Data Confidentiality
Last updated: August 18, 2026
You are being asked to connect your inbox and your client book to software you did not write. That is a reasonable thing to hesitate over. This page explains, in plain language, what Pipeflow can see, what it does with it, and what it will never do.
This page is a summary written for clarity. The Privacy Policy is the binding document, and if the two ever appear to disagree, the Privacy Policy governs.
The short version
- We never sell your data. Not to data brokers, not to advertisers, not to anyone.
- We never use your data to train AI models. Neither do our vendors, under our contracts with them.
- We do not read your mail. Access is automated. A human at Pipeflow does not browse your inbox.
- Your data is walled off from other brokerages. Enforced by the database itself, not by application code that could have a bug.
- You can disconnect and delete at any time, directly with Google or Microsoft, without asking us.
What Pipeflow actually sees
Connecting a mailbox is optional. Everything else in Pipeflow works without it.
If you do connect one, here is precisely what is kept:
Stored in your account:
- Who a message is from, its subject line, and a short preview
- When it arrived, and which mailbox it is in
- Whether it has an attachment
- Which of your contacts it matched
- Text pulled out of PDF attachments, where that text contains referral or deal information
Not stored:
- Full message bodies. When you open a message in Pipeflow, it is fetched from Google or Microsoft at that moment and is not kept afterward.
- Attachment files. Where a PDF is read, only the extracted text is saved. The file itself is never stored on our servers.
- Your email password. We never see it. Access is by a token you grant and can revoke.
How the AI part works
Pipeflow reads mail to find referrals you would otherwise lose. That reading is done by a large language model provided by Anthropic.
What that means concretely:
- Message text is sent to Anthropic over an encrypted connection, processed, and a result comes back.
- Under our commercial agreement, that content is not used to train models.
- We do not authorize retention of your content beyond what is needed to return the result.
- What comes back is a draft for you to confirm, not a fact. It can be wrong. You review before it becomes a record.
If you would rather no mail be processed this way, do not connect a mailbox.
Who can see your data
Nobody at another brokerage. Organization separation is enforced by row-level security in the database. A request that is not entitled to a row does not receive it — the isolation is at the data layer, not in application code where a mistake could leak.
Inside your own organization, visibility follows the role structure you configure. Owners and team leads may see records created by people on their team. Your sent mail is scoped to your own account and is not visible to colleagues.
At Pipeflow, access to production data is restricted to what is required to operate and secure the Service — investigating an error you report, responding to a security incident, or complying with a legal obligation. We do not browse customer data, and we do not read your mail for product research.
Where your data lives
| What | Where |
|---|---|
| Your CRM records and message metadata | Supabase (PostgreSQL), United States |
| Application and server functions | Vercel, United States |
| Language model processing | Anthropic PBC, United States |
| Mail access | Google or Microsoft, depending on what you connect |
All connections use TLS encryption. Mail credentials are held server-side and are never exposed to a browser or to another user.
What we ask of you
Pipeflow holds information about your clients — people who never signed up for anything. That responsibility is shared:
- Only connect a mailbox you are entitled to connect. If your brokerage provides it, make sure their policy permits it.
- Only enter client information you are permitted to store in third-party software under your brokerage's policy, your MLS rules, and any confidentiality obligations you carry.
- Review what Pipeflow drafts before you accept it. The AI can misattribute a person or misread a number.
Turning it off
- Disconnect a mailbox inside Pipeflow at any time, or revoke access directly at Google or Microsoft without involving us.
- Delete records individually from within the app.
- Delete your account by contacting support@pipeflowhub.com. See the Privacy Policy for what happens to your data and when.
Honest limitations
We would rather tell you these than have you discover them:
- No system is perfectly secure. We use encryption in transit, database-level isolation, and least-privilege access, and we still cannot promise absolute security. Nobody can.
- AI output can be wrong. Suggestions are drafts. Review them.
- We depend on other companies. Google, Microsoft, Supabase, Vercel, and Anthropic each have their own security posture and their own outages.
- Pipeflow is not your compliance system of record. Keep whatever records your license and your brokerage require.
Questions
Anything about how your data is handled: support@pipeflowhub.com. We will answer.