RentalMath
Account Security Notices
Authentication requirements, password responsibilities, and session security.
In This Document
1Accounts Are Optional and Free
RentalMath accounts are optional and free. Authentication is managed by Firebase Authentication (Google LLC):
- Without an account: The core analysis experience works fully signed out. Deal data is stored only in your browser (IndexedDB / localStorage). No authentication is involved.
- With an account: Signing in additionally enables property-level data lookups (RentCast) and Firestore cloud sync with multi-device access.
Creating an account constitutes acceptance of the Terms of Use and Privacy Policy.
2Authentication Methods
RentalMath supports the following authentication methods for account holders:
- Email and password: Credentials are stored and managed by Firebase Authentication (Google). Our own server never stores or sees your password.
- Google Sign-In: OAuth 2.0 authentication via Google. Your Google account credentials are never transmitted to or stored by us.
Apple Sign-In is not offered (it was previously described in earlier versions of these notices and has been removed).
The authentication method you use at account creation determines how you sign in going forward. You cannot switch authentication methods without creating a new account.
3Password and Credential Responsibilities
Your responsibilities include:
- Choosing a strong, unique password if using email/password authentication.
- Keeping your password confidential and not sharing it.
- Notifying us immediately at admin@housatonicholdings.com if you suspect unauthorized access to your account.
- Ensuring your registered email address remains current and accessible, as it is used for authentication recovery and important account notices.
We are not liable for loss or damage arising from your failure to maintain the security of your credentials.
4Password Reset and Recovery Emails
If you use email/password authentication and lose access to your password, you may request a password reset email through the App's sign-in screen. Password reset emails are sent by Firebase Authentication to your registered email address.
If you cannot access your registered email address, account recovery may not be possible. We strongly recommend keeping your registered email address current. The App does not currently include an account-settings screen for changing your email address; to update it, contact admin@housatonicholdings.com.
If you use Google Sign-In, password recovery is handled by Google and is outside our control.
5Social Sign-In (Google)
When you sign in using Google, the following applies:
- Your sign-in is authenticated directly with Google. We receive only a confirmation token and your name and email address from the provider.
- We do not receive your Google password.
- Revoking RentalMath's access through your Google account settings will prevent future sign-ins but will not delete your RentalMath account or data. Contact us to delete your account after revoking access.
- The security of your Google account (including two-factor authentication settings) is your responsibility and is governed by Google's terms and policies.
See the Third-Party Services Disclosure and Privacy Policy for more on what data we receive from social sign-in providers.
6Session Security
Authentication sessions are managed by Firebase Authentication using secure tokens. The following applies to your session:
- Session tokens are stored by the Firebase SDK in your browser's IndexedDB (with localStorage as a fallback) and are used to authenticate requests to Firestore.
- While you are signed in, the App attaches your Firebase ID token to analysis requests sent to our server. The server verifies the token against Google's public keys solely to confirm signed-in status before making paid third-party data calls; it does not store the token.
- Sessions may persist across browser restarts based on your browser's localStorage retention settings.
- Clearing your browser's site data (IndexedDB and localStorage) will sign you out of the App.
- You should sign out of your account when using shared or public devices. Use your browser's private/incognito mode on shared devices.
- We do not currently support forced remote session invalidation across all devices simultaneously. If you suspect account compromise, change your password (or revoke social sign-in access) and contact us.
All data transmitted between the App and Firebase/Firestore is encrypted using HTTPS/TLS.
7Accounts and Future Paid Subscriptions
RentalMath accounts are currently free and no paid subscriptions are offered. If paid subscriptions are introduced in the future, any subscription would be tied to your account (email address), would be non-transferable, and would be governed by the Subscription & Billing Terms. Deleting your account triggers the data deletion process described in the Data Retention & Deletion Disclosure.
8Account Compromise
In the event of suspected account compromise:
- Change your password immediately (if using email/password authentication) or revoke RentalMath's access through your Google account.
- Contact us at admin@housatonicholdings.com with subject "Account Compromise."
- We will investigate and may temporarily suspend the account pending verification.
- We are not liable for any loss resulting from unauthorized account access where you failed to maintain the security of your credentials.
9Account Deletion
To delete your account and all associated data:
- Email admin@housatonicholdings.com with subject "Account Deletion Request" from your registered email address.
- We will verify your identity and process the deletion within a reasonable timeframe.
- Account deletion permanently deletes all Firestore cloud data and your authentication record. This process is irreversible.
- We may retain certain information as required by law.
See the Data Retention & Deletion Disclosure for full details on data deletion timelines.
RentalMath