Privacy Policy

Last updated 2026-07-25

This describes what LeaseLab actually does with information, in plain language. It has not been reviewed by a lawyer, and it deliberately makes no claim about certifications, data residency, or deletion deadlines that we cannot back up.

1. Who operates LeaseLab

LeaseLab is operated by Jiajian Yang, a sole proprietorship based in Ontario, Canada. "We" and "us" below mean that operator.

This policy covers the LeaseLab web application and this website. Questions go to support@leaselab.io.

2. What we handle

Working through the product, the categories are:

  • Account and workspace data — your name, email address, and the organization you create, provided through our authentication provider.
  • Property and unit data — addresses and unit details you enter or import.
  • Tenant contact data — tenant names, and email or phone numbers where you provide them. Tenant name is required; contact details are optional.
  • Lease and rent data — rent amounts, dates, obligations, and the payment, reminder, adjustment, waiver and reversal records you create.
  • Files you upload — the CSV, XLSX, and PDF documents you import, retained as source files.
  • Maintenance email — messages forwarded or sent to your intake address, including the raw message, a text extract, and attachments, along with the resulting work orders.
  • Operational records — request identifiers, workflow run records, application logs, and usage counts. These deliberately record identifiers and outcomes, not message bodies or document contents.
  • Billing data — your subscription status and the customer and subscription identifiers our payment processor gives us.

3. Card details

Clerk manages organization billing and checkout, using Stripe as its connected payment provider. Card numbers are entered on Clerk’s own checkout and billing pages; they are never sent to, seen by, or stored by LeaseLab. We receive only the identifiers and subscription status Clerk reports back to us.

4. Why we handle it

  • To provide the service — storing your portfolio, generating rent obligations, and creating work orders.
  • To sign you in and to confirm which organization you may access.
  • To read structure out of files you import, and to show you what was read before anything is saved.
  • To process email sent to your intake address and turn it into work orders.
  • To send operational messages you trigger, such as rent reminders, and your monthly portfolio summary.
  • To keep the service secure, reliable and auditable, and to investigate problems you report.
  • To bill you and manage your subscription.

5. How AI is used

AI is used in three places: reading structure out of an imported spreadsheet or document, suggesting a category and priority for a maintenance request, and helping organise inbound messages. In each case the content you provided (the file, or the email) is processed by the model.

AI never writes your records directly. Imported records are staged for your review and only become part of your portfolio when you confirm them; maintenance suggestions are advisory annotations recorded alongside the work order, which is created from the email itself. Everything AI produces is visible to you. Imported records are yours to correct before you save them. A maintenance suggestion is not editable today, but it is advisory only — nothing in the product acts on it, and you set the work order’s own priority, notes and status yourself.

Inference runs on Cloudflare Workers AI, on the same platform that runs the rest of the service. We do not claim that the model provider retains nothing or trains on nothing, because we have not verified any such term — we state only what we do, which is not to send your data to any other AI provider.

6. Service providers

We use the following providers to run LeaseLab. This list reflects what the system actually uses today; it is not maintained as a formal subprocessor register, and we do not represent it as exhaustive for all time.

  • Cloudflare — application hosting, database, file storage, email intake, and AI inference.
  • Vercel — hosting for this website and the application interface.
  • Clerk — sign-in, account management, and organization billing and checkout.
  • Stripe — card processing, as Clerk’s connected payment provider.
  • Resend — delivery of the operational email the product sends.

7. Where data is processed

Our providers operate globally distributed infrastructure, and your data may be processed or stored outside Canada. We do not promise Canadian-only storage, because nothing in the current setup guarantees it.

8. Keeping, exporting and deleting data

We keep your data for as long as your workspace exists. Cancelling a subscription does not delete anything — the workspace becomes read-only and the data remains.

Imported source files are removed on a rolling basis roughly a month after upload; the records you committed from them stay in your portfolio.

There is no self-service export or delete button. If you want a copy of your data, or you want it deleted, email support@leaselab.io and a person will handle it. We do not publish a guaranteed turnaround, because we would rather not commit to a deadline we have not operationalised.

Because the record of changes is append-only, correcting a mistake adds a correcting entry rather than erasing history. That is what makes the audit trail trustworthy, and it is worth knowing before you enter something you would later want no trace of.

9. Security

Each organization’s data is scoped to that organization at the database layer, and every request is checked against your membership before it can read or write anything. Access to the application requires signing in through our authentication provider. Credentials and API keys are held as platform secrets, not in code. Traffic to our providers is encrypted in transit by those providers.

We do not hold SOC 2, ISO 27001, PCI or any other certification, and nothing here should be read as claiming one. No system is perfectly secure, and we make no absolute guarantee.

If you believe you have found a security problem, email support@leaselab.io.

10. Tenant and other people’s information

Most of the personal information in LeaseLab is about your tenants, not about you. When you enter or forward it, you are confirming that you are entitled to do so and that you are handling it in line with your own obligations as a landlord.

Only forward maintenance-related email. Anything you forward is stored in LeaseLab, so unrelated personal correspondence should not be sent to your intake address.

Tenants do not have LeaseLab accounts and cannot sign in. A tenant who wants to know what is held about them, or to have it corrected, should contact you; we will help you respond.

11. Changes to this policy

If this policy changes materially, we will update the date below and, where the change affects how we handle your data, tell you by email.

12. Contact

Privacy questions, access requests, corrections, export and deletion requests: support@leaselab.io. Security reports: support@leaselab.io. General support: support@leaselab.io.

See also Terms of Service and how your data is handled.