Data ownership & handling · Last reviewed 10 September 2026
Your data stays yours
You upload financial packages, rent rolls, loan documents, insurance policies, and operator reports. This page explains, in plain terms, what the platform does with them: where they are stored, which services touch them, how AI processing works, and what never happens to them. It is written from the code that runs the platform, not from a policy template.
the pipeline in one pass
When you upload a monthly bundle, the file is stored privately and read by deterministic parsers that pull out line items, units, leases, balances, and variance commentary. Those figures are written to your organisation’s tables in the platform database, scoped so that only members of your organisation can see them. Dashboard scores are then computed by the published scoring rubric — pure arithmetic, no model involved.
After the numbers are in place, the platform asks an AI model to write the narrative layer: the per-module insights, ranked interventions, forecast commentary, and investor-report prose. That step reads from the figures already parsed. Everything it produces is labelled Modeled so it is never mistaken for source data.
every service that touches it
| Service | Role | What it holds |
|---|---|---|
| Platform database | System of record | Parsed figures, computed scores, AI-written narratives, and your Analyst chat history. Every row is tagged with your organisation and isolated from every other client. |
| Private file storage | Original uploads | The files exactly as you uploaded them, stored with private access. They are readable only by the platform's own servers with a server-side credential; there are no public links. |
| Anthropic (Claude API) | AI processing | Receives the figures and, for document extraction, the document itself, for the duration of a request. Inputs and outputs are deleted from Anthropic's systems within 30 days and are never used for training. Details below. |
| Background job service | Runs the ingestion pipeline | Holds job identifiers, file names, and progress diagnostics while a bundle is processed. It does not receive document contents or parsed figures. |
| Identity provider | Sign-in | Your name and email address, used only to authenticate you and manage membership. It never sees asset data. |
That is the complete list. There is no analytics vendor reading your figures, no data broker, and no second AI provider.
one code path · one provider
Every AI call the platform makes goes through a single, audited code path to Anthropic’s Claude API, using Anthropic’s official software library and nothing in between. That path enforces your organisation’s AI budget before each call and records token usage after it. No AI call is made from your browser, and no other model provider is used anywhere in the platform.
| The model receives | The model never receives |
|---|---|
| Parsed figures for one asset and one period: financial subtotals and variances, rent-roll aggregates, debt terms, comparable-property data, and the operator’s variance commentary. For document extraction, the uploaded loan agreement, insurance policy, mortgage statement, condition report, or rate curve itself, so the model can read terms a parser cannot. In the AI Analyst, the question you typed and the recent turns of that conversation. | Your name, email address, or any user identifier. Requests carry no account metadata. Resident names. The at-risk lease table the model sees is keyed by unit number only; names stay in the platform for display. Data from any other client. Each request is built from one organisation’s tables and nothing else. |
What comes back is kept in structured form: extraction returns typed fields (a rate, a maturity date, a carrier name) and the free text around them is discarded. Narrative outputs are stored as the Modeled blocks you see on the dashboards.
Some Anthropic models require extended retention of prompts at Anthropic for safety review. The platform excludes those models from selection so that client documents are only ever processed by models eligible for the shortest retention terms Anthropic offers.
quoted from the published terms
The platform uses Anthropic’s commercial API under Anthropic’s Commercial Terms of Service. Those terms, not a consumer chat product’s terms, govern what Anthropic may do with what it receives.
“Anthropic may not train models on Customer Content from Services.”
Anthropic Commercial Terms of Service, section B
“Customer Content is Customer’s Confidential Information.”
Anthropic Commercial Terms of Service, section E
“By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models.”
Anthropic Privacy Center · Is my data used for model training?
Anthropic deletes API inputs and outputs from its systems within 30 days of a request. During that window the data is held as confidential information under the terms above; it is not read by people and not used for any purpose beyond serving the request and Anthropic’s legal and safety obligations.
an option in Settings
By default, AI processing runs under the platform’s Anthropic account and the commitments above. An organisation administrator can instead enter your own Anthropic API key. When you do, the same requests are sent under yourAnthropic account, and Anthropic’s handling of that data is governed by your account’s terms, your retention period, and any zero-data-retention agreement you hold with Anthropic. The platform cannot see or change those settings. Everything else on this page is unchanged: what is sent, what is kept, and what is never shared.
| Control | Where |
|---|---|
| Who in your organisation can view, upload, or administer. Viewers can read dashboards and ask the Analyst; uploading and settings require higher roles. | Settings · Members |
| The monthly AI budget. When it is reached, AI generation pauses and dashboards keep showing parsed figures. | Settings · AI |
| Whether AI runs on the platform key or your own Anthropic key. | Settings · AI |
| An audit trail of administrative actions: uploads, re-runs, approvals, settings changes, and every platform-administrator access to your organisation. | Kept in the platform database per organisation |
Realty Automation staff do not browse client data in the course of normal operations. Platform administrators have an explicit, logged elevation path for support, and every use of it is recorded against your organisation.
verified on the review date above
Realty Automation · data ownership & handling · reviewed against the implementation on 10 September 2026Questions: your account contact at Realty Automation