Legal

Privacy Policy

Last updated October 1, 2026

1. What we collect

Three categories. Account data: your email, workspace name, and team membership. Workspace content: the deals, rent rolls, operating statements, and other documents you upload, and the models built from them. Source documents may contain resident, tenant, or contact names supplied by you, although Pencil does not need resident names to calculate an underwrite. Usage data: server logs and metering records (for example, a count of AI document extractions for billing). Payments run through Stripe; we never see or store full card numbers.

2. How we use it

To operate the service: computing your models, processing the documents you ask us to read, enforcing plan quotas, sending transactional email (account confirmation, password resets and billing notices), and support. We don't run ads, we don't sell your data, and we don't use your deal data for anything other than serving your workspace.

3. AI document processing

When you import a document, its contents are sent to our AI provider (Anthropic) over an encrypted API connection to extract the data into your model. API traffic of this kind is not used by the provider to train AI models. Extraction runs when you trigger it and the results land in your workspace, where every extracted number is visible and editable.

4. Connected AI clients

If you connect Pencil to ChatGPT, Codex, Claude, or another supported MCP client, that client can request the deal facts, assumptions, model outputs, and source-data summaries needed to answer your prompt. It can also send changes you explicitly request back to your Pencil workspace. Pencil does not send your full workspace or resident names by default. Access is tied to your Pencil account through OAuth, limited to your workspace, and can be revoked from the connected client at any time.

The connected client processes the prompt and tool results under its own terms and privacy policy. Do not connect a client unless your firm permits that provider to process the commercial real estate data you choose to use in the conversation.

5. Subprocessors

We use a small set of infrastructure providers to run Pencil:

  • Supabase: database and authentication
  • Vercel: application hosting
  • Anthropic: AI document processing
  • OpenAI: connected ChatGPT and Codex tool requests, when enabled by you
  • Stripe: payments and billing
  • Resend: transactional email

Each processes data only as needed to provide its function. We'll update this list if the set changes.

6. Isolation and security

Workspaces are isolated at the database layer with row-level security: your team's data is only visible to your team. Data is encrypted in transit and at rest. Access to production systems is restricted and credentialed.

7. Retention and deletion

We keep your workspace content for as long as your account exists, including through subscription lapses (that's what makes the read-only, never-hostage promise work). If you want your account and data deleted, email us and we'll remove it from production systems, with residual copies aging out of encrypted backups on their rotation schedule.

8. Your rights

You can access and export your data from the app at any time, including full Excel exports of every model. You can also ask us for a copy, a correction, or deletion of your personal data. Depending on where you live, local law may give you additional rights; we honor reasonable requests regardless.

9. Cookies

Pencil uses cookies for one thing: keeping you signed in. No advertising cookies, no cross-site tracking.

10. Changes and contact

If this policy changes materially, we'll notify you by email or in the app before the change takes effect. Questions or requests: support@pencil.deals.