Skip to content

Privacy policy

How we handle your data.

Plain English. No dark patterns. Written for the agent who expects the truth and wants to know exactly what happens to their book.

Last updated: April 11, 2026

Who we are

Kotii is a digital employee for real estate agents, operated by the Kotii team out of British Columbia, Canada. This policy covers everything on kotii.live and the Kotii product itself. If anything here is unclear, email hello@kotii.live and a human on the team will write back.

What we collect

Three categories:

  • Account data. Your name, email, hashed password, and any preferences you set (morning briefing time, writing voice, notification channels).
  • Your book. The client profiles you add or import, every conversation you have inside Kotii, the MLS listings Kotii watches for you, contracts and documents you upload, and the notes Kotii writes as she learns. Your book is the product — we hold it so Kotii can work, and nothing more.
  • Basic usage. Which pages you visit, which CTAs you click, and error logs when something breaks. No fingerprinting, no cross-site tracking, no advertising pixels.

How we use it

  • Run Kotii for you — draft messages, watch the MLS, remember client details, brief you every morning.
  • Send transactional email — welcome, trial reminders, billing, password resets. Nothing else.
  • Improve the product using aggregated, anonymized usage patterns. Never your client data or conversation content.
  • Troubleshoot problems — if Kotii breaks for you, engineers may need to look at the specific failing record. That requires an audited internal access request and a specific reason.

What we do NOT do with your data

  • We do not train AI models on your client data. Kotii's memory and context are siloed to your account. What Kotii learns from your conversations with Sarah Chen does not help any other Kotii user, ever.
  • We do not sell data to anyone. Not to brokerages, not to MLS boards, not to ad networks, not to any aggregator.
  • We do not run third-party ad pixels or social trackers on kotii.live or in the Kotii product.
  • We do not impersonate you to your clients without explicit approval. Every client-facing message goes through your approval queue. This is a product decision and a contractual commitment.

Subprocessors

Kotii is built on a small stack of third-party services. Each one processes specific data on our behalf and is bound by its own privacy and security commitments:

  • Vercel — hosts the website and the Kotii application. US-based. Sees HTTP request metadata and runs the code.
  • Neon — managed Postgres database. Your account data and your book live here, encrypted at rest.
  • Anthropic — runs the AI models Kotii uses to generate drafts and briefings. Prompts and responses are processed by Anthropic for the duration of the API call; per our enterprise terms, your prompts are not used to train their models.
  • Resend — sends transactional email. Receives your email address and the contents of the message we're sending you.
  • Sentry — error monitoring. Sees stack traces and request context when something breaks. We scrub personally identifiable information from error payloads wherever possible.
  • Stripe — payment processing (post-launch). Handles your card details directly; Kotii never sees full card numbers.

If we add or remove a subprocessor, this list gets updated and the “Last updated” date at the top of the page changes. Active customers will be notified by email for material changes.

Data retention and deletion

While your account is active, we keep your data for as long as you need Kotii to work. If you cancel, we delete your book and your account data within 30 days of cancellation. Backups rotate on a 30-day cycle, so anything in those backups is purged within the same window.

You can export everything — client profiles, conversations, notes, activity history — at any time from inside the dashboard. If export breaks for any reason, email hello@kotii.live and a human will run the export manually.

Your rights under PIPEDA

Kotii is a Canadian company and complies with the Personal Information Protection and Electronic Documents Act (PIPEDA). You have the right to:

  • Access — request a copy of everything we hold about you.
  • Correction — ask us to fix anything that's wrong.
  • Deletion — ask us to delete your account and everything in it.
  • Portability — export your data in a machine-readable format.
  • Withdraw consent — stop us from processing your data at any time by deleting your account.

To exercise any of these rights, email hello@kotii.live from the address associated with your account. We'll respond within 30 days — usually much sooner.

If you're unsatisfied with how we handle a request, you can file a complaint with the Office of the Privacy Commissioner of Canada at priv.gc.ca.

How to delete your account

From inside the dashboard, go to Settings → Account → Delete account. One click starts the process. You'll get a confirmation email, and your data is permanently deleted within 30 days. If the in-product flow fails, email hello@kotii.live and we'll do it manually.

Security

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Passwords are hashed with bcrypt. Engineers access customer data only through an audited internal process with a specific, documented reason.

We take this seriously because the whole product falls apart if agents can't trust us with their book. If you find a security issue, email hello@kotii.live with the subject line “security” and we'll respond the same day.

Cookies

Kotii uses the minimum cookies needed to run. One session cookie keeps you logged in. If you hit the demo sandbox at /demo, a second short-lived cookie tracks that you're in demo mode so the banner shows up. That's it — no analytics cookies, no tracking pixels, no third-party cookies.

Children

Kotii is built for licensed real estate agents. It is not for anyone under 18, and we do not knowingly collect data from minors. If we discover we've collected data from a minor, we delete it immediately.

Changes to this policy

When we make material changes, we update the “Last updated” date at the top of this page and email active customers. Minor cleanups and clarifications happen without notification.

Contact

The Kotii team — hello@kotii.live. Every message is read by a human on the actual team.

See the Terms of Service →