Legal
Privacy Policy
Effective / last updated: August 12, 2026
1.Who this policy covers
This policy covers the R35 website and desktop app. When you use R35 to run outreach, you decide what data goes in and who you contact — for that data you're the controller and we're your processor.
This policy applies to the R35 marketing website, the desktop application for macOS and Windows, and the web console. It describes information we handle both about you (as our customer) and, where relevant, the property and contact data you bring into or source through the Service.
For much of the data you put into the Service — your leads, contacts, and the content of your outreach — you decide what is collected and how it is used. For that data you act as the controller and we act as your processor, handling it on your behalf and under your instructions and our agreement with you (see Section 5). For account, billing, website, and telemetry data, we are the controller.
2.Information we collect
We collect: account and firm details; license and device-binding data; the leads and property data you import or the system sources from public records; the content of communications you run through R35; payment info (handled by processors); and usage/telemetry to keep the product working.
We collect the following categories of information:
- Account and firm information. Your name, email, password credentials, Organization/firm name and details, team members and roles, and settings you configure.
- License and device-binding data. License keys, activation status, and identifiers used to bind an installation to a specific machine, plus app version and related device information used for licensing and security.
- Leads and property data. The contacts, owners, property records, buy-box criteria, and related data you import (for example from spreadsheets or integrations) or that the Service sources from public records and county, state, and federal data sources.
- Communications content. The content and metadata of outreach you run through the Service — SMS, email, and voice calls (including, where enabled, call recordings and transcripts) — and notes, documents, and e-signature records.
- Payment information. Billing contact details and subscription records. Card and bank details are collected and processed by our payment processors, not stored by us; we receive limited information such as the last four digits and payment status.
- Usage and telemetry. How the site and app are used — pages and features used, device and app version, diagnostics, and error logs — to operate, secure, and improve the Service.
- Support communications. Messages you send us and related records.
3.How we use information
We use information to provide and secure the Service, run your account and license, process payments, power AI features you use, provide support, prevent abuse, meet legal obligations, and improve the product. We don't sell your personal information.
We use the information above to:
- provide, maintain, and secure the Service, including license activation and device binding;
- perform the features you use — sourcing and organizing leads, running outreach, qualifying and negotiating, generating and signing documents, and marketing properties;
- process payments, manage subscriptions, seats, and AI credits, and prevent fraud;
- power AI features you enable, as described in Section 4;
- provide support and respond to your requests;
- monitor, diagnose, and improve performance and reliability, and develop new features;
- detect, prevent, and address abuse, security incidents, and violations of our Terms; and
- comply with legal obligations and enforce our agreements.
We do not sell your personal information, and we do not use the content of your outreach for our own advertising.
4.AI processing of your content
To generate drafts, research, and answers, R35 sends relevant prompts and content to AI/model providers, and creates embeddings so agents can search and remember. Those providers process the data under their own terms to return a result. You control which AI features run.
AI features work by sending relevant content to third-party AI and model providers to generate a result. Depending on the features you use, this can include the prompt and the context needed for the task — for example lead and property details, prior messages in a thread, documents, and instructions — sent to a model provider (directly or through a router such as OpenRouter) to draft outreach, research, negotiate, summarize, or generate documents.
We also generate embeddings (numerical representations) of certain content so AI teammates can search across your data and maintain memory and context. These may be stored to power search and recall.
Model providers process the data we send them to return a response and under their own terms and privacy commitments; providers we use are not permitted to use your content to train general models except as allowed by our agreements or your settings. You control which AI features run and how autonomously they operate. AI Output can be imperfect and should be reviewed before you rely on it (see our Terms).
5.Your outreach data and your role
The leads, contacts, and messages you manage in R35 are yours. We process them on your behalf to run the Service and don't use their contents for our own marketing. You're responsible for having the right to hold that data and to contact those people.
The leads, contacts, communications, and property data you manage in the Service belong to you. We process them as your processor, on your instructions, to provide the Service — and we do not use the contents of your outreach for our own marketing. You are responsible for having a lawful basis and the right to collect and hold that data and to contact the people it identifies, and for honoring their privacy and opt-out rights, as described in our Terms. If you are subject to laws such as the GDPR or CCPA/CPRA as a controller of that data, our processing on your behalf is governed by our agreement with you, including any data-processing terms.
7.Data retention and controls
We keep information while you have an account and as needed for legal, accounting, and dispute needs, then delete or anonymize it. The Service offers retention controls — including plan-based retention schedules and legal hold — and you can ask us to delete your account data.
We retain information for as long as your account is active and as needed to provide the Service, and afterward for a reasonable period to meet legal, accounting, security, and dispute-resolution needs. When we no longer need information, we delete it or make it anonymous.
The Service provides retention controls so you can manage your data — including, on applicable plans, configurable retention schedules, required-disclosure and record-keeping settings, and legal-hold functionality that preserves records when needed. You can also request deletion of your account and its data (see Section 9); we will honor such requests subject to records we are legally required to keep and to any active legal hold. Because some communications pass through third-party providers, their retention of logs is also governed by their policies.
8.How we protect information
We use administrative, technical, and organizational safeguards — including encryption in transit, access controls, and two-factor sign-in — to protect information. No system is perfectly secure, so we can't guarantee absolute security.
We use administrative, technical, and organizational measures designed to protect information, such as encryption in transit, access controls and role-based permissions, two-factor authentication, audit logging, and monitoring. You also play a role: keep your credentials and license keys secure, use strong passwords and two-factor sign-in, and manage your team's access. No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your information, we will notify you as required by law.
9.Your rights and choices
Depending on where you live, you can access, correct, export, or delete your personal information and object to or restrict certain processing. The desktop app and console support export and deletion. To make a request, contact us; we may verify your identity first.
Depending on your location and applicable law (such as the GDPR or CCPA/CPRA), you may have the right to access, correct, port/export, or delete personal information we hold about you; to object to or restrict certain processing; to withdraw consent; and to be free from discrimination for exercising these rights. You may also opt out of non-essential communications at any time.
The desktop application and web console include tools that support these rights — including exporting and deleting account and lead data. To make a request, use those tools or contact us at privacy@r35.to; we may need to verify your identity first, and you may use an authorized agent where the law allows. If the request concerns data you process about others through the Service, we will assist you, as your processor, in responding to that person's request. If you are unsatisfied, you may have the right to lodge a complaint with your local data-protection authority.
11.Children
R35 is a business tool and isn't directed to children under 18. We don't knowingly collect personal information from children.
The Service is intended for businesses and users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 18. If you believe a child has provided us personal information, contact us at privacy@r35.to and we will take appropriate steps to delete it.
12.International data transfers
We and our providers may process information in the United States and other countries. Where required, we use appropriate safeguards for cross-border transfers.
We are based in the United States, and we and our sub-processors may store and process information in the United States and other countries where they operate. These countries may have data-protection laws different from those where you live. Where required, we use appropriate safeguards for international transfers, such as the European Commission's Standard Contractual Clauses or another lawful transfer mechanism. By using the Service, you understand your information may be transferred to and processed in these locations.
13.Changes to this policy
We may update this policy as the product and law change. We'll update the date above and, for material changes, give reasonable notice. Continuing to use R35 means you accept the update.
We may update this Privacy Policy from time to time. If we make a material change, we will update the "Effective / last updated" date above and provide reasonable notice through the Service or by email when appropriate. Your continued use of the Service after a change takes effect means you accept the updated policy.
14.How to contact us
Questions about this policy or a request about your data? Contact us at privacy@r35.to or through our contact page. Mailing address: O2A2 LLC, 8524 Dahlia Drive, Charlotte, NC 28213. Data-protection contact: privacy@r35.to.
