Privacy Policy for Abodient

Last Updated: November 7, 2025
Effective Date: November 7, 2025

1. Introduction

Abodient ("we," "our," or "us") operates an AI-powered property management platform that helps landlords and property managers coordinate tenant issues and maintenance requests. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our mobile application and web services.

By using Abodient, you consent to the data practices described in this policy.

2. Information We Collect

2.1 Information You Provide

Account Information:

  • Email address
  • Name
  • Phone number (optional)
  • Property address and details
  • Tenant contact information

Tenant Issue Reports:

  • Text descriptions of maintenance issues
  • Photos uploaded for issue documentation
  • Chat messages with our AI assistant ("Alfred")
  • Availability preferences for maintenance scheduling

Professional Contacts:

  • Names, phone numbers, and categories of contractors/service providers
  • Communication history with professionals

2.2 Information Collected Automatically

Usage Data:

  • Device information (type, operating system, version)
  • IP address
  • App usage patterns and session duration
  • Error logs and crash reports

Authentication Data:

  • JWT authentication tokens (securely stored)
  • Login timestamps
  • Session identifiers

3. How We Use Your Information

We use collected information for the following purposes:

Core Service Delivery:

  • Process and respond to tenant maintenance requests using AI
  • Analyze uploaded documents (leases, inventories) to provide relevant information
  • Find and coordinate with appropriate service professionals
  • Send notifications and updates about maintenance issues

AI Processing:

  • Our AI assistant analyzes your messages and uploaded images using OpenAI's GPT models
  • Document analysis uses semantic search via vector embeddings
  • All AI processing is done to improve service quality and response accuracy

Account Management:

  • Authenticate users and maintain secure sessions
  • Manage property and tenant associations
  • Store conversation history for continuity

Service Improvement:

  • Monitor app performance and fix bugs
  • Analyze usage patterns to improve features
  • Track errors via Sentry for quality assurance

4. Third-Party Services

We use the following third-party services that may collect, process, or store your data:

Supabase (Authentication & Database):

  • Stores user accounts, properties, and session data
  • Provides secure authentication with JWT tokens
  • Privacy Policy: https://supabase.com/privacy

OpenAI (AI Processing):

  • Processes chat messages and analyzes uploaded images
  • Used for AI assistant responses and document analysis
  • Privacy Policy: https://openai.com/policies/privacy-policy
  • Data retention: Per OpenAI's API data usage policies

Telegram (Professional Communication):

  • Used to send messages to service professionals on your behalf
  • Only contacts you've added receive messages
  • Privacy Policy: https://telegram.org/privacy

Sentry (Error Tracking):

  • Collects anonymized error reports and crash logs
  • Does not include personally identifiable information
  • Privacy Policy: https://sentry.io/privacy

5. Data Sharing and Disclosure

We do NOT sell your personal information.

We may share your information in the following circumstances:

With Your Consent:

  • Messages sent to service professionals (plumbers, electricians, etc.) when you approve them
  • Information shared with property managers you've authorized

Service Providers:

  • Third-party services listed in Section 4 above
  • Only for purposes of providing our service

Legal Requirements:

  • When required by law, court order, or government regulation
  • To protect our rights, property, or safety

Business Transfers:

  • In connection with a merger, acquisition, or sale of assets (you will be notified)

6. Data Security

We implement industry-standard security measures to protect your data:

Encryption:

  • Data encrypted in transit (HTTPS/TLS)
  • Database encryption at rest
  • Secure JWT token authentication

Access Controls:

  • Row-Level Security (RLS) policies enforce data isolation
  • Multi-tenancy isolation prevents cross-property data access
  • Role-based access control (landlord, tenant, agent, admin)

Infrastructure:

  • Hosted on secure cloud platforms (Vercel, Render, Supabase)
  • Regular security updates and patches
  • Automated backups

Note: No method of transmission or storage is 100% secure. While we strive to protect your data, we cannot guarantee absolute security.

7. Data Retention

Active Accounts:

  • We retain your data while your account is active
  • Conversation history maintained for service continuity

Account Deletion:

  • You may request account deletion at any time (contact: privacy@abodient.ai)
  • Upon deletion, we remove personal data within 30 days
  • Some data may be retained for legal/compliance purposes (anonymized where possible)

Backups:

  • Deleted data may persist in backups for up to 90 days
  • Backups are securely stored and eventually purged

8. Your Privacy Rights

Depending on your location, you may have the following rights:

GDPR Rights (EU/UK Users)

  • Access: Request a copy of your personal data
  • Rectification: Correct inaccurate or incomplete data
  • Erasure: Request deletion of your data ("right to be forgotten")
  • Restriction: Limit how we process your data
  • Portability: Receive your data in a machine-readable format
  • Objection: Object to processing based on legitimate interests
  • Withdraw Consent: Withdraw consent for data processing at any time

CCPA Rights (California Users)

  • Know: What personal information we collect and how it's used
  • Delete: Request deletion of your personal information
  • Opt-Out: Opt-out of the sale of personal information (we don't sell data)
  • Non-Discrimination: Equal service regardless of privacy choices

To exercise your rights, contact us at privacy@abodient.ai

9. Children's Privacy

Abodient is not intended for users under 13 years of age. We do not knowingly collect personal information from children under 13. If we discover we have collected data from a child under 13, we will delete it immediately.

10. International Data Transfers

Your information may be transferred to and processed in countries other than your own, including:

  • United States (Supabase, OpenAI, Render hosting)
  • European Union (Supabase EU regions)

We ensure appropriate safeguards are in place for international transfers, including:

  • Standard Contractual Clauses (SCCs) where applicable
  • Compliance with GDPR adequacy decisions
  • Service provider certifications (SOC 2, ISO 27001)

11. AI-Specific Disclosures

How AI Processes Your Data

Our AI assistant ("Alfred") uses:

  • OpenAI GPT models to understand and respond to tenant issues
  • Semantic search on lease/inventory documents
  • Computer vision to analyze uploaded images

AI Data Usage:

  • Chat messages sent to OpenAI API for processing
  • Images analyzed for maintenance issue identification
  • Document chunks embedded for semantic search

AI Data Retention:

  • Conversation history stored in our database (not with OpenAI long-term)
  • Per OpenAI's policy: API data not used for model training (zero retention after processing)
  • You can request deletion of AI-processed data at any time

Automated Decision-Making

We use AI to:

  • Classify maintenance issues and suggest appropriate professionals
  • Analyze documents to extract relevant lease/inventory information
  • Human oversight: Landlords review and approve messages before sending to professionals (unless bypass setting enabled)

12. Cookies and Tracking

Web Application:

  • Session cookies for authentication (Supabase)
  • Service worker for offline functionality (PWA)
  • No third-party advertising/tracking cookies

Mobile Application:

  • Local storage for session management
  • No third-party tracking SDKs

Analytics:

  • LangSmith and LangFuse for AI performance monitoring
  • Anonymized error tracking via Sentry

13. Changes to This Privacy Policy

We may update this Privacy Policy periodically to reflect changes in our practices or legal requirements.

When We Make Changes:

  • Update the "Last Updated" date at the top
  • Notify you via email or in-app notification for material changes
  • Post updated policy at https://abodient.ai/privacy

Your continued use of Abodient after changes constitutes acceptance of the updated policy.

14. Contact Us

For questions, concerns, or requests regarding this Privacy Policy or your personal data:

Email: privacy@abodient.ai

Website: https://abodient.ai

Address: Abodient Ltd, Flat 36 Kimpton Court, 2 Murrain Road, London, N4 2BN

Company Number: 16783207 (registered in England and Wales)

For GDPR/EU inquiries, please include "GDPR Request" in your subject line.

15. Platform-Specific Disclosures

Apple App Store Privacy Nutrition Label

Data Linked to You:

  • Contact Info (email, phone)
  • User Content (messages, photos, property details)
  • Identifiers (user ID, device ID)

Data Not Linked to You:

  • Crash Data (anonymized)
  • Performance Data (anonymized)

Data Used for Tracking: None

Google Play Data Safety

Data Collected:

  • Personal info (name, email, phone)
  • Photos and videos (for issue reporting)
  • Messages (tenant-AI chat history)
  • App activity (usage patterns)

Data Sharing:

  • Shared with service professionals (with your approval)
  • Shared with AI providers (OpenAI) for processing

Data Security:

  • Data encrypted in transit
  • Data encrypted at rest

16. Legal Basis for Processing (GDPR)

We process your personal data based on:

Contract Performance:

  • Providing property management services as agreed

Legitimate Interests:

  • Improving service quality
  • Preventing fraud and ensuring security
  • Marketing our services (with opt-out option)

Consent:

  • AI processing of chat messages and images
  • Sending notifications
  • Sharing data with professionals you approve

Legal Obligation:

  • Compliance with applicable laws
  • Responding to legal requests

You may withdraw consent at any time by contacting privacy@abodient.ai.

17. Additional State-Specific Rights

California (CCPA/CPRA)

  • Right to know what personal information is collected
  • Right to delete personal information
  • Right to opt-out of sale/sharing (we don't sell)
  • Right to correct inaccurate information
  • Right to limit use of sensitive personal information

Virginia (VCDPA), Colorado (CPA), Connecticut (CTDPA)

Similar rights to CCPA for residents of these states

To exercise state-specific rights, email privacy@abodient.ai with your state of residence.

This privacy policy is designed to comply with Apple App Store, Google Play Store, GDPR, CCPA, and other major privacy regulations as of November 2025. We recommend consulting with a legal professional to ensure full compliance with all applicable laws in your jurisdiction.