ClosingDay
PRIVACY POLICY
What we collect. What we do with it.
ClosingDay handles real-estate transaction data — contracts, contacts, deadlines, communications. This page is the precise version of how that information is collected, used, shared, and protected. Plain-language summary up top, the formal sections beneath.
Last updated: August 10, 2026. Privacy questions: privacy@getclosingday.ai.
The short version
We do not sell your data and we do not share it for advertising.
Your contracts, emails, and communications are not used to train any AI model — ours or our providers'.
By default, drafts do not send themselves — every AI-generated email waits for your approval. If you turn on auto-send, only your own saved templates going to outside parties send automatically, after a cancel window you control.
When you connect Gmail we ask for `gmail.send` only — we cannot read your inbox. Calendar Sync is opt-in and only writes ClosingDay-generated events to sub-calendars we create.
Deleting your account removes every transaction, file, and audit row that belongs to you.
1. Who we are
ClosingDay is an AI-first all-in-one workspace for real-estate deals — listings, private showings, open houses, offer management, seller portal, and the full contract-to-close transaction record — used by real-estate agents and transaction coordinators (TCs). This Privacy Policy describes what personal information we collect when you use ClosingDay, how we use it, who we share it with, and the controls available to you. By creating an account or using the service, you agree to this Policy.
2. Information we collect from you
Account details — name, email address, phone (if provided), brokerage / team name, real-estate license number, state, role (agent or transaction coordinator), and an optional avatar / headshot.
Authentication — a hashed password (bcrypt), and if you sign in with Google, the Google account ID associated with your email. We never receive or store your Google password.
Email integration credentials — when you connect Gmail, we store an OAuth refresh token; when you connect via SMTP, we store your SMTP host/port/username/password. SMTP passwords and OAuth refresh tokens are encrypted at rest with a per-deployment key.
Listing data — property addresses, target listing dates, marketing checklist entries, vendor assignments, photo uploads, and any custom tasks you add to the prep plan.
Showing data — date, time, buyer-agent and brokerage you record for each private showing; feedback collected from buyer agents via the no-login follow-up form (rating, pros/cons, free-text comments). Showings flagged as "seller-visible" appear in the seller portal; the rest stay internal.
Open-house data — events you schedule, plus the visitor sign-in submissions through the QR code (name, email, agent association, optional feedback ratings + comments). Visitors are told at sign-in that the agent will see their information.
Offer data — submissions through the public offer-submission link (/o/<slug>): buyer-agent contact details, buyer names, price, financing terms, contingencies, dates, the uploaded purchase agreement PDF, and any documents or notes the buyer agent attaches. The buyer agent receives a private token-authed revise/withdraw link by email.
Seller-portal share data — magic-link tokens you generate for sellers (no login required for them), the listing identifier they grant access to, expiry time, revocation status, and a view count.
Transaction data — property addresses, contract dates, parties, contacts (name, email, phone, brokerage), tasks, deadlines, vendor assignments, and uploaded files (executed contracts, inspection reports, property photos, headshots, other supporting documents).
Communications data — emails ClosingDay sends on your behalf are recorded in the relevant transaction or listing's communication log (sender, recipient, subject, body, timestamp). We do not read your inbox.
AI-derived data — checklists, deadlines, email drafts, contract / offer extractions, offer-comparison summaries, and tone-profile training samples generated from the data you upload or paste in.
Billing data — Stripe customer + subscription IDs, current period end, subscription status. We do not store your card number — Stripe holds payment details directly.
Audit log — every meaningful action (task status change, document upload, draft sent, deadline adjustment, offer status change, comparison export) is recorded against the user who performed it.
Device & usage data — IP address (transient, used for rate limiting and abuse prevention), browser/device info from your User-Agent header (used in support and audit contexts), and any feedback you submit through the in-app "Share feedback" widget (with an optional screenshot you choose to attach).
3. How we use your information
To run the ClosingDay product — generating checklists, tracking deadlines, drafting follow-up emails, sending those emails on your behalf when you approve them, and showing you a real-time dashboard.
To send essential transactional email (account verification, password resets, team invites, billing receipts) via our email provider Resend.
To improve and debug the product — server logs, error traces, and aggregated usage patterns. We do not target ads.
To bill you — Stripe processes recurring subscription payments; we use it to mirror subscription state into our database so we know when your trial ends and your access status.
To enforce our terms and protect against abuse — fraud, automated scraping, account takeover, and unsolicited bulk email.
To respond to your support requests and feedback.
4. Third-party services we share data with
Anthropic — powers all AI features (contract extraction, draft generation, tone analysis, and Scout, our in-app assistant). Data submitted via Anthropic's API is not used to train their models. We do not opt into any data-sharing program.
Stripe — payment processing and subscription management. They receive your name, email, and payment method when you subscribe. PCI compliance is on Stripe's side; we never see card details.
Google (OAuth, Gmail API, Calendar API) — only if you sign in with Google or connect Gmail. For Gmail we request `gmail.send` only — we cannot read your inbox or existing threads. If you enable Calendar Sync (Settings → Calendar Sync, off by default), we additionally use `https://www.googleapis.com/auth/calendar` to create one sub-calendar per transaction on your Google account and write deadline events (contract execution, EMD, contingencies, closing). We do not read or modify your primary calendar or other calendars, and we do not write any events the application did not generate from your own transaction data. Sign-in uses the standard `openid` / `email` / `profile` scopes.
Resend — sends ClosingDay's system emails (invites, password resets, in-app feedback). Receives the recipient's email and the message body.
Render — our compute and managed Postgres provider. SOC 2 Type 2 compliant, encryption at rest.
Cloudflare — CDN, TLS termination, and object storage for uploaded files.
Mapbox — used only for address autocomplete inside the listing-creation form. Receives the partial address text you type, no account information.
Gravatar — when you have not uploaded an avatar and have not signed in with Google, we probe Gravatar with a SHA-256 hash of your email to see if a public avatar exists. We do not send your raw email address.
RentCast — used to look up property characteristics (year built, square footage, etc.) when you create a listing, given the address you type.
Twilio — delivers SMS / text-message notifications when you have opted in (see section 10). Receives your verified mobile phone number and the message body at the moment of each send. Contractually prohibited from any other use of the data.
We do not sell your information. We do not share it for advertising, profiling, or any purpose unrelated to running ClosingDay.
5. How long we keep your information
Account & customer data — for as long as your account is active, plus a short window after deletion or cancellation while we wind things down.
Audit logs — retained for the lifetime of the related transaction so you can review what happened on a given deal.
Backups — encrypted database backups are retained on a rolling basis (typically 30 days). Deleted records may persist in backups during this window before aging out.
When you delete your account (Settings → Account → Delete account), we cascade-delete every transaction, task, contact, document, draft, communication, share, audit log, listing, cached contract extraction, and uploaded file you own. Files on disk are removed best-effort. The deletion is immediate and not reversible.
The one exception is anonymous operational telemetry — counts of how many contract uploads succeeded or failed, and how long they took. Those records are stripped of your account link, the file name, and the document fingerprint at the moment you delete, leaving nothing that identifies you, your clients, or a property.
6. Your rights and choices
Access & edit — you can view and update your profile, email signature, brokerage, and other account information from Settings.
Disconnect email & calendar — you can revoke ClosingDay's access to Gmail/SMTP at any time from Settings → Email Configuration, and turn off Calendar Sync (or revoke the calendar permission entirely) from Settings → Calendar Sync. Your existing Gmail and Google Calendar data is unaffected; disconnecting also deletes the per-transaction sub-calendars ClosingDay created.
Remove your photo — if you uploaded a headshot, the Remove button reveals your Google profile picture (if signed in with Google) or your initials, in that order.
Delete account — Settings → Account → Delete permanently. Triggers the cascade described in section 5.
Export — for now, export is available on request via privacy@getclosingday.ai. We will respond within 30 days.
If you live in California, see section 7 for your CCPA / CPRA rights and the categorical disclosures that statute requires. If you live in the EU/UK or another jurisdiction with formal data-protection rights (GDPR, similar), the rights above implement those frameworks; email privacy@getclosingday.ai with any access or deletion request that the in-app controls do not cover.
7. California privacy rights (CCPA / CPRA)
If you are a California resident, the California Consumer Privacy Act (CCPA, as amended by the CPRA) gives you specific rights over your personal information. The rights below are additive to the general controls in section 6.
Right to know — the categories of personal information we have collected about you, the sources we collected it from, the business or commercial purposes for collecting it, and the categories of third parties we shared it with. Section 2 of this Policy answers this; the categorical mapping below restates it in CCPA terms.
Right to delete — request deletion of personal information we hold about you. The in-app Settings → Account → Delete account button performs this for active account data; section 5 describes the cascade.
Right to correct — request correction of inaccurate personal information. Most fields are user-editable in Settings; for anything else, email privacy@getclosingday.ai.
Right to data portability — receive a copy of personal information you provided us in a portable, machine-readable format. Email privacy@getclosingday.ai for an export.
Right to limit the use of sensitive personal information — we use sensitive personal information (account credentials, contents of communications) only to provide the ClosingDay service. We do not use it for advertising, profiling, or any disclosed secondary purpose.
Right to opt out of sale or sharing — we do not sell your personal information and do not share it for cross-context behavioral advertising. There is therefore no "Do Not Sell or Share My Personal Information" toggle to action; if our practices ever change, we will provide one before that change takes effect.
Right to non-discrimination — we will not deny service, charge a different price, or provide a different level of quality because you exercised any CCPA right.
Categories of personal information collected in the last 12 months (under Cal. Civ. Code §1798.140): Identifiers (name, email, phone, IP address, account ID); Customer records (license number, brokerage, billing identifiers); Commercial information (subscription plan, Stripe customer/subscription IDs); Internet or network activity (server logs, error traces, audit logs); Geolocation (coarse, derived from IP only — no precise GPS); Professional information (real-estate role, license number, brokerage, team); Sensitive personal information (account credentials and the contents of email and communications you generate through ClosingDay — all encrypted at rest); Inferences (AI-derived artifacts such as drafts, checklists, and contract extractions generated from data you provided).
Sources: directly from you; from your authenticated email integration (Gmail/SMTP, on send only); and from a small number of third-party lookups you initiate (e.g., Mapbox address autocomplete, RentCast property lookup).
Business and commercial purposes: as described in section 3. Categories of third parties: as described in section 4.
How to exercise your rights — email privacy@getclosingday.ai. We verify requests against the email address on file and any account-bound identifiers we already hold. We respond within 45 days; complex requests may extend to 90 days with prior notice. You may designate an authorized agent in writing; we will request reasonable proof of the agent's authority and of your identity before acting.
8. Gramm-Leach-Bliley Act (GLBA)
Real-estate transactions sometimes involve nonpublic personal financial information ("NPI") about consumers — loan amounts, lender contacts, and certain disclosures contained in a purchase agreement. ClosingDay is a software vendor and not itself a "financial institution" under the Gramm-Leach-Bliley Act, but our customers (real-estate agents and transaction coordinators) may upload or generate NPI through the service. This section describes how we treat that data.
Use limitation — we use NPI only to operate the ClosingDay service for the customer who provided it: extracting deal terms from a contract you uploaded, populating the transaction checklist, drafting the emails you approve.
No redisclosure — we do not disclose NPI to nonaffiliated third parties except (a) to the subprocessors named in section 4, each acting on our behalf to deliver the service, (b) as you explicitly direct (e.g., sending a draft to a lender), or (c) as required by law.
No marketing reuse — NPI is never used for advertising, third-party marketing, or to train any AI model — ours or our providers'.
Safeguards — administrative, technical, and physical safeguards aligned with the FTC Safeguards Rule (16 CFR Part 314), including encryption at rest and in transit, role-based access, audit logging of every meaningful action, and an incident-response procedure. Section 9 and the Security page describe these in detail.
Service-provider role — when one of our customers is itself a financial institution (e.g., a settlement provider or mortgage broker), we operate as a service provider to that customer under written agreement and follow that agreement's NPI handling terms. We do not redisclose NPI for any purpose outside the contracted service.
GLBA-specific questions can be sent to privacy@getclosingday.ai.
9. Google API Services — Limited Use
ClosingDay uses certain Google APIs (Google Sign-In, the Gmail API, and the Google Calendar API) when you choose to sign in with Google, connect your Gmail account for sending email, or enable Calendar Sync. This section describes our handling of data received from those APIs, in addition to the broader privacy commitments in sections 2 through 8.
ClosingDay's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy (https://developers.google.com/terms/api-services-user-data-policy), including the Limited Use requirements.
Specifically: we do not transfer Google user data to others except as necessary to provide or improve the ClosingDay service (and only to the subprocessors listed in section 4 of this Policy); we do not use Google user data for advertising, profiling, or credit-decisioning of any kind; we do not allow humans to read your Google user data (we do not view your email content), with the narrow exceptions where you have given us explicit consent, where doing so is necessary for security purposes such as investigating abuse, where doing so is necessary to comply with applicable law, or where the data has been anonymized.
Which Google API scopes we use, and why: (a) `openid email profile` for Google Sign-In — to identify you and create or recognize your ClosingDay account; (b) `https://www.googleapis.com/auth/gmail.send` for Gmail integration — to send emails that you have personally reviewed and approved via the ClosingDay drafts inbox. We do NOT request any Gmail scope that grants read access to your inbox or any other thread or message; (c) `https://www.googleapis.com/auth/calendar` for Calendar Sync — only requested if you turn Calendar Sync ON in Settings (it is OFF by default). We use this scope to create one new sub-calendar per real-estate transaction on your Google account and to write transaction deadline events (contract execution, earnest money due, inspection / loan / appraisal contingencies, final walk-through, closing date) to that sub-calendar. We do not read, modify, or delete events on your primary calendar or any other calendar that ClosingDay did not itself create. We do not list, share, or transfer the calendars we create to anyone other than the agent who connected the account.
Less-permissive Calendar scopes (`calendar.events`, `calendar.readonly`) cannot replace `calendar` because Calendar Sync requires creating new calendar entities (one per transaction, color-coded for visual separation), which is not exposed by the more granular scopes. The full `calendar` scope is the narrowest one Google offers that supports calendar creation.
You can revoke ClosingDay's access to your Google account at any time. From within ClosingDay, use Settings → Email Configuration → Disconnect (this also invalidates calendar access since both share the same OAuth grant), or Settings → Calendar Sync to turn just the calendar feature off. From Google, visit https://myaccount.google.com/permissions and remove ClosingDay from the list of connected apps. Either path immediately invalidates our stored OAuth tokens; we cannot send any further messages or write any further calendar events on your behalf.
Data retention: OAuth refresh tokens are stored encrypted at rest and are kept only for as long as your account is connected. When you disconnect, we delete the token within our regular cleanup cadence. We do not retain copies of the email bodies after the message has been sent — they are stored on the recipient and sender mailboxes per normal email behavior, not in ClosingDay. For Calendar Sync, we store the Google calendar ID and Google event ID for each transaction sub-calendar / event we create so we can keep them in sync with the source-of-truth deadlines stored in ClosingDay; we do not store event bodies, attendee lists, or any other calendar content. When you turn Calendar Sync off or archive a transaction, we delete the corresponding sub-calendar from your Google account.
10. SMS / text-message communications
When you verify a mobile phone number and enable SMS notifications inside ClosingDay (Settings → Notifications), you consent to receive automated text messages from ClosingDay at the number you provided. SMS is strictly opt-in — verifying your number AND enabling notifications are two separate, explicit steps, both reversible at any time.
Categories of messages we may send: (a) one-time verification codes during account signup, sign-in, or sensitive-action confirmation; (b) transactional notifications about activity on your own deals — new offers received on your listings, new showing requests, buyer-agent feedback submissions, open-house visitor sign-ins, task deadline reminders, and overdue task alerts. We do not send marketing, promotional, advertising, or third-party messages over SMS.
Message frequency varies based on how many active listings and transactions you have. A typical active user receives between 0 and 10 messages per day. Message and data rates may apply per your mobile carrier plan; ClosingDay does not charge for SMS.
Mobile information (your phone number and your SMS opt-in status) will not be shared with third parties or affiliates for marketing or promotional purposes. Your phone number is shared only with our SMS delivery subprocessor (Twilio, listed in section 4) for the sole purpose of delivering the messages described above, and only at the moment of each send. Twilio is contractually prohibited from using the data for any other purpose.
Opt-out: reply STOP to any ClosingDay SMS to immediately opt out — Twilio will stop further sends to that number and we will mirror the opt-out in your account settings on the next sync. You can also opt out at any time by disabling SMS notifications in Settings → Notifications, which both invalidates the verified-number status and revokes the consent. Opting out does not cancel your ClosingDay account.
Help: reply HELP to any ClosingDay SMS for a short response with our support contact (support@getclosingday.ai). Consent to receive SMS is not a condition of purchase or of using any other part of the ClosingDay service.
Carrier disclaimer: mobile carriers are not liable for delayed or undelivered messages. ClosingDay is not responsible for messages that fail to deliver due to carrier issues, blocked numbers, ported numbers, or any other condition outside our SMS provider's control.
11. How we secure your data
Encryption at rest with AES-256 (Render Postgres + Cloudflare R2). Encryption in transit with TLS 1.3 — we do not accept plain-HTTP traffic. Sensitive tokens (OAuth refresh tokens, SMTP passwords) are additionally encrypted with a per-deployment key before being written to the database. Sessions use short-lived (15-minute) access tokens with bcrypt-hashed refresh tokens. See the Security page for the full picture, including the roadmap items we are working on.
12. Children
ClosingDay is not intended for or directed at anyone under 18 years old. We do not knowingly collect information from children. If you believe a child has signed up, contact privacy@getclosingday.ai and we will delete the account.
13. International users
ClosingDay is operated from the United States and our infrastructure (Render, Cloudflare, Stripe) is hosted in the U.S. If you use the service from outside the U.S., you understand that your information will be transferred to and processed in the U.S. We rely on standard contractual clauses where applicable to protect cross-border transfers.
14. Changes to this Policy
When we make material changes to this Policy, we will update the "Last updated" date at the top of this page and notify active users by email. Continued use of ClosingDay after a change indicates your acceptance of the revised Policy.
15. Contact us
Questions, concerns, or requests can be sent to privacy@getclosingday.ai. We aim to respond within 5 business days for general inquiries and within 30 days for formal access / deletion / portability requests under CCPA, GDPR, or similar laws.
Built for trust, not surveillance.
Read our Security page for the technical specifics, or reach out to privacy@getclosingday.ai with any question this page does not answer.
ClosingDay
© 2026 CLOSINGDAY · getclosingday.ai. All rights reserved.
Operated by CLOSINGDAY · 3988 Scottfield St, Dublin, CA 94568 · legal@getclosingday.ai