Trust center

Privacy, without the fog.

This policy explains what BrokerBot processes, why it is needed, where it goes, and the choices available to customers and individuals.

Effective July 16, 2026Last updated July 23, 2026
Not a lead marketplace

We do not sell lead or conversation data.

Customer-directed

Mortgage teams decide which systems and workflows to connect.

Bounded operations

Short-lived operational records are cleaned on a defined schedule.

1. Who this policy covers

This policy applies to the public website, customer console, and messaging-assistant service known as The Broker Bot. It covers information supplied by mortgage teams, their authorized users, and the systems they choose to connect.

For lead and borrower information, the customer determines why the information is processed and how the assistant is configured. The Broker Bot processes that information to provide the service under the customer's instructions. A customer's own privacy notice may also apply.

2. Information we process

Account and user information

We process names, work email addresses, account roles, authentication identifiers, company settings, and integration configuration needed to operate and secure the console.

Lead and conversation information

When a customer connects its systems, we may process lead identifiers and contact details, assigned loan officer, pipeline and stage information, message content and delivery identifiers, replies, appointment context, opt-out state, and related workflow events.

Usage, support, and technical information

We process feature usage, audit events, error records, model-token counts, device and network information used for security, and communications sent to support.

Billing information

Subscription and usage totals are processed for billing. Payment-card details are collected and handled by Stripe, not stored by The Broker Bot.

3. How we use information

  • Provide, configure, secure, troubleshoot, and improve the service.
  • Route inbound replies, maintain conversation context, carry out customer-selected workflows, and record delivery state.
  • Authenticate users, enforce account permissions, and keep administrative audit history.
  • Measure account usage, prepare invoices, prevent duplicate billing, and support customers.
  • Detect misuse, investigate incidents, and meet applicable legal obligations.

We do not use customer lead data to create or sell lead lists. We do not use it for unrelated advertising.

4. Where information goes

Information is disclosed only as needed to operate the service, follow a customer's instructions, or comply with law. The product currently relies on selected providers for specific jobs:

  • Bonzo for customer-directed CRM and messaging activity.
  • Supabase for authentication, database, and server-side functions.
  • OpenAI for customer-directed AI processing used to draft or classify conversation activity.
  • Anthropic for customer-directed Claude processing when a customer connects its own Anthropic API key.
  • Stripe for subscription, payment, and usage billing.
  • Customer-selected scheduling and application services when a customer configures those links.

Providers receive only the information needed for their function and operate under their own terms and privacy commitments. We may also disclose information in a corporate transaction or when legally required, with appropriate safeguards.

5. AI-assisted messaging

The Broker Bot uses the customer-selected AI provider to help classify messages and prepare configured responses. Relevant conversation context is sent to OpenAI or, when the customer selects Claude and supplies a key, Anthropic. OpenAI and Anthropic are both United States companies and are the only AI providers that receive conversation content; The Broker Bot does not send conversation content to AI providers outside the United States. If that ever changes, this policy will be updated before the change takes effect. AI output can be incomplete or wrong. Customers remain responsible for their workflows, representations, regulatory obligations, and appropriate human oversight.

Keep sensitive information out of ordinary SMS. Customers should not ask individuals to send Social Security numbers, full financial-account details, passwords, or similarly sensitive records through the assistant.

6. Retention and deletion

We retain customer account and conversation information while it is needed to provide the service, maintain the customer's requested record, or satisfy security, billing, dispute, and legal obligations.

Short-lived operational data—such as completed job records, transient webhook records, public rate-limit buckets, and released signup claims—is subject to bounded cleanup. The default operational retention target is 30 days. Billing-delivery records and administrator audit history may be retained longer for financial integrity and security.

Expired, revoked, and consumed invitation records are also cleaned on a bounded schedule. A customer administrator may contact us to request an account export or deletion. Some information may remain in backups or be retained where law or a legitimate security or accounting need requires it.

7. Security

We use account-scoped access controls, encrypted transport, restricted service credentials, one-time invitation links, administrative audit logging, optional multi-factor authentication, and operational controls intended to limit unauthorized access and accidental duplicate actions.

No system can guarantee absolute security. Customers should protect their accounts, use unique credentials, enable multi-factor authentication for administrators, and promptly report suspected compromise.

8. Your choices and requests

Customer administrators can manage users, connected services, assistant settings, and certain retention controls from the console or through support.

Individuals may ask the mortgage team that contacted them to access, correct, or delete information. They may also opt out of text messages using the instructions provided in the conversation. Because the mortgage team controls the underlying relationship and source records, it is normally best positioned to respond first.

Depending on where you live, privacy law may provide additional rights. Email us at info@ethanwood.org with the relevant company name and enough detail to route the request. We may need to verify identity before acting.

9. Processing location

The service and its providers may process information in the United States and other locations where they operate. Where required, customers should ensure that appropriate contractual and transfer safeguards are in place.

10. Changes to this policy

We may update this policy as the product or applicable requirements change. We will post the revised version here and update the date above. Material changes may also be communicated through the console or by email.

11. Contact

Questions, privacy requests, or security reports can be sent to info@ethanwood.org.

This policy describes the current product design and is not a substitute for a customer's own privacy notice or legal advice.