Privacy
Last updated: August 28, 2026
This is the privacy policy for Property Bot (property.bot), operated by Sterling Cobb. It is not a FlowStay policy.
Public URL: https://property.bot/privacy
Deletion instructions: https://property.bot/privacy#deletion
Who we are
Property Bot is a roommate and room-matching product. Conversation is the product. You call or message us. We learn what you need. We try to match you with a room or a roommate.
Contact for privacy and deletion:
- Call Grahm at +1 (385) 442-9768 (voice only; this number does not do SMS)
- Email sterlingcobb@gmail.com with the subject Property Bot data deletion or Property Bot privacy
- WhatsApp, only after the Meta app is published and you have an open chat
There is no walk-in office and no visitor street address on this site.
What this product does
You can:
- Call +1 (385) 442-9768 and talk to Grahm (xAI / Grok Voice Agent, voice only)
- Use the public website at https://property.bot
- Message a WhatsApp Cloud API test number (the Meta app is unpublished; live inbound user messages are not delivered until publish)
- Call a second Utah number, +1 (385) 453-1919 (Telnyx + Pipecat / Gemini Live). That is not the published marketing number
The matching brain stores a person keyed by phone number, plus the need or room you described and any matches. Live matching runs on Cloudflare Workers + D1. A leftover copy of that graph may still exist on our server. There is no public people-search API.
Match cards shown to our agent runtime are redacted: city, budget band, side, and first name. They do not include phone, last name, or street address.
If both people reply YES, we introduce the pair. That introduction discloses personal information to the other person. Until then we do not hand one person’s phone to another through the matching tools.
Personal information we process
From a voice call
- Phone number (the person key)
- First name or the name you give Grahm
- Structured need or room facts you volunteer (city or area, budget band, timing, pets, and similar)
- A call identifier and a short summary used so the next conversation has context
- “YES” / opt-in replies used to introduce a match, when that path is used
Property Bot does not store call audio files. After a Grok call we store structured person / need / room rows keyed by phone. That graph is kept. Whether xAI / Grok retains audio or transcripts is unknown. On +1 (385) 453-1919 we did not build an audio store; Google / Gemini retention is unknown. This page is not a California all-party recording notice.
From WhatsApp (unpublished)
Our preview Worker keeps secrets (tokens) only. It does not persist inbound message bodies, user phones, or opt-in timestamps. It replies through Meta’s Graph API and returns 200. Meta / WhatsApp hold message content on their side (Cloud API, typically up to 30 days). WhatsApp is not wired to the matching brain yet. When that is wired, this policy will be updated before we store WhatsApp content or a WhatsApp id.
We do not ask for full payment-card numbers or government ID numbers.
From the website
First-party analytics and session replay on https://property.bot go to PostHog US (project 575474, org property.bot). That includes:
- IP address (not anonymized) and GeoIP
- Browser, pages viewed, autocapture, exception autocapture, dead clicks, and heatmaps
- First-party cookies (cookieless mode is off)
- Session replay (on, 30-day retention; form inputs are masked; console and performance capture are on). Anonymous recordings already exist
- Inbound click ids that appear on page URLs (including some
fbclidvalues). Those are stored in PostHog. This is not a Meta Ads destination
The homepage does not call PostHog identify(). There are no ad pixels, no PostHog ad integrations, and no batch exports. We do not claim cookieless mode, replay-off, or the California “we do not sell or share” statement.
Inferences
We may keep structured fields derived from what you said (for example: “needs a room,” city, budget band). We do not rate people.
Children
Property Bot is for people 18 or older. We do not knowingly collect personal information from children.
How we use it
- Answer your call or, after publish, your WhatsApp message
- Remember your need or listing so we can match later
- Propose redacted matches
- Introduce two people after both reply YES
- Operate and debug the site (PostHog first-party analytics, session replay, heatmaps, and autocapture, without phone numbers as identify keys)
- Honor deletion when you ask (see How to request deletion)
- Comply with law and Meta / WhatsApp platform rules
We process WhatsApp / Meta Platform Data only to receive a message, reply, and (when matching is wired) run matching. We do not use WhatsApp data about a person except as needed to message them and run this product. We did not turn on optional Meta AI on Cloud API.
When we disclose information
- Match introductions. After both people reply YES, we introduce them. That is disclosure of personal information to another person.
- Service providers
- Meta / WhatsApp — Cloud API. Meta may retain message content for up to 30 days. This is not end-to-end encryption against Meta. - xAI / Grok — live voice on +1 (385) 442-9768 - Cloudflare — Workers, D1, DNS, the WhatsApp webhook worker, and the voice tunnel - PostHog — first-party website analytics and session replay in the US - Telnyx — DID +1 (385) 453-1919 - Google Gemini Live — voice on that Telnyx path
- Law or safety if required, or to prevent harm.
- A successor if the product is transferred, with notice if we can give it.
We do not sell phone numbers as a contact list. We do not claim the California “we do not sell or share personal information” statement.
WhatsApp, voice, and SMS consent
These are three different consent surfaces. A WhatsApp opt-in does not replace voice or SMS consent.
- Voice. If you call +1 (385) 442-9768, we use the call to interview and match. First turn: “This is Property Bot. We use this call to match rooms and roommates. Privacy is at property.bot/privacy.”
- WhatsApp. We only message a number that opted in (you messaged us, or you were added as a tester). Business name: Property Bot. You can block the business in WhatsApp. A STOP / marketing opt-out handler is not built and is not the same as deleting your matching record. First reply (after publish): “This is Property Bot. We use this message to match rooms and roommates. Privacy is at property.bot/privacy.”
- SMS. The Grok number is voice only. A WhatsApp opt-in is not SMS consent. If we later send SMS on a phone carrier, it will be Telnyx.
Cookies and PostHog
The site sets first-party PostHog cookies. Cookieless mode is off. PostHog in the US receives events, un-anonymized IPs, GeoIP, autocapture, heatmaps, and session replay as described above. Your browser can block or clear cookies; that is not the same as deleting your matching record.
This page is not a cookies-only policy. Voice is a collection point. WhatsApp will be one after publish.
How long we keep information
- Match graph (phone key, need, room, match): while you may still want a match. Closing a need sets an end time and is not deletion. On an explicit delete request we hard-delete the person and related graph rows.
- WhatsApp bodies on Meta’s side: up to 30 days (Meta). We do not persist those bodies on our Worker today.
- Call summary / call id: while tied to your person record
- PostHog events and session replay: replay is kept 30 days; other event retention is that project’s default
- Leftover server copy: a rollback copy of the graph may still exist on our server
Your choices
- Stop WhatsApp: block the business in WhatsApp (STOP handler not built)
- Stop voice: do not call
- Delete your matching record: see How to request deletion
- Limit site analytics: block or clear cookies in your browser (does not delete PostHog copies already stored, and does not delete your matching record)
We do not claim CCPA, CPRA, or Utah Consumer Privacy Act rights. Those laws apply only over their revenue and volume thresholds. At current scale we do not treat Property Bot as a CCPA “business” or a UCPA controller.
Controller
For WhatsApp Business Terms, Sterling Cobb operating Property Bot is the controller of personal information in the matching brain. Meta provides Cloud API. No EU representative is appointed.
Security
Phone numbers are personal information. Bearer tokens stay off the public site. There is no public lookup-by-arbitrary-phone. No internet system is perfectly secure.
How to request deletion
User Data Deletion Instructions for Meta App Dashboard: https://property.bot/privacy#deletion
Closing a need is not deletion. Blocking us on WhatsApp is not deletion.
How to ask
- Call Grahm at +1 (385) 442-9768 and say you want your Property Bot data deleted. We erase the matching record tied to the phone on that call. A mismatched number deletes nothing.
- Email sterlingcobb@gmail.com, subject Property Bot data deletion. In the same thread, confirm the phone you used with Grahm and/or your WhatsApp id. We confirm it is you, then erase that record.
- WhatsApp “please delete”: we confirm identity, then run the same wipe. There is no automatic delete from a WhatsApp message. Do not treat STOP or block as deletion.
What we erase from the graph we control:
messages (to you and match-tied), matches, stays, rooms you own, needs, calls, and your person row (name, brief, phone, WhatsApp id).
What we cannot erase
- Meta WhatsApp copies
- Telnyx carrier logs
- Cloudflare logs
- Grok / xAI recordings and provider logs
- Database backups until they age out
- The email thread used to process the request
- Public site caches (no user matching record there)
- Information the other person already received after a YES introduction
- PostHog events, heatmaps, and session recordings until they age out
We do not implement Meta’s signed data-deletion callback. Facebook Settings → Apps and Websites is Meta’s remove-app flow.
Changes
If we change how we process data (including wiring WhatsApp to matching, or storing audio or transcripts), we will update this page before we rely on that processing.
Notice at collection
Voice (first turn): “This is Property Bot. We use this call to match rooms and roommates. Privacy is at property.bot/privacy.”
WhatsApp (first reply, after publish): “This is Property Bot. We use this message to match rooms and roommates. Privacy is at property.bot/privacy.”