CURBCAPTION

Effective August 17, 2026

Privacy Policy

CurbCaption turns a real estate agent’s listing emails into on-brand social captions and graphics, then routes them through human approval before anything is scheduled or published. This policy explains what information the service handles, why, and who it is shared with. It covers curbcaption.com and the CurbCaption application.

Who we are

CurbCaption is operated as a service for real estate professionals. For questions about this policy or about data we hold, contact [email protected].

CurbCaption is not affiliated with, endorsed by, or sponsored by the National Association of REALTORS®, Buffer, Meta, or any social network.

Information we collect

Account information

When an operator or a client user signs in, we store their name, email address, role, workspace assignment, and sign-in timestamps. Authentication is handled by Clerk; CurbCaption never receives or stores passwords.

Listing intake

Each client workspace is given a unique intake email address. When a message is sent to that address we store the sender and recipient addresses, subject line, message body, message identifiers, delivery-authentication results, and any image attachments. Attachments are stored in Cloudflare R2 and referenced by the workspace they belong to.

Operator correspondence

Operational email an operator sends to a client through the service, and replies received back, are archived in the same record as intake email — sender and recipient addresses, subject line, message body, and the account that sent it — kept for the same period, and included in the access, export, and deletion requests described below.

Content we generate

We store the listing facts extracted from intake messages, the captions and alt text drafted from them, the graphics produced for a post, and the approval record for each post — including who approved it, when, and a hash of the exact content that was approved.

Connected Buffer accounts

If you connect a Buffer account, we store the OAuth access and refresh tokens Buffer issues, the organization and channel identifiers and display names of the channels you select, and the identifiers, permalinks, scheduled times, and aggregate engagement metrics (such as likes, comments, reach, and impressions) for posts CurbCaption created. See Data from your Buffer account below.

Operational data

We keep application and error logs, which may include IP addresses, request paths, and timestamps, for security monitoring and debugging.

What we do not collect

  • No advertising or cross-site tracking cookies. The only cookies set are those Clerk requires to keep you signed in.
  • No payment card details are collected or stored by the application.
  • We do not ask for or intentionally collect sensitive personal information such as government identifiers, financial account numbers, or health data. Please do not send it to an intake address.

How we use information

  • To extract listing facts from intake email and draft captions and graphics from them.
  • To route drafts to the operator and to the client for approval.
  • To schedule and publish approved posts to the social channels you have connected.
  • To show performance metrics for posts CurbCaption published on your behalf.
  • To authenticate users and keep workspaces separated from one another.
  • To secure, debug, and improve the service, and to meet legal obligations.

We do not sell personal information, we do not share it for cross-context behavioral advertising, and we do not use client content to train machine learning models.

Automated processing

Listing content is sent to Anthropic’s API to extract structured facts and to draft caption text. Under Anthropic’s commercial terms, data submitted through the API is not used to train their models. Every draft is reviewed by a human before it is approved, and nothing is scheduled or published without an explicit human approval.

Data from your Buffer account

CurbCaption connects to Buffer using OAuth. You authorize the connection from your own Buffer account, and you can withdraw it at any time.

What we access and why

  • Account information — to identify the Buffer organization you are connecting and to list the channels available to it.
  • Channel information — to let you choose which Instagram or Facebook channel a workspace publishes to.
  • Posts and queue — to schedule approved posts, to confirm they sent, to store their permalinks, and to read back their engagement metrics.
  • Ideas — to draft content into Buffer where a workspace is configured to use it.

How it is handled

  • Tokens are held as secrets, are scoped to the workspace that authorized them, and are never displayed to or shared with other clients or users.
  • We only write to Buffer in response to a post that a human has approved inside CurbCaption.
  • Buffer data is not sold, rented, or shared with third parties, and is not used for advertising.
  • Our use of Buffer data complies with Buffer’s developer terms and with the platform terms of the connected social networks.

Disconnecting

You can disconnect Buffer from your workspace settings in CurbCaption, or revoke CurbCaption from the connected-apps section of your Buffer account. On disconnection we delete the stored tokens and stop scheduling. Posts already scheduled in Buffer remain under your control in Buffer. To have the associated channel identifiers and stored metrics deleted as well, email [email protected].

Who we share information with

We share information with the service providers below, only to the extent needed to run CurbCaption. We do not sell personal information.

ProviderPurposeData involved
RailwayApplication hosting and PostgreSQL databaseAll service data at rest
ClerkAuthentication and session managementName, email address, sign-in metadata
ResendInbound listing intake and outbound notification emailEmail addresses, message contents, attachments
Cloudflare R2Storage for listing imagesPhotos and graphics supplied by the client
AnthropicExtracting listing facts and drafting captionsListing details and message text submitted for processing
BufferScheduling and publishing approved postsApproved caption text, images, channel identifiers, post metrics
CanvaGraphics an operator designs by hand; CurbCaption sends nothing automaticallyListing photos and details, only when an operator builds a graphic there

We may also disclose information where required by law, to enforce our terms, or to protect the rights and safety of our users. If CurbCaption is involved in a merger or acquisition, data may transfer as part of that transaction; we will give notice before it becomes subject to a different policy.

Retention

  • Account records are kept while the account is active and for up to 12 months after it is closed.
  • Intake email, operator correspondence, listing facts, drafts, and images are kept while the workspace is active, so that published posts remain auditable. They are deleted within 30 days of a deletion request or of workspace closure.
  • Approval records are retained for the life of the workspace as the record of who authorized each published post.
  • Buffer tokens are deleted immediately on disconnection.
  • Logs are retained for up to 90 days.

Security

Traffic is served over HTTPS with a content security policy. Access to the operator dashboard requires an authenticated account that has been explicitly authorized; client users can reach only their own workspace. Credentials and API tokens are held as environment secrets, not in source control. No system is perfectly secure, but we work to protect data in line with these practices and will notify affected users of a breach as required by law.

Your choices and rights

Depending on where you live, you may have the right to access, correct, delete, or receive a copy of your personal information, and to withdraw consent. California residents have the right to know what is collected, to request deletion and correction, to opt out of sale or sharing (we do neither), and not to be discriminated against for exercising these rights.

To make a request, email [email protected] from the address on your account. We will respond within the timeframe required by applicable law. If a real estate brokerage or agent is our customer and you are their client, we act as a service provider on their behalf — we will refer your request to them and assist in fulfilling it.

International users and children

CurbCaption is operated from the United States and information is processed there. If you use the service from outside the United States, you understand that your information will be transferred to and processed in the U.S.

The service is intended for business use by real estate professionals. It is not directed to children under 13, and we do not knowingly collect their personal information.

Changes to this policy

We may update this policy as the service changes. The effective date above will be revised, and material changes will be communicated to account holders by email.

Questions, requests, or concerns: [email protected]
CurbCaption · curbcaption.com