Legal

Privacy Policy

Effective Date: May 9, 2026Last Updated: April 20, 2026

1. Introduction

EM Underwriting ("EM," "we," "us," or "our") operates the commercial real estate underwriting platform at underwriting.eyalmehaber.com (the "Service"). This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use the Service.

By accessing or using the Service you agree to this Privacy Policy. If you do not agree, please do not use the Service.

2. Information We Collect

2.1 Account Information

When you register we collect your name, email address, and (if you use password authentication) a bcrypt-hashed password. If you sign in with Google OAuth, we receive your Google profile name, email, and profile picture.

2.2 Deal & Document Data

When you upload documents (Offering Memorandums, T-12s, rent rolls, Excel files) or enter deal information, we store that data in our database so the Service can perform underwriting calculations, generate exports, and provide AI-powered analysis.

2.3 Payment Information

We do not collect or store credit card numbers. All payment processing is handled by Stripe, Inc. We receive from Stripe your subscription status, plan tier, and a Stripe customer identifier.

2.4 Automatically Collected Information

We collect standard server logs including IP address, browser type, pages visited, and timestamps. We use this data for security (rate limiting, abuse prevention) and to improve the Service.

3. How We Use Your Information

We use your information to:

  • Provide, operate, and maintain the Service
  • Process your documents and perform underwriting calculations
  • Generate AI-powered extractions, analysis, and investment memos
  • Process payments and manage your subscription
  • Send transactional emails (account confirmation, password reset, billing notices)
  • Enforce our Terms of Service and prevent abuse
  • Improve the Service based on aggregated, de-identified usage patterns

4. Legal Bases for Processing (GDPR)

If you are located in the European Economic Area (EEA) or United Kingdom, our legal bases for processing your data are:

  • Contract performance — processing necessary to provide the Service you signed up for
  • Legitimate interest — security, fraud prevention, and service improvement
  • Consent — where you have given explicit consent (e.g., optional marketing communications)
  • Legal obligation — where processing is required by applicable law

5. Data Processors & Third Parties

We share your data only with the service providers necessary to operate the platform. We do not sell your personal information. Our data processors are:

ProcessorPurposeData Shared
Anthropic (Claude API)AI document extraction, analysis, and chatDocument content, deal data sent for processing
StripePayment processing and subscription managementEmail, payment method (handled by Stripe; we never see card numbers)
Google (OAuth)Optional sign-in authenticationEmail, name, profile picture (only if you choose Google sign-in)
NeonServerless PostgreSQL database hostingAll Service data (encrypted at rest and in transit)
VercelApplication hosting and serverless computeServer logs, request metadata

We do not use any additional analytics, advertising, or tracking services beyond what is listed above.

6. Data Retention

  • Trial accounts: If you do not convert to a paid plan, your account and all associated data are automatically deleted 14 days after your trial ends.
  • Paid accounts: Your data is retained for the duration of your subscription. After cancellation, your data is retained for 30 days (so you can reactivate if needed) and then permanently deleted.
  • Server logs: Retained for up to 90 days for security and debugging, then automatically purged.

7. Security Measures

We implement industry-standard security controls to protect your data:

  • Passwords are hashed using bcrypt with a cost factor of 12 — we never store plaintext passwords
  • Sessions are managed via signed JWT tokens with 7-day absolute expiry and 24-hour sliding renewal
  • All connections are encrypted via HTTPS with HSTS enforced (includeSubDomains, preload)
  • API routes are protected by per-IP sliding-window rate limiting
  • Database connections use TLS encryption in transit; data is encrypted at rest by our database provider

For more detail, see our Security page.

8. International Data Transfers

The Service is operated from the United States. If you access the Service from outside the United States, your data will be transferred to and processed in the United States. Our data processors may also process data in other jurisdictions. Where required by law (e.g., GDPR), we rely on Standard Contractual Clauses (SCCs) or other approved transfer mechanisms to ensure adequate protection of your data.

9. Your Rights

9.1 GDPR & UK-GDPR Rights (EEA/UK Residents)

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten")
  • Restrict or object to processing
  • Data portability (receive your data in a structured, machine-readable format)
  • Withdraw consent at any time (where processing is based on consent)
  • Lodge a complaint with your local supervisory authority

9.2 CCPA/CPRA Rights (California Residents)

Under the California Consumer Privacy Act and California Privacy Rights Act, you have the right to:

  • Know what personal information we collect and how it is used
  • Request deletion of your personal information
  • Opt out of the sale or sharing of personal information — we do not sell or share your personal information
  • Non-discrimination for exercising your rights
  • Correct inaccurate personal information
  • Limit the use of sensitive personal information

9.3 Exercising Your Rights

To exercise any of these rights, email us at [email protected]. We will respond within 30 days (or sooner where required by law). We may ask you to verify your identity before processing your request.

10. Cookies & Local Storage

The Service uses strictly necessary cookies for authentication (session tokens) and user preferences (e.g., onboarding tutorial completion). We do not use advertising cookies or third-party tracking cookies.

11. Children’s Privacy

The Service is not directed to individuals under 18. We do not knowingly collect personal information from children. If we learn that we have collected data from a child under 18, we will delete it promptly. If you believe a child has provided us with personal data, please contact us at [email protected].

12. AI-Specific Disclosures

When you use the AI features of the Service, your uploaded documents and deal data are sent to Anthropic’s Claude API for processing. Anthropic processes this data under their privacy policy. Under Anthropic’s commercial API terms, your data is not used to train their AI models.

13. Changes to This Policy

We may update this Privacy Policy from time to time. If we make material changes, we will notify you by email or by posting a prominent notice on the Service at least 30 days before the changes take effect. Your continued use of the Service after the effective date constitutes acceptance of the updated policy.

14. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at:

EM Underwriting
Email: [email protected]

Changelog

2026-04-20Initial version published.