Privacy Policy

Effective 30 July 2026

Plain-English summary

  • Nelkins Technologies FZ-LLC operates Broker OS; Nelkins Properties is the related real-estate agency brand.
  • We collect and process data only to provide the features you choose.
  • We never sell your data or your contacts' data.
  • We do not use Google Workspace data or customer content to train shared or general-purpose AI models.
  • You can disconnect a mailbox, disable style learning, export data or request deletion.

1. Data we collect

Account data: name, email, profile photo where provided by your sign-in provider, broker registration number if you provide it, and authentication and security metadata.

Operational data: contacts, listings, deals, viewings, messages, documents and activities that you create or import into the platform.

Connected-mailbox data: when you expressly connect Google Workspace, Gmail, Outlook or Microsoft 365, we receive the connected email address, provider account identifier, granted OAuth scopes and encrypted OAuth credentials. When read access is granted and a sync runs, we may store sender and recipient addresses, subject, timestamps, provider message and thread identifiers, labels or equivalent metadata, and a bounded message preview of up to 4,000 characters. We do not request permission to delete, archive, label or modify Gmail messages.

Usage data: minimal analytics, error reports and access logs used for security, reliability and support.

Payment data: handled by Stripe. We store customer and subscription identifiers, not card numbers.

2. How we use data

  • Provide, secure and support Broker OS.
  • Send email or messages on your behalf only through user-directed, approved or configured workflows.
  • Synchronise authorised mailbox history into your private CRM workspace.
  • Match email history to contacts, detect replies and suppress inappropriate automated follow-ups.
  • Generate user-facing suggestions and drafts from authorised, tenant-scoped context.
  • Send operational notices such as billing and security alerts.
  • Meet legal obligations and investigate abuse or security incidents.

We do not use contact or mailbox data for advertising, sell it, or disclose it to third parties for their independent marketing purposes.

3. Google Workspace API data and Limited Use

The Google connection requests gmail.send so you can send email from your own authorised address and gmail.readonly so the product can provide the optional private CRM history, reply detection, follow-up suppression and mailbox intelligence described above.

Nelkins Technologies's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

Google Workspace data is used only to provide or improve prominent, user-facing features that the user requests. It is not used to determine creditworthiness, serve advertising, build user profiles for advertising, or train or improve a general-purpose, shared or foundational AI model.

Human access to Google Workspace data is prohibited except when the user gives specific consent for support, access is required to investigate a security or abuse incident, or disclosure is required by applicable law.

4. Optional style learning and AI processing

Style learning is disabled until you separately opt in and mailbox read permission is present. When enabled, the product analyses a bounded set of authorised sent-message previews to derive inspectable features such as greeting style, formality, typical length and preferred terminology. It does not copy an old email verbatim into a campaign.

When you request an AI-assisted draft, relevant tenant-scoped CRM context and, where enabled, derived style features may be sent to an approved AI inference provider acting as a processor. The data is used only to return the requested user-facing result and is not authorised for provider model training. Current processors and purposes are listed in our Sub-processors register.

5. Security and tenant isolation

We use TLS in transit, encryption at rest, encrypted OAuth tokens, scoped database access, role-based access control and audit logging. Sensitive contact identifiers are encrypted and blind-indexed where used for matching. Mailbox and CRM records are scoped to the authorised user and workspace.

6. Retention, disconnection and deletion

OAuth credentials are retained while the mailbox connection remains active. Disconnecting removes stored access and refresh tokens and stops future access. Previously synchronised CRM history is retained so the user's business record does not disappear unexpectedly; it can be removed through the product's deletion controls or a verified deletion request.

We otherwise retain account and operational data while the account is active. On verified account deletion, personal data is removed within 30 days except where retention is legally required. Backups expire under the applicable backup schedule.

7. Sub-processors and international transfers

We use service providers for hosting, database storage, authentication, mailbox APIs, payments, monitoring, message delivery and AI inference. They process data only under our instructions and applicable contractual safeguards. The maintained list is available in the Trust Center.

8. Your choices and rights

  • Disconnect Google or Microsoft at any time from Email settings.
  • Disable or reset optional style learning independently of the mailbox connection.
  • Revoke the app directly from your Google or Microsoft account security settings.
  • Export, correct or request deletion of your account and stored personal data.
  • Object to processing where applicable law permits.

Privacy requests can be sent to privacy@nelkins-os.xyz. We respond within 30 days unless a shorter period is required by law.

9. Children

The service is not intended for anyone under 18.

10. Changes

Material changes will be notified by email or in-product before they take effect where required. The effective date above identifies the current version.