from the date of the record and even after account deletion, each consent attestation an agent signs (their name, the operation, the recipient count, the time, and the IP address it came from).

16. Browser Extension

Eidice does not currently publish a browser extension. There is nothing to install, and no extension collects anything from you today. A browser extension has been built but has not been submitted to or listed on any browser store.

If we publish one, this section will describe — before it ships, not after — exactly which sites it runs on, what it reads on each of them, what it sends to your Eidice account, and what it never touches. Until then, treat any browser extension claiming to be Eidice as not ours.

17. Children's Privacy

Eidice is not intended for use by individuals under 18. We do not knowingly collect personal information from children.

18. Changes & Contact

We may update this Privacy Policy from time to time. When we do, we will post the updated policy on this page and change the "Last updated" date at the top. Oliver Labs LLC Address: 220 S Prospect Ave #12, Redondo Beach, CA 90277 Email: support@eidice.com Website: https://eidicecrm.com