Privacy policy

Last updated October 6, 2026

Realbard is a marketing assistant and client book for estate agencies. This policy says what personal data Realbard LLC (“Realbard”, “we”) handles when you use it, why, who else is involved, and what you can do about it.

In short

  • We keep what you give us to run your account and your marketing, and what the accounts you connect let us see.
  • Your clients’ details and messages are yours. We handle them only to do the work you have asked Realbard to do.
  • We ask Google, Meta and Microsoft only for the permissions listed on the permissions page, and use them only for features you can see in Realbard.
  • We never sell personal data, and we do not use your data, or data from a connected account, to train general-purpose AI models.
  • You can disconnect an account or delete your whole account yourself, at any time — here is how.

This box is a summary. The text below is the document.

1.Who this covers, and who is responsible

Realbard handles personal data in two different roles, and which one applies decides who you should ask.

  • You use Realbard — you have an account, or you work at an agency that does. For your account details, how you use the product and your billing, Realbard is the controller: we decide why and how that data is used, as this policy describes.
  • You are a client of an agency that uses Realbard — you sent an enquiry about a home, wrote to an agency, booked a viewing, or receive emails about homes. The agency decides why and how your details are used; it is the controller, and Realbard is its processor (a service provider acting on its instructions). Ask the agency first. If you cannot reach it, write to [email protected] and we will pass your request on and help it answer.
  • You visit realbard.com without an account — Realbard is the controller for the little that involves (see the cookies page).

Realbard is provided by Realbard LLC, a limited liability company registered in the United States, 30 N Gould St Ste 38748, Sheridan, WY 82801, United States.

2.What we collect

About you, the person using Realbard

  • Your account: name, email address and a password stored only as a one-way hash. If you sign in with Google instead: your name, email address, profile picture and the identifier Google gives your account. Your role in each workspace.
  • Billing: your plan, invoices and payment status. Card details go to our payment processor, Stripe, and never reach our servers.
  • How you use Realbard: what you create, approve and change, the AI credits you spend, and server logs (IP address, browser, the pages and actions requested, times) kept for security and to find faults.

What you put into your workspace

  • Listings: descriptions, prices, addresses, photographs, floor plans and documents.
  • Your brand: name, logo, colours, how you write, contact details.
  • Everything Realbard makes for you or you make in it: posts, adverts, pictures, videos, emails, the pages of your website.

About your clients and the people who contact you

You, the agency, are the controller of this data; we hold it for you.

  • Names, email addresses, phone numbers, and what they are looking for or selling.
  • Enquiries and conversations: what people write to you by email, through your website’s forms and assistant, through a Facebook or Instagram lead form, by Messenger, Instagram direct message or WhatsApp, and in comments under your posts and adverts — and what you, or Realbard on your behalf, write back. Where a message comes from a messaging app, the sender’s profile name and picture as that app provides them.
  • Viewings, valuations, deals, tasks and notes; what a person said about a home they were sent or shown.
  • A record of what each person agreed to receive, when and how — and of anyone who asked to stop.

From the accounts you connect

Only when you connect one, and only what the permissions you grant allow — listed one by one on the permissions page: the identifiers of your advertising accounts, Facebook Pages, Instagram accounts, WhatsApp number and mailbox address; the results of what was published; and the access tokens that let Realbard act, which are stored encrypted. Sections 5 to 7 say exactly what each platform’s data is used for.

From visitors to a website Realbard hosts for an agency

To count visits, a page of an agency’s website or advert page records that it was opened, with a random number kept in the visitor’s browser. We do not store the visitor’s IP address with it and do not build a profile across websites. An agency may add its own Meta Pixel to its pages; that is the agency’s decision and responsibility (see the cookies page).

3.What we use it for

Purpose
Providing Realbard
What it involves
Running your account and workspace; writing and designing your marketing; publishing what you approve to the accounts you connected; receiving and answering enquiries and messages; sending emails to your clients as you instruct; hosting your website; showing you results.
Legal basis (where one is required)
Performance of our contract with you. For your clients’ data: your instructions as controller.
Purpose
Billing
What it involves
Charging for your plan, credits and any advert budget; invoices and tax records.
Legal basis (where one is required)
Contract; legal obligation.
Purpose
Keeping it safe and working
What it involves
Preventing abuse, investigating faults, protecting accounts.
Legal basis (where one is required)
Legitimate interests in a secure, reliable service.
Purpose
Telling you things about the service
What it involves
Sign-in and security emails, receipts, notices of changes to these documents, what is waiting for you.
Legal basis (where one is required)
Contract; legitimate interests.
Purpose
Meeting legal duties
What it involves
Responding to lawful requests; keeping records the law requires.
Legal basis (where one is required)
Legal obligation.

We do not sell personal data. We do not use your clients’ details to market Realbard to them. We do not use what is in your workspace, or anything received from an account you connected, for advertising of our own.

4.How AI is used

Realbard uses AI models to do work for you. It is worth being exact about what that means.

  • What it makes: posts, adverts, emails, website text, pictures and videos from your listings and your brand; replies and follow-ups to enquiries and messages; short readings of an enquiry (how serious, what they want); plain-language summaries of your results.
  • What is sent to a model to do that: the listing’s facts and photographs, your brand, and — for a reply — the recent messages of that conversation and the person’s name. For a summary of results, the figures on your results page. Nothing more than the task needs.
  • What goes out on its own: you choose. As Realbard is set up when you start, posts wait for your approval and no advert is published or spends money without it. A first answer to a new enquiry or message, follow-ups to someone who has not replied, and emails about new homes to buyers who asked for them are sent automatically unless you turn each off. A message Realbard sends for you says that it comes from your agency’s assistant.
  • Training: we do not use your data, your clients’ data, or data from connected accounts to train general-purpose AI or machine-learning models. The model providers we send data to process it to return the result you asked for, under terms that restrict their further use of it.

AI can be wrong. What Realbard writes is drawn from the facts you gave it, and it is yours to check, change or reject.

5.Google user data

Realbard can use a Google account in three separate ways. Each is asked for on its own, on Google’s consent screen, and you can use Realbard without any of them.

What you do
Sign in with Google
What Realbard receives from Google
Your name, email address, profile picture and Google account identifier.
What it is used for
To create your Realbard account and sign you in. No access to anything else in your Google account is requested, and no Google access token is kept.
What you do
Connect Gmail to send from your address
What Realbard receives from Google
Permission to send email as you (gmail.send), and your address. Realbard cannot read, search or delete the mail in your mailbox.
What it is used for
To send the emails you write or approve in Realbard — replies to enquiries, emails about homes — from your own address, so your clients hear from you.
What you do
Connect Google Ads
What Realbard receives from Google
The Google Ads accounts you can use, and permission to manage campaigns in them.
What it is used for
To create the search adverts you approve in your Google Ads account, and to read how they performed so the figures appear on your results page.

Access and refresh tokens are stored encrypted and are deleted when you disconnect. Performance figures from Google Ads may be passed to an AI model, with the rest of your results, to write the summary you ask for on your results page — a feature you see and start yourself.

Realbard’s use and transfer to any other app of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements.

In particular:

  • we use Google user data only to provide or improve the features described above, which you can see in Realbard;
  • we do not transfer it to anyone else except as needed to provide those features, to comply with the law, or as part of a merger or sale of the business with notice to you;
  • we do not use it for advertising, including retargeting, personalised or interest-based advertising;
  • we do not use it to develop, improve or train generalised AI or machine-learning models;
  • no person at Realbard reads it unless you ask us to (for example for support), it is necessary for security or to comply with the law, or it has been aggregated and anonymised.

You can take the access away at any time: in Realbard under Settings → Connections (or Outreach → Sending from, for Gmail), or from your Google account’s permissions.

6.Data from Facebook, Instagram, Messenger and WhatsApp

When an administrator of your workspace connects Facebook, Realbard receives, through Meta’s login and its published interfaces, only what the permissions granted allow. Each permission and its purpose is on the permissions page. In summary:

  • Who connected and what they chose: the name and identifier of the person who connected, and the Facebook Pages, Instagram professional accounts and advertising accounts they selected.
  • Publishing: Realbard publishes the posts and adverts you approve to your Page and Instagram account, and reads how they performed.
  • Enquiries from lead forms: when someone fills in a form on one of your adverts, Realbard receives what they entered and adds it to your clients.
  • Messages and comments — only if you turn that channel on: what people write to your Page by Messenger, to your Instagram account by direct message, to your WhatsApp Business number, and in comments on your posts and adverts; and the replies sent from Realbard.
  • Adverts Realbard runs for you: if you ask Realbard to run adverts from its own advertising account, your Page is shared with Realbard’s business account at Meta so the adverts can carry your Page’s name. You can remove that sharing at any time.

We use this data only to provide those features to you. We do not sell it, do not use it for advertising other than the adverts you run, do not use it to train AI models, and share it only with the service providers in section 8 who process it for us — for example, an AI model that drafts a reply to a message you received. Access tokens are stored encrypted. Our use of it follows the Meta Platform Terms and Developer Policies.

You can disconnect at any time in Realbard under Settings → Connections (and Inbox → Channels for messaging), or from Facebook under Settings → Business integrations. To have what Realbard holds from Meta deleted, see Delete your data.

7.Microsoft account data

If you connect an Outlook or Microsoft 365 mailbox, Realbard receives your address and permission to send email as you (Mail.Send). It is used only to send the emails you write or approve in Realbard from your own address; Realbard cannot read your mailbox. Tokens are stored encrypted and deleted when you remove the mailbox under Outreach → Sending from.

8.Who else handles it

We use other companies to run parts of the service. Each receives only what its job needs, under a contract.

Who
Amazon Web Services
For what
Hosting, file storage and email delivery
What it handles
Everything in your workspace; the emails Realbard sends and receives for you.
Who
Stripe
For what
Payments
What it handles
Your billing details and payments. Card numbers go to Stripe directly.
Who
AI model providers — OpenAI, Anthropic, Google (Gemini), DeepSeek and Replicate, depending on the task and the model your workspace uses
For what
Writing, reading and summarising; making pictures and video
What it handles
The listing, brand, conversation or figures a task needs (section 4).
Who
Firecrawl
For what
Reading a public web page you point Realbard at
What it handles
The address of the page — for example your existing website, or a listing to import.
Who
Google, Meta and Microsoft
For what
Publishing, messaging and sending through the accounts you connected
What it handles
What you approve for publishing; the messages and emails you send. Each handles it under its own terms with you.

We also disclose data when the law requires it, to protect people or the service from harm, and — with notice to you — to a successor if the business is merged or sold. We do not sell personal data or share it for anyone else’s advertising.

9.How long we keep it

  • Your account and workspace: for as long as the account exists.
  • Access tokens for a connected account: deleted when you disconnect it.
  • When you delete something, or your account: removed from our live systems within 30 days and from encrypted backups within 90 days.
  • Billing and tax records: for as long as the law requires.
  • Server logs: up to 12 months.
  • Records that someone asked not to be contacted are kept so that the request is honoured. Delete your data gives the detail.

10.Security

Data travels encrypted. Access tokens for connected accounts are encrypted at rest with AES-256; passwords are stored only as hashes. Each workspace’s data is separated from every other’s, and within a workspace people see and do what their role allows. No system is perfectly secure; if a breach affects your data we will tell you and the authorities as the law requires.

11.Where it is processed

Realbard LLC is established in the United States. We and our providers may process data there and in countries other than yours. Where data protected by the GDPR or a similar law leaves its region, we rely on safeguards the law recognises, such as the European Commission’s Standard Contractual Clauses.

12.Your rights

Depending on where you live, you may have the right to see the personal data held about you, to have it corrected or deleted, to restrict or object to its use, to take a copy elsewhere, and to withdraw a consent you gave. Residents of California have the rights the CCPA gives them, including to know and to delete; we do not sell or share personal information as that law defines those words.

Write to [email protected]. We answer within 30 days. If you are a client of an agency, ask the agency (section 1). You may also complain to your data-protection authority.

13.Children

Realbard is a tool for businesses and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has given us data, write to [email protected] and we will delete it.

14.Changes to this policy

When this policy changes we change the date at the top. If a change is significant — a new kind of data, a new purpose — we tell account owners by email or in the product before it takes effect.

15.Contact

Privacy questions and requests: [email protected]. Anything else: [email protected]. By post: Realbard LLC, 30 N Gould St Ste 38748, Sheridan, WY 82801, United States.