Data we handle
BrokerOS processes information supplied by the brokerage, its authorized users, and the systems the brokerage chooses to connect. Depending on the package and configuration, that can include:
- Brokerage configuration: organization profile, terminology, offices, teams, markets, service package, roles, permissions, scopes, owners, and support contacts.
- People and account information: names, work contact details, recipient addresses, account identity, role assignments, invitation state, and access status.
- Relationship work: watched people, pipeline stage, notes, tasks, follow-up dates, meetings, contact history, outcomes, onboarding answers, and document status.
- Reports and delivery evidence: report definitions, audiences, schedules, source snapshots, exact rendered artifacts, delivery attempts, provider events, suppressions, and authorized engagement evidence.
- Security and operations records: authentication events, privileged changes, support access, source health, error context, and audit records needed to operate and protect the service.
- Public-site performance: page-load and performance measurements collected through Cloudflare Web Analytics to maintain the public website. BrokerOS does not use those measurements for advertising.
- Public inquiries: the name, work email, brokerage details, phone number, and message a visitor chooses to submit when requesting a conversation with BrokerOS.
Connected brokerage sources
BrokerOS uses only sources the brokerage authorizes and that the running product supports. A standard package may use MLS or RESO market and agent-activity data. An Enhanced package may also use authorized internal production, pipeline, roster, office, or related brokerage data.
Source access is tenant-specific. BrokerOS does not use one brokerage's source connection, credentials, or records to serve another brokerage. Unsupported or incomplete source combinations remain inactive.
BrokerOS does not write back to an MLS or an internal brokerage source unless a future connection is separately identified, authorized, and disclosed.
Connected Google Workspace and Microsoft 365 accounts
Connecting a work account is optional. Calendar and email are separate connections, and BrokerOS requests each permission only when the user chooses that feature.
- Account identity. BrokerOS receives the provider account ID and email address needed to bind the connection to the correct authenticated user and brokerage.
- Calendar. BrokerOS uses calendar-event access to create, update, and remove private BrokerOS task and meeting events. BrokerOS does not list, copy, or analyze unrelated calendar events and does not add a recruit or another person as an attendee unless the user explicitly chooses a future attendee feature.
- Email. BrokerOS requests send access so it can send a message from the connected work account after the user approves the message. BrokerOS does not request permission to read, search, download, or monitor the mailbox.
- Authorization credentials. Refresh tokens are stored using authenticated encryption. Short-lived access tokens stay on the server and are not returned to the browser or written into an audit record.
Google account information is handled in accordance with the Google API Services User Data Policy, including its Limited Use requirements.
Jet and assisted work
When an authorized user asks Jet a question or requests an update, BrokerOS may send the prompt and the minimum permitted context needed to a configured model provider. The available context and tools depend on the user's brokerage, role, scope, page, package, and connected sources.
Tool actions remain subject to the same server permissions and confirmation rules as direct controls. BrokerOS records tool activity for security and accountability. BrokerOS does not use customer content to train a general-purpose BrokerOS model.
How data is used
BrokerOS uses customer data to authenticate users, enforce brokerage and role boundaries, operate relationship workflows, prepare and deliver configured reports, complete explicitly requested calendar or email actions, support onboarding and signing, maintain audit history, respond to support requests, and improve service reliability.
BrokerOS does not sell customer data, transfer it to data brokers, use it for third-party advertising, or expose private brokerage records to another tenant.
Security and tenant boundaries
BrokerOS uses managed authentication, server-side permission checks, database row-level security, encryption in transit, encrypted provider credentials, scoped service access, rate limits, immutable audit records, and monitored delivery boundaries. Support access is explicit, time-limited, read-only, and audited.
No security program eliminates every risk. Customers are responsible for maintaining accurate user access, protecting account credentials, and promptly removing access that is no longer needed.
How long data is kept
BrokerOS retains active customer data for as long as needed to provide the service and meet the applicable customer agreement. Exact report artifacts, delivery evidence, signing evidence, security events, and other audit records may be retained longer when needed for accountability, dispute handling, or legal obligations.
Disconnecting Calendar or Email removes the stored refresh token and stops future provider access. Existing calendar events or sent messages remain with the provider. Connection metadata and security audit records may remain, but they do not contain a usable provider token.
Your choices
Authorized brokerage administrators can manage users, recipients, roles, sources, delegated connections, report audiences, and activation inside BrokerOS. A user may also revoke BrokerOS from Google or Microsoft account settings.
Requests to access, correct, export, or delete personal information can be sent to jonathan@getbrokeros.ai. The response and available action may depend on the brokerage's instructions, the customer agreement, and applicable retention obligations.
Children
BrokerOS is a business service for real estate brokerages and their authorized users. It is not directed to anyone under 18, and BrokerOS does not knowingly collect personal information from children.
Changes and contact
Material changes to this policy will be reflected on this page and communicated to active customers when appropriate.
Questions about this policy can be sent to jonathan@getbrokeros.ai.
Last updated / July 28, 2026