Last Updated: May 7, 2025
Welcome to our real estate investment platform. We value your privacy and want to be clear about how we collect, use, and share your personal information. This Privacy Policy explains what information we collect from you, how we use it, how we share it, your rights and choices, and how we protect your information. By using our platform, you agree to the practices described in this Policy.
We collect information to provide and improve our services. This includes:
• Information You Provide: When you sign up, we ask for your name and email address. If you create an account, you will also provide a password or other login credentials (which we store securely in encrypted form). You may also provide additional information on the platform, such as property details or any data you input into our investment analysis tools or chat features. We do not intentionally collect sensitive personal information (like Social Security numbers, financial account numbers, or health information), and we ask that you do not share such sensitive data on our platform.
• Derived & Aggregated Data: We create de-identified or aggregated statistics from the information you input (for example, average rehab budgets or rental assumptions across users). These data sets cannot reasonably identify you and are used for analytics, model-training, and product development.
• Communication Information: If you contact us (for example, via customer support or feedback), we will collect the information you share, such as your contact details and the content of your messages.
• Automatically Collected Information: When you use our platform, we collect certain information automatically. This may include your IP address, browser type, device information, and how you navigate or use our website (e.g. pages visited, actions taken). We do this through server logs and may use cookies or similar technologies to remember your preferences and enhance your experience. (Note: At this early stage, we are not using advanced analytics tools like Google Analytics, but we may introduce analytics in the future. We will update this Policy if we do.)
• Location and Address Information: Our platform uses the Google Maps Places API to provide an address autocomplete feature. When you begin typing an address, that partial address is sent to Google to suggest possible matches. This means we collect the address queries you enter in order to forward them to Google and show you results.
• Third-Party Services Data: We integrate certain third-party services to power our platform's features. For example, we use OpenAI's API to provide AI-based chat analysis of property investment data. When you use our chat analysis feature, the text and data you input in the chat may be transmitted to OpenAI's service in order to generate a response. Similarly, if you make (or in the future, choose to make) payments through our platform, we will use a payment processor (such as Stripe) which will collect your payment information. When you use our chat analysis feature, the content you enter—along with, solely for personalization, the first name on your account—is transmitted to OpenAI to generate a response.
We use the information we collect for various purposes in operating our real estate investment platform, including:
• Providing and Improving Our Services: We use your information to create and manage your account, authenticate you when you log in, and provide you with the features of our platform. For example, your name and email let you sign in and receive updates, and your input data (like property details or chat queries) is used to deliver the analysis or results you request. We also use collected information to maintain, personalize, and improve our platform's functionality and user experience.
• AI-Powered Analysis: We send your prompt, any property data you include, and your first name to OpenAI to obtain a personalized response. We store the returned output for your later reference and may reuse de-identified portions of your inputs in aggregated form to improve our models and features.
• Address Autocomplete: We use your partial address inputs to provide the Google-powered autocomplete suggestions, making it easier for you to fill in address forms. This usage helps streamline data entry for property addresses.
• Communication: We use your email (and name, if needed) to communicate with you about your account, to send important service updates (such as changes to features or this Privacy Policy), or to respond to your inquiries. If you agreed to receive marketing communications, we may also send you newsletters or offers about our platform. You can opt out of marketing emails at any time (see Your Choices and Rights below).
• Product Analytics & Model Training: We analyze de-identified or aggregated user inputs to build new features, train forecasting models, benchmark typical assumptions, and publish statistics—never in a way that identifies you.
• Security and Fraud Prevention: We may use IP addresses and other identifiers to monitor for suspicious activity, verify user activity, and to help keep our platform secure. Information we collect (including automated logs) is used to prevent fraud, abuse, or violations of our Terms of Service, and to troubleshoot and debug issues.
• Legal Compliance: We may use your information as necessary to comply with applicable laws and regulations, or to respond to lawful requests or court orders. We also use and retain information to exercise or defend legal claims.
• Future Features and Services: If we integrate new features or third-party services (for example, payment processing via Stripe or customer relationship management (CRM) tools to help manage user accounts and communications), we will use your information to support those services. For instance, if you make a payment, we will use your provided information to process the transaction and send you a receipt. If we use a CRM, we might store your contact details and communication history to better assist you. We will update this Privacy Policy to reflect any significant new uses of your information.
We retain your personal information only for as long as necessary to fulfill the purposes described above (unless a longer retention period is required or permitted by law). For example, we will keep your account information while your account is active and for a reasonable period afterwards if needed for legal, tax, or accounting purposes, or to enforce our rights. When your personal information is no longer needed for these purposes, we will delete or anonymize it in accordance with our data retention policies and applicable law.
We understand the importance of your personal information and we are careful about how we share it. We do not sell your personal data to third parties. We share information in the following ways and with the following types of parties:
• Service Providers: We share your information with trusted third-party service providers who need the data to perform services on our behalf. These providers assist us in operating and improving the platform. They are contractually required to only use your information for our specified purposes and to protect it. Key service providers include:
OpenAI (AI Service Provider): We send your prompt and first name (no surname, email, or other contact info) to OpenAI's API. OpenAI uses this data exclusively to return the requested output and is contractually prohibited from using it for its own marketing. All traffic is encrypted in transit. See the OpenAI Privacy Policy (https://openai.com/policies/privacy-policy) for details.
Google Maps Places API: We use Google's Places API for address autocomplete. This means when you type an address into our platform, the characters you enter are sent to Google to retrieve address suggestions. We incorporate by reference the Google Privacy Policy, which will govern the information Google receives. (In other words, by using the address autocomplete feature, you are also subject to Google's Privacy Policy.) We only use the returned address suggestions to help you complete forms; we do not otherwise store the full query data from this feature beyond what is needed for audit/logging. See the Google Privacy Policy (https://policies.google.com/privacy) for details.
Hosting and Infrastructure: We may use web hosting providers or cloud services to store data securely and deliver our website/app to you. These providers may process your personal information for storage, backup, and security.
Email and Communications Tools: If we use an email service (for example, a service to send out newsletters or support emails), your email address and necessary contact info will be shared with that provider solely for sending communications to you.
Payment Processors: If and when we integrate payment processing (such as Stripe) for transactions on our platform, we will share the necessary personal and financial information with that processor to handle the payment. For example, if you decide to invest or purchase a service through our platform in the future, your payment card details and billing information would be sent directly to our payment processor. (We do not store full payment card details ourselves; the processor handles that information securely.)
CRM and Analytics (Future Integration): In the likely event we integrate a Customer Relationship Management tool or analytics tools, we may share your contact information and usage data with those platforms to help us manage user relationships, provide customer support, analyze how our users use the platform, and improve our services. Any such providers will be bound to use your data only for our business purposes as instructed by us.
• Business Transfers: If our company is involved in a merger, acquisition, financing due diligence, reorganization, bankruptcy, receivership, sale of company assets, or transition of service to another provider, your information may be transferred to a successor or affiliate of our company as part of that transaction. In such cases, we will ensure that your personal information remains subject to confidentiality commitments and, if applicable, will give you notice before your personal information is transferred and becomes subject to a different privacy policy.
• Legal Compliance and Protection: We may disclose your information if we believe in good faith that such disclosure is necessary to (a) comply with any law, regulation, legal process, or governmental request (for example, responding to a subpoena or court order); (b) enforce or investigate potential violations of our Terms of Service or other agreements; (c) detect, prevent, or address fraud, security, or technical issues; or (d) protect our rights, property, and safety, or that of our users or the public. This could include sharing information with law enforcement or regulators, or with authorized third parties (such as auditors or legal counsel) when needed to address misconduct.
• With Your Consent: In certain cases, we may ask for your consent to share your information with third parties. For example, we might present an option to share certain information with a partner or to use your information in a way not covered by this Privacy Policy. In those situations, we will only share or use the information as described at the time you give your consent. You have the right to revoke such consent at any time.
No Sale of Personal Information: We do not sell your personal information to third parties for money or any other valuable consideration. We also do not share your personal information with third parties for cross-context behavioral advertising (targeted advertising) purposes. This means there is no need for you to opt-out of the sale or sharing of your data — we don't do it. If in the future we ever consider selling personal information, we will update this Privacy Policy and provide any required notices and opt-out mechanisms as required by law. (In addition, we do not knowingly sell or share personal information of minors under 16 years of age in any way.) Because aggregated or de-identified statistics cannot reasonably identify you, we may share or publish such statistics without further notice.
We believe in giving you control over your personal information. Here are the choices and rights you have regarding the information you provide to us:
• Access and Update Your Information: You have the ability to review and update certain personal information by logging into your account (for example, you can update your profile or contact details, if our platform provides those settings). If you are unable to change the information through your account, or if you need to update information that is not editable in your profile, you may contact us at the email provided in the Contact Us section and request the update or correction. We will respond consistent with applicable laws.
• Opt-Out of Marketing Communications: If you no longer want to receive promotional or marketing emails from us, you can opt out at any time by clicking the "unsubscribe" link in those emails or by contacting us. Please note that even if you opt out of marketing messages, we may still send you transactional or administrative emails (for example, information about your account, security updates, or changes to our terms or policies) as those are necessary for us to provide our services to you.
• Cookie Choices: Most web browsers allow you to control cookies through your settings. You can set your browser to refuse all or some cookies or to alert you when cookies are being used. If you do so, please note that some parts of our platform (such as keeping you logged in) might not function properly. As of now, we use only necessary cookies for site operation (and not for analytics or advertising), so the impact of blocking cookies should be minimal beyond standard login functionality. If we implement analytics or additional cookies in the future, we will provide appropriate notice or consent mechanisms as required.
• Do Not Track: Some browsers have "Do Not Track" features that allow you to tell websites not to track you. Currently, there is no universal standard for how to interpret Do Not Track signals. Accordingly, our platform does not respond to Do Not Track signals. We will update our practices if an official standard emerges.
If you are a resident of California, you have specific legal rights under the California Consumer Privacy Act (CCPA) as amended by the California Privacy Rights Act (CPRA). We extend similar courtesy to all our users where feasible. These rights include:
• Right to Know: You have the right to request that we disclose what personal information we collect, use, and share about you. This includes the categories of personal information we have collected, the categories of sources of that information, the business or commercial purpose for collecting it, the categories of third parties with whom we share it, and specific pieces of personal information we hold about you. Upon verifiable request, we will provide this information for the 12-month period preceding your request (or longer, as required by law).
• Right to Delete: You have the right to request that we delete personal information we have collected from you, subject to certain exceptions. Once we receive and confirm a verifiable deletion request, we will delete (and direct our service providers to delete) your personal information from our records, unless an exception applies. For example, we may retain information needed to complete a transaction you initiated, to detect security incidents, to comply with legal obligations, or other such exceptions allowed under the law.
• Right to Correct: You have the right to request that we correct any inaccurate personal information we maintain about you. If you believe that any of your information is incorrect or out-of-date, you can request a correction. We will take appropriate steps to verify and rectify the information as needed.
• Right to Opt Out of Sale or Sharing: You have the right to direct us not to sell your personal information or share it for certain targeted advertising purposes. However, as noted above, we do not sell personal information or share it for cross-context behavioral advertising. Therefore, there is no need to opt out in our case, since we don't engage in those practices. If our practices change, we will provide a clear method for you to exercise an opt-out.
• Right to Limit Use of Sensitive Personal Information: Under the CPRA, California residents can request that a business limit the use or disclosure of "sensitive personal information" (as defined by law) if it's used for purposes beyond what is necessary to provide the services. In our case, the only sensitive personal information we may collect could be your account login credentials (password) or, in the future, payment information for transactions. We only use such sensitive information to provide you with the service you expect (e.g., using your password to authenticate your login, or sending your payment details to a payment processor for a transaction). We do not use sensitive information for other purposes like profiling or targeted advertising. Because of this, the right to limit use of sensitive information is generally not applicable to our practices. Should our use of sensitive data ever expand beyond what is necessary, we will honor requests to limit it as required by law.
• Right to Non-Discrimination: We will not discriminate against you for exercising any of your privacy rights. This means we won't deny you our services, charge you a different price, or provide a different level of quality of service just because you exercised your rights under CCPA/CPRA or other applicable laws. However, please note that if you request deletion of certain data or decline to provide certain information, it may affect our ability to provide some services to you (for example, if you ask us to delete your account information, we cannot provide account-based services to you).
To exercise any of your rights described above, please contact us using the information in the Contact Us section below. We will need to verify your identity before fulfilling most requests (to ensure that we do not disclose or delete someone else's information by mistake). For verification, we may ask you to provide certain information that we already have on file (such as confirming your email address or other account details). If you have an authorized agent making a request on your behalf, we will require proof of that authorization and still take steps to verify your identity directly (as required by law).
Note: While we build self-service tools, you may exercise your privacy rights by emailing us at the address below. We will honor verified CCPA/CPRA requests (access, deletion, correction, etc.) through this manual process.
We take the security of your personal information seriously. All API traffic between our servers and OpenAI is encrypted over TLS to protect the prompts and first-name data we transmit. We implement reasonable and appropriate security measures designed to protect your information from unauthorized access, loss, misuse, or alteration. These measures include technical, administrative, and physical safeguards such as encryption of data in transit (for example, we use HTTPS for our website to ensure your data is encrypted between your browser and our servers) and encryption or hashing of sensitive data at rest (for instance, we store passwords in a hashed/encrypted form). We also limit access to personal information to employees and contractors who need it to operate or improve our platform, and they are bound by confidentiality obligations.
Despite our efforts, please understand that no method of transmission over the Internet or method of electronic storage is 100% secure. We cannot guarantee absolute security of your data. It is important for you to protect your account credentials and to notify us immediately if you suspect any unauthorized access to your account. If we become aware of a security breach that affects your personal information, we will notify you as required by applicable laws.
Our platform is not intended for children under the age of 13. We do not knowingly collect personal information from anyone under 13 years old. If you are under 13, please do not use the platform or provide any information to us. If we learn that we have inadvertently collected personal information from a child under 13, we will take steps to delete that information promptly in compliance with the Children's Online Privacy Protection Act (COPPA) and other applicable laws.
We do not impose a specific age restriction above 13 for using our platform, but if you are under the age of 18, we encourage you to use our services with the involvement of a parent or guardian, especially when it comes to any financial decisions. In any case, our platform is aimed at a general audience and not specifically directed to minors. We also do not knowingly "sell" or share the personal information of consumers under 16 years of age for any purpose.
Parents or guardians: If you believe that a minor under your care has provided us with personal information without your consent, please contact us and we will work to delete the data and, if needed, disable the account.
We may update this Privacy Policy from time to time to reflect changes in our practices, technologies, legal requirements, or for other operational reasons. If we make changes, we will post the updated Policy on this page and update the "Last Updated" date at the top. If the changes are material (for example, if we start collecting additional personal information or using it in new ways), we will notify you of the updated Policy by prominent means. This may include a notice on our website, within the app, or sending an email to the address associated with your account. We encourage you to review this Privacy Policy periodically to stay informed about how we are protecting the personal information we collect.
Your continued use of our platform after any update to this Privacy Policy will signify your acceptance of the changes. If you do not agree to the revised Policy, you should discontinue use of our services or contact us to address any concerns.
If you have any questions, concerns, or requests regarding this Privacy Policy or your personal information, please contact us. We are here to help and will respond to your inquiry as soon as reasonably possible.
Email: mark@riots.ai
Mail: Privacy Team, Riots AI
310 E Chalmers St, Unit 104
Champaign, IL 61820
United States
("Our Company" refers to Riots AI, a Delaware C-Corporation with its principal place of business in California.)
Please feel free to reach out with any questions about this Privacy Policy or our privacy practices. Your privacy is important to us, and we will do our best to address any issues. Thank you for trusting our platform with your real estate investment journey.
Let me help you, boss! I can see everything on this page and leverage AI for deeper investment analysis.