1. Introduction
EM Underwriting ("EM," "we," "us," or "our") operates the commercial real estate underwriting platform at underwriting.eyalmehaber.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.
By accessing or using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.
2. Information We Collect
2.1 Account Information
When you register we collect your name, email address, and (if you use password authentication) a bcrypt-hashed password. If you sign in with Google OAuth, we receive your Google profile name, email, and profile picture.
2.2 Deal & Document Data
When you upload documents (Offering Memorandums, T-12s, rent rolls, Excel files) or enter deal information, we store that data in our database so the Service can perform underwriting calculations, generate exports, and provide AI-powered analysis.
2.3 Payment Information
We do not collect or store credit card numbers. All payment processing is handled by Stripe, Inc. We receive from Stripe your subscription status, plan tier, and a Stripe customer identifier.
2.4 Automatically Collected Information
We collect standard server logs including IP address, browser type, pages visited, and timestamps. We use this data for security (rate limiting, abuse prevention) and to improve the Service.
3. How We Use Your Information
We use your information to:
- Provide, operate, and maintain the Service
- Process your documents and perform underwriting calculations
- Generate AI-powered extractions, analysis, and investment memos
- Process payments and manage your subscription
- Send transactional emails (account confirmation, password reset, billing notices)
- Enforce our Terms of Service and prevent abuse
- Improve the Service based on aggregated, de-identified usage patterns
4. Legal Bases for Processing (GDPR)
If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your data are:
- Contract performance — processing necessary to provide the Service you signed up for
- Legitimate interest — security, fraud prevention, and service improvement
- Consent — where you have given explicit consent (e.g., optional marketing communications)
- Legal obligation — where processing is required by applicable law
5. Data Processors & Third Parties
We share your data only with the service providers necessary to operate the platform. We do not sell your personal information. Our data processors are:
| Processor | Purpose | Data Shared |
|---|---|---|
| Anthropic (Claude API) | AI document extraction, analysis, and chat | Document content, deal data sent for processing |
| Stripe | Payment processing and subscription management | Email, payment method (handled by Stripe; we never see card numbers) |
| Google (OAuth) | Optional sign-in authentication | Email, name, profile picture (only if you choose Google sign-in) |
| Neon | Serverless PostgreSQL database hosting | All Service data (encrypted at rest and in transit) |
| Vercel | Application hosting and serverless compute | Server logs, request metadata |
We do not use any additional analytics, advertising, or tracking services beyond what is listed above.
6. Data Retention
- Trial accounts: If you do not convert to a paid plan, your account and all associated data are automatically deleted 14 days after your trial ends.
- Paid accounts: Your data is retained for the duration of your subscription. After cancellation, your data is retained for 30 days (so you can reactivate if needed) and then permanently deleted.
- Server logs: Retained for up to 90 days for security and debugging, then automatically purged.
7. Security Measures
We implement industry-standard security controls to protect your data:
- Passwords are hashed using bcrypt with a cost factor of 12 — we never store plaintext passwords
- Sessions are managed via signed JWT tokens with 7-day absolute expiry and 24-hour sliding renewal
- All connections are encrypted via HTTPS with HSTS enforced (includeSubDomains, preload)
- API routes are protected by per-IP sliding-window rate limiting
- Database connections use TLS encryption in transit; data is encrypted at rest by our database provider
For more detail, see our Security page.
8. International Data Transfers
The Service is operated from the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. Our data processors may also process data in other jurisdictions. Where required by law (e.g., GDPR), we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure adequate protection of your data.
9. Your Rights
9.1 GDPR & UK-GDPR Rights (EEA/UK Residents)
You have the right to:
- Access the personal data we hold about you
- Rectify inaccurate or incomplete data
- Erase your data ("right to be forgotten")
- Restrict or object to processing
- Data portability (receive your data in a structured, machine-readable format)
- Withdraw consent at any time (where processing is based on consent)
- Lodge a complaint with your local supervisory authority
9.2 CCPA/CPRA Rights (California Residents)
Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:
- Know what personal information we collect and how it is used
- Request deletion of your personal information
- Opt out of the sale or sharing of personal information — we do not sell or share your personal information
- Non-discrimination for exercising your rights
- Correct inaccurate personal information
- Limit the use of sensitive personal information
9.3 Exercising Your Rights
To exercise any of these rights, email us at [email protected]. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.
10. Cookies & Local Storage
The Service uses strictly necessary cookies for authentication (session tokens) and user preferences (e.g., onboarding tutorial completion). We do not use advertising cookies or third-party tracking cookies.
11. Children’s Privacy
The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at [email protected].
12. AI-Specific Disclosures
When you use the AI features of the Service, your uploaded documents and deal data are sent to Anthropic’s Claude API for processing. Anthropic processes this data under their privacy policy. Under Anthropic’s commercial API terms, your data is not used to train their AI models.
13. Changes to This Policy
We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.
14. Contact Us
If you have questions about this Privacy Policy or our data practices, contact us at:
EM Underwriting
Email: [email protected]