1Overview
RentalMath integrates with the following third-party services. This Disclosure names each service, its purpose, what data it receives, and links to its privacy policy. Services marked "Signed-in users" are not used for users who do not create accounts (accounts are free and optional). Shareable deal links are normally stored on our own server; if our server fails to return a short link when a share is created (unreachable, rate-limited, out of storage, or erroring), the third-party URL shorteners is.gd / v.gd are used as a fallback and receive the full share link — see Section 9 and the Sharing Disclosure.
2Google Firebase Authentication (Signed-in users)
| Purpose | User account creation, sign-in, and authentication token management (project rental-math-cc40e). Sign-in methods: email/password and Google Sign-In. |
| Data Received | Email address, hashed password (never plaintext; our own server never stores passwords), authentication tokens, and sign-in event metadata. Our server verifies Firebase ID tokens against Google's public keys to confirm signed-in status and does not persist them. |
| Policies | Firebase Terms of Service · Google Privacy Policy |
3Google Cloud Firestore (Signed-in users)
| Purpose | Cloud database for backing up and syncing saved deal records across devices. Per-user access-controlled: each user can only read and write their own data. |
| Data Received | All deal data you save: property addresses, financial inputs, calculated values, notes, and server timestamps. |
| Policies | Firebase Terms of Service · Google Privacy Policy |
4Google Sign-In (Signed-in users, optional)
| Purpose | Optional social sign-in using an existing Google account. |
| Data Received | Google provides your name and email address to Firebase Authentication. We do not receive your Google password. |
| Policies | Google Identity · Google Privacy Policy |
5RentCast (Signed-in users)
| Purpose | Property-level valuation, rent estimates, comparable sales/rentals, and active listing data for the specific address you analyze. Used only for signed-in users; signed-out analyses use the free public data sources below and are never shown RentCast data. |
| Data Received | The property address you analyze, sent from our server. No account information is sent to RentCast. |
| Policies | RentCast Terms · RentCast Privacy Policy |
6Public Property & Market Data Sources (All users)
| Services | US Census Bureau, FEMA, HUD, FRED (Federal Reserve Bank of St. Louis), OpenStreetMap (Nominatim, and Overpass via the independently operated mirrors overpass-api.de, overpass.kumi.systems, overpass.private.coffee and overpass.osm.ch), Walk Score, and Urban Institute. |
| Purpose | Geocoding and retrieval of neighborhood, market, hazard, school, and amenity data used in the analysis. |
| Data Received | The property address you analyze, or coordinates derived from it, sent from our server to perform the analysis. These requests are not linked to any user identity. |
| Note | Responses are cached on our server keyed by address or geography (up to about 30 days per source) to reduce repeat fetching. These caches contain property and geography data, not user identities. |
7jsDelivr CDN (All users)
| Purpose | Delivery of Bootstrap CSS/JS and the lz-string compression library via content delivery network. |
| Data Received | Your browser's IP address and request metadata when downloading these files. |
| Policy | jsDelivr Privacy Policy |
8Google Fonts (Pro forma export only)
| Purpose | Typefaces for the pro forma document produced by the Export function. The App itself and these legal pages no longer contact Google Fonts — as of 29 July 2026 every typeface they use is served from RentalMath's own domain. The exported document is a standalone file that may be opened outside the browser, so it still references Google's copies. |
| Data Received | IP address and browser metadata, sent to fonts.googleapis.com and fonts.gstatic.com only when you export a pro forma. Browsing the App or these legal pages sends Google nothing. |
| Policy | Google Privacy Policy |
9URL Shortening Fallback: is.gd / v.gd (All users, fallback only)
| Purpose | Producing a short shareable link when our own link-shortening server fails to return one at the moment a share is created (unreachable, rate-limited, out of storage, or erroring). Never used when our server successfully creates the short link. |
| Data Received | The complete share link, which encodes the shared deal data (property address, prices, assumptions, notes) in compressed form in the URL, plus the IP address and browser metadata of the sharer at the moment of creation. The services store the link in order to redirect visitors to it. Links longer than about 1,800 characters are never sent to these services; the long link is used directly instead. |
| Policy | is.gd Privacy Policy · v.gd Privacy Policy |
10Resend: Transactional Email (Account creation & feedback senders)
| Purpose | Delivering two kinds of transactional email on our behalf via Resend: (1) a single welcome email sent to your email address when you create an account, and (2) notes you choose to submit through the feedback form at /feedback, which are forwarded to the operator with the contact email you provide. No mailing list is created and no marketing email is sent. |
| Data Received | The recipient email address and the content of each message. Feedback submissions (your note, optional property/page reference, and contact email) pass through Resend to reach the operator and are not stored on our server. Every welcome email carries an unsubscribe link, honored permanently; our server stores only a one-way hash of unsubscribed addresses, never the address itself. |
| Policy | Resend Privacy Policy |
11Services No Longer Used or Not Yet Active
| Apple Sign-In | No longer offered. Apple Sign-In was removed in July 2026; existing sign-in methods are email/password and Google Sign-In. |
| Mashvisor | No longer used. The Mashvisor integration is inactive and no data is sent to Mashvisor. |
| Stripe | Not active. No paid subscriptions are offered and no payment data is collected or sent to any payment processor. |
| AI Inference Provider | Planned — not yet active. No AI inference provider is currently used and no deal data is transmitted to any AI service. |
12Changes to This List
We may add, remove, or replace third-party services. Material changes will be reflected in an updated Disclosure. We encourage periodic review.