Privacy Policy

RateSpot, Inc. (“RateSpot,” “we,” “us,” or “our”) · Last updated: September 11, 2026

This Privacy Policy describes how RateSpot collects, uses, discloses, and retains information in connection with the RateSpot website and account services, the RateSpot MCP (Model Context Protocol) server available at https://mcp.ratespot.io/mcp and related APIs (collectively, the “Services”). The Services provide real-estate, property, and mortgage data tools to AI assistants, including clients such as ChatGPT, and other software clients.

This policy applies to the Services. Third-party applications that connect to RateSpot may also process information under their own privacy policies.

If you have questions about our privacy practices, contact us at [email protected].

1. Information we collect

A. Information you provide to us

Account information. When you register for an account at ratespot.io/register, we collect your name, email address, and username. Depending on how you access the Services, RateSpot may authenticate you using an API key or an OAuth authorization flow. For API keys, we store only a cryptographic (SHA-256) hash of the key — never the plaintext key.

Communications. If you contact us for support or other inquiries, we collect the contents of those communications and any contact information you provide.

Queries and tool parameters. To fulfill your requests, we process the parameters you submit through the Services — for example, property addresses, geographic locations, loan scenarios (amounts, LTV, credit score ranges), and natural-language queries. When you use RateSpot through an AI assistant such as ChatGPT, the assistant may send the information needed to perform the tool request to RateSpot. We do not ask for, and you should not submit, sensitive personal information (such as Social Security numbers, full credit reports, or government IDs) through the Services.

B. Information collected automatically

Identifiers.For each API request we record a client identifier: for registered users, your account ID; for unregistered (“anonymous”) callers, a truncated SHA-256 hash derived from your IP address and browser/client User-Agent string. We use this pseudonymous identifier for rate-limiting and abuse prevention; it is not designed to identify you personally.

Authentication and session data. When you sign in, register, or authorize an integration through our website, we may process authentication tokens and use strictly necessary session cookies or similar technologies to maintain the authentication or authorization flow. These technologies are not used for advertising or cross-site behavioral tracking.

Usage data. We record each tool invocation: the tool name, timestamp, and daily usage counts (in aggregate and per tool, per client). This powers quota enforcement, billing, and service transparency.

Log data. Our servers and network providers automatically record IP address, User-Agent, request paths, timestamps, and error information in rolling operational logs.

C. What we do not collect

2. How we use your information

We use the information we collect to:

3. Routing data and retention-limited storage

When you use our natural-language tool-routing feature, your query text and the resulting tool plan may be stored to improve routing quality for all users. These records are not linked to your account identity. Their lifecycle:

This process runs automatically on a daily schedule.

4. How we disclose information

We do not sell your personal information, and we do not share it with third parties for their own marketing purposes. We disclose information only as follows:

Service providers (processors). We engage third-party companies to perform services on our behalf, and they may process information strictly as needed to provide those services to us, under contractual obligations consistent with this policy:

Category of providerWhat may be sharedPurpose
Property & real-estate data providersProperty addresses, parcel identifiers, geographic locationsRetrieve property details, valuations, ownership and comparable data
Mortgage & financial data providersLoan scenario parameters (amount, LTV, credit score ranges, location)Retrieve rate quotes and loan product data
AI/LLM infrastructure providersNatural-language queries and tool metadataTool routing, embeddings, and language-model processing
Email delivery providersRecipient email address and message content you explicitly ask us to sendTransactional email delivery
Geocoding providersLocation stringsConvert addresses/places to coordinates
Cloud hosting & infrastructure providersAll Service data (in transit/at rest)Hosting, compute, storage
Content delivery & network security providersRequest metadata (IP, headers)TLS termination, DDoS protection, performance

Connected AI clients.If you choose to connect RateSpot to an AI assistant or other software client, that client may send requests and information to RateSpot and receive tool results from RateSpot according to the actions you initiate. The client's handling of information is governed by its own terms and privacy policy.

Legal and safety. We may access, preserve, and disclose information if we in good faith believe it is required or appropriate to comply with law, regulation, legal process, or governmental request; enforce our agreements; or protect the rights, property, or safety of RateSpot, our users, or others.

Business transfers. If RateSpot is involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to this policy or notice to you as required by law.

Aggregated or de-identified data. We may use and disclose aggregated or de-identified information that cannot reasonably be linked to you for analytics, research, and service improvement.

5. Data retention

DataRetention
Account profile (name, email, username)Until you delete your account
API key hashUntil key rotation or account deletion
Authentication/session dataFor the duration needed to maintain the applicable session or authorization, subject to expiration and revocation
Daily usage counters (aggregate + per-tool)Approximately 25 hours (expires shortly after each UTC day)
Tool response caches5 minutes to 7 days, depending on data volatility
Routing records: raw text/parameters/reasoning30 days, then permanently anonymized
Routing records: anonymized structure90 days, then deleted
Operational server logsRolling short-term retention (days)

We retain information only as long as necessary for the purposes described in this policy, or as required by law.

6. Your choices and rights

Depending on your jurisdiction, you may have the right to:

To exercise any of these rights, email [email protected]. We will take reasonable steps to verify your identity (for example, by confirming control of your account email) before fulfilling a request, and will respond within the timeframe required by applicable law.

Note on anonymous and anonymized data. Pseudonymous usage counters (hashed identifiers) and fully anonymized routing records cannot reasonably be linked back to you; we therefore may be unable to locate or delete them in response to an individual request.

Marketing communications. We do not send marketing email from the Services. Any transactional email you receive (such as a report you explicitly requested) cannot be opted out of while using that feature.

Do Not Track. We do not use third-party advertising trackers. Browser Do Not Track signals do not change the operation of strictly necessary account, session, authentication, or security functionality.

7. California residents

Under the California Consumer Privacy Act (CCPA), California residents have specific rights regarding their personal information:

8. Security

We maintain technical and organizational measures appropriate to the nature of the data we process, including: TLS encryption in transit; hashed (never plaintext) storage of API keys; authentication gating on paid-data tools with per-call audit logging; private, non-publicly-routable networks for our databases; and firewall-restricted internal service segments. No system is 100% secure; if we learn of a breach affecting your personal information, we will notify you as required by law.

9. International data transfers

The Services are operated from the United States. If you access the Services from outside the U.S., you understand that your information will be transferred to, processed, and stored in the U.S., where data protection laws may differ from those in your jurisdiction.

10. Children’s privacy

The Services are intended for general business audiences and are not directed to children under 13. We do not knowingly collect personal information from children under 13; if we learn we have, we will delete it promptly.

11. Third-party sites and services

The Services may interact with third-party websites, data sources, and applications (including AI assistants and other clients you use to reach us). Their privacy practices are governed by their own policies, which we encourage you to read. We are not responsible for third-party practices.

12. Changes to this policy

We may update this Privacy Policy from time to time. We will post the revised policy at this URL and update the “Last updated” date. For material changes, we will provide additional notice (such as by email to registered users) as required by law. Continued use of the Services after the effective date constitutes acceptance of the updated policy.

13. Contact us

RateSpot, Inc.
Email: [email protected] — privacy questions, access/correction/deletion requests, and security reports.