Draft — pending owner review
This document has been redrafted against what the product actually does and is awaiting the owner's sign-off. It is operative — we hold ourselves to it — but the wording may still change before it is final, and the version identifier will change with it.
Privacy Policy
Version 2026-08-02 · effective 2 August 2026
This policy covers personal data about you, our user. It does not describe the public mortgage-market data the Service analyses; that is covered in section 6 and on the Data Attribution page. The Service is in beta, so the systems described here are still changing; this page changes with them rather than describing an intended end state.
1. What we collect
- Account details you give us: email address, and optionally your name, company, job title, and the "what best describes you" segment you pick at signup. The segment is one of a fixed set of categories, never free text.
- Authentication data: a hashed password (we never store the plaintext), session cookies, and — for API keys — a SHA-256 hash plus a short display prefix. The plaintext key is shown once, at creation, and is not recoverable afterwards.
- Subscription and trial records: your plan, status, trial grant and, if you subscribe, the customer and subscription identifiers issued by our payment processor. Card numbers never reach our systems.
- Usage records: for each API request, the route, method, response status, the entitlement it was gated on and your tier at the time. For exports, the job type, parameters and row count. For organisation actions, an audit entry naming the actor.
- Consent records: when you accepted these documents, and which version.
- AI feature records: for each AI call, which feature, which model, token counts, cost, latency and outcome — not the text of your prompt. The one exception is the report builder, which stores the prompt that produced a saved report so the report stays reproducible and its numbers remain traceable. Section 5 has the detail.
We do not sell personal data, we do not buy contact lists, and we do not run advertising or cross-site tracking.
2. Why we use it
To provide the Service and authenticate you; to resolve what your account is entitled to; to apply rate limits and export budgets and to detect abuse; to bill you if you subscribe; to send transactional email (sign-in links, the alerts and digests you configured, and service notices); and, in aggregate, to understand which parts of the product are used so we know what to build. Where a legal basis is required, ours is performance of our contract with you, or our legitimate interest in operating and securing the Service.
3. Who we share it with
Only the processors needed to run the Service: our hosting and database providers, our authentication provider, our transactional email provider, our product-analytics provider, and the model provider behind the AI features (section 5). Our payment processor is on that list and is connected in test mode during beta: no live charge can be taken and we never receive or store a card number — card details go to the processor's own hosted form, not to us. If you complete a test checkout, what lands in our database is the processor's customer and subscription identifiers and the resulting plan and status, on the account the checkout was started from. Each processor is bound to use the data only to provide its service to us. We also disclose data where we are legally required to, and we will tell you unless we are prohibited from doing so. If we are ever party to a merger or acquisition we will give notice before your data becomes subject to a different policy.
4. Retention and security
Account, subscription and consent records are kept while your account exists, and afterwards only for as long as we need them for tax, accounting and dispute purposes. Export files are deleted after seven days. Usage and audit records are retained for security and capacity analysis. Access to production data is restricted to the operators who need it; data is encrypted in transit, passwords and API keys are stored only as one-way hashes, and every table is subject to row-level access rules that keep one account out of another's data.
5. AI features — what leaves our systems
Some features generate prose using a third-party large language model. When you use one, the text you typed and the data rows we retrieved for it are sent to that model provider to produce a response. The provider is a processor under section 3: it is bound to use what we send only to return that response to us, and we do not authorise it to use your inputs for any other purpose.
On our side we log the fact of each call — the feature, the model, token counts, cost, latency and whether it succeeded, was refused or was blocked by our grounding check — so we can meter usage and control spend. That log does not contain your prompt. The report builder is the deliberate exception: a saved report stores the prompt that produced it, because a report whose question has been thrown away cannot be checked or refined. Saved reports are capped at the 40 most recent per account and older ones are deleted automatically; closing your account deletes all of them. Do not paste confidential or personal information into an AI feature.
6. The market data is public, and it is not about you
The mortgage data in the Service comes from public government publications — HMDA (CFPB/FFIEC), Ginnie Mae, FHFA, FFIEC/NCUA — and describes institutions, not named consumers. HMDA loan records are published by the CFPB with disclosure controls already applied by the regulator. We do not attempt to re-identify anyone, and doing so is prohibited by our Terms of Service.
7. Your choices and rights
You can view and correct your profile from your account page, revoke API keys yourself, turn off any alert or digest, and close your account — which deletes your profile, subscription, keys and referral records. Depending on where you live you may also have rights to access, port, restrict or object to processing. Email support@mortradar.com and we will respond within 30 days. We use cookies only for authentication and session state, never for advertising.
8. Changes and contact
Material changes will be notified in the product or by email before they take effect, and the version above will change. Questions: support@mortradar.com.