Privacy

Last updated: August 28, 2026

This is the privacy policy for Property Bot (property.bot), operated by Sterling Cobb. It is not a FlowStay policy.

Public URL: https://property.bot/privacy

Deletion instructions: https://property.bot/privacy#deletion

Who we are

Property Bot is a roommate and room-matching product. Conversation is the product. You call or message us. We learn what you need. We try to match you with a room or a roommate.

Contact for privacy and deletion:

There is no walk-in office and no visitor street address on this site.

What this product does

You can:

The matching brain stores a person keyed by phone number, plus the need or room you described and any matches. Live matching runs on Cloudflare Workers + D1. A leftover copy of that graph may still exist on our server. There is no public people-search API.

Match cards shown to our agent runtime are redacted: city, budget band, side, and first name. They do not include phone, last name, or street address.

If both people reply YES, we introduce the pair. That introduction discloses personal information to the other person. Until then we do not hand one person’s phone to another through the matching tools.

Personal information we process

From a voice call

Property Bot does not store call audio files. After a Grok call we store structured person / need / room rows keyed by phone. That graph is kept. Whether xAI / Grok retains audio or transcripts is unknown. On +1 (385) 453-1919 we did not build an audio store; Google / Gemini retention is unknown. This page is not a California all-party recording notice.

From WhatsApp (unpublished)

Our preview Worker keeps secrets (tokens) only. It does not persist inbound message bodies, user phones, or opt-in timestamps. It replies through Meta’s Graph API and returns 200. Meta / WhatsApp hold message content on their side (Cloud API, typically up to 30 days). WhatsApp is not wired to the matching brain yet. When that is wired, this policy will be updated before we store WhatsApp content or a WhatsApp id.

We do not ask for full payment-card numbers or government ID numbers.

From the website

First-party analytics and session replay on https://property.bot go to PostHog US (project 575474, org property.bot). That includes:

The homepage does not call PostHog identify(). There are no ad pixels, no PostHog ad integrations, and no batch exports. We do not claim cookieless mode, replay-off, or the California “we do not sell or share” statement.

Inferences

We may keep structured fields derived from what you said (for example: “needs a room,” city, budget band). We do not rate people.

Children

Property Bot is for people 18 or older. We do not knowingly collect personal information from children.

How we use it

We process WhatsApp / Meta Platform Data only to receive a message, reply, and (when matching is wired) run matching. We do not use WhatsApp data about a person except as needed to message them and run this product. We did not turn on optional Meta AI on Cloud API.

When we disclose information

  1. Match introductions. After both people reply YES, we introduce them. That is disclosure of personal information to another person.
  2. Service providers

- Meta / WhatsApp — Cloud API. Meta may retain message content for up to 30 days. This is not end-to-end encryption against Meta. - xAI / Grok — live voice on +1 (385) 442-9768 - Cloudflare — Workers, D1, DNS, the WhatsApp webhook worker, and the voice tunnel - PostHog — first-party website analytics and session replay in the US - Telnyx — DID +1 (385) 453-1919 - Google Gemini Live — voice on that Telnyx path

  1. Law or safety if required, or to prevent harm.
  2. A successor if the product is transferred, with notice if we can give it.

We do not sell phone numbers as a contact list. We do not claim the California “we do not sell or share personal information” statement.

WhatsApp, voice, and SMS consent

These are three different consent surfaces. A WhatsApp opt-in does not replace voice or SMS consent.

Cookies and PostHog

The site sets first-party PostHog cookies. Cookieless mode is off. PostHog in the US receives events, un-anonymized IPs, GeoIP, autocapture, heatmaps, and session replay as described above. Your browser can block or clear cookies; that is not the same as deleting your matching record.

This page is not a cookies-only policy. Voice is a collection point. WhatsApp will be one after publish.

How long we keep information

Your choices

We do not claim CCPA, CPRA, or Utah Consumer Privacy Act rights. Those laws apply only over their revenue and volume thresholds. At current scale we do not treat Property Bot as a CCPA “business” or a UCPA controller.

Controller

For WhatsApp Business Terms, Sterling Cobb operating Property Bot is the controller of personal information in the matching brain. Meta provides Cloud API. No EU representative is appointed.

Security

Phone numbers are personal information. Bearer tokens stay off the public site. There is no public lookup-by-arbitrary-phone. No internet system is perfectly secure.

How to request deletion

User Data Deletion Instructions for Meta App Dashboard: https://property.bot/privacy#deletion

Closing a need is not deletion. Blocking us on WhatsApp is not deletion.

How to ask

  1. Call Grahm at +1 (385) 442-9768 and say you want your Property Bot data deleted. We erase the matching record tied to the phone on that call. A mismatched number deletes nothing.
  2. Email sterlingcobb@gmail.com, subject Property Bot data deletion. In the same thread, confirm the phone you used with Grahm and/or your WhatsApp id. We confirm it is you, then erase that record.
  3. WhatsApp “please delete”: we confirm identity, then run the same wipe. There is no automatic delete from a WhatsApp message. Do not treat STOP or block as deletion.

What we erase from the graph we control:

messages (to you and match-tied), matches, stays, rooms you own, needs, calls, and your person row (name, brief, phone, WhatsApp id).

What we cannot erase

We do not implement Meta’s signed data-deletion callback. Facebook Settings → Apps and Websites is Meta’s remove-app flow.

Changes

If we change how we process data (including wiring WhatsApp to matching, or storing audio or transcripts), we will update this page before we rely on that processing.

Notice at collection

Voice (first turn): “This is Property Bot. We use this call to match rooms and roommates. Privacy is at property.bot/privacy.”

WhatsApp (first reply, after publish): “This is Property Bot. We use this message to match rooms and roommates. Privacy is at property.bot/privacy.”