Privacy Policy
Effective date: August 1, 2026
1. Who We Are
FairDraft is a product of Rizvex, operated by Haider Ali (rizvex.com). FairDraft is a text drafting and scanning tool for US real estate professionals. It is a drafting aid only — not legal advice. References to "we," "us," or "our" mean Rizvex. You can reach us at support@rizvex.com.
Rizvex, operated by Haider Ali, is the data controller for the personal information described in this policy. That means we decide what is collected and why, and we are accountable for it.
2. What We Collect
When you use FairDraft, we collect:
- Account data — your name and email address, provided via Google or Microsoft sign-in.
- Listing text — the property description text you paste into the scanner or generator. This text is processed to provide the service.
- Usage data — scan counts, generation counts, selected state, plan tier, and timestamps. Stored in our database to enforce usage limits and display your history.
- Session data — authentication session tokens managed by Better Auth, stored in cookies.
- Security and activity logs — for each sign-in we record your IP address, your browser and operating system (from the user-agent your browser sends), which provider you signed in with, and the time. We also record a log of requests to our drafting service — the time, your plan, how long the request took, and whether it succeeded or was refused — plus any technical errors.
- Billing records — for paid plans we store a record of each payment, refund, or failed payment reported to us by Paddle: the amount, currency, tax, your billing email address, and the related subscription reference. We never receive or store card numbers.
We do not collect payment card details. Payment data is handled exclusively by Paddle (see Section 4).
3. How We Use Your Data
- To authenticate you and maintain your session.
- To process listing text through our scanning engine and generate listing descriptions.
- To enforce free tier limits and plan-based usage caps.
- To display your scan history in your dashboard.
- To respond to support requests sent to support@rizvex.com.
- To keep the service secure and working. We use the security and activity logs described above to detect and investigate abuse, shared or resold accounts, fraudulent or failed payments, and technical faults, and to monitor the reliability, capacity, and running cost of the service. Where you are in the UK or EEA, our lawful basis for this is our legitimate interest in protecting the service and its users.
- To keep an internal audit record of administrative actions taken on accounts, so changes to a plan or quota can be traced.
We do not use your listing text to train machine learning models. We do not sell your data to third parties.
Our lawful basis for each purpose (relevant if you are in the UK or EEA):
| Purpose | Lawful basis |
|---|---|
| Creating your account, signing you in, and providing the drafting and scanning service | Performance of a contract |
| Enforcing plan limits and quotas | Performance of a contract |
| Taking payment and handling refunds | Performance of a contract |
| Keeping billing records for the periods tax law requires | Legal obligation |
| Security logging, fraud and abuse prevention, service reliability and cost monitoring, and administrative audit records | Legitimate interests — protecting the service and its users |
| Responding to your support requests | Legitimate interests — answering the person who contacted us |
Where we rely on legitimate interests, you have the right to object — see Section 7. We do not rely on consent for anything described in this policy, so there is no consent for you to withdraw.
4. Third-Party Services
FairDraft uses the following third-party services that may process your data:
- Google OAuth — used for sign-in. Governed by Google's Privacy Policy. We receive only your name and email address.
- Microsoft OAuth — an alternative sign-in option. Governed by Microsoft's Privacy Statement. We receive only your name and email address.
- Groq — your listing text is sent to Groq's API to generate listing descriptions. Groq processes this text on their infrastructure. We do not send your name, email, or account data to Groq. Review Groq's privacy policy at groq.com.
- Cloudflare — our application runs on Cloudflare Workers and D1. Cloudflare may process request metadata (IP address, headers) in the normal course of serving web traffic. Review Cloudflare's privacy policy at cloudflare.com.
- Paddle — payment processing for paid plans. Paddle acts as the Merchant of Record. Your payment card data is collected and stored by Paddle, not by FairDraft. Review Paddle's privacy policy at paddle.com.
5. Where Your Data Is Processed
FairDraft runs on Cloudflare's global network, and the providers listed in Section 4 process data on infrastructure located in the United States and elsewhere. If you use FairDraft from the United Kingdom or the European Economic Area, your personal information will be transferred outside your country.
We use established providers that publish data protection terms covering international transfers, and we rely on those published terms. You can review them on each provider's own website: cloudflare.com, groq.com, paddle.com, google.com, and microsoft.com.
6. Data Retention
We retain your account data and scan history for as long as your account is active. If you request account deletion, we will delete your account record and associated usage data from our database within 30 days. Residual data in backups may persist for up to 90 days.
Security, activity, and billing records are deleted automatically once they pass the periods below. Deletion is enforced by an automated daily sweep, not by request — you do not need to ask, and we cannot quietly keep a record longer. Each period is counted from the moment the individual record was created, so a sign-in on 1 March is deleted the following 1 March, not at the end of some later batch.
| Record | Created when | Deleted after |
|---|---|---|
| Service request logs One record per drafting request: the time, your plan, whether it succeeded or was refused, how long it took, and the size of the request sent to our AI provider. | Each time you generate or scan a listing. | 90 days |
| Error records Technical fault messages, and the organisation involved where relevant. | When a request fails or a payment webhook cannot be processed. | 90 days |
| Sign-in records For each sign-in: your IP address, your browser and operating system, which provider you signed in with (Google or Microsoft), and the time. | Each time you sign in, and once when you first create an account. | 12 months |
| Subscription event records Notifications received from our payment provider — the event type, your billing email, the subscription reference, and the raw notification. | When you subscribe, change, renew, or cancel a paid plan. | 24 months |
| Cancellation records A record of each request to cancel a subscription: your email address, whether it completed, and the reason if it did not. | When you cancel a subscription, or ask us to cancel one for you. | 24 months |
| Administrative audit records Any change an administrator makes to an account or organisation — what changed, which account, and when. | When support or an administrator changes your plan, quota, or seats. | 24 months |
| Billing records Each payment, refund, or failed payment: amount, currency, tax, your billing email, and the subscription reference. Never card numbers. | When a payment succeeds, fails, or is refunded. | 7 years |
Why these periods, and not shorter or longer:
- Service request logs — 90 days. 90 days is the shortest window that still allows a fault or abuse pattern to be investigated after it is reported. Operational logs are not needed beyond that.
- Error records — 90 days. Matches the service request logs — errors are only useful alongside the requests they relate to.
- Sign-in records — 12 months. 12 months. Detecting a shared or resold account depends on comparing sign-in locations across seasons, which a 90-day window cannot show. This is a common retention period for security logs.
- Subscription event records — 24 months. 24 months, so a full subscription lifecycle including a year-on-year comparison remains reviewable. The durable financial record lives in the billing records below.
- Cancellation records — 24 months. 24 months, matching the subscription event records above, so a later dispute about when a cancellation was requested can still be answered.
- Administrative audit records — 24 months. 24 months. Accountability records must outlive the change they describe so a disputed account modification can still be traced.
- Billing records — 7 years. 7 years, to satisfy financial record-keeping obligations — UK HMRC requires 6 years, and US federal and state tax rules commonly require up to 7. This is a legal obligation, not a choice.
Your account record, listing history, and usage counts are not on this schedule — they are kept while your account is active and removed when you close it, as described above.
To request deletion, email support@rizvex.com with the subject line "Delete my account." Note that we may keep a minimal security or billing record where we are required to, or where it is necessary to prevent fraud or abuse.
7. Your Privacy Rights
If you are in the United Kingdom or the European Economic Area, data protection law gives you the following rights. They are free to exercise, and we will respond within one month.
- Access — ask for a copy of the personal information we hold about you.
- Rectification — ask us to correct information that is wrong or incomplete.
- Erasure — ask us to delete your personal information. See the note on limits below.
- Restriction — ask us to pause processing while a dispute about accuracy or our grounds is resolved.
- Portability — receive the information you gave us in a structured, machine-readable format, or ask us to send it to another provider.
- Objection — object to processing we carry out on the basis of legitimate interests, including our security and activity logging. We will stop unless we can show compelling grounds that override your rights.
To exercise any of these, email support@rizvex.com from the address on your account, stating which right you are exercising. We may ask you to confirm your identity before we act.
Limits on erasure. Deleting your account removes your account record, listing history, and usage data. We may keep billing records for as long as tax law requires, and a minimal security record where it is necessary to prevent fraud or abuse. We will tell you if either applies to your request.
8. US State Privacy Rights
If you are a resident of California, Virginia, Colorado, Connecticut, Utah, Texas, or another US state with a comprehensive privacy law, you have rights over your personal information. Depending on your state, these include the right to know what we collect and why, to obtain a copy, to correct it, to delete it, and not to be treated differently for exercising any of them.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We have never done so. We do not serve targeted advertising, and we run no advertising or analytics trackers on this site.
In the twelve months before the effective date of this policy, we collected the categories of personal information described in Section 2 — identifiers (name, email, IP address), commercial information (plan and payment records), internet activity (request and error logs), and the listing text you submit. We collected it for the purposes in Section 3, from you directly, and disclosed it only to the service providers in Section 4. We do not collect sensitive personal information as that term is defined under California law.
To exercise a state privacy right, email support@rizvex.com. You may use an authorised agent; we will ask for proof of their authority. If we decline a request we will tell you why, and you may appeal by replying to our response.
9. Cookies
FairDraft uses cookies solely for authentication session management. We do not use advertising cookies, tracking pixels, or third-party analytics cookies.
10. Security
Data is transmitted over HTTPS. Authentication tokens are managed by Better Auth with secure cookie settings. We do not store listing text permanently — scan results are displayed in-session and in your history log, but raw listing text is not retained as a separate store after processing.
Access to the security and activity logs described in Section 2 is restricted to the operator of the service. Administrative actions taken on an account are themselves recorded in an internal audit log.
11. Automated Decision-Making and AI
FairDraft uses an AI model to draft and rewrite listing text, and a word list to flag language that may raise fair housing concerns. These outputs are suggestions. They are reviewed and published by you, and they do not decide anything about you.
We do not carry out automated decision-making that produces legal effects concerning you or similarly significantly affects you, and we do not profile you. Flags raised by the scanner describe the text you submitted — they are not judgements about the person who submitted it, and they are never shared with anyone outside your account.
FairDraft is a drafting aid, not legal advice, and its output is not a determination of legal compliance.
12. Children
FairDraft is a professional tool intended for adults. We do not knowingly collect data from anyone under 18. If you believe a minor has created an account, contact us at support@rizvex.com.
13. Changes to This Policy
We may update this policy. If we make material changes, we will update the effective date at the top of this page. Continued use of FairDraft after changes constitutes acceptance of the updated policy.
14. Contact and Complaints
For privacy questions, to exercise any right in Section 7 or Section 8, or to request deletion, contact us at support@rizvex.com. We aim to respond within one month.
Please contact us first — most questions are resolved quickly and directly. If you are in the UK or EEA and remain dissatisfied with our response, you also have the right to complain to your data protection authority; in the UK this is the Information Commissioner's Office (ico.org.uk).