Privacy Policy
Last updated: August 7, 2026
1. Who We Are
RentAuth ("we", "us", or "our") operates the RentAuth platform at rentauth.ca and rentauth.app. We are based in Toronto, Ontario, Canada. This policy describes how we collect, use, and protect your personal information in accordance with the Personal Information Protection and Electronic Documents Act (PIPEDA).
2. What We Collect
We collect the following categories of personal information:
- Account data: name, email address (via Clerk authentication)
- Profile data: name, phone number (optional), occupation, employer, annual income, credit score — provided voluntarily by renters
- Rental documents: government-issued ID, proof of income, credit report, rental history, and rental application forms — uploaded voluntarily by renters
- Student & newcomer documents: if you identify as a student or newcomer, you may also upload immigration status documents (study or work permits), bank statements, school enrollment letters, sponsor support letters, and Canadian employment letters — all uploaded voluntarily
- Sponsor & guarantor information: you may add a guarantor (a co-signer) to your household and may upload a sponsor's bank statement to demonstrate financial backing. These items contain another person's personal information — by uploading them you confirm you have that person's consent to share their information with RentAuth and with any landlord you choose to share your profile with
- AI verification data: when you request verification, your uploaded documents and profile data are analyzed by our AI verification agent (Vera) to produce a Verification Report. We store the extracted structured fields (e.g. document type, employment status, income range) and the resulting report. We do not store raw document content beyond what you upload.
- Identity verification data (Stage 2): if you complete Stage 2 verification, you provide government-issued ID and a live selfie to our identity provider (Persona). Persona returns a verified name, date of birth, and a pass/fail outcome; we store the outcome plus the identity provider's inquiry reference. We do not store the selfie or the raw ID image.
- Payment authorization data (Stage 2): Stage 2 uses a Stripe authorize-and-capture hold ($1 CAD authorization released after verification completes). We store only the Stripe payment intent reference and status — never your card number or CVV, which are entered directly with Stripe.
- Pre-screening answers: when you inquire about a listing, you may answer standard pre-screening questions (move-in date, occupant count, employment status, income band, pet ownership, parking need). Answers are shared with the specific landlord you inquired with and are drawn from a fixed code-owned bank that never asks about protected grounds under the Ontario Human Rights Code.
- AI chat conversations: if you ask a question in the "Ask a question" chat on a listing page, your message and the AI response are stored so the landlord can review the conversation and improve their listing. If your message discloses information touching a Human Rights Code protected ground (family status, disability, religion, etc.), we neutralize the AI reply and flag the exchange for compliance review; the landlord never sees the disclosure.
- Sharing & access records: when you share your profile with a property professional, we record the connection (who has access), when consent was granted, when it was revoked, and each time your documents are viewed (viewer identity, timestamp, IP, and user-agent). This is the audit trail that lets you see who has looked at your information.
- Anonymous format patterns: after a successful verification we store anonymized structural fingerprints of your documents (e.g. pay frequency, whether an HR contact was present, salary range bracket) to improve future verification accuracy. These patterns contain no names, dates, document numbers, or identifying information.
- Usage data: pages visited, features used, timestamps — collected via PostHog analytics (only with your consent)
3. Why We Collect It
- To provide the RentAuth verification service
- To allow renters to share a verified profile with landlords and agents
- To run AI-powered verification analysis when you request it (Vera)
- To answer renter questions about a listing using an AI chat grounded only in what the landlord has authored
- To confirm the identity of a renter or property professional when they opt into Stage 2 verification (via Persona)
- To authorize the one-time Stage 2 payment hold via Stripe
- To improve the accuracy of our verification system over time using anonymized structural patterns
- To improve the platform and fix bugs
- To send transactional emails (viewing confirmations, notifications)
- To maintain a compliance audit log of AI decisions and document views
We do not sell your personal information to third parties.
4. AI Processing
RentAuth uses Anthropic's language models for a small number of tightly-scoped tasks. Every AI call is made through Anthropic's API under the following terms:
- Not used for AI training: under Anthropic's API terms, data submitted via the API is not used to train their models.
- Transient processing: content is transmitted to Anthropic's API solely to generate the specific output described below and is not retained by Anthropic beyond the duration of the API call.
The four AI-backed surfaces:
- Vera verification analysis— when you click "Get Verified by Vera", your uploaded documents and self-reported profile data are analyzed to produce a Verification Report. Explicit and opt-in — verification only runs when you press the button. Vera returns structured fields (employer name, income range, document type, etc.) and a verification score. The raw document images/PDFs remain in your storage under your account. You may re-run verification at any time; previous reports are replaced.
- Landlord FAQ chat— when you ask a question on a listing page, we send your question plus the landlord's authored listing facts and FAQs to the model. The model is instructed to answer onlyfrom those sources and to refuse (with a clear "flagged for the landlord" response) if the answer isn't present. We do not send your account, profile, or documents to the model on this surface.
- Answer normalization— when you answer a pre-screening question in your own words, the model converts your free-form answer into the structured value the question expects (e.g. "early September" → "2026-09-01"). Only the question text, the expected shape, and your answer are sent.
- HRC classifier — when a landlord adds a custom FAQ to their listing, the FAQ text is sent to the model to check whether it touches an Ontario Human Rights Code protected ground (family status, religion, disability, etc.). No renter data is sent on this surface.
By clicking "Get Verified by Vera" or by sending a message in the listing chat, you consent to the corresponding processing above.
5. Identity Verification and Payment (Stage 2)
Stage 2 is an optional deeper verification tier that combines a live identity check (Persona) with a small payment authorization (Stripe). You only enter Stage 2 by starting it yourself from your dashboard.
- Persona identity check: you upload a government-issued ID and complete a live selfie on Persona's hosted flow. Persona returns a verified name and a pass / needs-review / fail outcome to us. We store only the outcome and the Persona inquiry reference — never the selfie or the raw ID image.
- Stripe authorization: Stage 2 places a temporary $1 CAD hold on your card via Stripe (auth-and-capture). The hold is released automatically after your verification result is settled. Card details are entered directly with Stripe; RentAuth never receives your card number, CVV, or expiry.
- Refunds and cancellations: if verification cannot be completed or if you cancel, the hold is released and no charge is finalized.
6. Document Access and Sharing
Your uploaded documents are private by default. You control who can see them through three explicit choices:
- Private (default): only you can view your documents from your own dashboard.
- Individual professional connection: when you connect with a specific landlord or property manager and grant them analysis consent, that specific professional can view the documents you've uploaded. Every view they perform is recorded (viewer, timestamp, IP, user-agent). You can revoke the connection at any time; revocation takes effect immediately.
- Public profile with documents unlocked: if you publish your profile and toggle "documents unlocked", anyone with your profile link can view your documents. This is the broadest sharing option and is off by default.
Watermarking:every document view — whether by you, a connected professional, or an anonymous viewer on your public profile — is watermarked with the viewer's identity (or "public preview") and the exact timestamp of the view. The watermark is burned into the page pixels, so screenshots and downloads carry it too. This is intentional: it means a leaked screenshot can always be traced back to the specific session that produced it.
What professionals see: a landlord viewing your Vera Verification Report sees per-category outcomes (identity: passed / needs review / failed; income: passed / needs review / failed; etc.). They do not see the numeric Vera score — RentAuth never surfaces the score to any professional-facing view, because a numeric score can carry adverse-decision liability under Canadian human rights law. You can see your own score on your own dashboard.
Chat message anchoring: when the AI chat detects that your message touched a protected ground, the flag is anchored to your original message in the compliance audit — not to the neutralized AI reply — so the landlord never sees the disclosure but our review process can.
7. Data Retention
We retain your data for as long as your account is active. You may request deletion of your account and all associated data at any time from your dashboard settings. Upon deletion, your documents are removed from storage and your profile is permanently erased within 30 days.
Two types of records survive account deletion for a limited period, because they are required for regulatory compliance and dispute resolution:
- Document view audit log: the record of which professional viewed which document, and when, is retained for two years so the audit trail remains reliable for both parties in any subsequent dispute.
- Consent and revocation events: the timeline of consents you granted (analysis consent, Stage 2 opt-in) and revocations is retained for two years for the same reason.
These surviving records contain identifiers and timestamps only — no document contents, no financial details, no chat messages.
8. How We Protect Your Information
We apply layered safeguards appropriate to the sensitivity of the information we hold:
- Private document storage: uploaded documents are kept in a private storage bucket and are never publicly accessible. Access is always mediated by the server, which checks that you or the viewer has an explicit grant (owner, active connection with consent, or public-unlocked profile) for every page fetched.
- Per-viewer watermarking: every document view is served through a proxy that composites an identity + timestamp watermark into the page pixels. No shared cache stores watermarked images (server responses are marked no-store), so one viewer's identity can never leak into another viewer's response.
- Encryption in transit: all traffic to and from RentAuth is encrypted over HTTPS.
- Database access controls: row-level security is enabled on all data tables with a deny-all default. Your data is reachable only through our authenticated server — never directly from the browser.
- Signed webhooks: incoming events from Persona, Stripe, and Clerk are cryptographically signature-verified before we act on them, and we support dual-secret rotation so signing keys can be rolled without downtime.
- Abuse protection: sensitive endpoints are rate-limited to guard against automated abuse and scraping.
- Authentication: sign-in is handled by Clerk; RentAuth never stores your password.
- Internal access controls: administrative review of profiles and documents is gated to staff with an explicit admin role assigned in our identity provider. Other team members cannot view your data.
- AI safety guardrails: pre-screening questions are drawn from a fixed code-owned bank that never asks about protected grounds; a two-layer check (regex blocklist + AI classifier) reviews custom landlord FAQs before they can be published; grounded-only AI replies refuse questions we can't answer from the landlord's authored content.
- Error monitoring with personal data removed: server and browser errors are captured so we can find and fix bugs. Personal identifiers (your name, email, profile slug, and the dynamic portions of page URLs) are removed from these error reports before they leave RentAuth.
No system is perfectly secure, but we protect your information using industry-standard measures and review our safeguards as the platform grows.
9. Third-Party Service Providers
We use the following sub-processors to operate the platform:
- Clerk — authentication and identity (SOC 2 Type II certified)
- Supabase — database and file storage (SOC 2 Type II certified, data hosted in US-East)
- Vercel — hosting and edge compute (SOC 2 Type II certified)
- Anthropic — AI processing for Vera verification, listing FAQ chat, answer normalization, and HRC-compliance classification (data is transmitted transiently for processing only; not retained or used for training — see Section 4)
- Persona — Stage 2 identity verification (SOC 2 Type II certified; you interact with Persona's hosted flow directly; we receive only the pass/fail outcome and inquiry reference)
- Stripe — payment authorization for Stage 2 (PCI DSS Level 1 certified; card details entered directly with Stripe, never received by RentAuth)
- Resend — transactional email delivery (viewing invitations and confirmation notifications)
- PostHog — product analytics (only activated with your consent)
- Sentry — application error monitoring (server and browser errors with personal identifiers scrubbed before send; see Section 8)
- Inngest — background job dispatcher (used to schedule and retry long-running work such as verification and document rendering; receives only the identifiers needed to route the job, not your documents)
10. Your Rights Under PIPEDA
You have the right to:
- Access the personal information we hold about you
- Correct inaccurate information
- Withdraw consent for the collection or use of your information
- Request deletion of your account and data
- See the audit log of who has viewed your documents, from your dashboard
- Revoke a specific professional's access to your profile without deleting your account
To exercise these rights, use the account deletion or connection-revocation features in your dashboard, or contact us at privacy@rentauth.app.
11. Cookies and Analytics
We use PostHog to understand how users interact with the platform. Analytics cookies are only set after you consent via the cookie banner. You may withdraw consent at any time by clearing your browser cookies.
Analytics events never include your documents, document contents, or financial details. Page addresses are stripped of profile, household, and application identifiers before any analytics event is recorded, so your shareable profile link is never sent to our analytics provider.
12. Contact
Questions about this policy or your data? Email us at privacy@rentauth.app.