Legal / Security

Security at Lintel

Lintel operates inside your buildings' most sensitive workflows — tenant conversations, application documents, and the accounts you connect. This page describes how that data is protected.

Encrypted in transit

All traffic protected by HTTPS/TLS.

Encrypted at rest

OAuth tokens sealed with AES-256-GCM authenticated encryption.

Email never stored

Message content stays in your Gmail or Outlook account.

No AI training

Your data is never used to train foundation models.

Infrastructure

Encryption

Email content stays in your mailbox

Lintel connects to Gmail and Outlook through their official APIs, using the minimum OAuth scopes needed to read inquiries, send replies, and manage showings. Email message content is never persisted in our systems — we store only thread identifiers for conversation continuity, and fetch messages directly from your provider when you view them. Revoke access at any time from your Google or Microsoft account settings; stored tokens are automatically invalidated and deleted.

Application documents

AI sub-processors

Document extraction runs on enterprise API agreements with Anthropic, OpenAI, and Microsoft Azure OpenAI, each governed by a Data Processing Addendum. Under those agreements, your documents and the data extracted from them are not used to train any foundation model. AI-extracted fields may contain errors and are surfaced for human verification — Lintel does not make leasing decisions. Full details, including DPA links for each provider, are in our Privacy Policy §7.

Data deletion & your controls

Reporting a vulnerability

If you believe you've found a security issue in Lintel, email nate@usedealdesk.com with details and steps to reproduce. We review every report and will respond promptly. Please avoid accessing other users' data while testing.