Information collected
We collect information you choose to submit through available features: account names and emails, secure authentication records, network applications (name, business email, brokerage, license details, service areas and optional website), profile claim evidence, corrections, reviews, real estate agent contributions, inquiries, and contact requests. A contact request can include your name, reply email, request category, message, and any source link you provide. Public real estate agent information comes from attributed sources. We avoid publishing private residential addresses or private contact information from licensing datasets.
Purpose and sharing
Account information supports authentication and abuse prevention. Network application details are private and used to review participation requests. An application does not create an account or grant profile ownership. Claim evidence supports review of real estate agent profile ownership. Contact requests are kept out of public profiles and used to handle support, privacy, and source concerns. Inquiries are shared with the verified intended real estate agent; they are not sold to unrelated real estate agents. Service providers process information needed to deliver the hosting, database, email, storage, payment, and error-monitoring features that are enabled.
Analytics and operational logs
First-party event records measure searches, profile views, inquiries, and use of comparison features without storing raw inquiry text in analytics. Rate limits use a hashed network identifier. Audit logs record critical decisions. Vercel web analytics and performance measurement may process technical request information under their own service policies.
AI operations
The operating agent receives bounded operational summaries and public-source information. Inquiry contact details, passwords, authentication tokens, and payment credentials are not supplied to the model. If external visibility sampling is enabled, its public research prompts are sent to the configured model provider. A planned monitoring feature does not mean sampling is currently running or that an AI service has cited AgentCerta.
Retention
Authentication sessions expire after seven days. Short-lived rate-limit identifiers are cleaned after their expiry. Operational records, claims, source history, and correction evidence are retained to maintain provenance and handle disputes. Requests to access, correct, or delete your information can be submitted through Contact and are reviewed in light of record integrity, fraud prevention, and applicable obligations.
Your choices
You can submit a privacy request, account concern, or profile correction through Contact without an account. Include enough context to identify the request; do not send passwords, payment details, or identity documents. A request does not itself verify identity or authorize a change to another person's record, and additional verification may be needed. Existing subscribers can manage a subscription through the billing portal when billing is enabled. Do not post sensitive identity documents or private information in public reviews or answers.
Security and scope
Access to inquiries and profile administration is restricted to authorized accounts. Service connections use transport encryption. No internet service can promise absolute security. AgentCerta is not intended for children under 13.