Back to Home

Privacy Policy

Last updated: September 20, 2026

Overview

ROE Engine ("we," "our," or "us") respects your privacy. This policy explains what information we collect, how we use it, and your choices regarding your data. We are committed to protecting your personal and financial information.

Information We Collect

Account Information

When you create an account, we collect your name, email address, and password (stored as a salted, one-way hash). If you enable two-factor authentication, we store an encrypted TOTP secret.

Property & Financial Data

You voluntarily enter property details, mortgage terms, operating expenses, and transaction records. This data is used solely to calculate portfolio metrics and generate recommendations. We never access your bank accounts, brokerage accounts, or credit reports.

You can also upload documents and receipts, such as leases, insurance policies and inspection reports, and keep them with a property or a transaction. We store those files and the details you enter about them. They may include personal information about other people, such as your tenants.

Usage Data

We collect standard web analytics data including pages visited, feature usage, browser type, and device information. This helps us improve the product and diagnose issues.

Cookies & Local Storage

We use essential cookies for authentication and session management. We use local storage to save your UI preferences (e.g., table column order, theme settings). We do not use third-party advertising cookies.

Newsletter Signup

If you sign up for product updates on our marketing pages, we store the email address you provide and the page path you signed up from (for example, /pricing) in our database (hosted by Supabase — see Third-Party Services below). This applies whether or not you have an ROE Engine account. We use this information only to send you product updates, and we retain it until you ask us to remove it. We do not currently send any newsletter emails, so there is no separate unsubscribe link yet — to have your newsletter signup removed, email info@roeengine.com or use our contact form (see Contact Us below).

How We Use Your Information

  • Portfolio Analytics: Calculate ROE, DSCR, cash flow, cap rate, and other metrics based on the data you provide.
  • Recommendations: Generate refinance, hold, and sell recommendations using your property data and current market rates.
  • Market Data Integration: Pull publicly available mortgage rates from the Federal Reserve (FRED API) to power refinance analysis.
  • Account Management: Manage your subscription, send transactional emails (e.g., password resets), and provide customer support.
  • Product Improvement: Analyze usage patterns in aggregate to improve features and fix bugs.
  • Newsletter Signup: Use your email address and signup page solely to send you product updates.

What We Don't Do

  • We never sell, rent, or share your personal or financial data with third parties for marketing purposes.
  • We never access your bank accounts, brokerage accounts, or credit reports.
  • We never use your property data to train machine learning models or for purposes unrelated to your account.
  • We never display third-party advertising.

Data Security

All data is encrypted in transit (TLS 1.2+) and at rest (AES-256, via our database provider's infrastructure-level encryption). Passwords are hashed using bcrypt with per-user salts. Two-factor authentication secrets are encrypted with AES-256-GCM. We enforce access controls, audit logging, and rate limiting on all authentication endpoints.

Third-Party Services

We use the following third-party services to operate ROE Engine:

  • Stripe (payments): Processes subscription payments. We never store your full credit card number — Stripe handles all payment data under PCI DSS compliance.
  • Vercel (hosting): Hosts the application and serves static assets.
  • Supabase (database & file storage): Hosts our PostgreSQL database and stores uploaded owner statement and P&L PDFs, and the documents and receipts you upload.
  • Resend (transactional email): Delivers every email ROE Engine sends — account verification, password reset, portfolio alerts, your digest, the public calculator's optional emailed result, and messages submitted through our contact form. Resend receives the recipient's email address and that email's content, which can include tenant, property, or loan names and portfolio figures such as equity and cash flow for alerts and digests, or your name and a reply-to address for the contact form.
  • Anthropic (Claude API): Uploaded owner statements and P&L documents are sent to Anthropic's Claude API to extract transactions. Anthropic does not use API inputs to train its models and retains them only as needed to provide the service (see Anthropic's commercial terms).
  • Upstash (rate limiting): Stores request counters, keyed by IP address, to enforce rate limits on authentication and other sensitive endpoints.
  • Sentry (error monitoring): When our servers or your browser hit an error, Sentry receives the error message, a stack trace, and the page or request it happened on. While you're signed in, errors captured on our servers — not those from your browser — are also tagged with an opaque account id, never your email or any other personal information, so we can trace an error to an affected account without seeing who it belongs to. A small sample of requests also sends Sentry timing information with aggregate counts (for example, how many properties an analysis covered) — never property names, addresses, or dollar figures. Session Replay, a screen-recording feature, is built into our Sentry setup but its recording rate is set to zero, so no session has ever been recorded.
  • Plausible Analytics (site analytics): Privacy-focused, cookie-free page-view analytics. Plausible receives the page address, the referring site, and your browser and device type — no cookies, no cross-site tracking, and nothing that identifies you.
  • Google (optional sign-in): If you choose “Sign in with Google,” Google tells us your name, email address, and profile picture so we can create or open your account. We never link a Google sign-in to an existing account by email alone, and Google receives nothing about your portfolio.
  • FRED API (market data): Federal Reserve Economic Data, a public data source for mortgage rates and economic indicators. No user data is sent to FRED.
  • RentCast (property valuations): We send a property's address to RentCast to retrieve automated market value and rent estimates.
  • HERE (geocoding): We send a property's address to HERE to determine its ZIP code, county, and coordinates, which power downstream market-data lookups.
  • HUD (Fair Market Rents): We send a property's ZIP code and state — not the full address — to HUD's public API to retrieve Fair Market Rent data.
  • U.S. Census Bureau (demographic data): We send a property's ZIP code to the Census Bureau's public API to retrieve area-level population, income, and housing statistics. No address is sent.
  • Bureau of Labor Statistics (employment data): We send a property's county code to the BLS public API to retrieve local unemployment and employment data. No address is sent.

Data Retention

Your data is retained as long as your account is active. If you cancel your subscription, your data is preserved and your account becomes read-only until you reactivate. You may request full account deletion at any time by contacting support — we will permanently delete all your data within 30 days. When you delete a document or a receipt, its file is kept for about 30 days and is then permanently erased.

Your Rights

Depending on your jurisdiction, you may have the right to:

  • Access and download your personal data
  • Correct inaccurate data
  • Request deletion of your data
  • Object to certain types of data processing
  • Data portability (export your data in a standard format)

To exercise any of these rights, contact us at privacy@roeengine.com.

Children's Privacy

ROE Engine is not intended for use by individuals under the age of 18. We do not knowingly collect personal information from children.

Changes to This Policy

We may update this privacy policy from time to time. Material changes will be communicated via email or an in-app notification. Continued use of the service after changes constitutes acceptance of the revised policy.

Contact Us

If you have questions about this privacy policy or your data, contact us at privacy@roeengine.com.