FFreehold

Privacy policy

Last updated August 3, 2026.

This policy covers Freehold Cloud, the hosted service operated by Freehold Studio ("we," "us"). It does not cover self-hosted installations of the open-source Freehold software; see "If you self-host Freehold" below.

This is a plain-language summary of a document we intend to have reviewed by counsel before Freehold Cloud takes paid customers at scale. If anything here is unclear, email privacy@freeholdtc.dev.

What we collect

Account information. Name, email, username, and (optionally) phone number, when you sign up or update your profile. If you sign in with Google or Microsoft, we receive only what that provider shares for sign-in: your name and email.

Workspace content. The clients, contacts, transactions, tasks, notes, and documents you and your team put into Freehold. This is the core of the service, it is your data, and it is what Freehold exists to help you manage.

Payment information. Subscription payments are processed by Stripe. We receive your billing name, address, and subscription status; we never see or store your card number.

Technical and usage data. IP address, browser and device type, and login timestamps, collected automatically to run and secure the service (for example, our concurrent-session limit uses device type and IP to tell sessions apart).

Voice data. If you use dictation or voice search, your microphone audio is streamed to our speech-to-text and text-to-speech providers for the length of that session and is not stored by Freehold afterward.

Cookies and analytics. Freehold Cloud uses Vercel Web Analytics, a cookieless, aggregate page-view analytics product, across the whole application, including the dashboard. We also ship PostHog, a product-analytics tool, in our code, but it only activates if we configure an API key for it; it is not currently active. Neither is an advertising tracker, and we place no advertising pixels of any kind. Sign-in itself requires a session cookie to work.

How we use it

We use your information to operate Freehold Cloud, secure your account, process payments, respond to support requests, and improve the product. We do not use your workspace content to train AI models, ours or anyone else's.

Categories of personal information (last 12 months)

The table below is written to satisfy CCPA/CPRA's disclosure requirement directly.

CategoryExamplesSourcePurpose
IdentifiersName, email, username, phone number, IP addressYou, automaticallyCreate and secure your account, run the service
Customer recordsBilling name and address, payment method on file with StripeYou, StripeProcess subscription payments
Commercial informationPlan tier, transaction and credit usage, invoice historyYou, automaticallyBill correctly, enforce plan limits
Internet or network activityPages viewed, session device type, login timestampsAutomaticallySecurity, session limits, product analytics
Audio dataVoice captured during dictation or voice search, transientYouConvert speech to text and read answers aloud
User-generated contentClient, contact, and transaction records; documents you uploadYouRun the transaction coordination service you signed up for
Precise or approximate locationAddress text typed into address fields, approximate location from IPYou, automaticallyAddress autocomplete, security

The commercial purpose for collecting these categories is, in every case, providing the Freehold Cloud service you signed up for: running your workspace, billing your subscription, and keeping the account secure.

Who we share it with

We share data only with the vendors that help us run the service (our infrastructure, payments, AI, email, and voice providers) and only what each one needs to do its job. The complete, current list, including exactly what each vendor sees, lives on our subprocessors page, updated the day we start sending a new vendor data. Contract text you upload is sent to Anthropic's Claude API for extraction; Anthropic does not train on this data under the API terms we operate under.

We do not sell your personal information, and we do not share it for cross-context behavioral advertising. Nothing on this page changes that without saying so explicitly and giving you a way to opt out first.

Data retention and security

We keep your data for as long as your account is active, plus a reasonable period afterward in case you want to return, then delete it. Documents you upload and credentials you store in the vault are envelope-encrypted before they reach the database or storage. We use industry-standard physical and electronic safeguards, including encryption in transit and at rest, database-enforced workspace isolation, and audit logging. No internet-connected system is 100% secure, and we can make no guarantee as to the security of your information; see the security disclaimer in our terms.

You stay in control of where your documents live. Connect your own S3-compatible storage bucket in Settings and new documents are written there, in infrastructure you own; with it connected, we also push a full nightly copy there automatically. You can download your entire workspace, records and documents, as one archive at any time from Settings.

International transfers

Our infrastructure and most subprocessors are based in the United States; one voice provider also processes data in the European Union. If you are located outside the United States, your information will be transferred to and processed there.

Your rights

If you are a California resident (CCPA/CPRA): you have the right to know what personal information we hold about you, to request its deletion, to correct inaccurate information, and to opt out of the sale or sharing of personal information. As stated above, we do not sell or share personal information, so there is no opt-out to exercise; if that ever changes, we will provide a clear "Do Not Sell or Share My Personal Information" control before it does. We will not discriminate against you for exercising any of these rights.

Freehold Cloud is US-focused: we have no EU or UK operations and don't market to customers there, so GDPR does not apply to us today. If that ever changes, we will extend the same rights above to EU and UK users under GDPR.

Wherever you're located, you can request the same access, correction, or deletion rights described above by emailing privacy@freeholdtc.dev. Exporting your own workspace data is instant and self-service from Settings; account and workspace deletion is currently handled by request rather than a self-service button, and we aim to complete it within 30 days.

Children's privacy

Freehold Cloud is a business tool for licensed real estate professionals and is not directed at, or knowingly used by, anyone under 18. We do not knowingly collect personal information from children.

If you self-host Freehold

None of the above applies. Freehold's source code is public, and self-hosting it means your data lives on your own server and never reaches us. You are the data controller for your own installation.

Changes to this policy

If we make a material change to how we handle your data, we will update the date at the top of this page and, for significant changes, notify workspace owners directly.

Questions: open an issue on GitHub or email privacy@freeholdtc.dev.