Privacy Policy
Last updated: March 18, 2026
Overview
Trevy LLC ("Trevy," "we," "us") operates an AI-powered assistant for real estate professionals. This Privacy Policy explains what data we collect, how we use it, who we share it with, and your rights. We believe in being straightforward — if you have questions, email us at support@trevy.io.
1. Information We Collect
Account Information
When you sign up, we collect:
- Name and email address
- Password (hashed with bcrypt — we never store or see your actual password)
- Profile preferences (display name, timezone)
- Billing information (processed by Stripe — we store your Stripe customer ID but not your card number)
CRM Data (Follow Up Boss)
When you connect your Follow Up Boss account, we access:
- Contacts — names, emails, phone numbers, stages, tags, assignments, sources, custom fields
- Activity — notes, calls, texts, events, emails logged in FUB
- Deals — deal stages, pipelines, values, associated contacts
- Configuration — stages, tags, groups, ponds, users, automations, templates
Your FUB API key is encrypted at rest using AES-256-GCM and never exposed in logs or API responses.
Email Data (Gmail / Outlook)
When you connect Gmail or Outlook, we access:
- Email messages — subject, body, sender, recipients, timestamps
- Calendar events — title, date/time, attendees, location
OAuth tokens (access and refresh tokens) are encrypted at rest. We only access your email and calendar to perform actions you specifically request through the AI assistant (reading emails, sending replies, creating events). We do not scan your email for advertising or any purpose beyond serving your requests.
Conversations & AI Interactions
We store:
- Chat messages between you and Trevy (for conversation history and continuity)
- AI-generated summaries and extracted topics (for search)
- Learned preferences and memories (things you tell Trevy to remember)
- AI usage metrics — model used, token counts, response times, costs (for billing and performance monitoring)
Customer Data Platform (CDP)
Trevy maintains a customer data platform that tracks lead activity to help you understand your pipeline. This includes:
- Lead activity events from FUB (contact created, notes added, calls logged, stage changes)
- User actions within Trevy (searches performed, actions executed, emails sent)
- Behavioral profiles — activity counts, last contact dates, property viewing history, deal history
- Automation events — sweep rule triggers, agent pauses, lead reassignments
Email Tracking
When you send emails through Trevy, we track opens and clicks using a tracking pixel and link redirection. Specifically:
- Whether the recipient opened the email and when
- Which links were clicked and when
- Property links are identified (Zillow, Redfin, Realtor.com) with address extraction
This data is used to help you understand lead engagement and is visible only to you and your team.
Property & Market Data
When you search for properties or run CMAs, Trevy accesses public data from Zillow (autocomplete and property details), RentCast (comparable sales and valuations), WalkScore (walkability scores), U.S. Census (demographics), and FRED (economic indicators like mortgage rates). No personal data is sent to these services — only addresses, coordinates, or public identifiers.
2. How We Use Your Information
- To provide the AI assistant and process your requests
- To send emails and manage calendar events on your behalf
- To run automation rules (sweeps) that you configure
- To build lead profiles and track activity in your CDP
- To track email engagement (opens, clicks)
- To remember your preferences across conversations
- To process payments and manage your subscription
- To monitor and improve platform performance and reliability
- To send you service-related communications (billing, security, feature updates)
We do NOT use your data to train AI models. Your conversations, emails, CRM data, and property searches are never used for model training by Trevy or by Anthropic (our AI provider).
3. How We Share Your Information
AI Processing (Anthropic)
When you send a message, Trevy sends your conversation context to Anthropic's Claude API for processing. This includes your message, relevant conversation history, CRM context (stages, tags, agent names), and any memories you've stored. Anthropic processes this data to generate responses and does not retain it for model training. See Anthropic's Privacy Policy for details.
Service Providers
We share data with the following providers solely to operate the platform:
- Stripe — payment processing (billing data, subscription management)
- Vercel — hosting and serverless functions (application data in transit)
- Supabase — database hosting (all stored data, U.S. region)
- Resend — authentication emails (email address only)
- Google Analytics — marketing site analytics (page views, traffic sources — marketing site only)
- Microsoft Clarity — marketing site usability analytics (session replays, heatmaps — marketing site only)
We Do NOT
- Sell your data to third parties
- Share your data with advertisers
- Use your data for model training
- Share your CRM data with other Trevy customers
- Access your data for any purpose beyond providing the service
Legal Requirements
We may disclose information if required by law, subpoena, or court order, or to protect the rights, safety, or property of Trevy, our users, or the public.
4. Google API Limited Use Disclosure
Trevy's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Specifically:
- We only use Google user data (Gmail messages, calendar events) to provide the features you request
- We do not use Google data for advertising, market research, or email campaigns unrelated to your requests
- We do not transfer Google data to third parties except as necessary to provide the service (Anthropic for AI processing)
- We do not use Google data to train AI models
- OAuth tokens are encrypted at rest and only used to authenticate API requests on your behalf
- You can revoke Trevy's access to your Google account at any time from your Google Account settings or from Trevy's Settings page
5. Data Security
- All data in transit encrypted with TLS 1.2+
- Sensitive credentials (API keys, OAuth tokens) encrypted at rest with AES-256-GCM
- Passwords hashed with bcrypt (never stored in plaintext)
- Database hosted on Supabase (AWS us-east-2) with connection pooling and SSL
- Stripe webhook signatures verified with HMAC
- FUB webhook signatures verified with HMAC-SHA256
- All API endpoints require authentication via JWT session tokens
- Multi-tenant isolation — all database queries filtered by account ID
For more details, see our Security page.
6. Data Retention
- Your data is retained while your account is active
- After cancellation, data is retained for 30 days, then permanently deleted
- You may request deletion at any time by contacting support@trevy.io
- AI usage logs and billing records may be retained longer for legal and accounting purposes
- Session tokens expire after 7 days
7. Your Rights
You can:
- Access your data — request an export by contacting support@trevy.io
- Correct your data — update your profile, preferences, and memories in Settings
- Delete your data — request deletion by contacting support@trevy.io
- Disconnect integrations — remove Gmail, Outlook, or FUB connections from Settings at any time
- Delete memories — ask Trevy to forget specific information, or clear all memories from Settings
- Cancel your subscription — from Settings → Billing at any time
8. Cookies & Analytics
Essential Cookies
The Trevy app uses a single session cookie (session-token) to keep you logged in. This is a first-party, HTTP-only, secure cookie that expires after 7 days. We do not use advertising cookies.
Analytics (Marketing Site Only)
Our marketing website (trevy.io) uses the following third-party analytics services to understand how visitors find and interact with our site:
- Google Tag Manager / Google Analytics — page views, traffic sources, and site usage. Google may set cookies. See Google's Privacy Policy.
- Microsoft Clarity — session replays and heatmaps to improve site usability. Clarity may set cookies. See Microsoft's Privacy Statement.
These analytics tools are only present on the marketing site (trevy.io). The Trevy application (ai.trevy.io) does not include any third-party analytics or tracking scripts.
9. Children's Privacy
Trevy is designed for real estate professionals. You must be at least 18 years old to use the platform. We do not knowingly collect information from anyone under 18.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by email or through the platform. Continued use after changes take effect constitutes acceptance.
11. Contact
For privacy-related questions or requests, contact us at support@trevy.io.
Trevy LLC
Florida, United States