Legal
Privacy Policy
Last updated: September 23, 2026
This policy describes what Polygon Research, Inc. (“Polygon Research,” “we,” “us”) collects from visitors and users of mortgagedata.ai, app.mortgagedata.ai, and api.mortgagedata.ai (the “Service”), why we collect it, and how we handle it. Our starting commitments:
- We do not sell your personal information, and we do not run third-party advertising trackers.
- We collect the minimum we need to operate, secure, and improve the Service.
- When we rely on another company to process your data, we name the category of provider here.
1. What we collect and why
Waitlist signups
If you join the waitlist we collect your email address and, optionally, your name, so we can contact you about early access. We will not use the waitlist for unrelated marketing.
Account and identity
Accounts are created and authenticated directly by the Service using your email address and one-time sign-in codes — we do not use a third-party identity provider. We collect your email address, your name if you provide it, and authentication identifiers. We use these to sign you in, associate your work and usage with your account, and communicate with you about the Service.
Purchases and billing
One-time report purchases are processed by our payment processor (Stripe); subscription plans are processed by our subscription billing provider (Chargebee). Card details go directly to the processor and never touch our systems. We receive billing contact details and transaction status, and for report purchases we keep an order record including the email address you provide at checkout — that address is how we deliver your download link and honor re-send requests, and we keep transaction records for accounting and tax purposes.
Watchlists and saved preferences
If you follow a market or a lender in the app, we store that choice with your account (including your account email address) so we can show you your watchlist and provide features you have asked for, such as briefings about the things you follow.
Questions you ask the Service
When you use AI-assisted features, the questions you submit are processed by our infrastructure and by the AI model providers we use to generate answers and to classify and route your questions. Today those providers are OpenAI and TypeSafe, reached through Cloudflare's AI Gateway. We log questions and answers to operate the feature, enforce usage limits, investigate abuse, and improve answer quality. Please do not include sensitive personal information in your questions.
Product usage and error data
We record product events (for example: page views of key flows, questions asked, signups) and application errors, tied to a coarse identifier (such as your account or an anonymous session), to understand product health and usage. ZIP orientation pages record the ZIP and the outbound directory you chose — not who opened the page. A homes.com listing hop looks up that ZIP’s city and state from a public postal directory so we can build their required URL; we send only the ZIP and do not store that lookup against you. We do not use third-party analytics trackers.
Anti-abuse measures
Public forms are protected by an anti-bot challenge (Cloudflare Turnstile), and our infrastructure provider (Cloudflare) processes request metadata such as IP addresses to serve and protect the sites.
Cookies and local storage
We use a small number of first-party cookies that are strictly necessary to operate the Service — for
example, a login-state cookie shared across our mortgagedata.ai subdomains so the public
site knows whether to show you “Sign in” or “Go to app.” We also store a few values
in your browser’s local storage: your theme preference, and an anonymous identifier used to apply
free-tier usage limits fairly. ZIP orientation pages (/go/22102) also keep a short-lived session
identifier in session storage so we can attribute directory hops from the same visit — that identifier is
hashed before it is stored, and it does not identify you. These are functional only. We do not set
advertising or cross-site tracking cookies.
2. When we disclose your information
We disclose personal information only:
- To service providers that process it on our behalf — payments (Stripe), hosting, security, and email delivery (Cloudflare), and AI model providers that generate answers to, and classify, your questions (currently OpenAI and TypeSafe).
- To comply with a valid legal request, or to protect the rights, safety, or property of us or others.
- As part of a corporate transaction (such as a merger or acquisition), with notice to you.
We do not sell or share personal information for advertising purposes.
3. Your rights
You may request access to, correction of, or deletion of your personal information, and you may opt out of waitlist or marketing email at any time, by contacting us at info@polygonresearch.com. Depending on where you live, you may have additional rights under state privacy laws; we honor applicable rights regardless of state.
4. How we secure your data
Data is encrypted in transit (TLS). Access to production systems and secrets is restricted and credentialed. Server-side credentials are never exposed to browsers. Where we log product activity for analytics, we use truncated one-way hashes of identifiers rather than raw account identifiers wherever the feature allows it.
5. Data retention
- Account information: for as long as you have an account with us.
- Waitlist entries: until we onboard or notify you, or you ask to be removed.
- Usage, question, and error logs: as long as reasonably necessary to operate, secure, and improve the Service, after which they are deleted or reduced to aggregates.
- Purchase and billing records: as required for accounting and tax law.
6. Where your data lives
The Service is operated from the United States and is directed to users in the United States. If you use the Service from elsewhere, you understand that your information is processed in the U.S.
7. Children
The Service is not directed to children under 13, and we do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, contact us at info@polygonresearch.com and we will delete it. Creating an account or making a purchase requires being at least 18 (see the Terms of Service).
8. Changes and questions
We may update this policy from time to time. We will post updates at this page with a new “Last updated” date and, for material changes, provide reasonable additional notice. Questions? Contact info@polygonresearch.com — Polygon Research, Inc., 14 Ridge Square NW, 3rd Floor, Washington, DC 20016.
Document structure adapted from the 37signals/Basecamp open-source policies (github.com/basecamp/policies), used under CC BY 4.0, with modifications.