Privacy Policy
How Brass Ridge LLC handles personal information in the HearthDraft web app, mobile app, API and client-facing share pages.
Effective September 6, 2026. Brass Ridge LLC · [email protected]
This Privacy Policy explains how Brass Ridge LLC ("Brass Ridge", "we", "us") collects, uses and shares personal information when you use HearthDraft — the web application at hearthdraft.com, the HearthDraft mobile app, the HearthDraft API and the client-facing pages that agents share from it (together, the "Services").
It covers two kinds of people: the real estate professionals and brokerages that hold an account ("Customers"), and the buyers, sellers and other individuals whose information Customers enter into HearthDraft or who submit information through a page a Customer shares with them ("Clients"). Where a Customer enters or collects Client information, the Customer decides why it is collected and how it is used; Brass Ridge processes it on the Customer's instructions under its agreement with that Customer. If you are a Client, contact the agent or brokerage you are working with for questions about how they use your information. This policy describes what Brass Ridge does with it.
What we collect and why
We collect only what the Services need in order to work, to be billed and to be kept secure. Nothing below is collected for advertising, and we do not sell personal information.
- Identity and access. When a Customer signs up we receive a name, an email address and, if they sign in with Google, the identifiers Google provides. Sign-in is handled by our authentication provider, Clerk; we never see a password. A Customer's organization membership and role also come from that provider so that we can show the right workspace.
- Billing information. Subscriptions are paid through Stripe's hosted checkout and customer portal. Card numbers are entered on Stripe's pages and never reach our systems. We receive a customer identifier, the plan, the subscription status and billing contact details so that we can provide the Services and answer billing questions.
- Product interactions. The content a Customer creates or imports in HearthDraft — their business profile and writing voice, Client records, notes, listing and comparable data, and the documents and messages HearthDraft drafts for them — is stored so that the Customer can review, edit, send and retrieve it. We also keep an audit trail of compliance reviews and overrides, because fair-housing screening is only useful if it can be audited.
- Client information. Customers enter Client names, contact details, preferences and transaction details, and Clients may submit the same kinds of information — for example a buyer questionnaire, a budget range or contact details — through a page a Customer shares with them. This is the Customer's data; we process it to produce the Customer's work product.
- General geolocation data. When a Customer enters an address or a target area, we send coordinates and the anchor address to our mapping provider to produce commute estimates and area maps. We also derive an approximate location from IP addresses for security, rate limiting and aggregate analytics. We do not track the precise location of any device, and the mobile app requests no location permission.
- Website interactions. Our servers and edge network log requests — IP address, user agent, pages requested and timestamps — to keep the Services running and to detect abuse. We use a product-analytics tool to understand which features are used; those events carry event names and account identifiers only, never Client personal information.
- Anti-bot assessments. Traffic passes through Cloudflare, which may challenge requests that look automated using signals such as IP reputation and browser characteristics.
- Advertising and cookies. We use only the cookies needed to keep you signed in, to protect against request forgery and to remember your preferences. We do not run advertising or tracking cookies and we do not participate in cross-site behavioral advertising.
- Voluntary correspondence. If you email us or contact support, we keep that correspondence and the address you sent it from so that we can respond and keep a record of what was agreed.
- Mobile app permissions. The HearthDraft mobile app requests network access only. It does not request access to your contacts, camera, microphone, photos or location.
When we access or disclose your information
We do not sell personal information and we do not share it with third parties for their own marketing. We access or disclose information only in these situations:
- To provide the Services. Our subprocessors, listed in the next section, process information on our behalf under contracts that limit them to that purpose — for example, our AI provider generates drafts from redacted inputs and our mapping provider returns commute estimates.
- To support you. Brass Ridge staff may look at a Customer's account when the Customer asks for help or when we need to investigate an error or an abuse report. Access is limited to what the task needs and is logged.
- When the law requires it. We will disclose information to comply with a subpoena, court order or other valid legal process. We will notify the affected Customer unless the law prohibits it or the request involves an emergency.
- To protect people and the Services. We may disclose information if we believe it is necessary to prevent fraud, abuse, a security incident or harm to a person, or to enforce our Terms of Service.
- In a business transfer. If Brass Ridge LLC is acquired, merges, or sells the HearthDraft business, information will transfer with it. The acquirer will be bound by this policy for that information until the policy is updated with notice.
Client information is disclosed to the Customer who collected it and to the members of that Customer's organization, as the Customer configures.
Subprocessors
The companies below process personal information on our behalf so that HearthDraft can run. Each is bound by a data-processing agreement or service terms that restrict it to the purpose shown and require appropriate security. Our AI provider is contractually prohibited from using the inputs we send it to train its models, and we redact financial account numbers, government identifiers and document metadata before anything is sent to it.
We will update this list at least 15 days before a new subprocessor begins processing Client personal information, except where an urgent replacement is needed to keep the Services secure or available, in which case we will update it as soon as practicable. A Customer who objects to a new subprocessor on reasonable data-protection grounds may cancel the affected subscription before the change takes effect.
| Subprocessor | What it does | Data it can see |
|---|---|---|
| OpenAI, L.L.C. | AI text generation (backend-only, through the gateway) |
|
| Clerk, Inc. | Authentication and organization membership |
|
| Mapbox, Inc. | Commute estimates and static area maps |
|
| Stripe, Inc. | Subscription billing: hosted Checkout, the Customer Portal and invoices |
|
| Cloudflare, Inc. | Domain registrar, DNS, edge network and the tunnel that terminates traffic: TLS termination, DDoS and bot protection; object storage (R2) for rendered exports when configured |
|
| Functional Software, Inc. (Sentry) | Error monitoring for the API, the worker and the web app |
|
| PostHog, Inc. | Product analytics events |
|
Reviewed and not disclosed
- Hosting — self-hosted — Runs the API, the database and default object storageHosting is self-hosted: the API, the database and default object storage run on infrastructure Brass Ridge LLC operates, so there is no hosting subprocessor to disclose. Cloudflare, which terminates traffic in front of it, is listed above.
This list and our internal vendor review are produced from the same record, so the two cannot disagree. We update it whenever a subprocessor is added, replaced or removed.
Your rights with respect to your information
Wherever you live, you can ask us to tell you what personal information we hold about you, to correct it, to delete it, to export it in a portable format, or to stop a particular use of it. Customers can do most of this themselves inside HearthDraft, including deleting Client records and exporting their work. Clients should send requests to the agent or brokerage they are working with, because that Customer controls the purpose of the collection; if you contact us directly we will forward the request to the Customer and help them honor it.
To exercise a right, email [email protected]. We will verify that a request comes from the person it concerns, or from someone authorized to act for them, and respond within 30 days or within the shorter period a law requires. We will not treat you differently for exercising a right.
California residents. Under the California Consumer Privacy Act, the categories of personal information we collect are identifiers, contact and professional information, commercial information about subscriptions, internet activity such as request logs, approximate geolocation derived from IP addresses, and the content Customers and Clients put into the Services. We collect it for the purposes described on this page, retain it as described under Data retention, and disclose it only to the subprocessors and in the circumstances listed on this page. We do not sell personal information, we do not share it for cross-context behavioral advertising, and we have not done either in the preceding 12 months. You may designate an authorized agent to make a request for you; we will ask the agent for proof of authorization.
Other U.S. states. Residents of states with comprehensive privacy laws have similar rights of access, correction, deletion, portability and opt-out, and a right to appeal a decision we make about a request by replying to our response. We handle those requests the same way.
How we secure your data
All traffic between your device and HearthDraft is encrypted in transit. Data at rest, including backups, is encrypted. Production systems are reached only through an authenticated edge tunnel — there are no inbound ports open to the public internet — and administrative access requires a key held by named Brass Ridge personnel; there are no shared passwords. Every request that reads or writes a Customer's data is authorized against a signature-verified session token that carries the user's identity, organization and role; nothing in a request can assert any of those. Rendered documents are served from expiring signed links. Compliance decisions and administrative actions are written to an audit log that cannot be edited.
Links that agents share with Clients contain a random token that is the only credential needed to open them. Anyone holding the link can open it, so Customers should share links only with the intended Client and can revoke a link at any time.
No system is perfectly secure. If we learn of a breach that affects your personal information we will notify affected Customers without undue delay and, where the law requires it, the affected individuals and regulators.
What happens when you delete content in your product accounts
When a Customer deletes a record in HearthDraft — a Client, a document, a note — it is removed from the live database immediately and is no longer accessible in the Services. Compliance audit entries that reference the deleted record are retained, because they are the record of a review that happened, but they contain the decision and the reason rather than the content that was reviewed. Deleted content persists in encrypted backups until those backups age out of rotation, after which it is gone.
When a Customer closes their account we delete the organization's content on the same basis after a 30-day window in which the Customer can export it or reactivate.
Data retention
We keep personal information for as long as a Customer's account is active and for as long as it is needed for the purposes described in this policy. After an account closes we keep what we are required to keep — billing records for tax and accounting purposes, and compliance audit logs for the period that fair-housing and real-estate licensing rules require — and delete the rest.
Retention periods for particular record types are set by a Customer's obligations as a licensed professional as much as by ours. A Customer can shorten retention for their own content at any time by deleting it. Server request logs are kept for a short, rolling period for security and are then discarded.
Location of site and data
HearthDraft is operated from the United States, and personal information is stored and processed in the United States. Our subprocessors may process data in other countries; each is bound to protect it to the standard described in this policy wherever it operates. By using the Services you agree that your information will be transferred to and processed in the United States, where privacy law may differ from the law where you live.
When transferring personal data from the EU
HearthDraft is built for real estate professionals working in the United States and is not offered to persons in the European Economic Area, the United Kingdom or Switzerland. We do not intentionally collect personal information from residents of those regions.
If a Customer enters information about a Client located there, the Customer is responsible for having a lawful basis and a valid transfer mechanism for doing so. On request we will enter into the European Commission's Standard Contractual Clauses with the Customer to cover that transfer, and we will honor the rights that apply to it.
Changes and questions
We may update this policy as the Services change or as the law requires. The effective date at the top of the page is the date of the current version. For a material change that reduces your rights or expands how we use personal information, we will notify Customers by email or an in-app notice at least 14 days before it takes effect; continuing to use the Services after that date means you accept the updated policy.
Questions, requests and complaints go to [email protected], or by mail to Brass Ridge LLC, Attn: Privacy, at the address we provide on request. We will do our best to resolve any concern directly with you.
Section outline adapted from the Basecamp open-source policies / CC BY 4.0. Source: https://github.com/basecamp/policies/blob/master/privacy/index.md (retrieved 2026-09-03; that repository is archived and the maintained versions are at https://37signals.com/policies). Licensed under CC BY 4.0. Only the section outline is reproduced; the wording on this page is Brass Ridge LLC's own.