Legal · Privacy
Privacy Policy
Nivora is underwriting software for real estate investment teams. This policy explains what information we collect, how we use it, and the choices you have. The short version: your deal data belongs to your organization, we don't sell data to anyone, and we collect only what the product needs to work.
Effective June 12, 2026
Who we are
Nivora (the “Service”) is operated by Nivora Capital (“we,” “us”). The Service is a multifamily real-estate underwriting platform: organizations upload property documents — rent rolls, trailing-twelve-month operating statements, offering memoranda — and the platform produces pro forma analyses, return metrics, and exports.
Information we collect
- Account information. Name, email address, password (stored only as a salted hash by our authentication provider), and two-factor authentication settings.
- Organization and deal data. The documents and figures your organization uploads or enters: rent rolls, operating statements, offering memoranda, underwriting assumptions, notes, and the analyses derived from them.
- Audit records. The Service keeps an audit log of changes to deals and assumptions — who changed what, and when — as a product feature for your organization.
- Usage and technical data. Log data such as IP address, browser type, pages viewed, and performance metrics, plus error reports when something breaks.
How we use information
- To provide the Service: run analyses on the data your organization uploads, generate exports, and keep your team’s work in sync.
- To secure the Service: authenticate sign-ins, enforce two-factor authentication, detect abuse, and maintain audit logs.
- To operate and improve the Service: monitor errors and performance, and understand which features are used.
- To communicate with you about your account, such as access approvals and security notices.
We do not sell personal information, and we do not use your organization’s deal data to train AI models.
AI-assisted document processing
When you upload an offering memorandum (or use other AI-assisted import features), the document is processed by Anthropic’s Claude API to extract figures such as unit counts and asking prices. These requests are made under API terms that do not permit the provider to train models on your data. Extracted values are always shown to you for review before they become part of your underwriting.
Service providers
We rely on a small set of infrastructure providers to run the Service:
- Supabase — database, authentication, and file storage.
- Vercel — application hosting, serverless functions, and performance analytics.
- Anthropic — AI document extraction, as described above.
- Sentry — error monitoring. Currently configured for server-side errors only; the in-browser error reporter is not enabled.
- Google Fonts — webfont delivery. Pages load typefaces from Google’s font CDN, which necessarily discloses your IP address and browser user-agent to Google as part of that request. No cookies are set by this, and it is not used to identify or track you.
- Microsoft — transactional email (two-factor codes, invitations, and account notices).
- Stripe — subscription billing and payment processing. Card details are entered directly with Stripe and are never stored on our servers; we retain only the subscription status and billing metadata needed to run your account.
Each provider processes data only as needed to provide its service to us.
Cookies and browser storage
The Service sets a single cookie: nv_device, an encrypted, HttpOnly token issued only after you complete two-factor authentication, which lets us remember a trusted device for 30 days. We set no other cookies, and no third-party cookies. Everything else described below is browser storage that stays on your device.
Across cookies and browser storage there are three narrow categories:
- Essential. Authentication tokens and session state (via our authentication provider) that keep you signed in and enforce two-factor authentication. The Service cannot function without these.
- Preferences. Interface settings such as theme, your last-active tab, and whether you have dismissed notices like the cookie banner.
- Analytics. First-party, cookieless performance and usage analytics (Vercel Web Analytics) that aggregate page views and load times without identifying or tracking individual visitors across sites.
We do not use third-party advertising cookies, cross-site trackers, or browser fingerprinting. Because the essential storage is required for sign-in and the analytics are cookieless, the Service shows an informational notice rather than a consent wall; you can clear all stored data at any time through your browser settings (you will simply be signed out).
Do we sell or share your information?
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use advertising cookies, ad networks, or cross-site trackers. Because we do not sell or share, there is no “Do Not Sell or Share My Personal Information” opt-out for us to offer.
Global Privacy Control
If your browser sends a Global Privacy Control (GPC) signal, we honour it: we disable our cookieless analytics for that visit. We do not sell or share personal information in any case, so there is nothing further for the signal to switch off.
Security
Every account belongs to an organization, and joining an existing organization requires an invitation from one of its administrators. Two-factor authentication is enforced. Organizations are isolated from one another at the database layer (row-level security), data is encrypted in transit and at rest, and an immutable audit log records changes to underwriting data. No system is perfectly secure, but security is a design constraint of the Service rather than an afterthought.
Data retention and deletion
Deal data is retained for as long as your organization’s account is active, so your team’s underwriting history stays available. If your organization ends its relationship with us, we will delete or return organization data on request, subject to legal retention requirements.
Other categories are retained on their own terms:
- Audit records. Kept for the life of the organization’s account, because their purpose is to show who changed an assumption and when.
- Account information. Kept while the account is active and deleted with it.
- Email records. Delivery metadata for two-factor codes, invitations, and account notices is retained only as long as our email provider retains it.
- Billing records. Retained as long as tax and accounting rules require, independently of account closure.
- Usage and technical data. Aggregated analytics are not tied to an identifiable person; server logs are retained on our hosting provider’s standard schedule.
Your rights
Depending on where you live, you may have rights to access, correct, export, or delete your personal information. To exercise them, contact your organization administrator or reach us through your Nivora representative, and we will respond within a reasonable period.
Changes to this policy
If we make material changes, we will update the effective date above and notify organization administrators. Continued use of the Service after a change takes effect constitutes acceptance of the revised policy.