Privacy
Privacy
Section titled “Privacy”Effective 2026-07. This policy describes the current public beta. It has not been reviewed by an attorney.
Optional beta analytics
Section titled “Optional beta analytics”The landing site and app do not use advertising trackers, analytics cookies, or tracking pixels. Each surface offers an explicit choice under the same limited, first-party analytics contract; browser storage is origin-scoped, so choices are not synchronized across subdomains. Analytics remain off on a surface unless you select Allow limited analytics there. A denial is remembered locally, and Global Privacy Control (Sec-GPC: 1) or Do Not Track (DNT: 1) is honored before an event body is parsed or stored.
When enabled, the browser creates a random ID for the current tab in sessionStorage. It sends coarse journey events such as selecting a landing-page map link, engaging the calculator, submitting the beta form, opening the map, submitting a search, viewing a property page, or receiving a suppressed underwriting result. Calculator values, email addresses, copied link text/URLs, and link destinations are never included. The server immediately replaces the tab ID with a salted one-way hash. The accepted event schema is closed: addresses, coordinates, search text, property/listing IDs, prices, IP addresses, user agents, referrers, free text, and protected-class or demographic/proxy fields have no accepted analytics field and are discarded before storage. No analytics cookie or persistent cross-device identifier is created.
Raw consented events expire after 30 days. Non-identifying daily counts are retained for up to 400 days to compare beta adoption and reliability over time. Selecting Privacy choices → No thanks stops collection and asks the service to delete raw events associated with the current tab session. Previously incremented aggregate counts cannot be tied back to a person or tab and are not decremented. Analytics are used only to improve the product and operate the beta, never for advertising, property scoring, valuation, eligibility, tenant screening, credit, or user profiling.
The docs site does not run this product-analytics client. Infrastructure providers still process ordinary request metadata to deliver and protect the service.
API and MCP access
Section titled “API and MCP access”- Rate limiting and security logs: anonymous rate limits use IP address counters. Most counters are per-Worker memory and roll over after their short rate window. Application logs record request ID, route, response status, latency, and a machine error code when present; they do not log request bodies, addresses, search text, analytics tab IDs, API tokens, or property payloads. Cloudflare may process and retain infrastructure metadata under its own policies. Public value reports store a salted hash of the sender IP for abuse control; the raw IP is not stored in the report row.
- API keys and OAuth: the service stores hashed API-key credentials, user identifiers, scopes, rate limits, and usage metadata. OAuth clients, authorization codes, access tokens, and refresh tokens are stored in Cloudflare KV for their configured lifetime. Plaintext API keys are returned only when an operator creates one. OAuth exchanges do not create a second durable API key.
- Agent usage: metering records use a derived hash/prefix identifier rather than the full bearer token. Tool arguments and agent conversations are not stored as usage records.
- No sale or advertising use: personal data is not sold, rented, or used for advertising.
Address and property lookups
Section titled “Address and property lookups”Address searches are sent first to the U.S. Census geocoder and may fall back to OpenStreetMap Nominatim. A normalized address query and the resulting coordinates may be cached in Cloudflare KV for up to 30 days to reduce repeated geocoder calls. Property coordinates, listing identifiers, and public-record property facts may also be processed by county and third-party data services described in the methodology and data-source pages.
Valuation responses can echo the subject’s listing identifier or geo key, submitted address, coordinates, tract/county, analyzed price and its provenance, unit count and its provenance, and available physical facts. They also include a deterministic inputs_hash used to detect calculation drift. That hash is a reproducibility key, not anonymization and not a security credential. Public API/MCP calculation reads return the artifact without persisting a valuation row; explicit authorized ingest/backtest workflows may store artifacts under the operational retention controls.
Saved state, alerts, notes, and webhooks
Section titled “Saved state, alerts, notes, and webhooks”Authenticated API-key users can store saved properties, underwriting presets, strategy profiles, notes, alert rules, and webhook destinations in D1. Those rows are scoped to the credential owner; the operator credential can administer all rows. Sync events and delivery/usage records are retained according to the service retention job. Webhook payloads are sent to the destination configured by the credential owner.
The production beta currently has a single operator and no self-service consumer account launch. Stored personal state is retained until the operator deletes it, except where an automated retention rule removes operational logs sooner.
Value reports
Section titled “Value reports”The public “report this value” form can store the submitted address or listing identifier, field name, message, optional contact information, creation time, status, and salted IP hash. These reports are retained until the operator resolves or deletes them. Do not submit sensitive personal or financial documents through this form.
Public records
Section titled “Public records”Sales, parcel, assessment, permit, and tax data may come from public records. Individual owner, buyer, seller, grantor, and grantee names are not displayed through consumer or MCP property payloads. Derived property-level flags may be shown without the underlying person’s name.
Retention and requests
Section titled “Retention and requests”Current automated retention removes analytics raw events after 30 days, analytics aggregates after 400 days, short-lived sync events, usage records, old alerts/dead letters, and long-idle revoked credentials on the schedules documented in the operations runbook. Address-geocode cache entries expire after 30 days. Saved state, notes, active credentials, and unresolved value reports otherwise remain until operator deletion.
To request an export, correction, or deletion, use the contact channel published on the Planted Money site. Identity verification will be proportional to the data requested. Data copied from a public-record source can be suppressed from Planted Money display but cannot be deleted from the source agency.
Changes
Section titled “Changes”Material changes will be published here and in the developer changelog before they take effect.
