Draft for legal review

Privacy notice

This draft explains how LeaseChronicle currently handles account, residential tenancy, and evidence information during development.

Draft updated August 14, 2026. This document is not the final launch policy.

Information LeaseChronicle handles

Account and organization information includes email addresses, authentication records, organization names, membership roles, and active-organization preferences.

Landlords may enter property addresses or labels, unit details, tenant names and contact details, lease dates, rent and payment records, maintenance history, notices, communications, case preparation records, and factual timeline entries.

Uploaded evidence may include leases, notices, receipts, photographs, communications, and other tenancy documents. LeaseChronicle also stores file metadata, cryptographic hashes, upload status, and audit activity such as downloads, case preservation, and exports.

How information is used

Information is used to authenticate accounts, organize residential tenancy records, verify evidence integrity, build timelines and case packages, maintain security and audit history, troubleshoot the service, and comply with applicable legal obligations.

LeaseChronicle does not use customer tenancy records for advertising and does not sell personal information.

Limited product analytics

LeaseChronicle records normalized screen names and a random browser-session identifier to understand which workflows are used and where visitors stop. Record identifiers are replaced with generic labels before collection.

This product analytics record does not contain account IDs, email addresses, IP addresses, form entries, tenant information, or evidence metadata. Raw screen-view records are retained for up to 90 days and are used only to improve the service.

Service providers and storage

Supabase provides authentication and PostgreSQL database services. Cloudflare R2 stores private evidence objects. These providers process information to operate their services under their own contractual and privacy terms.

Evidence downloads and uploads use short-lived signed links. Authentication requires session cookies. A first-party analytics cookie holds a random identifier for up to 30 days. The current application does not use third-party advertising cookies.

Retention and deletion

Records are retained while needed to provide the service, maintain security and audit history, meet legal obligations, and support legitimate recordkeeping needs. Preserved cases and attached records are intentionally protected against ordinary editing or deletion.

Authenticated users may submit access, correction, deletion-review, and account-closure requests from Settings. Requests are verified and reviewed before action because preserved records, security logs, legal holds, disputes, and applicable law may require limited retention. A final production retention schedule and backup deletion window require counsel review before launch.

Security

Current safeguards include organization-scoped access controls, private object storage, short-lived download authorization, immutable evidence identity metadata, SHA-256 integrity checks, restricted file formats, server-only audit writes, and security activity history.

No system can guarantee absolute security. Users are responsible for protecting their credentials and should upload only information they are authorized to collect and store. Before every evidence upload, users must review files for Social Security numbers, government IDs, complete financial credentials, and unrelated private information.

Privacy choices and contact

Depending on location, individuals may have rights to request access, correction, deletion, restriction, or a copy of personal information. Account holders can start a verified request from Settings. Requests concerning tenant information require identity and authority review because the tenant may not control the landlord’s underlying legal records.

The final policy must provide the operating company’s legal name, Florida mailing address, monitored privacy email, response deadlines, and jurisdiction-specific disclosures before public launch.

LeaseChronicle is intended for adults managing residential rental records and is not directed to children under 18.