SENESCHAL
Back to Help & Support

Privacy Policy

Version 2026-09-25

Seneschal handles your email and your clients' contact details. That is sensitive material and this policy says plainly what we do with it, what we never do with it, and how you get it back or get rid of it.

Seneschal is sold to licensed real estate brokers in Washington State and is operated from Washington. Your data is stored in the United States.

1. What we collect

What you give us

  • Your name, work email, phone and brokerage.
  • Contacts you import, with their names, emails, phones and any notes you add.
  • Transactions, deals, checklists and the dates you record on them.
  • Photos you upload, and settings you choose.
  • Billing details: your billing address and, when billing is active, the card brand and last four digits. Never the full card number.

What we read with your permission

  • Your mail, whether your mailbox is Outlook or Gmail, to build briefings, match signed documents to deals and show the email history on a contact record. Where you ask it to, Seneschal also sends, replies, files and archives on your behalf in that same mailbox.
  • Your calendar, in Outlook or Google Calendar, read-only, so your briefing knows what your day holds.
  • Your contacts in Outlook or Google, when you choose to import them.
  • Attachments on those emails, to read signed forms and pull dates from them.
  • Your phone's text messages and call log, only if you turn on phone backup import. Seneschal looks in your own OneDrive or Google Drive for the backup files the SMS Backup & Restore app saves there, opens only those files, stores the messages and calls, and links each one to the matching contact.

Google user data. If your mailbox is Gmail, Seneschal's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements. In plain terms: your Gmail, calendar, contacts and Google Drive data is used only to provide the features described on this page, it is never sold, never used for advertising, and never used to train AI models. No person at Seneschal reads your mail, except where you ask us to for support, where security or the law requires it, or where the data is aggregated and anonymised. You can withdraw this access at any time, either in Settings or from your Google account.

What we collect automatically

  • Sign-in times and a session cookie needed to keep you logged in.
  • Error logs and basic technical records used to fix faults.

We do not use advertising trackers and we do not run third-party analytics that follow you around the web.

The public website. The website at seneschalhq.com counts page views using Cloudflare Web Analytics. It sets no cookies, does not fingerprint your browser, and does not follow you to other websites. What it records is the page you looked at, the site you came from, the country and the general type of device. There is no advertising tracking anywhere on the site and never will be.

2. What we do with it

Only what is needed to run Seneschal for you: build your briefing, track your deals and deadlines, draft written material you asked for, file your email, publish posts you approve, support you when you ask, and bill you.

What we never do. We do not sell your data. We do not sell or share your clients' contact details. We do not market to your clients. We do not use your data to build anything for a competitor, and we do not use your client data to train AI models for other customers.

3. Artificial intelligence

Some features send relevant content to an AI provider to generate a draft, a summary or a help answer. That means the specific text needed for that task, not your whole mailbox. It is sent under a business agreement that prohibits the provider from using it to train their general models. Generated output can be wrong, which is why nothing is sent or published without your review.

4. Who else sees it

WhoWhat they getWhy
MicrosoftYour sign-in, and the mail, calendar, contacts and OneDrive access you grantedAuthentication, mailbox access and phone backups
GoogleWhere your mailbox is Gmail: your mail, and read-only access to your calendar, your contacts and the phone backup files in your Google DriveMailbox, calendar, contacts and phone backups
SupabaseYour email address, a hash of your password, and your two-factor setupSign-in and account security
RailwayEverything stored, encrypted in transit and at restHosting and the database
AnthropicThe specific text needed for a drafting, summarising or help requestDrafts, summaries, help answers
fal.aiThe prompt and any photo you choseListing images and video
ElevenLabsThe script you approvedVoiceover on videos you generate
ShotstackThe clips and captions for a video you asked to renderVideo rendering
CanvaThe post you chose to open in CanvaEditing a post you are publishing
Meta (Facebook, Instagram)Only the posts you choose to publishPublishing where you asked
StripeYour name, billing address, and the card details you enter on their pageTaking payment
PexelsA stock photo search term. No personal dataStock photography
PerplexityA market data question. No personal dataMarket figures in generated copy
Netlify and CloudflareThe public website only. No account data reaches themThe website and its request form

All of these are in the United States. Beyond them we disclose data only where the law requires it, or to establish or defend a legal claim. If a business transfer ever happened, you would be told before your data moved and the buyer would be bound by this policy.

Adding to this list. That table is the whole list, not an example of it. If we take on a new company that will handle your data or your clients' data, we will email you at least thirty days before it starts, saying who they are and what they would receive. You can end your subscription before that date if you would rather not have them involved. Replacing one of these with another company of the same kind counts, and so does giving an existing one access to something new. Swapping a vendor that never touches your data, such as the stock photo search, does not.

5. Other agents cannot see your data

Every record is scoped to the account that created it. Agents sharing a brokerage plan share a bill, not a database. No user of Seneschal can see another user's contacts, deals or email. The one exception is a deal you choose to co-list, and it works exactly as set out below. Otherwise no one ever sees another user's deal.

Co-listing a deal

You can name another agent, at any brokerage, as the co-listing agent on one of your deals.

  • Nothing is shared until they say yes. If they already use Seneschal, they are asked on their dashboard. If they do not, we send them one email with your name and the deal's property address, asking them to join. Until they accept they see nothing else, and if they decline the request is deleted.
  • The deal itself. Once they accept, they see that one deal: the property, price, MLS number, status, dates and deadlines, the terms recorded on it, the escrow company and lender, and any notes written on the deal. You both work on the same deal, so a change either of you makes shows for both of you.
  • The people on that deal, and only their contact details. Each person's name, email address, phone number and company. These are copied into their account as their own contact records.
  • Nothing else. Not your other deals or contacts. Not the notes, tags, pipeline stage, lead source, birthday or follow-up settings on your contact records. Never your email, calendar, text messages or call notes.
  • Ending it. Either of you can take the deal off your own account and it stays with the other. If you created the deal and end the co-listing, the other agent keeps their own copy of the deal and those contact details as they stood at that moment. If either account is deleted, the deal stays with the other agent.

6. How long we keep it

  • Your data stays while your account is open.
  • After you close the account, ninety days, so you can change your mind or export.
  • After that it is deleted, except billing records, which are kept for seven years because tax law requires it, and backups, which age out on their own cycle.

7. Your rights

You can ask us at any time to:

  • Show you what we hold about you.
  • Export your contacts, deals and history in a usable format.
  • Correct anything wrong.
  • Delete your account and its data.

Ask through Help & Support. We respond within thirty days, usually much sooner. There is no charge, and asking never affects your service.

8. Your clients' data

Contacts you import are your clients, not ours. You are responsible for having a proper basis to hold their information and for your own obligations to them. We process it on your behalf and on your instructions. If a client of yours asks you to delete their record, you can do that yourself, and we will help if you need it.

9. Security

Data is encrypted in transit and at rest. You sign in through Microsoft or with an email address and a password. A Microsoft password is never entered into Seneschal, and a Gmail mailbox is connected on Google's own page, so a Google password never is either. A password you set here is passed through to Supabase, our authentication provider, which keeps only a hash of it; Seneschal never stores it. Card numbers never touch our systems. Access to production data is limited to the people who need it to operate the service.

No system is perfectly secure. If a breach affects your data we will tell you as soon as we reasonably can, and in any case no later than thirty days after we discover it, which is what Washington law requires of us. We will say what happened, what was involved, what we are doing about it, and what you may want to do. If the breach affects your clients rather than you, we will tell you what you need in order to meet your own obligations to them.

Thirty days is the outside limit, not the plan. A breach we can describe on the day is one we will tell you about on the day.

10. Children

Seneschal is a professional tool for licensed brokers and is not intended for anyone under eighteen.

11. Changes

If we change this policy materially we will email you before the change takes effect. The version marker at the top of this page tells you which version you are reading.

12. Contact

Privacy questions and requests go through Help & Support, under Account and data. Put anything that needs a record in writing there.

Adapted from the Basecamp open-source policies / CC BY 4.0.

Terms of service Payment policy Refund policy Help & Support