Legal

Privacy Policy

Effective date: September 13, 2026

See also our Terms and Conditions and Security page. As an early-stage company, this policy will keep evolving — we'll update the effective date whenever it materially changes.

1. Who we are and what this policy covers

Nestly Inc. (Brokrly, we, us, or our) provides the Brokrly website at https://brokrly.com and the Brokrly web application on its service subdomains, together the Service. Our address is 425 Virginia Street, STE b, Vallejo, CA 94590, United States. Contact us about privacy at info@brokrly.com.

This policy explains how we handle information about website visitors, account holders, brokerage administrators and staff, and people whose information customers process through the Service, such as leads, clients and transaction participants. Our current pilot is offered to US customers and adult users. That service restriction does not determine the location or rights of every person mentioned in customer records.

For website inquiries, account administration, our business communications and service security, Nestly determines the purposes of its processing. For brokerage records processed on a customer’s instructions, the customer generally determines the purposes and we process the records on its behalf, subject to our agreement and applicable law. A brokerage customer controls its workspace and business records, subject to applicable law and third-party rights. Its administrators can manage authorized users, including removing access when an agent leaves. A customer’s own privacy notice explains its independent practices. This policy does not replace a data processing agreement with that customer.

Where Brokrly determines its own model-development purposes, that processing is distinct from acting solely on a customer’s instructions and is subject to the notices and controls in section 4.

2. Information we handle and where it comes from

The information depends on the features used, records submitted and permissions granted. We receive it from you, your customer organization and its authorized users, connected services you authorize, and interactions with the Service.

InformationExamples and sourcesPurposes
Account and business informationName, email, phone, business address, organization, professional role and account identifiers supplied by you or your administratorCreate and administer accounts, identify authorized users, provide support and communicate with customers
Customer recordsContact and lead records, property interests, transaction details, notes and documents submitted by customers or obtained through enabled CRM and transaction integrationsOrganize, retrieve and process records for the customer’s requested workflows
Connected-account informationAccount identity, access and refresh tokens, API credentials, connection settings and granted permissionsAuthenticate integrations and perform authorized operations
Communications and calendar informationDrafted or sent messages, recipients, relevant attachments, event details and participants processed through enabled sending and calendar featuresPrepare and send authorized communications and manage calendar events
AI and search informationPrompts, uploaded material, relevant retrieved records, tool results, generated responses and search representationsAnswer questions, draft content, summarize information, retrieve records and support authorized actions
Support and operational informationYour support correspondence, service activity, errors, access information and diagnostic recordsTroubleshoot, secure and maintain the Service, investigate misuse and respond to requests

Some records can contain sensitive information, including access credentials, private communication content, financial or identification information, or information about a person’s circumstances. Submit only information you are authorized to provide and that is necessary for the intended feature. A customer’s decision to include information does not remove our responsibilities for handling it.

3. Connected services

When you connect an account, the information and operations available depend on the provider, permissions granted and enabled features. Customer administrators may also control which connections and records users can access.

The Gmail and Microsoft mail connections support sending messages through connected accounts. Calendar connections support authorized event access and management. Brokrly processes outbound message content for these features. Connecting an account is not a general authorization for unrelated uses of its information.

CRM and transaction integrations can supply customer records described above. The customer’s provider account remains subject to that provider’s terms. Revoking provider access can prevent future operations but does not recall sent messages, undo completed changes or automatically remove copies already processed. Contact info@brokrly.com for help disconnecting an account or requesting deletion of information held by Brokrly.

Google API data

Brokrly’s use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including its Limited Use requirements, and the applicable Google Workspace user data policy.

Google-connected information is used for the user-facing features for which access was authorized. We do not use that information for advertising, sell it, or use it to train generalized AI models. Access, transfers and any human review are limited to purposes permitted by Google’s policies. These restrictions also cover applicable derived data. Additional data access or uses require the applicable disclosures and authorization and must remain within Google’s permitted uses; customer consent does not override prohibited uses.

4. AI processing and providers

Relevant prompts, document text, retrieved records and tool results can be sent to an AI provider to deliver the requested feature. Search indexing can require sending source text to an embedding provider; this is not necessarily anonymous information. Generated responses and search representations may also contain or relate to personal information.

Brokrly model improvement and your choice

We may develop, evaluate, train and improve models and features used in Brokrly with eligible Customer Content and service-use information, including improvements that benefit other Brokrly customers. Any such contribution program is subject to the eligibility rules, notices and controls below. This section describes permission for a program; it does not establish that a contribution program is currently operating.

Potentially eligible information includes prompts, corrections, generated outputs, submitted examples and feature-use information. Eligibility depends on the information’s source, the applicable agreement, third-party rights and required permissions. Credentials and secrets are excluded. Sensitive personal information and confidential transaction documents are excluded from the general contribution pipeline unless separately assessed for a specifically disclosed use with appropriate permissions. Removing names alone does not make information anonymous or remove source restrictions. We minimize personal information used for model improvement and do not publicly disclose private customer records or make them available to unrelated customers.

Google Workspace API data, including covered derived information, is excluded from shared-model training. Other connected-source restrictions also apply, including to prompts or outputs that contain restricted material. A customer’s agreement to participate does not override these restrictions. Providers may assist with authorized development of Brokrly models only on our instructions and under confidentiality and data-use restrictions; they may not use Customer Content to train or improve their independently offered models or products.

Before including a customer’s information in a contribution program, we will provide notice of its eligible data categories and an opportunity to opt out. Where affirmative consent is required, we will obtain it before the use begins. An authorized customer administrator can request a workspace-level opt-out at info@brokrly.com with the subject Model Improvement Opt-Out. Opting out excludes the customer’s eligible content and identifiable service-use information from future contributions once the request takes effect; it does not remove information already contributed, or affect models already trained on it, from before the opt-out. It does not disable AI features or exclude the customer from improvements available under its plan, including improvements from models trained on other eligible sources. Processing needed to answer requests, generate outputs or maintain customer-specific retrieval continues under the applicable service permissions.

The program notice will explain when an opt-out takes effect and how it affects queued datasets, previous contributions and existing models. Opting out is separate from requesting deletion under section 8. We do not treat a model-improvement permission as a waiver of applicable deletion rights or as permission to reuse historical information contrary to earlier commitments.

The data sent depends on the request, selected feature and relevant context. A provider’s privacy policy alone does not describe every term governing Brokrly’s account. Information about provider retention, permitted data use and processing locations must match the applicable service arrangements. Our permission to process customer content under the Terms is not permission to publicly disclose that content or use it for unrelated purposes.

5. How we use and disclose information

We use information for the purposes in section 2 and eligible model improvement under section 4, to comply with applicable obligations, resolve disputes, enforce agreements and respond to valid legal requests. We may send service notices and respond to business inquiries. You can ask us to stop sending promotional email at info@brokrly.com or use an unsubscribe mechanism included in the message. Necessary account and security messages are separate from promotional email.

Customer-directed outreach is performed for the customer. The customer is responsible for its recipient lists and communication instructions, subject to our Terms and applicable obligations. Nestly’s own email preferences do not automatically change a brokerage’s independently maintained contact records.

Information may be disclosed to:

Submitting private customer records does not make them available to unrelated customers or the public. The treatment of information by an independently chosen connected service is also governed by that service’s agreement with the customer.

6. Cookies, analytics and advertising

The web application uses browser storage for sign-in information, interface preferences and continuity of agent/automation builder conversations. Stored conversations can include the content of your interactions. Local storage can persist across browser sessions until cleared by the application or browser; temporary session storage and preference cookies have separate lifecycles. Browser settings let you manage storage, although clearing it can sign you out or remove locally saved history and preferences. Clearing browser storage does not itself delete server-side records.

Nestly does not currently run advertising or retargeting campaigns, and does not currently use any third-party analytics or tracking technology. Before adding tracking or advertising that changes our practices, we will update the relevant disclosures and provide choices required by applicable law.

7. Retention and deletion

We retain personal information for as long as reasonably necessary for its disclosed purpose, taking account of the following criteria:

RecordsRetention considerations
Account and business correspondenceDuration of the relationship, outstanding support issues, disputes and applicable recordkeeping obligations
Customer CRM, transaction and document recordsCustomer instructions, service agreement, export/deletion requests and applicable legal holds or retention requirements
Integration credentialsWhether the connection remains authorized and needed, and the steps required to revoke access and remove stored credentials
Prompts, outputs and search indexesThe related feature, customer records and deletion instructions; removing a source may require removing associated stored representations
Model-improvement contributionsProgram-specific eligibility, opt-out and deletion requirements; queued datasets, prior contributions and model treatment must be specified under section 4 before the program begins
Operational and security recordsTroubleshooting, investigation, abuse prevention and necessary evidence retention
Browser-held informationApplication clearing behavior and browser storage lifecycle; persistent local conversation history is distinct from server-side retention
Backups and provider-held copiesBackup lifecycle, restoration controls, applicable provider arrangements and legal preservation requirements

Disconnection, account closure and deletion are different actions. Deletion by Brokrly does not remove a record from the customer’s original CRM or recall material sent to an external recipient. Some records may need to be retained to comply with law, resolve disputes or protect legal rights.

8. Your choices and requests

Contact info@brokrly.com to request access to, correction of or deletion of your personal information, or to ask about processing, portability or available opt-outs. Depending on applicable law and our role, you may also have rights to limit certain sensitive-information uses, opt out of targeted advertising or certain profiling, and appeal a decision about a request.

We may need information proportionate to verifying your identity and authority. Please do not send passwords or unnecessary sensitive documents. Authorized agents may submit requests subject to verification. We will respond within applicable legal periods and explain any permitted denial or extension. Where an appeal right applies, reply to our decision or email us with the subject Privacy Appeal; our response will explain any further available complaint route. We will not unlawfully discriminate against you for exercising privacy rights.

For records controlled by a brokerage or another customer, we may direct the request to that customer or assist it under our agreement and applicable law. Customer administrators may be able to manage your organization account; their control does not eliminate rights you have under applicable law.

For the workspace model-improvement opt-out, see section 4. That choice does not cancel a subscription, close an account or withdraw the processing needed for requested AI features. Individual privacy requests remain available through this section, including for people who are not workspace administrators.

9. California residents

Where the CCPA/CPRA applies to our processing as a business, California residents have rights to know and access information, request deletion and correction, obtain information in a portable form, and exercise applicable sale/sharing and sensitive-information rights. These rights are subject to statutory conditions and exceptions. Processing we perform on behalf of a customer is considered separately from our own business processing.

You can submit California privacy requests using the contact method in section 8. If applicable to our practices, you may also ask about disclosures for third parties’ own direct marketing under California’s Shine the Light law.

10. International processing and security

Information may be processed outside your state or country where we and the relevant providers operate. US-only customer availability is not a promise of US-only data processing. See section 4 for the DeepSeek disclosure. Where applicable law requires transfer safeguards, those safeguards must govern the transfer; accepting this policy does not waive applicable protections.

We use safeguards appropriate to the nature of the information and our service obligations. No internet service or storage system can guarantee absolute security. Report suspected unauthorized account access to info@brokrly.com.

11. Children and minors

Brokrly accounts and use of the Service are intended for adults age 18 and older. Individuals under 18 may not register or use the Service. If you believe a minor has registered or submitted personal information directly, contact us so we can investigate and take appropriate action.

Customer records may contain information about other individuals, including minors. Adult-only account eligibility is not a statement that customer records never contain such information. We handle these records according to the customer relationship and applicable law, including applicable restrictions on children’s information.

12. Changes and contact

We will publish an updated effective date when this policy changes. For material changes we will provide notice appropriate to the change and obtain consent where required before beginning a new use. Notices may be provided through the Service or by email. We will not apply a new notice retroactively to authorize a use that requires separate permission.

Questions and requests: info@brokrly.com.

Nestly Inc., 425 Virginia Street, STE b, Vallejo, CA 94590, United States.

Connection