URBAI
Privacy Policy
Last updated: Aug 31, 2026
This Privacy Policy explains how URBAI LLC (“we”, “us”, or “our”) collects, uses, stores, discloses, and protects your information when you use the URBAI platform and related services (together, the “Service”), including any information we receive from Google APIs when you choose to connect a Google account. We encourage you to read this policy in full. If you have any questions or wish to exercise a privacy right, you can reach us at any time at privacy@urbai.ai.
1Who we are
URBAI is an AI-powered operating system for the modern real estate industry. It brings pipeline, contacts, listings, escrow files, tasks, appointments, documents, and optional email and calendar integrations into a single workspace for real estate teams. The Service is operated by URBAI LLC, a company based in Seal Beach, California, which acts as the controller of the personal information described in this policy. Our full contact details appear at the end of this policy.
2Information you provide to us
When you and your team use the Service, you provide us with information directly. This includes:
- Account and profile information, such as your name, email address, and role within your workspace, which we receive through our authentication provider when you create or sign in to your account.
- Workspace content that you create or upload, such as contacts and their details, deals, listings, escrow records, tasks, notes, appointments, and documents. Because URBAI is a real estate platform, this content routinely includes personal information about the clients and other individuals you work with, including their names, email addresses, telephone numbers, and property addresses, as well as transaction details such as prices and commission figures.
- Information you enter into forms, including addresses you begin typing into address fields. To help you complete these fields, we use a third-party mapping service to suggest matching addresses; only the partial text you enter is sent to that service, and it is used solely to return suggestions.
Information we receive from your connected Google account is subject to additional protections and is described separately in the sections that follow, because stricter rules apply to it.
3Google data we access, and how we use it
When you connect your Google account, you grant URBAI access only to the data described below. We request nothing beyond this. Each kind of access exists to power a specific feature that is visible to you in the Service.
| What we access | How we use it |
|---|---|
| Your Gmail messages | To read, send, draft, and organize (label, mark as read) email within the Service. We are not able to permanently delete your mail. |
| Your Google account email address | To identify which mailbox is connected and to route your email to the correct account. |
| Your Google Calendar | To display your events as an optional overlay within the Service, to let you choose which calendars appear, and to create and manage the appointments you schedule in URBAI as events on your calendar. |
Calendar access is requested only if you choose to enable the calendar integration. We use it in two ways. First, to display your existing events as an optional overlay: those events are read only when you view them and are not stored. Second, to create and manage appointments you schedule in URBAI as events on your calendar, including their reminders; when you add, change, or remove such an appointment in URBAI, we make the matching change to that event on your calendar. URBAI only creates and updates the events that correspond to appointments you schedule in URBAI, and does not otherwise alter or delete your other calendar events.
4How we use your Gmail data, feature by feature
When you connect a mailbox, we use your Gmail access exclusively to provide the following features that are visible to you within the Service:
- Synchronizing your email into the Service. We read and store message content (the subject, a short preview, and one rendered version of the message body), the message headers, labels, and attachment details, so that your conversations appear alongside the matching contact and deal records and remain available to you offline. The file contents of attachments are not stored; they are retrieved from Gmail only when you open one.
- Sending email that you write. Messages and replies you compose in the Service are sent through your own mailbox and placed in the appropriate conversation.
- Creating drafts for your review. Certain workflow features, such as preparing a coordinator’s email for a transaction, create a draft in your mailbox for you to review and send. We do not send these drafts automatically.
- Organizing messages with labels. We may create and apply a label to the drafts and messages the Service prepares, so that they are easy to find alongside the relevant transaction in Gmail.
- Keeping read status in sync. When you read a conversation in the Service, we clear its unread indicator in Gmail so that both views remain consistent.
What we will not do with your Gmail data
- We do not sell your Google data, or anything derived from it.
- We do not use your Google data for advertising, ad targeting, or advertising measurement.
- We do not use your Google data to build profiles of you unrelated to the features described above.
- We do not transfer your Google data to third parties except as described in this policy.
- We do not permanently delete mail from your mailbox; the access we hold does not permit it, and no feature attempts it.
5Limited Use of Google user data
Our Limited Use commitment
URBAI’s use and transfer of information received from Google APIs to any other application will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practical terms, this means that:
- we only use Google user data to provide or improve the user-facing features described in this policy;
- we do not transfer Google user data to others except as necessary to provide or improve those features, to comply with applicable law, or as part of a merger, acquisition, or sale of assets after giving you notice;
- we do not use Google user data for serving advertisements; and
- we do not allow humans to read Google user data, except (a) with your affirmative agreement for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized and is used to operate or improve the Service.
6Artificial intelligence features
The Service includes optional features that use artificial intelligence to help you work more efficiently. These features operate on the content within your workspace and include, for example, refining or rephrasing text that you compose (such as polishing an email draft before you send it), extracting details from documents that you upload (such as a scanned form or a business card), and turning notes that you record into structured tasks.
To provide these features, the relevant text or document is processed by a trusted third-party artificial intelligence provider that acts on our behalf and under a written agreement with us. The following limits apply to all of our artificial intelligence features:
- We do not send your received email content to any AI provider. These features operate on content that you create or upload within the Service, and not on the messages we synchronize from your connected mailbox.
- We do not train models on your data. Neither URBAI nor our AI provider uses your data, or any Google user data, to develop, improve, or train generalized artificial intelligence or machine learning models that serve anyone else.
- Our AI provider processes your content solely to return a result to you, and is contractually restricted from retaining it for its own purposes.
7Voice dictation
Some parts of the Service allow you to dictate text by voice instead of typing, for example when recording notes to hand off as tasks. When you use voice dictation, the audio from your microphone is streamed to a third-party speech-to-text provider that converts it to text and returns that text to the Service. This occurs only while you are actively dictating, and only the resulting text is kept; URBAI does not store the audio recording. Voice dictation is entirely optional and is used only when you choose to start it.
8Connecting other services you use
At your direction, the Service can connect to certain third-party services that you already use so that your records stay aligned across the tools your team relies on, such as an external customer relationship management (CRM) service.
When you connect such a service, you provide URBAI with the credentials for your own account with that service, which we store in encrypted form. The Service then synchronizes the contacts, notes, appointments, and documents that you create in URBAI to your account with that service, and reads from it as needed to keep the two in sync. This is a transfer that you initiate and control, to a service that you separately control. Your synchronized email content is never sent to a connected service. You may disconnect a connected service at any time, which removes the stored credentials for it.
9How we store, protect, and share information
- Where your data is stored. Your workspace content, synchronized email, and documents are stored in our databases and cloud storage, hosted in the United States. All storage is encrypted at rest, and information is transmitted over encrypted connections.
- How access credentials are protected. Credentials that let the Service act on your behalf, such as the tokens for your connected Google account and any connected service, are encrypted and stored on our servers, are never exposed to your browser, and are used only to perform the operations described in this policy. Disconnecting an integration removes them.
- Isolation between workspaces. Every record, including synchronized email, is scoped to your workspace and enforced at the database level, so that no other workspace can access it.
- Service providers. To operate the Service, we rely on a small number of trusted service providers who process information on our behalf and under contract: a cloud hosting and storage provider (Amazon Web Services); our authentication provider (Clerk); an error-monitoring provider, configured to exclude message content and attachments (Sentry); an artificial intelligence provider that powers the features described above (OpenAI); a speech-to-text provider for voice dictation (Deepgram); and a mapping provider that returns address suggestions (Google). Each provider processes information only on our instructions and only to provide its part of the Service.
- What we never share. We do not sell your personal information. We do not share your Gmail message content or attachments with advertising networks, data brokers, or other data recipients beyond what is described in this policy, and we do not transfer Gmail content to a connected CRM service.
10How long we keep information, and how it is deleted
- While a connection is active, we retain the information we synchronize for as long as needed to provide the Service to you, and we delete it in accordance with the events described below.
- Disconnecting a mailbox from within the Service revokes our access to your Google account, deletes the stored access credentials, and immediately deletes our synchronized copy of that mailbox’s messages, conversations, and attachment details. Your mail in Gmail itself is never affected.
- A mailbox whose access has otherwise ended can also be removed within the Service, and any such mailbox that is left unused after its access ends is purged automatically within 30 days.
- Deleting your account, or the deletion of your workspace, removes your workspace content, including any synchronized Google user data, within 30 days, except where a longer period is required by law.
- You may also revoke our access to your Google account at any time from your Google Account settings (at myaccount.google.com/permissions), which has the same effect as disconnecting.
- Encrypted backups are retained on a rolling schedule of up to 35 days; deleted information ages out of backups as they expire.
11Your privacy rights
Depending on where you live, you may have the right to access the personal information we hold about you, to request that it be corrected, to receive a copy of it, to request its deletion, and to object to or restrict certain uses of it. Members of a workspace can carry out many of these actions directly within the Service. For any other request, please contact us at privacy@urbai.ai, and we will respond within the time required by applicable law, and in any event within 45 days unless a longer period is permitted.
The categories of personal information we collect are described in the sections above and include identifiers (such as names, email addresses, telephone numbers, and postal addresses), professional information, and commercial and transaction information, together with the communications content and documents you choose to bring into the Service. We collect this information from you, from your team members, and from the accounts and services you choose to connect, and we use it for the business purposes described in this policy.
If you are a California resident, you have the right to know what personal information we collect and how we use it, the right to request access to and deletion and correction of that information, and the right not to be treated differently for exercising these rights. We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We do not use sensitive personal information for the purposes that would give rise to a right to limit its use. You may submit a request yourself or through an authorized agent using the contact details in this policy. If you are in a jurisdiction with a supervisory authority for data protection, you may also have the right to lodge a complaint with it.
12Cookies and similar technologies
We use cookies and similar technologies only for the purposes of keeping you signed in, keeping the Service secure, and remembering your preferences within the Service. We do not use advertising cookies or cross-site tracking technologies.
13Children
The Service is intended for business use by real estate professionals and is not directed to children under the age of 16. We do not knowingly collect personal information from children.
14Changes to this policy
We may update this policy from time to time. When we do, we will post the updated policy here and revise the dates at the top. If a change materially affects how we handle your Google user data, we will notify the administrators of your workspace by email before the change takes effect.