Privacy Policy
Last updated August 30, 2026
This policy explains what information Nosy Neighbor collects, how it is used, and the
choices you have.
Information we collect
- Account information. When you sign in with Google, we receive your
email address, which identifies your account and your access tier.
- Usage data. We record the property lookups and searches you run to
enforce plan limits and to operate features like your recent searches and saved
scenarios.
- Technical data. Like most web services, our infrastructure and
monitoring tools process standard request metadata (IP address, browser type,
timestamps, and pages visited) to keep the Service running securely and reliably.
How we use information
- To provide, secure, and improve the Service.
- To enforce usage limits and prevent abuse.
- To process payments for paid plans.
- To respond to your support requests.
Cookies
We use a single first-party, HttpOnly session cookie to keep you signed in after you
authenticate with Google, plus first-party Google Analytics cookies to understand
aggregate site usage. We do not use third-party advertising or cross-site tracking
cookies to profile you.
Service providers
We share limited data with providers who help us run the Service, only as needed:
- Google — sign-in (OAuth).
- Cloudflare — hosting and content delivery.
- Stripe — payment processing for paid plans. Your card details go
directly to Stripe; we never see or store them.
- Datadog — application performance and error monitoring.
- Google Analytics — usage analytics (pages visited, traffic sources).
Data sources
Property reports are compiled from public government records and third-party data
providers. That information concerns properties, not you, and is presented for
informational purposes only.
Developer API credentials & usage
If you create a personal API key or connect through our MCP server, we additionally
collect:
- API key metadata. The label you give a key, its prefix (shown in your
dashboard so you can tell keys apart), and its creation, last-used, and revocation
timestamps. We never store a key's secret in a form we can read back — only a one-way
cryptographic hash of it, used solely to verify requests.
- Usage counters. Per-minute and per-day unit consumption against your
account's published developer rate limits.
- API request logs. The IP address, timestamp, and endpoint of each
request made with a key or MCP grant, to secure the API, diagnose problems, and enforce
rate limits.
Key metadata is kept for as long as your account exists. A revoked key's metadata is
retained afterward for audit and abuse-investigation purposes — never the secret itself,
which cannot be recovered from its hash.
Data retention & your choices
We retain account and usage data for as long as your account is active. You may request
access to, correction of, or deletion of your account data by contacting us. Deleting your
account removes your profile, saved scenarios, and saved searches.
Selling your data
We do not sell your personal information.
Contact
Questions or requests about your privacy? Contact us.