Brownstone turns the apartment alert emails you already get into one feed you can share with a partner or roommates. This page explains, in plain English, what we collect, why, who processes it, and how to get rid of it.
What we collect and why
- Account info (email address, and the name you give us). Used to sign you in, restore your feed on a new device, and send account email. Sign in with Apple works with Apple's private relay address if you choose to hide your email.
- Apartment alert emails you send us. You choose to route alert emails from listing portals (such as Zillow, StreetEasy, and Apartments.com) to Brownstone, either with an iOS Shortcuts automation that uploads only portal alert emails or by forwarding to your private
u_<token>@getbrownstone.appaddress. We parse the listings out of them. We do not read the rest of your mailbox and have no way to. - Listing and decision data (the listings we parsed, your likes and passes, your group members and matches). This is the product.
- Search preferences (city, budget, bedrooms, neighborhoods) and your time zone, used to fill your feed and time notifications.
- Device push token, used only to send you alert and match notifications.
- Basic diagnostics and logs (errors, request logs), used to keep the service working.
We do not sell your personal information, and we do not pass your contact details to brokers, landlords, or lead buyers. Links that a portal generated for you personally are never shown to another user.
Optional Outlook connection
If you connect Outlook through Microsoft Graph, we use that permission once to create a single inbox rule that forwards portal alert mail to your Brownstone address, then discard the access tokens. We do not keep ongoing access to your mailbox.
Third parties that process data for us
- Google Cloud (us-east4): application servers.
- Supabase, on AWS us-east-1: database and authentication.
- Cloudflare: this website, inbound email routing, and short-term raw email storage (R2).
- Resend: transactional email such as sign-in and setup mail.
- Apple: Sign in with Apple, push notifications, and all subscription billing.
- Google Mobile Ads: advertising in the free tier (see below).
Advertising
Free accounts see a labeled "Sponsored" card roughly every ten listings, served by Google Mobile Ads. Ads are requested as non-personalized by default, so the ad SDK is not given an advertising identifier to profile you unless you separately allow tracking through Apple's App Tracking Transparency prompt. We do not send the ad network your email, your listings, or your swipes. Brownstone Plus removes ads entirely.
How long we keep things
- Raw emails are archived for 7 days in Cloudflare R2 for debugging, then automatically deleted.
- Listings and decision history are kept while your account is active (free accounts see 30 days of history, Plus 90 days) and pruned on a rolling basis.
- Account data is kept until you delete your account.
Deleting your account
Settings > Account > Delete Account removes your account, your feed, your decisions, and your forwarding address. Deletion is permanent. Turn off any forwarding rule or Shortcut you set up so mail stops arriving. See Support for details.
Children
Brownstone is not directed to children. You must be at least 13 years old to use it, and we do not knowingly collect personal information from anyone under 13. If we learn we have, we delete it. Contact us if you believe a child has created an account.
Your choices
You can turn notifications off, disconnect email forwarding, or delete your account at any time. If you would like a copy of your data or have a privacy question, email us and we will respond.
Changes
If we change this policy in a way that matters, we will update the effective date above and tell you in the app before the change takes effect.