Listing Cavy
Privacy Policy
This policy describes what Savalier Technologies LLC collects when you use Listing Cavy, why, who else sees it, how long it is kept, and what you can ask us to do with it. It covers the Listing Cavy web application and nothing else.
What we collect
What you give us
- Account details. Your email address and a password. The password is never stored — only an Argon2 hash of it, which cannot be reversed into the original.
- Your profile. The name, telephone number, email address, website, license number, headshot, brokerage logo, team logo and QR code you choose to add. These exist so they can be printed onto your marketing.
- Listing content. Addresses, prices, property facts, features, photographs and the marketing copy you write.
- Instructions to the image model. The creative selections you make and anything you type into an Advanced or Make Changes field.
What the service records
- Generated images and the settings that produced them, kept as a version history so you can go back to an earlier one.
- Credit activity. An append-only ledger of credits added and spent. Because it is append-only, a mistake is corrected by a compensating entry rather than by deleting the original — an accounting record, not a mutable balance.
- Security events. Sign-ins, password changes, email changes and similar, recorded so you and we can tell whether an account has been misused.
- Server logs containing account identifiers, timestamps and errors. They deliberately do not contain your email address, your marketing copy, your prompts or any key or token.
What we do not collect
There is no analytics service, no advertising pixel, no third-party tracker and no behavioral profiling in this application. We do not buy personal information about you from anyone, and we do not attempt to identify you across other websites.
Cookies
One cookie: the session that keeps you signed in. It is HttpOnly, so JavaScript cannot read it, and it exists only to recognize your browser between requests. There are no advertising or analytics cookies, which is why this application has no cookie banner — there is nothing to consent to.
Nothing of consequence is stored in your browser. The service keeps no drafts, no content and no settings in local storage; the server holds the only copy, which is why closing a tab loses nothing and clearing your browser loses nothing either.
Why we use it
- To run the service: to build your marketing and to show you your own work.
- To place your headshot, logos and QR code onto the pieces you make.
- To meter and bill credits accurately.
- To keep accounts secure and to investigate abuse.
- To send transactional messages — verification, password resets, security notices.
We do not use your content to train any model, our own or anyone else’s. We do not sell personal information, and we do not share it for cross-context behavioral advertising, as those terms are used in California and other state privacy laws.
The image model
Generating a design sends a text prompt and the photographs you selected to OpenAI, which returns an image. The prompt contains the marketing copy you wrote and, where you have switched them on, your contact details — because those are the words that must appear on the finished piece.
OpenAI states that content submitted through its API is not used to train its models by default, and that API inputs and outputs are retained for up to thirty days for abuse monitoring before deletion, unless a legal obligation requires longer. Their terms govern what they do with it, and they may change; this paragraph describes their published policy as of the effective date above and is not a promise on their behalf.
Some assets are deliberately never sent. Where a piece places your headshot, brokerage mark, team mark or QR code by compositing it after generation, that file is withheld from the request entirely and drawn from your own copy afterwards.
Who else sees it
Only the providers needed to operate the service, and only for that purpose:
- OpenAI — image generation, as described above.
- Our hosting and database providers — storage and delivery of the application and your files.
- Our email provider — transactional messages only.
We may also disclose information where the law requires it, or to establish or defend a legal claim. If the business is ever sold or merged, your information may transfer with it; you would be told before any new operator’s policy applied to you.
Other people in your workspace can see the workspace’s listings, assets and generated images. Nothing in your workspace is visible to another customer.
How long we keep it
- Your content — until you delete it, or until a reasonable period after your account closes.
- Uploaded photographs — stored exactly as you supplied them. They are never re-encoded or altered, which also means the original of every photograph remains available to you, something several states now require when a listing image has been digitally modified.
- Credit and billing records — retained as long as tax and accounting obligations require, because they are financial records rather than content.
- Security logs — retained for a limited period and then deleted.
Your rights
Depending on where you live, you may have the right to know what we hold, to get a copy, to correct it, to delete it, to take it elsewhere in a portable form, and to opt out of sale, sharing or targeted advertising. We do not sell or share personal information for advertising at all, so there is nothing for that last right to switch off.
Two dozen US states now have comprehensive privacy laws, and we apply the same practices to everyone rather than asking which state you are in. We honor a Global Privacy Control signal from your browser as an opt-out request.
To exercise any of these, write to a support address that has not been published yet. We will verify that the request comes from you — usually by asking you to send it from the account’s own email address — and answer within the time the applicable law allows. Exercising a right will never mean worse service or a different price.
Some of what you would ask for is already in the application: your content is visible and editable while you are signed in, and account and security settings are under Settings.
Security
Passwords are hashed with Argon2 and screened against known breached-password lists. Every database query is scoped to your workspace, so one customer’s request cannot reach another’s row. Traffic is encrypted in transit. No API key or secret is ever sent to your browser.
No system is perfectly secure, and we do not claim otherwise. If a breach affects your information we will tell you, and the relevant authorities, as the law requires.
Children
Listing Cavy is a business tool for licensed real-estate professionals and is not directed at children. We do not knowingly collect information from anyone under 18. If you believe a child has given us information, write to us and we will delete it.
Changes
If this policy changes in a way that matters, we will raise the version number, change the effective date and tell account holders before the new version applies. Continuing to use the service after that means the new version applies to you.
Contact
Savalier Technologies LLC[[REGISTERED BUSINESS ADDRESS]]
a support address that has not been published yet
See also the Terms of Use.