Legal

Privacy Policy

Effective Date: 31 March 2026 · Platform: KeydIn

Your privacy matters. This policy describes how KeydIn handles your personal data, email content, AI outputs, and cookies. Also see our Terms & Conditions.

1Introduction

KeydIn (“we”, “our”, or “the Platform”) respects your privacy and is committed to protecting personal data.

This Privacy Policy explains how we collect, use, process, and store information when users access or use the KeydIn platform.

By using KeydIn, you agree to the collection and use of information in accordance with this Privacy Policy.

2Information We Collect

We collect several types of information to operate and improve the platform.

Account Information

When users create an account, we may collect:

  • Name
  • Email address
  • Agency name
  • Phone number
  • Login credentials

This information is used to create and manage user accounts.

Buyer & Lead Information

KeydIn stores lead information submitted or captured through the platform, including:

  • Buyer names
  • Buyer email addresses
  • Phone numbers
  • Property enquiries
  • Conversation history
  • Lead status and pipeline stage

This information allows agents to manage buyer relationships.

Email Integration Data

If you connect an email account (Gmail or Outlook) to KeydIn:

  • KeydIn reads incoming emails to detect property enquiries from portals such as Domain, Trade Me, and REA Group.
  • Only relevant enquiry data is extracted and stored.
  • KeydIn may send emails on your behalf, either when you approve AI-drafted responses or automatically when AI Auto-Reply is enabled. Auto-Reply sends responses, schedules inspections, and books meetings autonomously without requiring manual approval.

KeydIn does not store full email inboxes or unrelated messages.

Parsed information may include:

  • Sender name
  • Email address
  • Phone number
  • Message content
  • Property address referenced in the enquiry
  • Portal source (e.g. Domain, Trade Me)

Calendar Integration Data

If you connect a calendar (Google Calendar or Outlook Calendar) to KeydIn:

  • KeydIn syncs calendar events to provide daily briefings and availability checking.
  • KeydIn may create calendar events on your behalf when booking inspections or meetings with buyers.

Stored calendar data may include:

  • Event titles, times, and locations
  • Attendee email addresses
  • Event type (inspection, meeting, appraisal)

Social Media Integration Data

If you connect a Facebook Page to KeydIn:

  • KeydIn stores an encrypted OAuth access token to publish posts to your connected Facebook Page on your behalf.
  • KeydIn stores your Facebook Page name and ID for display purposes.
  • KeydIn does not read your Facebook feed, messages, or personal profile data.

Posts are only published when you explicitly click “Publish to Facebook” on a social draft.

If your Facebook Page has a linked Instagram Business Account, KeydIn may also store your Instagram account ID to enable publishing to Instagram. The same OAuth connection and access token are used for both Facebook and Instagram publishing. Instagram posts are only published when you explicitly click “Post to Instagram” on a social draft that includes an image.

Free Trial Data

When you sign up for a free trial, KeydIn stores your trial start and end dates. During the trial, all platform features function identically to a paid subscription. If the trial expires without a paid subscription, AI features are disabled but your data (leads, conversations, listings) is retained and accessible in read-only mode. Your data is never deleted due to trial expiry.

Vendor & Seller Data

For properties listed through KeydIn, we may store vendor (seller) information including:

  • Vendor name and email address
  • Property listing details
  • AI-generated vendor reports (campaign performance, buyer feedback summaries, market insights)

Vendors may be invited to view a sanitised portal showing campaign data. Sensitive internal data such as commission rates is never exposed to vendors.

Subscription & Billing Data

Subscription payments are processed through Stripe. KeydIn stores your Stripe customer ID and subscription status but does not store credit card numbers or sensitive payment details on its own servers.

AI Processing Data

KeydIn uses artificial intelligence to provide features such as:

  • Email enquiry parsing and lead creation
  • Lead scoring, categorisation, and win-probability predictions
  • Draft email responses, autonomous auto-replies, and suggested follow-ups
  • Vendor transparency reports (buyer feedback, market insights, recommendations)
  • Daily briefings and AI preparation notes
  • Revenue intelligence and pipeline forecasting
  • Autonomous calendar scheduling, meeting booking, and rescheduling
  • AI-generated marketing and social media posts

To perform these features, relevant lead, property, and conversation data may be sent to our AI provider (OpenAI) for processing. Data is transmitted securely and is not used by the AI provider to train their models.

AI outputs are generated automatically and may not always be accurate.

Mobile App Data

KeydIn offers a native mobile application (iOS and Android). When using the mobile app, we may collect:

  • Device type and operating system version
  • Push notification tokens (for lead and conversation alerts)
  • App usage and session data

The mobile app uses Bearer token authentication. Access tokens are stored securely on-device and are used only to authenticate requests to KeydIn's servers. We do not access contacts, camera, microphone, or other device features unless explicitly granted by you.

Usage Analytics

KeydIn may collect platform usage data including:

  • Pages visited
  • Features used
  • Interaction timestamps
  • Device/browser information

This data is used to:

  • Improve product design
  • Understand feature usage
  • Identify errors and performance issues

3How We Use Information

We use collected data to:

  • Operate the KeydIn platform
  • Manage user accounts and subscriptions
  • Create and manage leads, conversations, and vendor reports
  • Provide AI-powered features (scoring, drafts, reports, briefings)
  • Sync and create calendar events for inspections and meetings
  • Send emails on behalf of agents (approved responses, confirmations)
  • Provide vendor portal access for campaign transparency
  • Process subscription payments via Stripe
  • Generate analytics and performance insights
  • Improve platform functionality
  • Provide optional two-factor authentication (MFA) for account security
  • Detect fraud or misuse

4Data Storage & Security

We take reasonable measures to protect user data.

Security practices include:

  • AES-256-GCM encryption for stored OAuth tokens and MFA secrets
  • Hashed passwords (never stored in plaintext)
  • SHA-256 hashed password reset tokens
  • Optional two-factor authentication (TOTP MFA) with encrypted secrets and bcrypt-hashed backup codes
  • JWT authentication with httpOnly, secure cookies
  • Secure databases with restricted access
  • Encrypted communications (HTTPS/TLS)

However, no system is completely secure and KeydIn cannot guarantee absolute security.

5Third-Party Services

KeydIn integrates with the following third-party services:

  • Google — Gmail API and Google Calendar API for email sync, calendar sync, and event creation (via OAuth 2.0)
  • Microsoft — Outlook Mail and Outlook Calendar via Microsoft Graph API (via OAuth 2.0)
  • OpenAI — GPT-4o for AI-powered lead scoring, email parsing, report generation, and content drafting
  • Stripe — secure subscription billing and payment processing (PCI-DSS compliant)
  • Resend — transactional email delivery for notifications, confirmations, and vendor reports
  • Facebook & Instagram (Meta) — Facebook Graph API and Instagram Graph API for publishing social media posts to connected Facebook Pages and Instagram Business Accounts (via OAuth 2.0 / Facebook Login for Business)

These services operate independently and have their own privacy policies. KeydIn is not responsible for how third-party services collect or use data.

KeydIn also processes enquiry emails originating from property listing portals (e.g. Domain, Trade Me, REA Group). These portals are not directly integrated and have their own data practices.

6Data Retention

We retain user data for as long as necessary to:

  • Provide platform functionality
  • Maintain account records
  • Comply with legal obligations

Users may request account deletion via Settings → Account in the platform. Account deletion is permanent and removes all agency data including leads, conversations, listings, integrations, and user accounts. Active subscriptions are cancelled immediately upon deletion. This action cannot be undone.

Alternatively, users can contact support to request deletion.

7User Rights

Depending on jurisdiction, users may have rights to:

  • Access their personal data
  • Request corrections
  • Request deletion
  • Withdraw consent for data processing

Requests can be submitted through the KeydIn support system.

8Cookies & Tracking

KeydIn may use cookies or similar technologies to:

  • Maintain login sessions
  • Store preferences
  • Analyse platform usage

Users may disable cookies in their browser, although this may affect functionality.

9Children's Privacy

KeydIn is intended for professional real estate use and is not designed for individuals under 18 years of age.

We do not knowingly collect personal data from minors.

10Changes to This Privacy Policy

KeydIn may update this Privacy Policy periodically.

Updates will be posted on the platform, and continued use constitutes acceptance of the updated policy.

11Contact Information

For questions about this Privacy Policy or data handling practices, please contact:

KeydIn Support

support@keydin.com

Questions about this policy? Reach out to us.

Contact KeydIn →