Version 2026-09-21 · Last updated September 21, 2026
Draft. This document has not yet been reviewed by an attorney. It describes how BrightCMA actually works today and is written in good faith, but it is not final. Questions: [email protected].
This policy explains what BrightCMA collects, why, who else sees it and how long we keep it. It describes how the product actually works today. When that changes, this page changes with it and the version above goes up.
Your name and email address, from the account we create for you, plus your sign-in activity. Used to identify you, sign you in and support you. Passwords are handled by our sign-in system and we never see them.
If you ask for early access from our home page, we store the email address you gave, the time and which form it came from. Used only to tell you when BrightCMA opens. We don't send marketing to that list.
When you use Smart Paste, we store the raw text exactly as you pasted it, alongside what was extracted from it and any corrections you made. Used to fill in the comparable, and kept as the provenance record behind the numbers in your report — so a figure can always be traced back to the text it came from, and so extraction can be re-run as it improves.
Subject and comparable property details, adjustments, pricing, net-proceeds inputs, your report history, and the logo and colours you upload. Used to produce your CMAs.
Property photos you upload, used in your reports and in the PDF you share.
When someone opens a report you shared — usually your client — we record the IP address, browser and time of that view. Used so you can see whether your report was opened, and to detect abuse of a public link. This is the only information we collect about people who are not BrightCMA users, and they see this policy through the link in the report footer.
Standard server logs, which can include IP addresses, and property addresses when a lookup fails. Used to keep the service running and to diagnose faults.
If that ever changes, it changes here first, with a new version and a notice — it will not happen quietly.
Our AI provider is OpenAI, through its API. Three features send data there, and nothing else in BrightCMA does. None of these send your name, your email address or your client's name — but property addresses are sent, as set out below.
Smart Paste first tries to read your pasted text on our own servers. When that does not produce a complete comparable, the entire text you pasted is sent to OpenAI to extract the fields — exactly as you copied it, including anything else caught in the selection, such as listing agent and office details, remarks or tax records. We also send a description of each form field to be filled, so the model knows what to look for. That happens whenever:
When we do read the listing completely on our servers — the normal path for an Unlock MLS listing copied whole — no request is made to OpenAI for that paste.
When you generate pricing for a report, we send the subject property's address, list price, size, bedrooms and bathrooms, year built and property type, and for each comparable its address, sold price, size, bedrooms and bathrooms, year built, days on market and adjusted price. The same request drafts the per-comparable explanations, which also send subdivision, school district, lot size, garage, storeys, pool and fireplace details, and the adjustments already applied.
When you ask for suggested adjustments, we send the subject property and the one comparable being compared: addresses, subdivision, school district, size, bedrooms and bathrooms, lot size, year built, property type, garage, storeys, pool and fireplace details, the subject's list price, and the comparable's sold price, sold date and days on market.
Checked on September 20, 2026, OpenAI's API data policy states that data sent through the API is not used to train or improve its models unless the customer opts in, and that abuse-monitoring logs are retained for up to 30 days. We have not opted in to training, and we have not arranged zero retention, so the 30-day window applies to our requests. We re-check these terms whenever this policy is updated.
AI output is a draft for you to check. It can be wrong, and you decide what reaches your client.
These companies handle your data on our behalf, under their own security and privacy terms:
To fill in property details and place comparables on a map, we look addresses up in public systems. These receive a property address or coordinates. They do not receive your name, your email address or anything identifying you or your client:
Our pages load typefaces from Google Fonts, so your browser contacts Google when a page loads and Google receives your IP address and browser details. We are working to serve these files ourselves instead.
We use only the cookies the application needs to work: one to keep you signed in, one to protect forms against cross-site request forgery, and short-lived cookies during sign-in. There are no advertising or analytics cookies, and we do not track you across other sites. Our network provider may set its own security cookie.
This is current practice, stated plainly rather than aspirationally:
Email [email protected] and we will delete your data, including your reports and the listing text you pasted. Ask and we will confirm when it is done. You can also ask for a copy of your data, or for a correction to anything inaccurate.
We may keep the minimum needed for legal or accounting obligations — payment records, for example — and, as noted above, backups roll off on their own 14-day cycle.
Traffic is encrypted in transit. Access to production systems is limited to the people who operate BrightCMA. Backups are encrypted. No system is perfectly secure, and if a breach affects your data we will tell you.
BrightCMA is a tool for licensed real estate professionals. It is not directed at anyone under 18, and we do not knowingly collect their data.
When this policy changes, the version and date at the top change with it. Significant changes are notified by email to account holders.
Questions, deletion requests or complaints: [email protected].