SENTINEL ("we," "us," "our") is operated as a sole proprietorship by Craig Headlee in Woodinville, Washington. This Privacy Policy explains how we collect, use, and protect information when you use our web app at app.sentineliq.net and website at sentineliq.net.
We do not sell your personal information. We do not share your personal information with third parties for advertising or marketing purposes.
1. Information We Collect
When you use SENTINEL, we collect:
- Account credentials — email address and a hashed password (we never see your raw password; authentication is handled by Supabase).
- Pre-account trial, Founding Agent Lab, and office-pilot requests — the email address you submit, the source page, and first/last submission timestamps. We use these details to continue secure signup and follow up about the request you made. New form submissions do not store an IP-derived identifier or browser user-agent fingerprint. Older lead records may contain a shortened salted IP hash and user-agent that were collected for abuse prevention; they are not used for advertising.
- Installation and support correspondence — if you ask Sentinel for free toolkit-installation help, your email app may send us the website URL, website platform, calculator choice, and any other details you choose to include. Do not include client information or confidential transaction details.
- Agent profile — name, brokerage, specialty, and farm ZIP codes you provide during onboarding.
- Chat content — messages you send in-app and the responses we generate.
- Optional contact data — if you use our Sphere of Influence tools, any contacts you add (name, phone, notes).
- Optional deal data — if you use our deal tracking, transaction details you provide.
- Usage analytics — which features you use, response latency, error rates. Aggregated and scoped to your account.
- Public acquisition analytics — before signup, we may record random per-tab and one-time campaign identifiers, the page you visited from a limited approved list, the referring website domain (not its full URL), and registered campaign labels such as source, medium, campaign, and content. Campaign fields accept only fixed identifiers from Sentinel's campaign registry; toolkit identifiers are accepted only in the exact fixed tuples used by its widget-credit and invitation links, and website hostnames are not accepted as campaign-content labels. We do not intentionally place your email, name, IP address, browser fingerprint, chat text, or arbitrary URLs in these events.
- First-party campaign attribution — if you create an account within 24 hours of a recorded campaign visit, we may associate that one-time campaign receipt and its registered labels with your new account. We use this only to understand which Sentinel campaigns lead to confirmed and activated accounts. It does not change your access, plan, trial, billing, or eligibility, and we do not use advertising network tracking pixels for this measurement.
- Free website-toolkit measurement — for each code preparation, the browser creates a fresh random UUIDv4 and a separate private verifier. This browser stores up to 12 of its latest tool/hostname credentials, including the raw hostname and verifier, so the installer can return and check the attempt. The toolkit treats them as expired after 30 days and removes expired entries on the next toolkit visit; clearing browser storage removes them sooner. The raw hostname and verifier are sent to Sentinel during preparation, and the verifier is sent again during status checks. Sentinel's server analytics database persists only a keyed HMAC of the hostname and a one-way hash of the verifier, plus the fixed calculator type and event timestamps. Neither raw value appears in the iframe URL. The fixed redirect records a matching iframe-request signal only when a previously prepared UUID receives both matching hostname-HMAC evidence and browser headers describing an iframe navigation. To perform that comparison, the installed iframe normally sends the public parent website origin (not its page path or query) in the request's Referer header. Sentinel processes that raw origin transiently, hashes its normalized hostname for comparison, and does not persist the raw origin in toolkit product analytics. The redirect then sends a no-referrer policy so the consumed parent origin is not forwarded to the final embed. Those headers and requests can be suppressed, replayed, or forged, so the signal is not ownership verification or proof that an installation remains live. After an explicit calculator interaction returns a successful result, the widget may present a short-lived signed receipt to report one first-result signal. We do not put the parent page path or query, calculator inputs or results, email, name, or visitor identity fields in the toolkit record. Raw IP addresses and the public parent origin are processed transiently and may appear in ordinary infrastructure security/access logs, but are not persisted in toolkit product analytics. If the installer then submits an email, a separate short-lived signed claim can qualify the bounded “agent-toolkit” lead-source label; the attempt ID, hostname HMAC, and verifier are not attached to that email or account. None of these signals proves a person, website ownership, professional license, lead, or unique visitor.
- Payment details — handled entirely by Stripe. We store a Stripe customer identifier but never see your card number.
2. How We Use Your Information
Your data is used solely to deliver SENTINEL’s services:
- Answer your chat queries with property data, market stats, and coaching.
- Maintain conversational context so responses are relevant to your prior messages.
- Calculate deterministic math (REET, net sheets, commissions, deadlines).
- Surface deadline alerts and optional morning action plans (Pro tier).
- Improve service quality and troubleshoot issues.
- Continue a requested trial, Founding Agent Lab, or office-pilot signup and respond to that request. We do not add these addresses to unrelated bulk marketing lists.
3. How We Share Your Information
We share limited data with infrastructure providers who process it on our behalf, bound by their own privacy commitments:
- Supabase — account authentication and database storage. Supabase Privacy Policy.
- Railway — application hosting. Railway Privacy Policy.
- Anthropic — processes message content via Claude AI to classify intent and generate responses. Anthropic does not use API-submitted content for model training. Anthropic Privacy Policy.
- Stripe — payment processing (only if you subscribe). Stripe Privacy Policy.
- Resend — transactional email delivery (trial welcome, weekly digest, deadline alerts). Resend Privacy Policy.
- Vonage (Nexmo) — phone-number verification on account signup. Phone numbers are never used for marketing. Vonage Privacy Policy.
- Cloudflare / Fastly — content-delivery network for our domains. Standard request logs (IP, user agent) only.
We do not share your data with ad networks, data brokers, or any third party for marketing purposes.
4. Data Retention
Account data is retained while your account is active. You can request deletion of your data at any time by emailing craig@sentineliq.net. We will delete your profile, contacts, deals, and chat history within 30 days of a verified request, except as required by law (e.g., records of payments subject to tax retention rules).
Pre-account trial, Founding Agent Lab, and office-pilot request records are retained while we evaluate and respond to the request and for reasonable business recordkeeping. You may ask us to delete one at any time using the same privacy-request address below.
Installation and support correspondence is retained while we respond to the request and for reasonable support and business recordkeeping. You may request deletion using the privacy-request address below.
The browser campaign receipt used for account attribution expires after 24 hours. Public acquisition events and account-attribution records may be retained for aggregate performance, reliability, abuse-prevention, and business recordkeeping. If an account is deleted, we remove the direct account association; de-identified campaign labels and their internal receipt relationship may remain in aggregate analytics. You may request deletion using the same privacy-request address below.
Website-toolkit attempt records may be retained for aggregate adoption, reliability, abuse-prevention, and business recordkeeping. Sentinel's server analytics records contain the opaque attempt ID, fixed tool, keyed hostname HMAC, one-way verifier hash, and bounded timestamps—not the raw hostname, raw verifier, page URL, calculator values, or a user/account link. The separate browser-local credentials described above are treated as expired after 30 days and removed on the next toolkit visit, or sooner when browser storage is cleared.
5. Your Rights
Washington residents have rights under Washington consumer privacy laws to:
- Know what personal information we hold about you.
- Request correction of inaccurate information.
- Request deletion of your information.
- Export your data in a portable format.
To exercise these rights, email craig@sentineliq.net with "Privacy request" in the subject line.
6. Security
We use industry-standard safeguards: encrypted transport (HTTPS/TLS), asymmetric JWT-based authentication (ES256 via Supabase JWKS), rate limiting, log redaction of sensitive fields, and prompt-injection defenses against adversarial inputs. No system is perfectly secure; we disclose breaches as required by law.
7. Children’s Privacy
SENTINEL is for licensed real estate professionals. We do not knowingly collect information from children under 13. If you believe we have, email us and we will delete it.
8. Changes to This Policy
We may update this policy occasionally. Material changes will be announced via an in-app notice and email to account holders at least 30 days before taking effect.
9. Contact
Questions about privacy? Email craig@sentineliq.net.