# Privacy

**Last updated:** August 28, 2026

This is the privacy policy for **Property Bot** (property.bot), operated by **Sterling Cobb**. It is not a FlowStay policy.

Public URL: https://property.bot/privacy

Deletion instructions: https://property.bot/privacy#deletion

## Who we are

Property Bot is a roommate and room-matching product. Conversation is the product. You call or message us. We learn what you need. We try to match you with a room or a roommate.

Contact for privacy and deletion:

- Call Grahm at **+1 (385) 442-9768** (voice only; this number does not do SMS)
- Email **sterlingcobb@gmail.com** with the subject **Property Bot data deletion** or **Property Bot privacy**
- WhatsApp, only after the Meta app is published and you have an open chat

There is no walk-in office and no visitor street address on this site.

## What this product does

You can:

- Call **+1 (385) 442-9768** and talk to Grahm (xAI / Grok Voice Agent, voice only)
- Use the public website at https://property.bot
- Message a WhatsApp Cloud API test number (the Meta app is **unpublished**; live inbound user messages are not delivered until publish)
- Call a second Utah number, **+1 (385) 453-1919** (Telnyx + Pipecat / Gemini Live). That is not the published marketing number

The matching brain stores a **person** keyed by **phone number**, plus the **need** or **room** you described and any **matches**. Live matching runs on **Cloudflare Workers + D1**. A leftover copy of that graph may still exist on our server. There is no public people-search API.

Match cards shown to our agent runtime are redacted: city, budget band, side, and first name. They do not include phone, last name, or street address.

If both people reply YES, we introduce the pair. That introduction discloses personal information to the other person. Until then we do not hand one person’s phone to another through the matching tools.

## Personal information we process

### From a voice call

- Phone number (the person key)
- First name or the name you give Grahm
- Structured need or room facts you volunteer (city or area, budget band, timing, pets, and similar)
- A call identifier and a short summary used so the next conversation has context
- “YES” / opt-in replies used to introduce a match, when that path is used

Property Bot does **not** store call audio files. After a Grok call we store **structured person / need / room rows** keyed by phone. That graph is kept. Whether **xAI / Grok** retains audio or transcripts is **unknown**. On **+1 (385) 453-1919** we did not build an audio store; **Google / Gemini** retention is **unknown**. This page is not a California all-party recording notice.

### From WhatsApp (unpublished)

Our preview Worker keeps **secrets** (tokens) only. It does **not** persist inbound message bodies, user phones, or opt-in timestamps. It replies through Meta’s Graph API and returns 200. **Meta / WhatsApp** hold message content on their side (Cloud API, typically up to 30 days). WhatsApp is **not** wired to the matching brain yet. When that is wired, this policy will be updated **before** we store WhatsApp content or a WhatsApp id.

We do not ask for full payment-card numbers or government ID numbers.

### From the website

First-party analytics and session replay on https://property.bot go to **PostHog US** (project **575474**, org **property.bot**). That includes:

- IP address (**not** anonymized) and GeoIP
- Browser, pages viewed, autocapture, exception autocapture, dead clicks, and heatmaps
- First-party cookies (cookieless mode is off)
- Session replay (on, 30-day retention; form inputs are masked; console and performance capture are on). Anonymous recordings already exist
- Inbound click ids that appear on page URLs (including some `fbclid` values). Those are stored in PostHog. This is **not** a Meta Ads destination

The homepage does **not** call PostHog `identify()`. There are **no** ad pixels, **no** PostHog ad integrations, and **no** batch exports. We do **not** claim cookieless mode, replay-off, or the California “we do not sell or share” statement.

### Inferences

We may keep structured fields derived from what you said (for example: “needs a room,” city, budget band). We do not rate people.

### Children

Property Bot is for people **18 or older**. We do not knowingly collect personal information from children.

## How we use it

- Answer your call or, after publish, your WhatsApp message
- Remember your need or listing so we can match later
- Propose redacted matches
- Introduce two people after both reply YES
- Operate and debug the site (PostHog first-party analytics, session replay, heatmaps, and autocapture, without phone numbers as identify keys)
- Honor deletion when you ask (see [How to request deletion](#deletion))
- Comply with law and Meta / WhatsApp platform rules

We process WhatsApp / Meta Platform Data only to receive a message, reply, and (when matching is wired) run matching. We do not use WhatsApp data about a person except as needed to message them and run this product. We did not turn on optional Meta AI on Cloud API.

## When we disclose information

1. **Match introductions.** After both people reply YES, we introduce them. That is disclosure of personal information to another person.
2. **Service providers**
   - **Meta / WhatsApp** — Cloud API. Meta may retain message content for up to 30 days. This is **not** end-to-end encryption against Meta.
   - **xAI / Grok** — live voice on +1 (385) 442-9768
   - **Cloudflare** — Workers, D1, DNS, the WhatsApp webhook worker, and the voice tunnel
   - **PostHog** — first-party website analytics and session replay in the US
   - **Telnyx** — DID +1 (385) 453-1919
   - **Google Gemini Live** — voice on that Telnyx path
3. **Law or safety** if required, or to prevent harm.
4. **A successor** if the product is transferred, with notice if we can give it.

We do not sell phone numbers as a contact list. We do **not** claim the California “we do not sell or share personal information” statement.

## WhatsApp, voice, and SMS consent

These are three different consent surfaces. A WhatsApp opt-in does **not** replace voice or SMS consent.

- **Voice.** If you call +1 (385) 442-9768, we use the call to interview and match. First turn: “This is Property Bot. We use this call to match rooms and roommates. Privacy is at property.bot/privacy.”
- **WhatsApp.** We only message a number that opted in (you messaged us, or you were added as a tester). Business name: **Property Bot**. You can block the business in WhatsApp. A STOP / marketing opt-out handler is **not** built and is **not** the same as deleting your matching record. First reply (after publish): “This is Property Bot. We use this message to match rooms and roommates. Privacy is at property.bot/privacy.”
- **SMS.** The Grok number is voice only. A WhatsApp opt-in is not SMS consent. If we later send SMS on a phone carrier, it will be **Telnyx**.

## Cookies and PostHog

The site sets **first-party PostHog cookies**. Cookieless mode is off. PostHog in the US receives events, un-anonymized IPs, GeoIP, autocapture, heatmaps, and session replay as described above. Your browser can block or clear cookies; that is not the same as deleting your matching record.

This page is not a cookies-only policy. Voice is a collection point. WhatsApp will be one after publish.

## How long we keep information

- **Match graph** (phone key, need, room, match): while you may still want a match. Closing a need sets an end time and is **not** deletion. On an explicit delete request we hard-delete the person and related graph rows.
- **WhatsApp bodies on Meta’s side:** up to 30 days (Meta). We do not persist those bodies on our Worker today.
- **Call summary / call id:** while tied to your person record
- **PostHog events and session replay:** replay is kept 30 days; other event retention is that project’s default
- **Leftover server copy:** a rollback copy of the graph may still exist on our server

## Your choices

- Stop WhatsApp: block the business in WhatsApp (STOP handler not built)
- Stop voice: do not call
- Delete your matching record: see [How to request deletion](#deletion)
- Limit site analytics: block or clear cookies in your browser (does not delete PostHog copies already stored, and does not delete your matching record)

We do **not** claim CCPA, CPRA, or Utah Consumer Privacy Act rights. Those laws apply only over their revenue and volume thresholds. At current scale we do not treat Property Bot as a CCPA “business” or a UCPA controller.

## Controller

For WhatsApp Business Terms, **Sterling Cobb operating Property Bot is the controller** of personal information in the matching brain. Meta provides Cloud API. No EU representative is appointed.

## Security

Phone numbers are personal information. Bearer tokens stay off the public site. There is no public lookup-by-arbitrary-phone. No internet system is perfectly secure.

## How to request deletion {#deletion}

**User Data Deletion Instructions** for Meta App Dashboard: `https://property.bot/privacy#deletion`

Closing a need is **not** deletion. Blocking us on WhatsApp is **not** deletion.

**How to ask**

1. **Call** Grahm at +1 (385) 442-9768 and say you want your Property Bot data deleted. We erase the matching record tied to the phone on that call. A mismatched number deletes nothing.
2. **Email** sterlingcobb@gmail.com, subject **Property Bot data deletion**. In the same thread, confirm the **phone** you used with Grahm and/or your **WhatsApp id**. We confirm it is you, then erase that record.
3. **WhatsApp** “please delete”: we confirm identity, then run the same wipe. There is no automatic delete from a WhatsApp message. Do not treat STOP or block as deletion.

**What we erase** from the graph we control:

messages (to you and match-tied), matches, stays, rooms you own, needs, calls, and your person row (name, brief, phone, WhatsApp id).

**What we cannot erase**

- Meta WhatsApp copies
- Telnyx carrier logs
- Cloudflare logs
- Grok / xAI recordings and provider logs
- Database backups until they age out
- The email thread used to process the request
- Public site caches (no user matching record there)
- Information the other person already received after a YES introduction
- PostHog events, heatmaps, and session recordings until they age out

We do not implement Meta’s signed data-deletion callback. Facebook Settings → Apps and Websites is Meta’s remove-app flow.

## Changes

If we change how we process data (including wiring WhatsApp to matching, or storing audio or transcripts), we will update this page **before** we rely on that processing.

## Notice at collection

**Voice (first turn):** “This is Property Bot. We use this call to match rooms and roommates. Privacy is at property.bot/privacy.”

**WhatsApp (first reply, after publish):** “This is Property Bot. We use this message to match rooms and roommates. Privacy is at property.bot/privacy.”
