Legal / Security
Security at Lintel
Lintel operates inside your buildings' most sensitive workflows — tenant conversations, application documents, and the accounts you connect. This page describes how that data is protected.
Encrypted in transit
All traffic protected by HTTPS/TLS.
Encrypted at rest
OAuth tokens sealed with AES-256-GCM authenticated encryption.
Email never stored
Message content stays in your Gmail or Outlook account.
No AI training
Your data is never used to train foundation models.
Infrastructure
- Account data lives in a PostgreSQL database hosted by Supabase with enterprise-grade security controls; Supabase also provides user authentication.
- The web application is hosted on Vercel; the backend API and Redis run on Railway.
- Access tokens are cached in Redis for at most 55 minutes and are automatically cleared on expiration.
Encryption
- All data in transit is protected by HTTPS/TLS.
- OAuth access and refresh tokens are encrypted at rest using AES-256-GCM authenticated encryption.
Email content stays in your mailbox
Lintel connects to Gmail and Outlook through their official APIs, using the minimum OAuth scopes needed to read inquiries, send replies, and manage showings. Email message content is never persisted in our systems — we store only thread identifiers for conversation continuity, and fetch messages directly from your provider when you view them. Revoke access at any time from your Google or Microsoft account settings; stored tokens are automatically invalidated and deleted.
Application documents
- Uploaded documents (pay stubs, bank statements, IDs) are held only briefly while AI extraction runs; originals are deleted from storage shortly after extraction completes. Only the structured fields — credit score, income, employer — are retained on the applicant's record.
- Extraction prompts explicitly instruct the AI to skip protected-class indicators (national origin, citizenship, immigration status, religion, familial status, disability, source of income, and similar), so they are not extracted into any record even if mentioned in the source document.
AI sub-processors
Document extraction runs on enterprise API agreements with Anthropic, OpenAI, and Microsoft Azure OpenAI, each governed by a Data Processing Addendum. Under those agreements, your documents and the data extracted from them are not used to train any foundation model. AI-extracted fields may contain errors and are surfaced for human verification — Lintel does not make leasing decisions. Full details, including DPA links for each provider, are in our Privacy Policy §7.
Data deletion & your controls
- Data is retained only while your account is active; deleting your account permanently removes listings, inquirer records, workflows, templates, and OAuth tokens.
- You can request access, correction, deletion, or a portable export of your data at any time.
- Disconnecting Google or Microsoft — from inside Lintel or from your provider's settings — invalidates and deletes stored tokens immediately.
Reporting a vulnerability
If you believe you've found a security issue in Lintel, email nate@usedealdesk.com with details and steps to reproduce. We review every report and will respond promptly. Please avoid accessing other users' data while testing.