Privacy Policy
Effective September 27, 2026
BrokerTunnel (“BrokerTunnel”, “we”, “us”) connects real-estate brokerages’ business systems — such as their back office, CRM and transaction management — to AI assistants such as Claude, ChatGPT and others that support connectors. This policy explains what information we handle when brokerages, their staff and their agents use the BrokerTunnel portal at app.brokertunnel.com and the BrokerTunnel connector in an AI assistant, and what we do with it.
A brokerage decides which systems to connect and who may use them. For information that comes from those systems, we act on the brokerage’s behalf.
Information we handle
- Account information. For each person with a BrokerTunnel account: name, email address, role (admin, broker or agent) and account status; for the brokerage: its name and office time zone. Passwords are stored only as a salted one-way hash.
- Connection credentials. API keys and sign-in tokens for the systems a brokerage or a user connects (for example BoldTrail BackOffice, Follow Up Boss or dotloop), and the name of the account they belong to. Credentials are encrypted with AES-256-GCM before they are stored.
- Information from connected systems. When someone asks a question, we read what is needed from the connected system — for example deals, commissions, contacts, leads, tasks, loops and their details — and return the answer to that person’s AI assistant. We don’t copy this information into a database of our own. Some responses, such as lists of agents or pipeline stages, are kept in a short-lived cache (usually minutes and never more than 24 hours) so we don’t ask the same system repeatedly.
- Requested changes. When someone asks for a change, we keep the plan (what would change, and the values it replaces) and, once it is approved, the outcome — so the brokerage can review it and, if needed, retry or undo it.
- Activity records. For each request: who made it, when, from which assistant or page, the request and its result. Admins of the brokerage can see all of the brokerage’s activity; other users see their own.
- Usage counts. Numbers of requests and calls to connected systems per minute or hour, used to keep the service reliable. They are kept for 90 days.
- Cookies. One cookie keeps you signed in to the portal. We don’t use advertising or analytics cookies, and we don’t track you across other websites.
How we use information
- To answer requests and carry out changes that a broker or admin has approved.
- To keep the service secure and reliable: signing you in, enforcing roles and limits, and investigating errors.
- To support your brokerage: our team can see a brokerage’s settings, connection status and activity records to help when something doesn’t work.
- To tell you about the service, for example changes to this policy.
We don’t sell or rent personal information, we don’t use it for advertising, and we don’t use information from your connected systems to train AI models.
AI assistants
You choose which AI assistant to connect to BrokerTunnel. The assistant receives your questions and the answers we return, and its provider (for example Anthropic for Claude or OpenAI for ChatGPT) handles them under its own terms and privacy policy. You can remove the BrokerTunnel connector from your assistant at any time.
Connected systems
We access a connected system only with the permission of the account holder — through an API key they provide or by them signing in and allowing access — and only in the ways that system permits. We use that access only to answer requests from people in the same brokerage, according to their role. Information from one brokerage is never shared with another.
- With one key for the whole brokerage, every request uses that key, and the connected system records actions under the person the key belongs to.
- With personal keys or accounts (for example dotloop, where everyone connects their own account), requests use the asking person’s own access. Brokers and admins of the same brokerage can ask for team summaries that include the information of everyone who has connected.
- Disconnecting deletes the stored credentials; where the system supports it, we also revoke the sign-in with that system.
Service providers
We use a small number of providers to run the service:
- Cloudflare — hosting, databases and storage, and Cloudflare’s AI service to match a request to the right action (it receives the text of the request).
- OpenAI — used by our team when building custom actions for a brokerage. These requests describe the action and can include short results of a test run.
- Google — web fonts on our pages (your browser loads them from Google), and looking up the icon of the AI assistant you connect (only the assistant’s web address is sent).
The systems you connect receive our requests on your behalf and handle them under your agreement with them.
Security
Information travels over encrypted connections (HTTPS). Credentials are encrypted at rest, passwords are hashed, access follows each person’s role, every change needs approval, and every request is recorded. No system is perfectly secure; if we learn of a breach that affects your information, we will notify you as required by law.
How long we keep information
- Account information, requested changes and activity records: for as long as the brokerage’s account exists.
- Credentials: until the system is disconnected or the account is closed.
- Usage counts: 90 days. Cached responses: at most 24 hours.
When a brokerage closes its account, we delete its information within 30 days of the request, except where we must keep something to comply with the law.
Your choices and rights
You can ask us to access, correct or delete your personal information, or for a copy of it, by writing to privacy@brokertunnel.com. Depending on where you live (for example California), you may have additional rights; we honor these requests for every user. Requests about information held in a connected system may also need to go to your brokerage or to that system’s provider. We won’t treat you differently for making a request.
Children
BrokerTunnel is a business service for real-estate professionals and isn’t meant for anyone under 18.
Changes to this policy
If we change this policy, we will update the date above; for significant changes we will also tell brokerage admins by email or in the portal before they take effect.
Contact
Questions about this policy or your information: privacy@brokertunnel.com.