Privacy Policy
Regent is an AI assistant for real estate professionals. It connects to your mailbox, your calendar, your CRM and a dedicated business phone line, and turns what arrives there into a daily brief, a ranked client list, tasks and draft replies.
This policy explains what Regent collects, why, who we share it with, how long we keep it and what you can ask us to do with it. It covers the Regent mobile app, the Regent website at regentapp.ca, and the Regent service at api.regentapp.ca.
Contact: support@regentapp.ca
01 — Two kinds of people in this policy
Regent handles information about two different groups, and your rights differ depending on which one you are.
If you are a Regent subscriber — a real estate agent or brokerage using the app — we are responsible for your personal information and this policy governs it directly.
If you are someone a subscriber deals with — a lead, client, co-operating agent, vendor, or anyone who emails, messages or telephones a subscriber — your information reaches Regent because that subscriber connected their own accounts to our service. In that case the subscriber decides what is collected and why, and we process it on their behalf and under their instructions, as their service provider. If you want your information corrected or deleted, contact the agent or brokerage you were dealing with. You may also write to support@regentapp.ca and we will route your request to them and assist.
Subscribers are responsible for having a lawful basis to bring their contacts’ information into Regent, and for telling those contacts how it is used, as required by applicable privacy law.
02 — Information we collect
2.1 Account information
- Name, email address, and phone number if you provide it
- Agency or brokerage name and general location, if you provide them
- Your password, stored only as a bcrypt hash and never in readable form — or your Google or Microsoft sign-in identifier if you sign in that way
- One-time login codes sent to your email, and password-reset tokens, both stored only as one-way hashes
- Account role, trial start date, last-active timestamp
- Your preferences: time zone, language, theme, notification settings, email sync settings, voice settings
- Your mobile push notification token
2.2 Email
You connect Gmail, Outlook or Exchange through our connectivity provider, Unipile, using that provider’s own hosted sign-in screen.
- We do not hold your mailbox password or your OAuth tokens. Unipile holds the credential. Regent holds only an account reference, your mailbox address, the provider name and sync status.
- We keep the text of an email only while we process it. When an email arrives in your mailbox or you send one, our provider passes it to us so it can be analysed. Its text is deleted as soon as that processing finishes, and a temporary working copy used for the analysis expires within 24 hours. If processing fails, the text is kept for up to 30 days so it can be retried, then deleted. When you open an email in Regent, it is fetched live from your provider and is not stored afterwards.
- What we do store for each analysed message is derived intelligence: sender name and address, thread and message identifiers, received time, a short AI-written summary, a category (urgent, active deal, new lead, administrative, other), a priority score, whether a reply is needed, any deadlines mentioned, a suggested action, and read, flag and reply status.
- Before any email is sent to an AI model it is stripped: HTML markup, images, tracking pixels, hyperlink targets, quoted reply chains and marketing footers are removed.
- Writing style profile. To make drafts sound like you, Regent reads up to 100 of your own sent messages and distils a style profile — typical greetings, sign-offs, sentence length, tone by recipient type, and a small number of verbatim example phrases. The source emails are not kept; the profile is.
- Drafts and replies. AI-generated drafts, your edits, and replies you send through Regent are stored so you can review what went out.
- Delivery tracking. For messages sent through Regent, our provider reports back delivery failures and, where available, whether the recipient opened the message. Recipients of email sent through Regent should be aware that opens may be recorded.
2.3 Calendar
- Google or Outlook calendar, connected through Unipile together with your email; or Apple Calendar, in which case the app-specific password you supply is stored encrypted with AES-256-GCM.
- Event title, description, location, start and end time, all-day flag, status, attendees, recurrence and colour.
2.4 Contacts, clients and lead intelligence
Assembled from your email, calls and CRM:
- Contact record: first and last name, one or more email addresses, one or more phone numbers, company, contact type (lead, client, agent, vendor), status, spoken language preference, your notes, last interaction date
- Client dossier: an AI-written summary of the relationship, plus structured notes on the contact’s stated preferences, behavioural patterns and negotiation posture, extracted from your correspondence with them
- Interaction log: a cross-channel record of who contacted whom, on which channel, in which direction, and when
- Signals: who owes whom a reply, days since last contact, whether a thread is open
- Lead score: a numeric score, a band (hot, warm, cooling, dormant), the reasons behind it, and the values it was computed from
- Reach-out suggestions: the daily list of people to contact, and whether you acted on, dismissed or snoozed each one
- Tasks: title, action item, due date, snooze state, and a short context snippet from the source message or call
2.5 Follow Up Boss (optional CRM connection)
If you connect Follow Up Boss:
- OAuth access and refresh tokens, stored encrypted with AES-256-GCM
- Your Follow Up Boss account identifier, and the name and email of the person who authorised the connection
- A read-only mirror of your CRM data: people, deals, pipelines, stages, notes, calls, appointments, text messages and lead activity events, including the raw records as returned by Follow Up Boss
- Write-back. When enabled — you can switch it off at any time on the CRM screen — Regent files two things back into your Follow Up Boss account: inbound receptionist calls, and new leads that arrived by email, each as a timeline event with a short note. Regent never changes stages, tags, assignments or messages in your CRM.
2.6 AI Receptionist (your business phone line)
When you enable the AI Receptionist, we provision a dedicated phone number through Twilio, answered by a voice agent running on ElevenLabs.
- Call audio is not recorded. Audio saving is switched off on every receptionist agent. There is no recording of the conversation to play back, at Regent or anywhere else.
- A text transcript is kept, along with the caller and called number, start and end time, duration, and the outcome of the call.
- Structured intake the agent collects during the call: caller name, caller type, what they want, property of interest, budget (only if the caller offers it), timeline, deadline, callback number and free-text notes.
- An AI call briefing: a headline and summary, what the caller asked for, property and timeline details, their questions, commitments made, objections, sentiment, and the follow-up owed. Parts of the briefing may quote the caller’s own words.
- Screening information: whether a call was blocked or judged to be spam, and a short reason shown to you in the call log.
- Your blocklist: numbers you have blocked, with your optional note.
- Caller context given to the agent at pick-up. If the incoming number matches one of your contacts, the agent is told that person’s name, company, language preference and the date you last dealt with them, so it can greet them properly. Nothing else from their record is shared with the agent.
- Voicemail. When the receptionist is switched off and set to take messages, Twilio does record the caller’s voicemail. We store the recording reference and its duration; the audio file itself is held by Twilio.
- What the caller hears. The receptionist answers by naming your office and itself. It does not announce that it is an AI at the start of every call, but it answers honestly and immediately if a caller asks. We record which version of the opening script each caller heard.
Callers are people we hold information about on a subscriber’s behalf — see section 1.
2.7 In-app voice assistant
Separate from the receptionist, the in-app assistant lets you speak to Regent.
- Your voice is streamed to ElevenLabs, which transcribes it, runs the conversation using a model we configure, and speaks Regent’s replies. The audio is not saved, and ElevenLabs keeps the conversation text for 30 days.
- The assistant works through your Regent account: it reads your email summaries, calendar and tasks, and anything it creates for you, such as a task or a draft, is stored like any other.
2.8 Billing
- Payments are handled by Stripe. Regent never sees or stores your card number.
- We store your Stripe customer and subscription identifiers, plan status, billing period dates, cancellation flag, and any failed-payment grace deadlines.
- Receptionist usage: talk-time minutes used in the period, your spend limit, and a per-call cost breakdown.
2.9 Notifications
Your push token, and the content, priority, delivery status and open time of the notifications we send you.
2.10 Technical and operational data
- Application logs with correlation identifiers, for debugging
- Error reports sent to Sentry, configured not to attach personal information by default
- Event records received from Unipile and Follow Up Boss, stored so no event is lost if a server restarts. For email and message events, the message text is removed as soon as the event is processed; an event that never finishes processing loses its text after 30 days.
- Failed background-job records, which include the identifier, subject and sender of the item that failed and, for an email or call, an excerpt of its content, so it can be retried. They are deleted after 30 days.
- Rate-limiting counters keyed to your account, or to an IP address where you are not signed in
- Administrative audit log. When a member of Regent staff performs an administrative action, we record who did it, what it was, the endpoint, the request and a summary of the response, plus that staff member’s IP address and browser user agent. This log covers staff actions, not ordinary use of the app.
We do not embed advertising trackers in the Regent service.
03 — How we use your information
- To run the features you switched on: syncing email and calendar, building your daily brief, ranking clients, creating tasks, drafting replies, answering your phone line and filing activity to your CRM
- To identify you and keep your account secure, including login codes, password resets and session revocation
- To send you notifications you have enabled, and service messages such as trial and billing notices
- To take payment, apply your plan entitlements and enforce your spend limit
- To detect and block spam and abusive callers
- To diagnose faults, retry failed work and keep the service reliable
- To meet legal, tax and accounting obligations
04 — Artificial intelligence
Regent is built on AI models, and it is important you understand what that means for your data.
Which models. Google Gemini performs email analysis, dossier extraction, task creation, draft writing and call briefings. Both voice agents — the receptionist and the in-app assistant — run on ElevenLabs, using a model configured by us. ElevenLabs also turns speech into text and text into speech.
What is sent. Only what the feature needs: a sanitised email body, a call transcript, contact context, or your spoken request. Email content is stripped of markup, images, tracking pixels, link targets and quoted history before it leaves our servers.
Training. We do not use your content to train our own models. We engage our AI providers under commercial terms that do not permit your content to be used to train theirs.
Automation limits. Regent does not send email on your behalf without your approval: drafts are held for review and you send them. The receptionist can take a message, answer questions and transfer a call, but it does not make commitments that bind you. AI output can be wrong — lead scores, summaries and briefings are aids to judgement, not decisions.
05 — Who we share information with
We share information with the service providers below, only as needed to run Regent. Each is bound by contract to protect it.
| Provider | What it handles | What it receives |
|---|---|---|
| Unipile | Mailbox and calendar connectivity | Holds your provider credentials; relays message and calendar content |
| Google (Gemini) | AI analysis, drafting and briefings | Sanitised email text, call transcripts, contact context, and requests you make to the assistant |
| Google Workspace / Microsoft 365 | Your mailbox and calendar | Accessed on your behalf via Unipile |
| ElevenLabs | Voice agents for the receptionist and the in-app assistant | Call audio and your voice in real time (not saved), conversation transcripts, caller context |
| Twilio | Phone numbers, call routing, voicemail | Caller and called numbers, call details, voicemail recordings |
| Stripe | Payments and subscriptions | Your name, email and payment details, collected directly by Stripe |
| Resend | Transactional email such as login codes and billing notices | Your email address and the message content |
| Expo | Mobile push notifications | Your push token and the notification content |
| Sentry | Error monitoring | Technical error data, configured to exclude personal information |
| Follow Up Boss | CRM, only if you connect it | Inbound call and new-lead events written back to your own account |
| Google Cloud | Servers, database and backups | All stored data, at rest |
We may also disclose information where the law requires it, to enforce our terms, to protect someone’s safety, or in connection with a merger or sale of the business — in which case we will tell you before your information becomes subject to a different policy.
06 — Where your information is held
Regent’s servers, database and backups are located in Toronto, Canada, on Google Cloud.
Several of our providers operate outside Canada, including in the United States and the European Union. Where that is the case, your information is processed abroad and may be accessible to the courts and authorities of those countries under their laws. We use providers that offer contractual protections for international transfers.
07 — How long we keep information
| Data | How long |
|---|---|
| Account and profile | For the life of your account |
| Email text | Only while it is being processed: deleted once processing finishes; the working copy within 24 hours; at most 30 days if processing fails |
| Email intelligence, summaries, drafts and tasks | For the life of your account, unless you delete them |
| Contacts, dossiers, scores and interaction history | For the life of your account |
| Call transcripts, briefings and call logs | For the life of your account |
| ElevenLabs’ own copy of conversation data | 30 days |
| Voicemail recordings | Held by Twilio under its retention settings |
| Mirrored Follow Up Boss data | Until you delete your account. Disconnecting Follow Up Boss clears the tokens but keeps what was already synced. |
| Billing records | As required by Canadian tax and accounting law, generally seven years |
| Administrative audit log | Retained for security and compliance purposes |
| Scrambled copy of the email of a deleted account | Kept after deletion, to prevent repeat free trials |
You can delete your account at any time in the app, under Profile → Delete Account. Deletion is immediate and cannot be undone. It cancels your subscription, releases your AI receptionist number, disconnects your mailbox, calendar and Follow Up Boss, and deletes the records tied to your account — email intelligence, contacts, dossiers, tasks, calls, CRM mirror, notifications and billing links.
We keep only two things after deletion:
- Billing records. Invoices and payment records stay with Stripe as tax and accounting law requires.
- A scrambled copy of your email address. It is a one-way keyed hash that cannot be turned back into your address, and it contains nothing else about you. We keep it only so the same address cannot start a second free trial. If you sign up again with that address, your new account starts without a free trial.
Deleted data can remain in our database backups for up to 30 days, until those backups expire.
08 — Your choices
- Disconnect an integration. You can disconnect your mailbox, calendar or Follow Up Boss at any time in the app. Disconnecting a mailbox also deletes the stored credential at Unipile.
- Turn off CRM write-back. A single switch on the CRM screen.
- Turn off the receptionist. Calls then forward to your mobile or go to voicemail — callers never reach dead air. You can also set a spend limit, or ask us to release the number entirely.
- Block a caller. Manage your blocklist in the app.
- Mute notifications. Per task, or globally in your preferences.
- Delete individual records. Tasks and notifications can be deleted in the app. For anything else, write to support@regentapp.ca.
- Delete your account. In the app, under Profile → Delete Account.
09 — Your rights
Under Canadian privacy law (PIPEDA, and Quebec’s Law 25 where it applies), and under the GDPR if you are in the European Economic Area or the United Kingdom, you have the right to:
- Access the personal information we hold about you
- Correct it if it is wrong or incomplete
- Delete it, subject to what we must keep by law
- Withdraw consent to a feature, by disconnecting it or closing your account
- Receive a copy of the information you gave us, in a portable format
- Object to or restrict certain processing
- Complain to a regulator — in Canada, the Office of the Privacy Commissioner at priv.gc.ca; in Quebec, the Commission d’accès à l’information; or your local authority in the EEA or UK
To exercise any of these, write to support@regentapp.ca from the address on your account. We respond within 30 days. You can also delete your account yourself in the app, under Profile → Delete Account.
10 — Security
- Passwords stored as bcrypt hashes, and login sessions revocable on demand
- Sensitive credentials — Follow Up Boss tokens, Apple Calendar app passwords — encrypted at rest with AES-256-GCM
- Mailbox credentials never held by us at all
- All traffic over HTTPS
- Every inbound event from Twilio, ElevenLabs, Stripe, Follow Up Boss and Unipile authenticated before it is acted on — by cryptographic signature, or by a shared secret for Unipile
- Every database query scoped to your account, so one customer’s data cannot be returned to another
- Staff access to production data restricted by role and recorded in an audit log
- Error reporting configured to exclude personal information
No system is perfectly secure. If a breach affects your information and presents a real risk of significant harm, we will notify you and the appropriate regulator as the law requires.
11 — Children
Regent is a professional tool and is not intended for anyone under 18. We do not knowingly collect information from children. If you believe a child has given us information, write to support@regentapp.ca and we will delete it.
12 — Changes to this policy
We will post any changes on this page and update the date at the top. If a change materially affects how we handle your information, we will tell you in the app or by email before it takes effect.
13 — Contact
Email: support@regentapp.ca
← Back to homepage