Legal
Privacy Policy
Effective date: September 1, 2026
This Privacy Policy explains how LAB9 INTELL (“LAB9 INTELL,” “we,” “us,” or “our”) collects, uses, stores, shares, and protects information when you use our websites, applications, analysis tools, Operators Network waitlist, and related services (the “Service”).
By using the Service, you acknowledge the practices described in this Policy. If you do not agree, do not use the Service.
1. Account and profile information
If you sign up with a password, we collect the email address you register and authentication credentials handled by our authentication provider. If you sign in with Google or another OAuth provider, that provider may supply your name, avatar image, and provider account identifiers.
Your profile and settings may include a full name, avatar, company, phone number, and a short bio, to the extent you choose to provide them. We may also associate your account with plan and usage status as well as role or authorization metadata used to determine what you can access.
We use this information to authenticate you, operate and secure your account, provide support, manage billing access, and communicate with you about the Service.
2. Deals, documents, and transaction information
When you use the Service you may enter and store deal and property names, addresses, asset class, financial assumptions, broker, agent, or seller contact details, underwriting adjustments, letter-of-intent fields, and other deal information.
Files you upload may include offering memoranda, T-12s, rent rolls, financial statements, listings, PDFs, spreadsheets, and other deal documents. Uploaded files are stored in private storage with access controls. We also store file metadata such as filename, MIME type, size, document kind, and the internal storage pointer.
Documents and deal fields you provide may contain personal or contact information about other individuals. You are responsible for having the rights and authority to provide that information to us for processing.
3. AI and automated processing of documents
The Service may use automated rules, deterministic calculations, document extraction, and AI or model providers to analyze deal documents and produce outputs.
For current provider-assisted analysis, the complete verified document file may be transmitted to a third-party AI/model provider for processing. The provider receives the file plus the limited context needed to perform the analysis. LAB9 INTELL does not intentionally send your email address, account password, authentication token, storage path, signed URL, or internal user and deal identifiers to the provider as metadata.
After processing, LAB9 INTELL attempts to delete the temporary provider-side uploaded file on a best-effort basis. We cannot guarantee provider-side deletion timing or that no copy is retained by the provider.
LAB9 INTELL does not intentionally opt uploaded deal documents into model-training or data-sharing programs. Provider handling is also subject to the provider’s then-current terms and privacy/data-processing practices.
Generated results, Investment Briefs, scores, and other analysis outputs may be stored in LAB9 INTELL databases as part of your deal history and the operation of the Service.
4. Usage, audit, and diagnostic information
We record operational information such as feature usage, analysis usage, request timing, plan and allowance state, model-call metadata (including token, cost, and outcome information), errors and diagnostics, browser and user-agent data, and audit events describing actions taken in your account.
Audit logs can include user-entered deal-field values or records of changes to them. They are not intended to store raw document files. Some error and diagnostic fields are redacted and length-bounded to reduce exposure of secrets and document content; we do not claim that every log field is scrubbed of every user-provided value.
We use this information for security, abuse prevention, reliability, billing and usage accounting, debugging, compliance, and product improvement.
At the effective date of this Policy, LAB9 INTELL does not use third-party advertising pixels or behavioral analytics SDKs in the Service.
5. Billing and payment information
Subscription checkout and the customer portal are provided by Stripe or another disclosed payment processor. Payment card details are entered into processor-hosted or processor-embedded payment interfaces and are not stored in LAB9 INTELL application databases.
We receive and store billing metadata such as customer and subscription identifiers, price and product identifiers, plan and status, renewal and current-period dates, cancellation status, and webhook or reconciliation metadata used to keep your access accurate.
The payment processor uses information it collects under its own privacy policy and terms.
6. Operators Network waitlist
If you submit the Operators Network waitlist, we collect and store your full name, email address, optional phone number, company name, role, primary markets, asset classes, experience level, interests, biggest challenge, an optional free-text answer, and the time of submission.
We use this to evaluate interest, plan the Network, understand market and role needs, communicate about availability and early access, and administer the waitlist. If you are signed in when you submit, a limited audit event may also record the email, role, and company associated with the waitlist action.
Submitting the waitlist means you are asking us to contact you about the Operators Network and related launch or availability updates.
7. Support, communications, and third-party contact data
When you email support@lab9intell.com, we receive your message and anything you choose to include in it.
Broker, agent, and seller names, email addresses, and phone numbers, as well as letter-of-intent recipient, buyer, seller, and contact fields, may be stored when you enter them into the Service.
Generated email and LOI drafts are prepared within the Service. The current application does not send those drafts through an email-delivery provider on your behalf; you copy the draft or open it in your own mail client.
Our authentication provider may send transactional authentication email, such as address verification and password reset messages.
8. Browser storage, cookies, and similar technologies
At the effective date, the Service uses the specific cookies and browser-storage entries described below. None of them are advertising or cross-site tracking technologies.
- Security (essential). Our hosting and edge network sets a short-lived bot-management cookie (currently named __cf_bm) to distinguish automated traffic from real visitors and protect the Service from abuse.
- Authentication (essential). Session and sign-in state is kept in your browser’s local storage or equivalent storage so you stay signed in. A short-lived local entry may also carry your acceptance of the Terms and this Policy from the signup click to your first session.
- Interface preferences (functionality). A limited cookie may remember sidebar or layout state, and local or session storage may remember dismissed notices such as usage banners and upgrade prompts.
- Upload resumption (functionality). Local storage may keep upload-resume fingerprints — non-secret references to an in-progress upload — so an interrupted document upload can continue instead of restarting.
- Error diagnostics (functionality and security). The application platform may keep limited error-diagnostic entries in browser storage to help identify and fix failures.
Not all of this storage is strictly essential: the security and authentication entries are required for the Service to work safely, while the interface, upload-resumption, and diagnostic entries support convenience and reliability.
Stripe and other third-party embedded services may set or use their own cookies or storage under their own policies when you use those features.
At the effective date of this Policy, we do not use third-party advertising pixels, advertising cookies, or behavioral analytics SDKs. If our use of these technologies changes materially, we will update this Policy.
9. How we use information
We use the information described above to:
- provide, operate, analyze, and secure the Service;
- authenticate users and manage accounts;
- process deals and documents and produce analysis outputs;
- enforce usage limits and plan entitlements;
- process billing and subscriptions;
- support users and respond to requests;
- detect and prevent fraud, abuse, and security incidents;
- debug and improve reliability, performance, and the product;
- administer the Operators Network waitlist;
- comply with law, enforce our agreements, and protect rights and safety.
10. How we share information
We share information with the following categories of recipients:
- infrastructure, database, authentication, and storage providers;
- AI and model providers for provider-assisted analysis;
- payment processors;
- hosting, communications, security, and operations service providers;
- professional advisors and authorities where required by law or legal process;
- transaction counterparties, only when you direct that sharing or share materials through your own actions;
- acquirers or successors in a business transfer such as a merger, acquisition, reorganization, or sale, subject to applicable law.
We do not sell your uploaded deal documents, and we do not share them with advertising networks or data brokers.
11. Data retention, archiving, and deletion
While your account is active, we retain account and profile information, deals, documents, generated outputs, and billing and usage information as needed to provide the Service.
You can delete eligible individual files and deals through the controls available in the application. Where deletion is permitted, this removes the registered storage objects and database rows for those items. Some deals with portfolio or history relationships may need to be archived instead of deleted, and therefore remain stored.
Audit logs may be retained for security, compliance, and operational history, and can include account email, action, entity, and change metadata. Analysis usage and billing ledger events may be retained and de-identified when the linked records are removed.
Billing records, fraud and security records, legal and compliance records, and backups or provider-side copies may persist for legitimate business and legal reasons after you delete content.
There is currently no self-service account deletion workflow. You can contact support to request account or data deletion, and we will evaluate and process the request subject to legal and operational retention needs.
12. Security
We use measures appropriate to the current stage of the product, including HTTPS/TLS for production transport, authenticated and server-authorized handling of privileged operations, row-level access controls on user data, private file storage with short-lived signed access links, server-derived file paths and file-type verification, signature validation on payment webhooks, redaction and bounding of diagnostic data, and security headers. A baseline content-security policy that blocks framing and restricts form targets is enforced; the broader resource-loading policy is currently deployed in report-only (monitoring) mode rather than full enforcement.
You are responsible for keeping your credentials confidential and for the security of the devices you use. No method of storage or transmission is completely secure, and we cannot guarantee absolute security.
13. Children
The Service is intended for adults 18 years of age or older and is not directed to children. We do not knowingly seek to collect personal information from children through the Service. If you believe a child has provided information to us, contact support and we will review the matter.
14. International and cross-border processing
LAB9 INTELL and its service providers may process or store information in the United States and other locations where they operate. Those locations may have data-protection laws different from your jurisdiction. Where required, we will use lawful mechanisms for cross-border transfers.
15. Your choices and requests
You can:
- update your profile in account settings where available;
- cancel your subscription through Billing or the customer portal;
- delete eligible files and deals where those controls are available;
- stop uploading documents at any time;
- contact support with privacy, access, correction, or deletion questions and requests;
- stop participating in Operators Network communications by contacting support until a dedicated unsubscribe mechanism is available.
Depending on where you live, applicable law may provide additional rights regarding your personal information. Contact support to exercise them, and we will respond as required by applicable law.
16. Changes to this Policy
We may update this Policy to reflect product, provider, legal, or business changes. When we do, we will update the effective date above. Where required, we will communicate material changes by reasonable means.
17. Contact / support
Privacy questions and requests: support@lab9intell.com.
