LandAIForYou
legal / 01──────effective · 2026-07-31

Privacy policy.

Plain-English summary first, full detail below. If any of this is unclear or you want to exercise a right listed here, email hello@landaiforyou.com.

tl;dr
  • We collect the minimum needed to run the MCP: an account email, request logs, and the parcels you look up.
  • The tools return public-record property data (owners, deeds, taxes). We do not resell your queries.
  • We never collect payment card data, government IDs, health data, or API keys through the MCP.
  • We do not sell personal data. We do not profile users for advertising.
  • Email hello@landaiforyou.com to access, correct, or delete your data.
[01]who we are

The controller.

landaiforyou is a boutique agency operating the landaiforyou MCP (Model Context Protocol) server at https://mcp.landaiforyou.com/mcp and this marketing site at https://landaiforyou.com. You can reach the data controller at hello@landaiforyou.com.

[02]what we collect

Data we actually hold.

account (Supabase Auth)
  • Email address you sign in with.
  • Password hash (managed by Supabase, never stored in cleartext).
  • OAuth authorization records for MCP clients you connect (client name, redirect URI, granted scopes, timestamp).
operational logs
  • Request IP address and user-agent (Modal + Vercel platform logs).
  • Tool name, arguments, and timing for each MCP call (for debugging and abuse prevention).
  • Error messages and stack traces when a tool fails.
tool inputs / outputs
  • APNs, state, county, addresses, or lat/lng you send to the tools.
  • The public-record data the tools return: owner names, mailing addresses, deed history, tax history, flood zone, wetland cover, maps.
  • We do not receive conversation transcripts from your AI assistant — only the arguments the assistant passes to each tool call.
contact form
  • Name, email, company, target counties, and the message body you send via /contact.
  • Delivered by SMTP to hello@landaiforyou.com. Not persisted to a database.
note. We do not collect: payment card numbers (PCI), Social Security numbers or other government identifiers, health information (PHI), biometrics, precise device location outside what your assistant sends as tool input, or third-party API keys.
[03]why we hold it

Purposes of processing.

Deliver the MCP. Authenticate you, run the tool you invoked, return results.

Debug and improve. Read logs when tools fail so we can fix them.

Prevent abuse. Rate-limit and block traffic that harms upstream data sources or paid APIs.

Answer your outreach. Reply to contact-form submissions.

Comply with law. Respond to lawful legal process.

[04]who we share it with

Sub-processors and recipients.

Supabase
Managed Postgres + Auth. Holds account emails, hashed passwords, OAuth authorization records.
Modal
Serverless compute. Runs the MCP server itself; sees tool inputs, outputs, and request logs at runtime.
Vercel
Hosts this marketing site, the OAuth consent app, and the contact API. Sees IPs and HTTP request logs.
Google Maps Platform
Called when you invoke map / geocode / street-view tools. Receives lat/lng or address.
FEMA NFHL / USFWS NWI
Public flood and wetland map services. Receives lat/lng.
County property portals
Public-records portals (Tyler EagleWeb, ActDataScout, county treasurer sites, etc.). Called when you invoke tax or title tools. Receives APN + state + county.
Browserbase
Managed headless-browser used for county portals that require a real browser session.
SMTP provider
Delivers the contact-form email to us.

We do not sell personal data. We do not share it with advertisers. We do not use it to train third-party AI models.

[05]how long we keep it

Retention windows.

Account records: kept while your account exists. Deleted on request within 30 days.

Request logs: Modal + Vercel platform default (typically 30 days for verbose logs; longer for aggregated metrics).

Tool inputs / outputs: not persisted server-side by us beyond the request. Cached briefly (minutes to hours) at the edge for performance.

Contact-form emails: retained in the inbox at hello@landaiforyou.com until you ask us to delete them.

[06]your rights

Access, correct, delete.

Regardless of jurisdiction, you can email hello@landaiforyou.com to:

  • Get a copy of the personal data we hold on you.
  • Correct anything inaccurate.
  • Delete your account and its data.
  • Object to specific processing or withdraw consent.
  • Export your data in a machine-readable format.

We respond within 30 days. EU/UK residents have the additional right to complain to a supervisory authority; California residents have the additional CCPA rights of access, deletion, correction, and to opt out of the sale or sharing of personal data — we do neither.

[07]security

How we protect it.

All traffic is HTTPS/TLS.

The MCP endpoint is OAuth 2.1 protected with signature-verified JWTs.

Access to production infrastructure is limited to authorized team members with 2FA.

We rely on Supabase, Modal, and Vercel for their respective infrastructure security controls.

No system is perfectly secure. If you find a vulnerability, email hello@landaiforyou.com.

[08]scope and updates

The small print.

The MCP is not directed at children under 13. The property data returned by the tools is public record — we do not curate or verify it, and it may be out of date. Always confirm with the county before relying on it for a transaction.

If we materially change this policy we'll update the effective date at the top and, when the change matters, email active account holders. Prior versions are available on request.

related → terms of servicequestions → hello@landaiforyou.com