Privacy Policy
Gave your details to a real estate agent on one of their pages? Section 11.7 explains what happens to them and how to exercise your rights.
1. Information We Collect
Account Information: name, email, phone, real estate license number, brokerage, service area cities — provided by you during registration. Lead & Contact Data: You import or enter lead information including names, phone numbers, emails, property preferences, status, notes, and communication history. You are the data controller — Eidice processes it on your behalf. Communication Data: When you send SMS (via Twilio) or email (via your connected Gmail or Outlook mailbox, or via SendGrid), we store message content, timestamps, delivery status, channel, and associated lead info. Inbound replies you log are also stored. Email Reply Routing & Storage: Emails sent through Eidice use the agent sender identity configured for your account. If you use a Eidice-provided sending handle, replies route through that handle's reply-routing address so the response can appear in your Eidice Inbox. If you configure a verified custom domain or direct agent reply address, replies route through that configured address. Older email threads sent before the current routing system may still be received through a legacy Eidice reply alias for continuity. Inbound email replies are received by Eidice's email infrastructure, stored in your account's communication history, and displayed in your Eidice Inbox tab. The content of inbound email replies is stored in Supabase, encrypted at rest, accessible only by your account, and subject to the same retention policy as other communication data (Section 15). You may optionally enable "Forward email replies to my inbox" in Settings → Integrations to also receive a copy in your personal email. You may disable this at any time. Usage Analytics: Usage analytics tied to your account — feature and screen usage counts, AI generation counts, message send counts, reply rates, session activity, and the device type, app version, and subscription tier attached to each event. Each event is stored against your account so we can support it and show you your own activity; we report on it only in aggregate. We do NOT collect message content or your leads' personal information in these analytics, and we use NO third-party advertising or web-analytics trackers (no Google Analytics, no Meta / Facebook pixel) — analytics are processed only through our own infrastructure (Supabase). We also capture limited diagnostic and error telemetry (crash reports, cloud-sync failures) to keep the Service working; email addresses, phone numbers, and access tokens are scrubbed before it is stored. You can opt out of usage analytics at any time in Settings → Privacy & Legal. When you opt out, behavioral and usage analytics stop; essential crash/error diagnostics and any reports you submit through the in-app bug/feedback tool keep running so we can keep your account working. Some aggregate counts that are an inherent byproduct of operating the Service — such as message-send logs retained for TCPA / CAN-SPAM compliance and quota counts retained for billing — are retained regardless of this setting (see Sections on data storage and retention). Email Open and Click Tracking (optional, off by default): If you turn on “Measure opens and clicks” in your email settings, emails Eidice sends on your behalf carry an invisible image and, where your sending domain supports it, rewritten links. When a recipient opens one of those emails or clicks one of its links, our email provider (SendGrid) tells us, and we record which email it was and who it was sent to, when it happened, which link was clicked, and the browser or device description the recipient’s email app reports. We do not keep the recipient’s IP address. We use these records to show you engagement with your emails inside Eidice and to detect abuse of the Service; we do not sell them or use or share them for advertising. Tracking does not apply to email you send through your own connected Gmail or Outlook mailbox, which leaves your account directly. You can turn tracking off at any time; emails sent after that carry no tracking image or rewritten links. Some email apps open images automatically or block them, so an “opened” record is an indication, not proof, that a person read the email. Referral Program Records: If you share a referral link or sign up through one, we keep who referred whom, each reward's status and amount, and a record of every reward decision. To stop fraud we compare accounts' sign-in email addresses, verified phone numbers and verified license numbers, stored for this purpose only as one-way hashes, and the payment-card fingerprint our payment processor (Stripe) provides; we never see or store full card numbers. We use these records only to run the referral program and to prevent fraud, and we do not sell or share them. They are kept for 3 years after a reward's final decision, including after you delete your account, because they are needed to detect repeat fraud; after that they are deleted. Email We Send You About Eidice: We use the email address on your account to send you service and account messages you cannot opt out of while your account is open — billing receipts, security alerts, password resets, and notices about changes to the Service or to these policies. We also send occasional product news about Eidice. You can stop the product news at any time using the unsubscribe link in any of those emails, or by emailing support@eidice.com, without affecting your account or the service messages above.
2. AI-Generated & AI-Inferred Data
Eidice's AI generates and stores the following data types from your interactions with leads. ALL items below are algorithmic inferences — NOT verified facts:
- Relationship Memories — Personal facts and preferences extracted from conversations. Stored per lead.
- Client Personas — Behavioral profiles: communication style, decision drivers, objections, response speed.
- Emotional Arc Classifications — AI-inferred emotional states classified from lead messages. These are PROBABILISTIC ASSESSMENTS, not confirmed emotional states.
- Communication DNA — Heuristic analysis of reply patterns: average length, formality, emoji usage, peak hours, preferred channel.
- Win Patterns — Analysis of successful deal closings: touchpoints, days to convert, channel mix.
- Conversion Probability — Algorithmic scoring (0-100%) estimating conversion likelihood based on engagement signals, not personal characteristics.
- Life Event Detection — Heuristic keyword detection of potential life events. THESE ARE AI-INFERRED APPROXIMATIONS, NOT CONFIRMED FACTS. All life event data is labeled "AI-inferred, not confirmed."
- Referral Readiness — Algorithmic assessment of whether a past client may be receptive to a referral request.
3. How We Use Your Data
We use your data to provide the Eidice CRM - Real Estate service including AI message generation, lead management, and analytics; classify emotional states and communication patterns to improve personalization; detect potential life events to surface relevant opportunities (never for discriminatory purposes); calculate conversion probabilities and referral readiness; schedule and deliver messages you approve via SMS and email; process auto-fire sequence messages you have explicitly activated; sync data across devices; create, update, and delete Google Calendar / Outlook Calendar events when you manage appointments in Eidice; improve the Service through aggregated analytics. We do NOT: train AI models on your data, sell or share lead data with third parties, target advertising, make discriminatory decisions based on protected characteristics, or contact your leads without your explicit approval.
4. Phone Numbers and SMS — Explicit Disclosure
Phone numbers collected by Eidice (both the agent's phone number and the phone numbers of your imported leads) are used exclusively for the following purposes:
- Delivering SMS messages you explicitly create, review, and approve through the Service, sent via Twilio or equivalent carriers.
- Receiving inbound SMS replies from your leads and displaying them inside your Eidice Inbox.
- Calculating analytics about your own communication activity (reply rates, send volume) for your own use.
- Honoring STOP, UNSUBSCRIBE, and other opt-out requests as required by TCPA.
Eidice does NOT: sell phone numbers to advertisers, share phone numbers with third parties for marketing purposes, use your leads' phone numbers for any marketing outside of the messages you (the agent) personally approve, or permit any other party (including Oliver Labs LLC, our employees, contractors, or service providers) to contact your leads via phone or SMS for any purpose other than service operation.
Phone numbers are never shared with third parties except as strictly necessary to deliver SMS messages you have approved (e.g., to Twilio as the carrier-routing service), and only for the single purpose of routing that message.
No mobile information will be shared with third parties or affiliates for marketing or promotional purposes. Information sharing to subcontractors in support services, such as customer service, is permitted. All other categories exclude text messaging originator opt-in data and consent; this information will not be shared with any third parties.
4.1 Call Recording and Transcription
If your agent turns on call recording, California law requires every party to consent before the call is recorded (Cal. Penal Code §632 and §632.7). In the announced mode, Eidice plays an automated announcement to the parties before the call connects, and keeps a recording only when it holds provider-attested proof that the announcement was delivered and that the party stayed on the line after it. A call whose consent Eidice cannot prove is not stored: the audio is deleted at the carrier and nothing reaches your agent's account. In the manual mode, your agent is responsible for announcing the recording themselves, and Eidice holds no proof that they did.
Recordings are held in your account for 90 days and are then deleted automatically. A recording may be transcribed by OpenAI's transcription service and summarised by an AI model; the transcript and the summary are stored in the lead's record inside your agent's account. A copy of each recording is also held by our telephony provider, Twilio, under their retention terms. The record of which announcement was played, to whom, and when is kept indefinitely as evidence of lawful recording, and is not deleted when an account is closed.
5. Sleep-Window Guardrail
Eidice does NOT auto-send during your sleep window. By default, no automated messages are sent between 10 PM and 7 AM in your configured agent timezone. The window is per-agent configurable in Settings → Profile → Working Hours. Messages you initiate manually from within the app (tap-to-send, click-to-send) are exempt and send immediately when you trigger them. Auto-fire sequences, scheduled sends, speed-to-lead replies, and Zero Work Mode auto-replies are all subject to the sleep-window check and queue (rather than fire) until the next allowed send time. The window is yours to change or to switch off entirely, and if you have not set a timezone we use Pacific time — so set yours in Settings if you work elsewhere.
6. Fair Housing Compliance
Eidice incorporates Fair Housing Act (42 U.S.C. §§ 3601-3619) and California FEHA guardrails into every AI generation. AI-generated content is designed to never reference, imply preference for, or steer based on protected characteristics. Life event detection is provided as informational context ONLY and must NEVER be used to discriminate in housing recommendations or any housing-related decision. You are responsible for ensuring all communications comply with Fair Housing laws.
7. DRE §10140.6 First-Contact Disclosure
California Business & Professions Code §10140.6 requires licensed real estate agents to identify themselves and their license number on first written solicitation to consumers. Eidice adds the agent's name and DRE license number to first-contact marketing email and to public agent pages, and refuses to send or publish those when the information is missing from the agent's profile. For text messages, Eidice adds the disclosure when the agent's profile records a California license; agents are responsible for confirming that their first-contact texts carry it. The disclosure is required on the first written solicitation only — it does not need to repeat on every CRM message in an ongoing conversation. Agents are responsible for verifying their first-contact templates contain the required disclosure for their license type and jurisdiction.
Service operator: Oliver Labs LLC (Zachary Oliver, principal licensee).
8. Microsoft / Outlook User Data
If you connect a Microsoft account (personal or work / school), Eidice requests OAuth access to a limited set of Microsoft identity and Microsoft Graph scopes. The same no-sell, no-share, no-AI-training commitments apply.
Scopes requested
- openid / profile / email — standard OIDC scopes to identify your Microsoft account during sign-in. No Microsoft data beyond identity is accessed at this step.
- User.Read — read-only access to your own basic Microsoft profile (your name, email address, and account identifier) so Eidice can display which mailbox is connected and, if you choose it, sign you in with Microsoft. Eidice reads only your own profile — never your organization's directory or other users' profiles.
- Contacts.Read — read-only access to your own Outlook contacts, used to show the names and photos of people you know in the Eidice Inbox and to import contacts you select as leads. For the Inbox, names, email addresses and photos are read when you open it and about every 15 minutes while it is open, kept only in your browser's memory, and never stored on our servers. It is requested with mail and calendar when you connect Outlook; Microsoft sign-in does not request it.
- offline_access - lets Eidice refresh the Outlook connection without repeatedly asking you to reconnect. Tokens are used only for the Microsoft features you enable.
- Mail.Send - send-only access used to deliver Outlook emails you explicitly generate, approve, or schedule through Eidice. Sent messages are saved to your Outlook Sent Items by Microsoft Graph.
- Mail.ReadWrite - read and write access to your own Outlook mailbox, used only for the Outlook inbox, reply-sync and email signature import features you use in Eidice: fetching mailbox messages, replies, and changed message metadata; marking messages read/unread; moving messages between folders; managing drafts; deleting messages you act on in Eidice; and, when you press Import from my email, reading your recent sent messages once to find your signature. Eidice acts only on your own mailbox — never a mailbox someone else has shared with you — and does not use Microsoft email content to train AI models.
- Calendars.ReadWrite - read and write access to the events on your own Microsoft 365 calendar, used only for the calendar features you enable in Eidice: listing your events, and creating, editing, or deleting events you act on in Eidice. Eidice does not access calendars that others have shared with you, and does not use your calendar data to train AI models.
Scopes we do NOT request: Eidice does not request Mail.ReadWrite.Shared, Calendars.ReadWrite.Shared, Files.Read, Files.ReadWrite, or Microsoft application permissions. If you see a Microsoft consent screen for Eidice requesting a scope outside identity, your own profile, offline access, Mail.Send, Mail.ReadWrite, Calendars.ReadWrite, or Contacts.Read, do not approve it and contact support immediately.
How we use Microsoft data
Microsoft user data is used solely to perform user-initiated actions inside Eidice. Microsoft user data is NEVER used to train AI models, NEVER shared with third parties for marketing, and NEVER sold.
Email signature import. Microsoft does not let apps read an Outlook signature. When you press Import from my email in your email branding, Eidice reads the text of up to 12 of your most recent Sent Items, once, to find the closing lines they share. The result appears in your signature box. Only the signature text is kept, and only if you choose Save; the messages it read are not stored, not sent to an AI provider, and not used for anything else.
Retention & revocation
OAuth tokens are stored server-side in our managed database (Supabase / PostgreSQL), encrypted at rest by the infrastructure layer, and additionally encrypted by Eidice before storage using application-layer token encryption; all transmission uses TLS. When you disconnect Microsoft in Settings → Integrations, all tokens are deleted within 24 hours. You can also revoke access at any time from your Microsoft account permissions page.
9. Landing Page Analytics
We do not load third-party session-recording scripts on the Eidice web origin. Our public marketing pages carry no session replay, no heatmap or click-map recorder, and no third-party analytics tag — on the marketing pages and inside the signed-in application alike.
Marketing-page measurement is limited to the usage analytics described in Section 1, processed only through our own infrastructure. There is no third-party recording to opt out of; the analytics opt-out in Settings → Privacy & Legal still governs our own usage analytics.
Do Not Track. Some browsers send a "Do Not Track" signal. There is no common standard for honoring it, so Eidice does not respond to it — but the answer it asks for is already true here: we run no third-party advertising or analytics trackers on any Eidice page, and no third party collects information about your browsing across other sites through us. The analytics opt-out in Settings → Privacy & Legal governs our own usage analytics.
10. Google User Data
If you connect your Google account, Eidice requests OAuth access to a limited set of scopes. We follow Google API Services User Data Policy and the Limited Use requirements.
Scopes requested
- openid / email — to identify the Google account you connect and bind its verified email address and account ID to your Eidice profile. Google may report the email permission under its equivalent userinfo.email name. We do NOT store your Google password.
- gmail.send (https://www.googleapis.com/auth/gmail.send) — the legacy send-only capability for delivering Gmail messages through Eidice without mailbox access.
- gmail.modify (https://www.googleapis.com/auth/gmail.modify) — requested only when you turn on Gmail Inbox. It authorizes the on-demand mailbox view, the send, label, read/unread, archive, and trash actions available in Eidice, and the email signature import described below. gmail.modify already includes the required mailbox-read capability, so Eidice does not also request the redundant gmail.readonly scope.
- contacts.readonly (https://www.googleapis.com/auth/contacts.readonly) — read-only access to your own Google contacts, used to show the names and photos of people you know in the Eidice Inbox and to import contacts you select as leads. For the Inbox, names, email addresses and photos are read when you open it and about every 15 minutes while it is open, kept only in your browser's memory, and never stored on our servers.
- calendar.events (https://www.googleapis.com/auth/calendar.events) — read, create, update, and delete calendar events. Eidice reads your Google Calendar to display your full schedule inside the app, so agents can see all their appointments in one place. Agents can also create, edit, and delete events through Eidice, which syncs those changes to Google Calendar. Calendar data is used only to display your schedule and manage appointments you create in Eidice — it is never analyzed, shared, or used for any purpose other than showing you your own calendar.
How we use Google data
Gmail Inbox renders mailbox content on demand through a live server proxy and stores none of it. Separately, an inbound message whose sender matches exactly one existing lead is stored durably as that lead's Eidice communication history; an unmatched or ambiguous sender is not stored by Gmail Inbox and never creates a lead. Features you explicitly enable may use that lead conversation for reply capture, cancellation of pending follow-ups, facts capture, notifications, and an opted-in automated reply. When Gmail Inbox is on, Eidice also notices when you send an email from Gmail to one of your existing leads, using only the recipient address and send time from that message, so it can pause that lead's automatic replies as your "after I reply myself" setting says; the message itself is not stored. Inbox Organizer, described below, works differently and does store the mail you select.
Inbox Organizer (optional, and off unless you turn it on)
Inbox Organizer is a separate feature from Gmail Inbox. It is off by default, it only ever runs if you switch it on yourself, and switching it off stops it. When you turn it on you choose which labels or folders it covers and an explicit date range. It never covers your whole mailbox unless you select that.
What it stores, and how this differs from Gmail Inbox. Gmail Inbox only displays mail and stores nothing. Inbox Organizer is different: to read your selected mail it keeps a durable copy of it in your Eidice account — the subject, the message text, and attachments where you allow files to be retained. This includes messages from senders who are not one of your leads. Those are kept and marked “needs review” so you can decide who they belong to. Nothing outside the coverage you selected is stored.
Where it is analysed. Text from your selected messages is sent to OpenAI so Eidice can extract facts, requests and commitments from it. Under OpenAI’s API terms, data sent through their API is not used to train their models; OpenAI may retain it for up to 30 days for abuse monitoring before deleting it. Eidice does not use your mail to train any model, does not share it for marketing, and does not sell it.
Turning it off and deleting. Switching Inbox Organizer off stops all further capture and analysis. Stored messages and files are deleted when you delete the lead they belong to or your account, and you can delete them sooner from your data controls.
Email signature import. When you press Import from my email in your email branding, Eidice reads the signature saved in your Gmail settings. If none is set, it reads the text of up to 12 of your most recently sent messages, once, to find the closing lines they share. The result appears in your signature box. Only the signature text is kept, and only if you choose Save; the messages it read are not stored, not sent to an AI provider, and not used for anything else.
Google user data is used only to provide capabilities you turn on, such as sending an email, displaying your live mailbox, capturing an existing lead's reply, pausing a lead's automatic replies when you reply from Gmail, importing a contact you selected, importing your email signature when you ask, or managing a calendar event. Google user data is never used to train Eidice's or any provider's AI models, never shared with third parties for marketing, and never sold. Where a feature you enabled sends content to an AI provider for analysis, that is stated in the section for that feature.
Retention & revocation
OAuth tokens are stored server-side in our managed database (Supabase / PostgreSQL), encrypted at rest by the infrastructure layer, and additionally encrypted by Eidice before storage using application-layer token encryption; all transmission uses TLS. Tokens are tied to your Eidice account and only readable by server processes serving the Google capabilities you enabled.
Gmail Inbox off stops Gmail's live mailbox view, watch, and lead-reply capture while leaving the shared Google grant available for Google Calendar and Contacts. Disconnect Google removes Eidice's local token and sync authority for the shared grant, so Gmail, Calendar, and Contacts all disconnect; Eidice also attempts to revoke the grant at Google and reports if that upstream confirmation is unavailable. You can revoke it directly from your Google account permissions page.
Messages already captured for an existing lead remain in Eidice as CRM communication history after Gmail Inbox off or Google disconnect and are deleted with the associated lead or account. Imported contacts and calendar records you created in Eidice also remain after disconnect. Messages sent through Gmail remain in your Gmail Sent folder under Google's normal retention.
Eidice's use of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements. We do not transfer Google user data to other parties except as necessary to provide the Service, to comply with applicable law, or as part of a merger, acquisition, or sale of assets with your prior notice.
11. CCPA — Your California Privacy Rights
California residents have the following rights under the California Consumer Privacy Act (CCPA), as amended by CPRA, and the California Generative AI Training Data Transparency Act (AB-2255):
- Right to Know — Request disclosure of personal information collected, used, and shared in the prior 12 months.
- Right to Delete — Request deletion of your personal information. Use "Delete My Data" in Settings → Data or visit Eidice Account Deletion. We respond to verifiable CCPA deletion requests within 45 days (extendable by 45 more if reasonably necessary, with notice). After your request is verified and approved, active account and lead data is purged within 30 days unless a legal-retention exception applies.
- Right to Correct — Request correction of inaccurate personal information.
- Right to Opt-Out of Sale or Sharing — Eidice does NOT sell or share personal information for cross-context behavioral advertising. There is nothing to opt out of, but the right is preserved.
- Right to Limit Use of Sensitive Personal Information — California law treats the contents of email and text messages, where we are not the intended recipient, as sensitive personal information. Eidice holds message contents for one reason: to show you your own conversations with your leads and to do the work you ask for on them. We do not use them to infer anything about you, we do not use them for advertising, and we do not sell or share them. Because we use sensitive personal information only for those permitted purposes under 11 CCR §7027, there is no separate "limit" mechanism to expose — but you may still write to us at the address in Section 11.5 to confirm this, and you may delete any message at any time in the app.
- Right to Non-Discrimination — We will not discriminate against you for exercising any CCPA right.
- Right to Data Portability — Use the Contacts (CSV) or Data export (JSON) download in Settings → Data. The JSON export is read from our servers and covers your profile, leads, messages, call records, sequences, saved posts, listings you entered, memories you entered or confirmed, settings, email-scanning items, held inbound mail, consent and opt-out records, and usage history. Some system, security and unconfirmed AI-generated records and fields are left out; the file lists exactly what it contains, and the app tells you when a copy is incomplete. For anything the file does not contain, email us at the address in Section 11.5 and we will send it to you within the same 45 days. AI-generated intelligence (relationship memories, client personas, emotional arc, communication DNA, win patterns, conversion probability, referral readiness) is excluded under the CCPA service-data carve-out. This is the operational mechanism for both the Right to Know and Right to Data Portability.
To exercise these rights, use the in-app features in Settings → Data, visit Eidice Account Deletion, or contact zacholiver@oliverlabsllc.com. We will respond within 45 days. We will verify your identity before processing requests.
11.1 Categories of personal information collected (CCPA §1798.110(c))
In the prior twelve months, Eidice has collected the following categories of personal information about California consumers. The list maps to the categories enumerated in CCPA §1798.140:
- Identifiers — name, email address, phone number, postal address, DRE license number, CRMLS member ID, IP address, browser cookie identifiers, OAuth user identifiers.
- Customer records information — payment method on file (last 4 digits + brand only; full card details held by Stripe), account billing address, Stripe customer ID.
- Commercial information — subscription tier, transaction history with Eidice, lead-import volume, AI-feature usage, signed consent attestation records (lead import + mass-text + CRMLS verification).
- Internet or other electronic network activity — pages visited within the Eidice app, click stream within Settings, AI prompt invocations, error events, login devices and sessions.
- Geolocation data — IP-derived approximate location only (city/state); no GPS or precise device location.
- Professional or employment-related information — brokerage affiliation, agent biography, and license state.
- Inferences drawn from other information — AI-generated lead intelligence (relationship memories, client personas, communication DNA, conversion probability, decay risk). These inferences are excluded from CCPA portability under the service-data carve-out, but you may request their deletion alongside the underlying lead via Settings → Data → Delete My Data.
- Sensitive personal information — the contents of the email and text messages in your CRM, including messages from your leads, and the recordings and transcripts of calls your agent chose to record. Used only to operate the features you turn on, as described in Section 11 above.
Eidice does NOT collect: biometric identifiers (no fingerprints, retina, facial recognition, or voiceprint identifiers), precise geolocation, race, religion, sexual orientation, immigration status, or union membership.
11.2 Sources of personal information (CCPA §1798.100(b))
Personal information is collected from: (a) you directly, when you sign up, enter agent profile data, import leads, send messages, configure integrations, or interact with Eidice features; (b) lead-source integrations you authorize (CRM imports from FUB / kvCORE / BoldTrail / Lofty / CINC / Real Geeks / BoomTown / Sierra / Chime / Zapier / Make / n8n / lead-gen vendors); (c) OAuth providers you connect (Google for Gmail/Contacts/Calendar; Microsoft for Contacts); (d) public real estate data feeds (CRMLS Trestle Member resource for license/office verification; CoreLogic Trestle MLS listings); (e) browser-derived data (IP for geolocation, cookies for session continuity).
11.3 Business and commercial purposes for collection (CCPA §1798.100(b))
Personal information is collected and used for the following purposes: (a) providing the Eidice Service (lead management, AI-assisted messaging, MLS integration, Chrome extension); (b) account creation, authentication, billing, and subscription management; (c) sending transactional emails (receipts, password resets, system notifications) and approved outbound messages (SMS / email / voice / browser-call) to your leads; (d) AI-driven personalization of drafts, summaries, and recommendations; (e) security, fraud prevention, abuse detection, and rate-limiting; (f) compliance with TCPA (SMS consent + opt-out tracking), CCPA (data subject request fulfillment), DRE §10140.6 (license disclosure on first contact), Fair Housing (protected-class proxy scrubbing); (g) product analytics and quality improvement (aggregate or de-identified where feasible); (h) communicating with you about service changes, Eidice updates, and product offerings (you may opt out of non-transactional emails).
11.4 Right to opt-out of sale or sharing — clarification (CCPA §1798.120)
Eidice does NOT sell personal information to third parties for monetary or other valuable consideration. Eidice does NOT share personal information for cross-context behavioral advertising. We do not display third-party advertising in the Eidice app, and we do not provide data to ad networks. The "Do Not Sell or Share My Personal Information" right under §1798.120 is structurally preserved: because no sale or sharing occurs, there is no opt-out mechanism to expose, but you may still confirm this posture by emailing zacholiver@oliverlabsllc.com.
11.5 Verifiable consumer request methods (CCPA §1798.130(a)(1))
You may submit a verifiable consumer request by either of two designated methods:
- In-app (preferred) — Settings → Data exposes Right-to-Know (Data export as JSON), Right-to-Delete (Delete My Data with multi-step confirm), Right-to-Correct (edit Profile / Lead / Listing data directly), Right-to-Data-Portability (Contacts as CSV or Data export as JSON).
- Email — send a request from your account-of-record email address to zacholiver@oliverlabsllc.com. Include the right you're exercising and any clarifying details. We will respond within 45 days (extendable by 45 more if reasonably necessary, with notice).
We confirm we have received your request within ten business days and tell you how we will handle it. We then respond substantively within 45 days, extendable by 45 more if reasonably necessary, with notice to you.
We verify your identity before processing any request that returns or alters data. For account-holders, verification is satisfied by requesting from the account-of-record email; non-account-holders may need to provide additional identifying information. We will not discriminate against you for exercising any CCPA right.
11.6 Authorized agents
You may name someone to submit a request for you. Send the request from your own account-of-record email confirming who is acting for you, or have your agent send us written permission signed by you. We will still verify your identity directly before we return or delete anything, and we may ask you to confirm with us that you gave the permission.
11.7 If you gave your details to a real estate agent
Real estate agents use Eidice to run their public pages and forms, such as an open-house sign-in, a home-value estimate or a market report. If you filled one in, this section is for you.
- What is collected — what you enter on the form (usually your name, email address and phone number, plus the form's own questions, such as the home you visited, your home's address or your quiz answers), and your device's IP address, which is used to prevent abuse and, for an open-house sign-in or a form where you give permission to receive texts, kept with the record of that sign-in or permission (on a text sign-up page, together with your browser details). Each form tells you what it collects.
- Who receives it — the agent whose page it is. The agent decides how to use it, for example to follow up with you about real estate services. Eidice stores and processes it for that agent as their service provider, and does not use it for its own marketing or advertising.
- Service providers — to run the service for the agent, your details may pass through the processors listed in Section 13, such as our database host, the email and text-message providers that deliver the agent's messages to you, the AI provider that helps the agent prepare results and draft messages, and Trestle IQ, which the agent may use to check a phone number or contact details.
- No sale — Eidice does not sell your information or share it for cross-context behavioral advertising, and our Terms of Service require the agent not to sell the information collected through these pages or share it for that kind of advertising.
- How long it is kept — until the agent deletes it, closes their account, or you ask them to delete it. If you gave or withdrew permission to receive texts, that record is kept for at least 7 years (Section 15).
- Your California rights — you may ask to know what personal information is held about you, to correct it, or to delete it, and you will not be treated differently for asking. Make your request to the agent, using the contact details on their page. If you cannot reach them, write to zacholiver@oliverlabsllc.com naming the agent, and we will pass your request to them and help them answer it. To stop texts, reply STOP; to stop marketing email, use the unsubscribe link in it.
12. CRMLS & MLS Data Redistribution
Eidice integrates MLS data through CoreLogic Trestle and similar approved syndication APIs under MLS-data-display licenses. MLS listing content (photos, descriptions, prices, status, agent attribution) is shown only to authenticated Eidice users who have a verified MLS membership for the originating MLS. We do not redistribute MLS data to non-members or to third parties.
MLS listing data is NEVER used to train AI models. AI features that summarize or surface MLS data operate on the data only at request time and do not persist a derivative training corpus.
Per CRMLS Photo Policy effective 2026-02-18, listing photos are filtered by status: Active and Pending listings show full photo sets; Sold, Withdrawn, Expired, and Closed listings show a status-conditional reduced set per the policy. Coming Soon listings respect the syndication windows defined by each MLS.
13. Third-Party Services & Vendor Data Processors
Eidice uses the following processors. We share only the minimum data necessary for each processor to function. None of these processors is permitted to use your data for marketing.
- Supabase — Cloud database (PostgreSQL) with row-level security. Stores your account, leads, communication history. Encrypted at rest.
- Stripe — Payment processing. Stripe receives card details directly; Eidice never sees full card numbers.
- SendGrid (Twilio) — Platform email delivery: system emails (password resets, receipts) and agent-to-lead email sent through an Eidice sending identity rather than a connected mailbox.
- Twilio — SMS and voice delivery. Receives phone numbers and message content only for the messages you approve.
- OpenAI — GPT API for AI inference (drafting, classification, enrichment), and transcription of call recordings your agent chose to record. Per the OpenAI API data usage policy, data submitted via the API is not used to train OpenAI's models. Eidice does not send your data to any other AI provider except Decor8 AI (below), used only for AI listing-photo staging when that feature is turned on; if you connect your own AI assistant under Section 13.1, that assistant reads your CRM under your own account with that provider, not through ours.
- ATTOM Data / Estated — Property records used for valuations and CMAs. Receives the property address being looked up; it does not receive lead names, phone numbers, or message content.
- OpenSRS (Tucows) — Domain registration, when you buy an agent-site domain through Eidice. Receives the registrant details a domain registry requires by ICANN rule.
- CoreLogic Trestle / CRMLS — MLS data feeds. Subject to the redistribution constraints in Section 12.
- Google — OAuth identity, Gmail send, Contacts read, Calendar events. Subject to scope and use limits in Section 10.
- Microsoft — OAuth identity (openid/profile/email), User.Read for your own basic profile, offline access for token refresh, Mail.Send and Mail.ReadWrite for enabled Outlook email and inbox features (your own mailbox only), Calendars.ReadWrite for enabled calendar features (your own calendar only), and Contacts.Read to show your contacts' names in the Inbox and for contact import. No shared-mailbox, shared-calendar, file, or application-permission access. Subject to scope and use limits in Section 8.
- Vercel — Hosting and serverless functions. No customer data persisted at edge.
- Cloudflare — Turnstile, the "are you human?" check shown on sign-up, sign-in, and password reset. Receives the challenge token and connection metadata for that request only; it does not receive your leads or message content.
- Microsoft Azure Maps — Address lookup and map display inside the app. Receives the address or map coordinates being looked up; it does not receive lead names, phone numbers, or message content.
- Mapbox — Address geocoding and autocomplete for the CMA and listing tools, used first when configured. Receives the address text you type; it does not receive lead names, phone numbers, or message content.
- U.S. Census Geocoder — Address geocoding fallback when Mapbox is unconfigured, over its daily budget, or unavailable. A free U.S. government service; receives the address text you type.
- OpenFreeMap — Map tiles for the CMA and listing map display. Receives the viewer's IP address and the map area being viewed; no API key or account is used.
- Lob — Off by default today; no Eidice deployment sends mail through it yet. If turned on, would receive a lead's name and mailing address for each direct-mail piece sent.
- Decor8 AI — Off by default today. If turned on, would receive the listing photo being staged, for AI-generated listing-photo staging.
- Trestle IQ — Contact enrichment. When Eidice looks up a lead's contact details, automatically for some new leads from a connected lead source or when you ask, Trestle IQ receives, depending on the lookup, the lead's phone number, name, email address or property address, and returns phone-line and contact details. It does not receive message content.
- Zillow (Bridge Interactive) — Off by default today. If turned on, would receive the property address being looked up, to return a Zillow home-value estimate.
13.1 AI Assistant Connections You Turn On (Anthropic / Claude)
Eidice offers an optional connection that lets you use your own AI assistant account — currently Anthropic's Claude — to work your pipeline. This connection is off unless you turn it on, and turning it on requires you to approve, on a consent screen, exactly what the assistant may do.
When you connect it, your CRM information — including your leads' names, phone numbers, email addresses, notes, and your message and call history with them — becomes readable by the AI assistant provider you connected, under your own account and your own agreement with that provider. Their privacy policy and terms govern what they do with it; ours do not. Oliver Labs LLC does not pay for, read, or store what your assistant does with that information, and is not a party to your account with that provider. You choose the permissions separately — reading your CRM, and writing drafts that wait for your approval — and you can approve one without the other.
A connected assistant can never send a text message, an email, or place a call; never book, move, or cancel an appointment; never delete anything; and never reach any account other than yours. Every draft it writes waits in your approval queue for you to send.
We keep a record of every request your assistant makes on your behalf — which tool it used, when, and how many records were returned. We do not store the contents of those requests. You can read this record, and disconnect the assistant, at any time in Settings > Integrations; disconnecting stops all access immediately. If you are a California resident, this record is part of what you may request under Section 11.
14. Data Storage & Security
Lead data stored in Supabase (PostgreSQL) with row-level security policies. Local device caching via localStorage. API keys and credentials stored server-side only. HTTPS / TLS encryption on all data transmission. Rate limiting on sensitive endpoints. 30-day session timeout. Prompt injection sanitization on all user-provided data before AI processing. A baseline Content Security Policy is enforced for frame-ancestors, object-src, base-uri, and per-route source allowlists for scripts, styles, fonts, images, connections, media, and frames; a stricter site-wide policy is being validated through Report-Only telemetry before enforcement, and CSP violation reporting remains wired for monitoring.
If there is a breach. If we discover that unencrypted personal information has been acquired by an unauthorized person, we will notify the affected users without unreasonable delay, in the form and with the contents required by California Civil Code §1798.82. Where a single incident affects more than 500 California residents, we will also submit a sample notice to the California Attorney General. We will tell you what was taken, when it happened, what we have done about it, and how to reach us.
15. Data Retention & Deletion
We keep each category of information for the period below, or for as long as we need it for the purpose it was collected, whichever is shorter. Where a category has no fixed period, we keep it while your account is active and delete it when your account is deleted.
- Account and profile information — while your account is active; deleted on account deletion.
- Lead and contact data, and your message history with a lead — while your account is active; deleted when you delete the lead, and on account deletion.
- AI-generated lead intelligence — for as long as the associated lead exists; deleted with it.
- Call recordings made through the phone line — held in your account for 90 days, then deleted automatically. A copy is also held by our telephony provider under their terms (Section 4.1).
- Call transcripts and summaries — kept for as long as the call's lead exists; deleted with the lead.
- Audio you record in your browser — synced to your account and capped at your most recent 200 recordings; no automatic purge, and removed when your account is deleted.
- Files retained from an import — 30 days from the import, then deleted automatically.
- Lead quality-assurance records — identifying detail is removed at 30 days and the record is deleted at 180 days.
- Demo bookings that never became an account — 90 days, then deleted automatically.
- Inbox Organizer copies and retained attachments — until you delete the lead they belong to, until you delete them from your data controls, or on account deletion, whichever is first.
- Usage analytics — individual usage events are deleted automatically 400 days after they are recorded, and on account deletion.
- Email open and click records — records linked to a lead are deleted when you delete that lead; all of them are deleted on account deletion.
- Referral Program Records — kept for 3 years after a reward's final decision, including after you delete your account, because they are needed to detect repeat fraud; after that they are deleted.
- Diagnostic and error telemetry — deleted automatically 90 days after it is recorded, and on account deletion.
- Inbound email held for review — while your account is active, and deleted when your account is deleted. We do not yet run a fixed clock on it, and we will state the period here when we do rather than state one we are not keeping.
- Security and access logs — kept for our security records and not tied to your account after deletion; sign-in attempt records are deleted automatically after 90 days, and admin security events after 400 days.
- Billing and tax records — as long as tax and accounting law requires.
- SMS consent records — as described below.
- MLS display license records — if you applied to show MLS listings on your own website: your CRMLS member ID, the brokerage you named, the name you signed the display attestation with and when you signed it, the dates and status of that permission, copies and digests of the CRMLS form and approval, and a log of each step, filed under your account's internal ID, and your name, office and website address as listed in the monthly registered-websites report we prepare for CRMLS. We keep these after your account is deleted, because our MLS data license lets the MLS audit which websites were allowed to display its listings, and when. We keep them for as long as that audit right lasts.
CCPA deletion requests follow the 45-day response period described in Section 11. After a verified account-deletion request is approved, active account and lead data is purged within 30 days unless a legal-retention exception applies. Deleting a lead permanently removes it, its communication history and the AI-generated data about it, except the do-not-contact and consent records described below, which we keep so that deleting a lead never lets anyone contact a person who asked us to stop.
TCPA Consent Records: Each permission to text a phone number that is recorded by hand on a lead, given by replying to a text, or given on a texting opt-in page (the phone number, when and how permission was given, and the evidence recorded with it, including the opt-in language for written permission), and each opt-out Eidice records (a STOP reply, an unsubscribe, or a request to stop in a reply), are retained for a minimum of 7 years, even after the lead is deleted and even after account deletion, as required for TCPA compliance and potential litigation defense. We also retain, for at least 7 years from the date of the record and even after account deletion, each consent attestation an agent signs (their name, the operation, the recipient count, the time, and the IP address it came from).
16. Browser Extension
Eidice does not currently publish a browser extension. There is nothing to install, and no extension collects anything from you today. A browser extension has been built but has not been submitted to or listed on any browser store.
If we publish one, this section will describe — before it ships, not after — exactly which sites it runs on, what it reads on each of them, what it sends to your Eidice account, and what it never touches. Until then, treat any browser extension claiming to be Eidice as not ours.
17. Children's Privacy
Eidice is not intended for use by individuals under 18. We do not knowingly collect personal information from children.
18. Changes & Contact
We may update this Privacy Policy from time to time. When we do, we will post the updated policy on this page and change the "Last updated" date at the top. Oliver Labs LLC Address: 220 S Prospect Ave #12, Redondo Beach, CA 90277 Email: support@eidice.com Website: https://eidicecrm.com