Skip to content

Last updated: 16 August 2026

Privacy policy

The short version

equy is in early access. We collect the minimum needed to run the product, we don't run analytics or trackers, and we never sell your data. You can export or delete everything yourself, in the app, at any time. This policy is written in plain English and reflects exactly what the product does today.

Who we are

equy.ai is operated by equy LTD, a private limited company registered in England and Wales (company number 17347459) with its registered office at 12 Hall View, Crook, DL15 0XF, United Kingdom. equy LTD is the data controller for the personal data described in this policy. You can reach us by email at support@equy.ai, or by post at that registered office.

What we collect, and why

Account data — your email address, your name, and — if you sign up with a password — a hash of that password (argon2id; we never store or see the password itself). If you sign in with Google, we store the identity Google shares with us (your email, name and profile photo) instead of a password. We process this to provide the service you signed up for (UK GDPR article 6(1)(b) — performance of a contract).

Portfolio data — the property and financial figures you enter: property details and addresses, values, mortgages, rents and compliance records. Derived figures such as LTV, equity, yield and cash flow are calculated from what you enter. Also processed to provide the service (article 6(1)(b)).

Tenancy data — if you record a letting, what you enter about it: your tenants' names, email addresses, phone numbers and any notes you write about them; the tenancy's dates and terms; the deposit amount, the scheme protecting it and its reference; and the dated history of rent charged. This is processed to provide the service (article 6(1)(b)).

Your tenants' details are personal data about someone other than you. As with the documents you upload, you are the data controller for it and equy acts as your processor — we hold it and return it to you on your instructions, and we never contact your tenants ourselves. Having a lawful basis to hold their details, and making sure they know you hold them, is your responsibility as their landlord or agent. What that means in practice is set out in the terms of service.

Documents you upload — files you choose to attach to your portfolio (for example tenancy agreements, gas safety certificates, EICRs, EPCs, inventories, insurance and mortgage paperwork, invoices, correspondence and photos), together with the filing details we record about each one (its title, type, original file name, size and format, and which property, tenancy or record you filed it against). We store these to provide the service (article 6(1)(b)). Some of these files may contain personal data about other people — most often your tenants. For that third-party content you are the data controller and equy acts as your processor, storing and returning the files only on your instructions; you are responsible for having a lawful basis to hold and upload it. Your responsibilities for what you upload are set out in the terms of service.

If you use the guided add flow to read a document automatically, we send that file's content to a third-party AI model (provided by Anthropic) to propose values back to you — nothing it proposes is saved as fact until you confirm it yourself. The document is sent for that one read only: no other document, no other user's data and no identifying account information travels with it, and Anthropic does not use it to train its models. This use is metered — the plan you're on carries a monthly document-read allowance, stated on the pricing page and in the app, and a read that fails because we couldn't process the file still counts against it (a read we successfully refuse for being too large or an unsupported format still spent the attempt; a read that fails because of an outage or a spend limit on our side does not). See "Where your data lives, and who processes it" below for the transfer this involves.

Public property records — when you ask us to, we look your property up in the government's Energy Performance of Buildings register and, once you confirm the match is right, we keep that property's public record: its unique property reference number (UPRN), the address the register holds for it, and each energy certificate's number, rating, dates, floor area, dwelling type and room count. We also keep the sales HM Land Registry has published for your property's postcode — the address, price and date of each one — and, where a sale's address is an exact match for your building's, we record it as that building's own sale history. We refresh both from time to time so they don't go stale. This is processed under article 6(1)(f) — our legitimate interest, and yours, in filling in your property's details and compliance dates from the official record instead of by hand. You can unlink a property at any time.

This record is about a building, not about you, so it's shared: if two people track the same property, they see the same public record, and neither ever sees anything the other has entered. Because it's about a building it can also be personal data about the people who live there or own it, so we keep only what the registers publish, we never add anything ourselves, and we delete a property's record 12 months after the last person tracking it unlinks or deletes it. Sold prices are deleted on the same 12-month rule, counted from the last time anyone looked at that postcode. If you'd rather your property's public record wasn't held here, email support@equy.ai.

What we send out to look it up. Matching happens on our own servers, so the address you typed never leaves them: we send the register a postcode, or a property reference number, or a certificate number — and nothing else. Sold prices are looked up by postcode alone. No account details of any kind are sent, and nothing is sent when you simply browse your portfolio.

Security data — we rate-limit sign-in and registration attempts by IP address to protect accounts. These IP addresses are held briefly in memory and are never written to our database or logs. Our request logs record the path, status and timing of API calls, not who made them. This is processed under article 6(1)(f) — our legitimate interest in keeping the service secure.

Marketing consent — if you opt in (a separate, unticked checkbox at sign-up, or the "Product updates" toggle in settings), we'll email you occasional product updates. This runs on your consent (article 6(1)(a)), and you can withdraw it at any time — either in Settings → Notifications, or with the one-click unsubscribe link in every marketing email we send. We keep a record of when consent was given and withdrawn. We don't send marketing email without it.

Cookies and local storage

We use one strictly necessary session cookie to keep you signed in (an opaque token, __Host- prefixed, never readable by scripts), plus short-lived cookies that exist only during a Google sign-in. There are no advertising or tracking cookies, and no third-party analytics run anywhere in the app — which is why you don't see a cookie banner.

Interface preferences are stored on our servers with your account and mirrored in your browser's local storage so pages can read them quickly.

Where your data lives, and who processes it

We use five service providers (processors) to run equy:

  • DigitalOcean — our API, our managed PostgreSQL database (where your account, portfolio and tenancy data live) and our object storage (DigitalOcean Spaces, where the document files you upload are held). All of it runs in their London region.
  • Cloudflare — serves the app itself, and provides our DNS.
  • Google Workspace — hosts our support@equy.ai and security@equy.ai mailboxes, so anything you email us is processed there.
  • Resend — delivers our email: address verification, password resets, account notices, and — only if you've opted in — product updates.
  • Anthropic — reads documents you submit through the guided add flow, one file per call, to propose values back to you. See "Documents you upload" above for what this covers and how it's metered.

Data is encrypted in transit everywhere, and the document files you upload are also encrypted at rest.

Data that leaves the UK. Everything in our database and object storage stays in the UK. Two things are the exception. Email: Resend processes and delivers our messages in the United States, so your email address and the content of the messages we send you are transferred there, and Resend keeps sent messages in its delivery logs for 30 days. The safeguard we rely on for that transfer is the set of standard contractual clauses with the UK International Data Transfer Addendum in Resend's data processing terms. Document reads: when you use the guided add flow, the document's content is transferred to Anthropic, which processes it in the United States. Anthropic does not retain the content by default once the call returns; content its own automated safety systems flag may be retained for up to 2 years under its trust-and-safety process, which we have not asked it to switch off, because doing so would remove that safety mechanism rather than reduce what is held about you day to day. The safeguard we rely on for this transfer is the same shape as Resend's — standard contractual clauses with the UK International Data Transfer Addendum, incorporated into Anthropic's commercial terms. Email support@equy.ai if you'd like a copy of either.

Public data services we look things up in. To fill in your property's details and market context we query UK public-sector open-data services — today the Energy Performance of Buildings register (Ministry of Housing, Communities and Local Government) and HM Land Registry's sold-price data, and in future police.uk and the Office for National Statistics. These are public bodies publishing public records, not our processors, and what we send them is always the minimum needed to identify a place: a postcode, a property reference number or a certificate number. We never send them your name, your email, your account, or the address you typed in. They all operate in the UK.

Google is not in the list above, because it isn't our processor. If you choose to sign in with Google, Google acts as its own, independent controller: signing in shares your email address, name and Google account identifier with us, and tells Google that you signed in to equy. Separately, if your account has a Google profile photo, your browser loads that image directly from Google's servers every time you load a signed-in page — which means Google receives your IP address each time, whether or not you are actively using Google. You can stop that by removing the photo from your Google account, and Google's handling of it is governed by Google's privacy policy, not ours.

How long we keep things

Your account, portfolio and tenancy data are kept while your account exists and deleted when you delete it. The documents you upload are kept until you delete the individual file or your account, at which point the file is removed from object storage as well as our database. A property's public register record is kept while anyone is tracking that property, and for 12 months after the last person stops — the countdown starts when the last link goes, not when we first fetched it, so unlinking by mistake is recoverable. Sign-in sessions expire 30 days after you sign in, or after 7 days without being used, whichever comes first; expired sessions are purged automatically. Email we've sent you stays in Resend's delivery logs for 30 days, which means it can briefly outlive the data in our own systems. A document you submit for automatic reading is not retained by Anthropic once the read completes, except where its own trust-and-safety systems flag it, in which case it may hold that content for up to 2 years under its own retention rules, not ours. When you delete your account we keep one minimal record — a one-way cryptographic hash of your email address and the date, and no other details — solely so we can confirm the deletion happened if it's ever disputed. Our database provider's encrypted backups age out on their standard rotation, so deleted data also leaves backups within that window.

Your rights

You can act on most of your data-protection rights directly in the app, under Settings → Data & privacy: access and portability — export everything we hold about you as a JSON file; erasure — delete your account and all of its data, immediately and permanently. To correct your name or email, or to exercise your rights to restrict or object to processing, email support@equy.ai and we'll act on it promptly. You can withdraw marketing consent at any time in Settings → Notifications, or with the unsubscribe link in any marketing email.

If you're unhappy with how we handle your data, you have the right to complain to the Information Commissioner's Office at ico.org.uk. We'd appreciate the chance to sort it out first.

How we protect it

Passwords are hashed with argon2id and never stored or logged in the clear. Session tokens are stored only as SHA-256 hashes, so a database leak can't yield usable sessions. Everything travels over TLS, and our logs are deliberately minimal — no IP addresses, no emails, no request bodies.

Who equy is for

equy is a tool for adults: you must be 18 or older to create an account. The service is not directed at children and we don't knowingly collect children's data.

Changes

If this policy changes in a way that matters, we'll tell you by email — and, for material changes, ask you to re-accept in the app — before the change takes effect.