Skip to main content
← TrueCap

Privacy Policy

Last updated: August 23, 2026

TrueCap (“TrueCap,” “we,” “us”) operates the website at usetruecap.com and the related rental property analysis tools (the “Service”). This Privacy Policy explains what information we collect, how we use it, and the choices you have. We've tried to write it in plain English. If anything is unclear, email us at hello@usetruecap.com.

The short version

  • We do not sell, rent, or trade your personal information.
  • We collect what you give us (account info, deals, forms, and optional client-roster data) plus the limited analytics described below.
  • Payments are processed by Stripe — we never see your card number.
  • You can delete your account anytime by emailing us.

1. Information we collect

Information you give us

  • Account info — email address (required) and, if you sign up with Google, your Google account's name and profile picture.
  • Deals you save — property addresses, purchase prices, rents, expenses, and any notes you save against a deal.
  • Agent workspace data — client names and any optional email, phone, Buy Box criteria, or deal assignments an Agent Pro user chooses to save.
  • Forms and branding — contact details, messages, logos, and business information you submit through lead, support, newsletter, or branding forms.
  • Communications — anything you email us at hello@usetruecap.com.

Information collected automatically

  • Usage data — pages visited, calculator actions, broad referrer (e.g. “came from Google Ads”), browser type, approximate location based on IP. Nonessential browser analytics through Google and PostHog follows your cookie choice; Vercel also provides limited operational analytics. When you are signed in, necessary product, account, and billing lifecycle events may be associated with your account ID and email so we can deliver the Service, understand activation, and troubleshoot account-specific issues.
  • Cookies — session cookie for keeping you signed in (set by Supabase Auth), plus analytics and advertising storage only according to the choice you make in our cookie banner. You can reject nonessential analytics.
  • Diagnostics — error, performance, device, and request context used to detect failures and security incidents. Sensitive purchase tokens and encoded share-link paths are scrubbed from diagnostic URLs and event text before events are sent.

Information we do NOT collect

  • Payment card details — Stripe handles those directly.
  • Government-issued ID, SSN, or any KYC data.
  • Property enrichment is retrieved only as part of an address-based analysis or lookup you initiate; we do not continuously monitor unrelated property or transaction records.

2. How we use information

  • To run the Service (save your deals, log you in, render reports).
  • To measure marketing performance (which ads drive signups).
  • To communicate with you about your account, billing, and product updates.
  • To detect abuse, fraud, and security incidents.
  • To comply with legal obligations.

We do not use your saved deal data to train AI models, build resale datasets, or share with third-party advertisers.

You must be signed in to create a new deal share link. The analysis snapshot and its financial assumptions are stored by TrueCap; the exact property address is included only if you choose to disclose it. A new opaque share is associated with your account, expires after 180 days by default, and can be revoked from your account. Anyone with the link can view it without an account, so share it only with people you intend to receive the analysis. Historical opaque links created without account ownership remain viewable until they expire but cannot be managed or revoked. Previously issued legacy links may contain an encoded snapshot in the URL and cannot be remotely revoked; replace those links with a new signed-in share when practical.

3. Third-party services

The following sub-processors help us run TrueCap:

  • Supabase — database, authentication, file storage. Privacy
  • Vercel — hosting + analytics. Privacy
  • Stripe — payment processing. Privacy
  • Google — Places address suggestions, Analytics, Ads, and optional sign-in. Text entered into the address autocomplete and the selected place are processed by Google Places. Privacy
  • PostHog — product analytics and account-lifecycle measurement; nonessential browser tracking follows your cookie choice. Privacy
  • Sentry — error reporting, performance monitoring, and security diagnostics. Privacy
  • Resend — transactional and marketing email delivery, including the recipient address and the content needed to send the message. Privacy
  • RentCast — optional property, sale-comparable, and rent-comparable lookups. The full property address is sent for a requested lookup; your TrueCap account identity is not. Privacy
  • HUD & FRED — public government data sources queried for area rent and national mortgage-rate benchmarks. Requests use the relevant public geography or economic-series identifier, not your TrueCap account identity.

4. How long we keep your data

Account data and saved deals are kept until you delete your account or request deletion. Server logs are generally kept for about 30 days. Analytics, diagnostic, payment, and email-delivery records follow the applicable processor settings and legal requirements. Backups may persist for up to 30 days after deletion.

5. Your rights

Regardless of where you live, you can:

  • Access the personal data we hold about you — email us and we'll send it.
  • Correct inaccurate data — fix it in your account, or email us.
  • Delete your account and all associated data — email hello@usetruecap.com with the subject “Delete my account.”
  • Opt out of marketing emails (unsubscribe link in every marketing email).

If you're in the EU/UK (GDPR) or California (CCPA), you have additional rights including data portability and the right to object to certain processing. Email us to exercise them.

6. Security

We use industry-standard practices: HTTPS everywhere, encrypted database connections, hashed passwords (Supabase Auth), and limited internal access on a need-to-know basis. No system is perfectly secure — if you suspect a security issue, please email us at hello@usetruecap.com.

7. Children

TrueCap is not directed to children under 13. We do not knowingly collect information from anyone under 13. If you believe a child has provided us information, email us and we will delete it.

8. International transfers

We're a U.S.-based service. If you access TrueCap from outside the U.S., your data will be transferred to and processed in the U.S. by us and our sub-processors.

9. Changes to this policy

We'll update the “Last updated” date at the top whenever we make changes. Material changes (e.g. new categories of data we collect) will be announced in-product or by email to active users.

10. Contact

Questions about this policy? Email hello@usetruecap.com.