Who this covers
This policy covers KeyRally: the web app, the public pages we publish for you (single-property pages, open-house sign-in, client portal), and the emails and text messages the service sends on your behalf.
You are the agent. Your clients and open-house visitors are the people whose details you put into the service. This policy explains what we do with both.
KeyRally is operated by QuantumLoop Labs ("we", "us"). You can reach us at support@quantumlooplabs.com.
What we collect
- Account details: your name, email address, phone number if you add one, brokerage name, and your profile branding.
- Documents you upload: purchase contracts, buyer agreements, disclosures, and anything else you file against a deal.
- Deal data: what the contract read produced, plus the deadlines, notes, commissions, expenses and mileage you record.
- People you add: client and lead contact details, open-house sign-ins, and their communication preferences.
- Billing data: your plan, subscription status, and the payment records Stripe returns to us. We never see or store your card number.
- Technical data: sign-in events, IP address, browser type, and error logs used to keep the service running and secure.
What happens to a contract you upload
Your file is stored in our Supabase project (Postgres and object storage, hosted in the United States) under your account, protected by row-level security so other accounts cannot read it.
To read it, we send the document contents to Anthropic’s Claude API with instructions to extract dates, money, parties, contingencies and risks. Anthropic processes that request to return the result to you; API inputs are not used to train models. The extraction comes back to your account.
AI drafts elsewhere in the app - listing copy, follow-up messages, counteroffers, talking points - go through the same API and are always labelled as drafts for you to review.
We do not sell your documents or the data pulled out of them, we do not share them with your broker, and we do not use them to build a product for anyone else.
Service providers we use
We keep the list short and name every one:
- Supabase - authentication, database and file storage (United States).
- Anthropic - reading contracts and generating AI drafts.
- Stripe - subscriptions, deal credits and invoices.
- Render - runs our API servers.
- Netlify and Vercel - host the web app your browser loads.
- Our email provider - transactional email such as deadline reminders, signature requests and portal invitations.
- Twilio - text updates, only when texting is enabled for your account and only to clients who opted in.
- fal.ai - photo enhancement, only for the photos you send through the listing-kit photo tools.
- ATTOM - public property data lookups, only when you use property intel on a listing kit.
- Sentry - crash and error reports from the app when error monitoring is switched on. Reports carry no document contents and no signing or portal links.
Each provider receives only what it needs to do its part, and is bound by its own agreement with us.
Your clients and visitors
When you add a client, capture an open-house sign-in, or invite someone to the portal, you decide what goes in and what we send. You are responsible for having a lawful reason to contact them.
Text updates go only to clients who are marked as opted in, every text identifies you (your name and brokerage, or the sender name set in your team branding), and a client can reply STOP to stop them at any time. Every marketing email carries an unsubscribe link, and you can turn text updates off per client.
If a client asks you to remove their details, delete them in the app. Their client record goes, and their phone number, email address and the wording of the texts and emails sent to or received from them are erased from your message history; an open-house sign-in linked to them loses their name and contact details, and any message still waiting to go to them is cancelled. Two things are not erased: messages matched only by a phone number or email address that another of your clients still uses (they may belong to that client), and buyer representation agreements naming them, which stay as your contract records until you delete them. We also keep the evidence that their choices were honoured: when they opted out of (or back into) texts, with their number stored as a keyed one-way hash that cannot be matched to a number without our secret key, and the consent boxes they ticked at a sign-in. Deal records that name them stay with the deal (see below).
Text message privacy
QuantumLoop Labs LLC uses FieldTempo as its registered messaging Brand for KeyRally. We use a client’s phone number and recorded consent only to send the real-estate transaction updates their agent requested and to honor replies and opt-out requests.
We do not sell or share your SMS opt-in data or personal information with third parties for marketing purposes. Twilio processes phone numbers and message content to deliver and receive these texts as described above.
Keeping and deleting data
Documents and deal records stay until you delete them or close your account. Deleting a document removes its file from storage (a signed document is kept as signing evidence and cannot be deleted). Deleting a deal archives it: it leaves your deal lists, but its records, including the people named in it, stay with your account until the account is closed.
Encrypted backups can hold a copy for up to 30 days after deletion, after which they roll off.
Billing records are kept as long as tax and accounting rules require, even after an account closes.
Your choices
You can view, correct and delete your data in the app at any time. You can ask us for a copy of what we hold, or ask us to delete your account entirely, and we will act on it: the files you uploaded are removed from storage, your account and everything in it (deals, clients, message history) is deleted, your subscription is cancelled, and only the billing records tax and accounting rules require are kept. Unsubscribe requests your clients made to other agents on the platform are not affected.
Depending on where you live you may have additional rights under state privacy laws; we apply the same process to everyone rather than making you prove your zip code.
Security
Traffic is encrypted in transit. Data is separated per account by row-level security in the database, and file access runs through signed, time-limited URLs. Administrative access is limited to the people who keep the service running.
No system is perfect. If a breach ever affects your data, we will tell you what happened and what to do about it.
Changes and contact
If this policy changes in a way that matters, we will say so in the app before it takes effect and update the date at the top of this page.
Questions about privacy, a data request, or a complaint: email support@quantumlooplabs.com or reply to any email the service sends you. A person reads it.