1. What we collect
From you (the account holder)
- Account info: name, email address, photo, and Google sign-in identifier.
- Tenant info: the workspace you create or join, including the workspace name and your role (admin or member).
- Settings: brokerage profile, voice profile, coaching playbook rules, calendar booking preferences.
- API keys: when you generate keys for the MCP server, we store a SHA-256 hash of each key (never the raw key).
About prospects you add
- Contact data: name, brokerage, email, phone, county, license number where you provide it.
- Production data: sales volume and transaction counts you import or enter.
- Activity history: calls, meetings, notes, tags, broadcasts, and tasks you log against each prospect.
- Communications: outbound and inbound emails and texts associated with prospects, including subject lines, message bodies, and reply timestamps.
- Opt-out flags: Do-Not-Contact status, STOP-replies, bounced emails — so we never message anyone who's asked to be left alone.
From connected services (only if you connect them)
- Google Calendar: with your consent, we read your free/busy times to power booking pages, and create calendar events when you create tasks. We use the
calendar.eventsandcalendar.readonlyscopes. - Gmail (read-only): if connected, we scan inbox metadata and message bodies for STOP replies and bounce notifications, so prospects who opt out are excluded from outreach.
- OpenPhone / Quo: if you enable our webhook, we receive call recordings and transcripts to auto-summarize into the prospect activity log.
2. How we use it
- To run the Talent Attractor product features you signed up for: the prospect list, communication tracking, scoring, broadcasts, calendar booking, and AI coaching.
- To power AI features — drafting messages, summarizing calls, generating talking points, suggesting playbook rules — using Anthropic's Claude API. Prompts and responses are processed by Anthropic per their data handling terms; Anthropic does not train models on this content.
- To send transactional emails — invitations, password recovery, error notifications.
- To improve the product through aggregated, de-identified usage analytics.
We do not sell personal data. We do not show advertisements. We do not share your prospect data with other tenants.
3. Who we share data with (subprocessors)
We use these services to deliver Talent Attractor. Each is a "subprocessor" and only receives the data it needs to perform its function:
- Google Cloud / Firebase — authentication, Firestore database, hosting. Data is stored in Google's US-based data centers.
- Netlify — web hosting and serverless function execution.
- Anthropic — the Claude AI model that powers the in-app coach (Pisgah), drafting, and analysis.
- OpenPhone / Quo — telephony, SMS, and call transcription if you connect a phone account.
- SendGrid — outbound transactional email.
We may also disclose data when required by law, to enforce our Terms of Service, or to protect the safety of our users.
4. How long we keep it
- Account and tenant data — until you delete your account or close your workspace.
- Prospect and activity data — until you delete it. Admins can run "Delete All Prospects" from Settings → Danger Zone to wipe all prospects in their tenant.
- API key records — until you revoke them.
- Call transcripts and message bodies — same retention as the prospect record they belong to.
5. Your rights
You can:
- Access — view all data attached to your account from inside the app.
- Correct — edit prospect records, settings, and your profile at any time.
- Delete — remove individual prospects, or wipe everything via Settings → Danger Zone (admins only).
- Export — request a JSON or CSV export of your tenant's data by emailing us.
- Disconnect integrations — revoke Google Calendar, Gmail, or OpenPhone connections in Settings or from the respective provider's account dashboard.
- Close your account — email us and we'll delete your tenant within 30 days.
If you're a resident of the EU, UK, or California, you may have additional rights under GDPR, UK GDPR, or CCPA — including the right to file a complaint with your local data protection authority.
6. Security
- All traffic is encrypted in transit (TLS).
- Data at rest is encrypted by Firestore's default at-rest encryption.
- API keys are stored as SHA-256 hashes; the raw key is never written to the database.
- Access to the production database is limited to authenticated administrators of Talent Attractor.
No system is perfectly secure. If we discover a breach affecting your data, we will notify you within 72 hours of becoming aware.
7. Children
Talent Attractor is a business tool not directed at children. We do not knowingly collect data from anyone under 16. If you believe we have, please contact us and we will delete it.
8. Changes to this policy
If we make material changes, we'll notify account holders by email and update the "Last updated" date at the top of this page.
Talent Attractor (operated by J. Michael Manley)
Email: jmichaelmanley@kw.com
Address available on request for legal correspondence.