Privacy Policy
Last Updated: April 24, 2026 · Effective: April 24, 2026
1. Introduction
Vocally Yours LLC ("Company," "we," "us," or "our"), operating as Keystir, respects your privacy and is committed to protecting your personal information. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our platform at keystir.com and any associated applications (collectively, the "Service").
This policy is designed to comply with applicable privacy laws across all 50 United States, including the California Consumer Privacy Act as amended by the California Privacy Rights Act (CCPA/CPRA), Virginia Consumer Data Protection Act (VCDPA), Colorado Privacy Act (CPA), Connecticut Data Privacy Act (CTDPA), Utah Consumer Privacy Act (UCPA), Texas Data Privacy and Security Act (TDPSA), Iowa Consumer Data Protection Act (ICDPA), Montana Consumer Data Privacy Act (MTCDPA), Oregon Consumer Data Privacy Act (OCDPA), and other applicable state privacy laws, and the New Jersey Data Privacy Act (NJDPA), effective January 15, 2025.
By using the Service, you agree to the collection and use of information in accordance with this policy. If you do not agree with this policy, please do not access or use the Service.
2. Information We Collect
2.1 Information You Provide Directly
- Account Information: Name, email address, phone number, brokerage name, real estate license number, state of licensure, preferred language, and profile photo.
- Client Data: Information you enter about your real estate clients, including names, contact information, property preferences, transaction details, and notes.
- Transaction Data: Property addresses, listing details, offer terms, closing dates, commission information, and documents you upload or generate through the Service.
- AI Conversation Data: Messages, prompts, and queries you submit to Joey, our AI assistant, including context provided within conversations.
- Paper Import Images: Photographs or scans of physical documents you upload for digitization and processing.
- Payment Information: Billing details processed through LemonSqueezy (we do not directly store payment card numbers).
- Communications: Emails, support requests, and other correspondence you send to us.
2.2 Information Collected Automatically
- Usage Data: Pages viewed, features used, time spent on the Service, click patterns, and navigation paths.
- Device Information: Browser type and version, operating system, device type, screen resolution, and unique device identifiers.
- Log Data: IP address, access times, referring URLs, and error logs.
- Location Data: Approximate geographic location derived from your IP address (we do not collect precise GPS location).
- Cookies and Similar Technologies: Essential authentication cookies and minimal preference data. See our Cookie Policy for details.
2.3 Information from Third Parties
- Authentication Providers: If you sign in via a third-party service, we may receive your name and email address from that provider.
- Weather Data: Location-based weather information from OpenWeatherMap to power local features.
3. How We Use Your Information
We use the information we collect for the following purposes:
- Provide and maintain the Service: Operate your account, process transactions, manage subscriptions, and deliver core platform features.
- AI assistant functionality: Process your conversations with Joey to generate relevant responses and recommendations.
- Communication: Send transactional emails (account verification, password resets, billing receipts), service announcements, and, with your consent, marketing communications.
- Improvement and analytics: Analyze usage patterns to improve features, fix bugs, and enhance user experience.
- Security: Detect, prevent, and address fraud, unauthorized access, and other security issues.
- Legal compliance: Comply with applicable laws, regulations, and legal processes.
- Customer support: Respond to your inquiries and resolve issues.
4. How We Share Your Information
We do NOT sell your personal data. We have not sold personal data in the preceding twelve (12) months and have no plans to do so.
We may share your information in the following limited circumstances:
- Service Providers: With third-party vendors who perform services on our behalf (see Section 5), subject to contractual obligations to protect your data.
- Legal Requirements: When required by law, subpoena, court order, or governmental regulation, or when we believe disclosure is necessary to protect our rights, your safety, or the safety of others.
- Business Transfers: In connection with a merger, acquisition, reorganization, or sale of assets, in which case your data would be transferred to the successor entity.
- With Your Consent: When you explicitly authorize us to share your information with a specific third party.
We do not share your personal information for cross-context behavioral advertising or profiling in furtherance of decisions that produce legal or similarly significant effects.
5. Third-Party Services and Data Processors
We use the following third-party services to operate the platform. Each processes data only as necessary to provide their respective services:
| Provider | Purpose | Data Processed |
|---|---|---|
| Supabase | Database, authentication, file storage | Account data, client data, documents, auth tokens |
| Google (Gemini API) | AI conversational assistant (Joey chat) | Conversation messages, contextual data sent with prompts |
| Anthropic (Claude) | AI document and image processing (Snap & Save) | Uploaded images, document content, extracted data |
| Resend | Transactional email | Email addresses, email content |
| LemonSqueezy | Payment processing | Billing name, email, payment details, subscription status |
| Printful | Print-on-demand fulfillment | Shipping address, order details, design files |
| Vercel | Application hosting | Server logs, IP addresses, request metadata |
| OpenWeatherMap | Weather data | Approximate location (city/ZIP level) |
6. Data Retention
We retain your personal information for as long as your account is active or as needed to provide you with the Service. Specific retention periods include:
- Account data: Retained while your account is active and for 30 days after account deletion to allow for recovery.
- Transaction records: Retained for 7 years to comply with tax and real estate regulatory requirements.
- AI conversation logs: Retained for 90 days for service improvement, then automatically deleted unless you have saved specific conversations.
- Paper import images: Retained for 30 days after processing, then automatically deleted.
- Server logs: Retained for 90 days.
- Billing records: Retained for 7 years as required by tax law.
When data is no longer needed, it is securely deleted or anonymized. You may request earlier deletion subject to legal and regulatory retention requirements.
7. Data Security
We implement industry-standard technical and organizational measures to protect your personal information, including:
- Encryption of data in transit (TLS 1.2+) and at rest (AES-256).
- Row-level security (RLS) in our database ensuring users can only access their own data.
- Passwordless authentication via secure magic links to reduce credential-based attack vectors.
- Regular security audits and vulnerability assessments.
- Access controls limiting employee access to personal data on a need-to-know basis.
- Secure hosting on Vercel and Supabase with SOC 2 Type II compliance.
While we strive to protect your information, no method of electronic transmission or storage is 100% secure. We cannot guarantee absolute security but will promptly notify affected users and relevant authorities in the event of a data breach as required by applicable law.
8. Children's Privacy
The Service is intended solely for users who are at least 18 years of age. We do not knowingly collect personal information from anyone under the age of 18 in compliance with the Children's Online Privacy Protection Act (COPPA). Our platform includes an age verification gate at registration. If we learn that we have inadvertently collected personal information from a user under 18, we will take steps to delete that information as soon as possible. If you believe a child under 18 has provided us with personal information, please contact us at support@keystir.com.
9. Your State Privacy Rights
Depending on your state of residence, you may have specific privacy rights under applicable state law. We are committed to honoring these rights for all users regardless of location. Below is a summary of rights by state.
9.1 California (CCPA/CPRA)
If you are a California resident, the California Consumer Privacy Act as amended by the California Privacy Rights Act grants you the following rights:
- Right to Know: You may request disclosure of the categories and specific pieces of personal information we have collected about you, the categories of sources, the business purposes for collection, and the categories of third parties with whom we share your information.
- Right to Delete: You may request deletion of your personal information, subject to certain exceptions (e.g., legal obligations, ongoing transactions).
- Right to Correct: You may request correction of inaccurate personal information we maintain about you.
- Right to Opt-Out of Sale or Sharing:We do not sell or share your personal information for cross-context behavioral advertising. If this practice changes, we will provide a "Do Not Sell or Share My Personal Information" link.
- Right to Limit Use of Sensitive Personal Information: You may request that we limit our use of sensitive personal information to purposes necessary for the Service.
- Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights.
Categories of personal information collected (per CCPA categories): Identifiers, commercial information, internet/electronic activity, geolocation (approximate), professional information, and inferences drawn from the above.
9.2 Virginia (VCDPA)
Virginia residents have the following rights under the Virginia Consumer Data Protection Act:
- Right to Access: Confirm whether we are processing your personal data and access that data.
- Right to Correct: Correct inaccuracies in your personal data.
- Right to Delete: Request deletion of personal data you have provided or that we have obtained.
- Right to Data Portability: Obtain a copy of your personal data in a portable, readily usable format.
- Right to Opt-Out: Opt out of the processing of your personal data for targeted advertising, sale, or profiling in furtherance of decisions that produce legal or similarly significant effects.
You may appeal a denial of your request by contacting support@keystir.com. If your appeal is denied, you may contact the Virginia Attorney General.
9.3 Colorado (CPA)
Colorado residents have the following rights under the Colorado Privacy Act:
- Right to access, correct, and delete personal data.
- Right to data portability.
- Right to opt out of targeted advertising, sale of personal data, and profiling.
Colorado law requires us to honor universal opt-out mechanisms. We recognize Global Privacy Control (GPC) signals as a valid opt-out request. You may also appeal a denial by contacting us, and then the Colorado Attorney General.
9.4 Connecticut (CTDPA)
Connecticut residents have the following rights under the Connecticut Data Privacy Act:
- Right to access, correct, and delete personal data.
- Right to data portability.
- Right to opt out of the sale of personal data, targeted advertising, and profiling.
We honor universal opt-out mechanisms including GPC signals for Connecticut residents. Appeals may be directed to support@keystir.com and subsequently to the Connecticut Attorney General.
9.5 Utah (UCPA)
Utah residents have the following rights under the Utah Consumer Privacy Act:
- Right to access personal data we process about you.
- Right to delete personal data you have provided to us.
- Right to data portability (obtain a copy of your data in a readily usable format).
- Right to opt out of the sale of personal data and targeted advertising.
9.6 Texas (TDPSA)
Texas residents have the following rights under the Texas Data Privacy and Security Act:
- Right to confirm whether we are processing your personal data and to access that data.
- Right to correct inaccuracies in your personal data.
- Right to delete personal data.
- Right to obtain a portable copy of your personal data.
- Right to opt out of the processing of personal data for targeted advertising, the sale of personal data, or profiling.
We honor universal opt-out mechanisms including GPC signals. Appeals may be directed to support@keystir.com and subsequently to the Texas Attorney General.
9.7 Iowa (ICDPA)
Iowa residents have the following rights under the Iowa Consumer Data Protection Act:
- Right to confirm processing and access personal data.
- Right to delete personal data.
- Right to data portability.
- Right to opt out of the sale of personal data and targeted advertising.
We will respond to your request within 90 days as required by Iowa law.
9.8 Montana (MTCDPA)
Montana residents have the following rights under the Montana Consumer Data Privacy Act:
- Right to confirm processing and access personal data.
- Right to correct inaccuracies in personal data.
- Right to delete personal data.
- Right to data portability.
- Right to opt out of the sale of personal data, targeted advertising, and profiling.
We honor universal opt-out mechanisms including GPC signals for Montana residents.
9.9 Oregon (OCDPA)
Oregon residents have the following rights under the Oregon Consumer Data Privacy Act:
- Right to confirm processing and access personal data.
- Right to correct inaccuracies in personal data.
- Right to delete personal data.
- Right to data portability.
- Right to opt out of the sale of personal data, targeted advertising, and profiling.
- Right to obtain a list of specific third parties to whom we have disclosed personal data.
We honor universal opt-out mechanisms including GPC signals for Oregon residents.
9.10 New Jersey (NJDPA)
New Jersey residents have the following rights under the New Jersey Data Privacy Act (NJDPA), effective January 15, 2025:
- Right to Access: Confirm whether we are processing your personal data and obtain a copy of that data.
- Right to Correct: Request correction of inaccurate personal data we maintain about you.
- Right to Delete: Request deletion of personal data you have provided to us or that we have obtained about you.
- Right to Data Portability: Obtain a copy of your personal data in a portable, readily usable format.
- Right to Opt-Out: Opt out of the processing of your personal data for targeted advertising, the sale of personal data, or profiling in furtherance of decisions that produce legal or similarly significant effects.
- Sensitive Data Protections: The NJDPA classifies financial data, precise geolocation, and certain other categories as sensitive data requiring your express consent before processing. Keystir processes real estate transaction and commission data that may qualify as financial data under the NJDPA; we obtain your consent for this processing at account registration.
We will respond to your request within 45 days as required by the NJDPA. If we need additional time, we will notify you of the extension (up to an additional 45 days) and the reason for the delay. If we deny your request, you may appeal by contacting support@keystir.com. If your appeal is denied, you may file a complaint with the New Jersey Division of Consumer Affairs or the New Jersey Attorney General.
9.11 All Other States
Even if your state does not currently have a comprehensive consumer privacy law, we are committed to providing all users with meaningful privacy protections. Regardless of your state of residence, you may contact us at support@keystir.com to request access to, correction of, or deletion of your personal information, and we will make commercially reasonable efforts to honor your request. As new state privacy laws take effect, we will update this policy accordingly.
10. How to Exercise Your Rights
You may exercise your privacy rights in any of the following ways:
- Email: Send a request to support@keystir.com with the subject line "Privacy Rights Request."
- In-App Data Request Form: Use the Data Request page on our website to submit an access, deletion, portability, or opt-out request.
- Universal Opt-Out: We honor Global Privacy Control (GPC) signals sent by your browser or browser extension.
We will verify your identity before processing your request using the email address associated with your account. We will respond to your request within 45 days as required by applicable law. If we need additional time, we will notify you of the extension (up to an additional 45 days) and the reason for the delay.
You may designate an authorized agent to make a request on your behalf. The authorized agent must provide proof of authorization (e.g., a signed power of attorney or written authorization from you).
11. Cookie Policy Summary
We use only essential cookies necessary for the operation of the Service, primarily for authentication (Supabase session management) and user preferences (reading mode, language selection). We do not use third-party advertising or tracking cookies. For full details, please see our Cookie Policy.
12. International Users
Keystir is a United States-based service designed for U.S. real estate professionals. The Service is not intended for users outside the United States, and we do not actively market to or solicit data from individuals in the European Economic Area, United Kingdom, or other international jurisdictions. If you access the Service from outside the United States, you do so at your own risk and are responsible for compliance with your local laws.
13. Do Not Track Signals
We honor Do Not Track (DNT) browser signals and Global Privacy Control (GPC) signals. When we detect a DNT or GPC signal, we will not engage in any tracking beyond what is strictly necessary for the operation of the Service.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or other factors. When we make material changes, we will:
- Update the "Last Updated" date at the top of this page.
- Notify you via email and/or a prominent notice within the Service at least 30 days before the changes take effect.
- Where required by law, obtain your consent before applying material changes.
We encourage you to review this Privacy Policy periodically to stay informed about how we protect your information.
15. Contact Us
If you have any questions, concerns, or complaints about this Privacy Policy or our privacy practices, please contact us:
If you are unsatisfied with our response to a privacy concern, you may contact your state's Attorney General. California residents may also contact the California Privacy Protection Agency.