Privacy Policy
What we collect, how AI parsing works, exactly how long we keep your files, and what you can do about it.
v1 draft — have counsel review before public launch
This is a complete, good-faith draft written to govern Tieout's v1 product honestly. It has not been reviewed by an attorney. That review happens before Tieout accepts its first paying customer — this label is here so nobody mistakes a draft for a finished legal document. Last updated July 24, 2026.
Changed on July 24, 2026: the free Tie-Out Check is currently run by a person at Tieout rather than by an unattended pipeline. Sections 3, 4 and 6 have been updated to say so plainly. If you uploaded files before this date, nothing about them was handled differently than described — this change makes the description match the practice, not the other way round.
1. Overview
Tieout ("Tieout," "we," "us") is an advisory reconciliation copilot for small property management companies. This policy covers the Tieout marketing site (gotieout.com), the free Tie-Out Check, and the paid product. It does not cover third-party sites we link to, including AppFolio, Buildium, or Capterra.
2. What we collect
Depending on how you use Tieout, we collect:
- Files you upload — a bank statement export, an AppFolio or Buildium trust ledger export, and a tenant/property balance export. These contain financial transaction data and may contain tenant names and unit numbers. We never ask for bank credentials, a PMS login, or an API key to obtain these files — you export and upload them yourself.
- Account information (paid plans only) — name, work email, company name, and billing details. Card details are handled entirely by our payment processor; we never see or store your full card number.
- Contact information — if you email [email protected] or submit the free check, we keep the email address needed to send you your result or respond to you.
- Basic usage data — standard web server logs (IP address, browser type, pages visited) for security and debugging. We don't run third-party ad-tracking pixels on this site.
3. How we use it — including the human-review and AI disclosures
We use uploaded files to run the three-way tie-out and per-property coverage check, generate your discrepancy inbox and audit PDF, and — on paid plans — maintain your monthly reconciliation history.
A person at Tieout reads the files you send to the free Tie-Out Check. The free check is currently run by hand, not by an unattended pipeline: a named individual at Tieout opens your exports, runs the reconciliation, and writes the result you get back. We do it this way on purpose. Exports are frequently scoped differently from one another — a report run with a narrow filter next to a full general ledger will look like a large discrepancy when the real problem is the export — and a human catches that before a wrong number reaches you. Access is limited to the people who need it to produce your result, and to that purpose only.
AI parsing runs on an enterprise API that does not train on your data. To normalize the many different export formats AppFolio and Buildium produce into a consistent structure Tieout can reconcile, uploaded files are processed by a third-party large-language-model API. That API is configured for zero training-data retention — your files are not used to train that provider's models, or ours, or anyone else's. A human always reviews and approves every proposed match before anything is treated as final; nothing is auto-posted back to your books. (Operator note logged on our own launch checklist: the specific subprocessor's zero-retention / data-processing agreement is signed before Tieout accepts its first paying customer, and will be named here before launch.)
4. Data retention & deletion
One policy, everywhere Tieout is used:
- Free Tie-Out Check. Your files are encrypted when they arrive, read by a person at Tieout to generate your result (Section 3), and deleted once that result has been sent to you. We don't create an account for you, and the email address you give us is used to deliver the result — not added to a marketing list. We do not keep your files to build an evaluation or training corpus unless you separately and explicitly tell us we may — there is no silent retention, and consent is never bundled into the upload itself.
- Paid plans. Source files and generated reports are retained for 13 months — long enough that you have history on hand when an auditor asks for it — and are deletable in-app at any time, individually or in bulk.
- On cancellation. All of your data is deleted within 30 days. We offer you an export first, so nothing is lost — just gone from our systems once you've had the chance to take it with you.
We never ask for bank credentials or a PMS login, in v1 or ever. There is nothing to revoke because nothing was ever authorized.
5. Subprocessors
We use a small number of third parties to run Tieout: a cloud hosting provider, a payment processor for paid subscriptions, an email delivery provider, and the AI parsing subprocessor described in Section 3. Each is bound to use your data only to provide their service to us, not for their own purposes. Specific vendor names and data-hosting regions will be published here before public launch, once those contracts are finalized — that's a launch-checklist item, not a hidden fact.
6. Security
Files are encrypted in transit (HTTPS) and at rest. Free Tie-Out Check uploads are encrypted with AES-256-GCM by our own application before they are written to storage, so the stored object is ciphertext rather than a readable export; the key is held separately in our server environment and is not stored alongside the files.
Access to production data is limited to what's needed to operate the service and, for the free check, to the person producing your result. We're a small team and we're not yet SOC 2 certified — if that's a requirement for your firm, tell us at [email protected] and we'll let you know when that changes. We'd rather tell you that now than have you find out during a security review.
7. What we don't do with your data
We never sell your data. We never share it with AppFolio, Buildium, or any other property-management platform. We don't run ad-retargeting on your uploaded financial data. We don't use your files for anything beyond generating your tie-out and, on paid plans, your reconciliation history.
8. Your rights and choices
You can export your data, delete individual files or reports, or delete your account entirely, at any time, in-app. You can also email [email protected] to request an export or deletion — a person reads and handles these. If you're in a jurisdiction with statutory data-access or deletion rights (e.g., GDPR, CCPA), this section will be expanded with the specific mechanics before public launch; the substance — you can always get your data and always delete it — is true today.
9. Children's privacy
Tieout is a B2B tool built for property management professionals. It is not directed at, and we do not knowingly collect data from, anyone under 18.
10. Changes to this policy
If we make a material change to how we handle your data, we'll update this page and, for paid customers, email you directly. The "last updated" date at the top of this page always reflects the current version.
11. Contact
Questions about this policy, or a security questionnaire you need filled out before you'll upload anything? [email protected] — a person reads these.