KasaTool Privacy Policy
Product / operating name: KasaTool Operator: Leonardo Gomez Version: 1.0 Effective date: August 17, 2026 Last updated: August 17, 2026
KasaTool is operated by Leonardo Gomez under the KasaTool name. Leonardo Gomez is an individual / sole proprietor. KasaTool is not a limited liability company, corporation, or other incorporated entity.
This Privacy Policy describes how KasaTool handles personal information in the product that exists today. It is a founder-ready draft, not a certification of legal compliance and not legal advice.
KasaTool is operated by Leonardo Gomez under the KasaTool name. Public contact for privacy questions: hello@kasatool.com.
1. Scope
This Policy covers the KasaTool websites and apps that link to it, including homeowner, renter, landlord, Business/Pro, and Staff-facing tools.
It does not cover independent Businesses' own practices off KasaTool, Stripe's independent card processing, OpenAI's independent model-provider practices, or other sites we link to.
2. Information We Collect
We collect information you provide, information created when you use the product, and information we receive from processors that help us operate (for example, Stripe payment-status events, Geoapify address matches, or email delivery status).
We do not collect information we have no product reason to collect. We also do not claim that a category is unused if a table, upload, or vendor call exists for it.
3. Information You Provide
Depending on how you use KasaTool, you may provide:
- Account: name, email, password, phone, language, timezone, units, avatar
- Profile: public handle, bio, social links if you opt into a public personal profile
- Property: addresses, nicknames, property details, photos, documents, appliance/system records, maintenance schedules
- Projects: titles, descriptions, photos, follow-up answers, bid requests
- Business: legal and display names, contact info, trades, service areas, portfolio, licenses, insurance documents, team members
- Rental: tenancy invitations, condition reports, maintenance requests, leases and related documents
- Messaging: message text and attachments
- Reviews: ratings and written reviews
- Support / insurance intake: support messages and insurance-quote questionnaires
- Payment references: you enter card details with Stripe; KasaTool stores customer/subscription/wallet references, not full card numbers
- Legal acceptance: the exact Terms and Privacy versions you accepted and when
4. Automatically Collected Information
When you use KasaTool we may record:
- sign-in and sign-up attempt metadata used for rate limiting
- session cookies needed to keep you signed in (Supabase Auth)
- product-analytics events and, if Staff has enabled it, session replay through PostHog
- email delivery logs (template, status, provider message id — not the full email body)
- lifecycle-reminder job records
- security events such as password or email changes
- coarse device type derived from user-agent for analytics context
We do not operate our own advertising pixel network. Paid Discover advertising is built but the paid-advertising switch is off in the current invited beta.
5. Property / Location Information
Addresses and coordinates are used to store your property, match service areas, calculate distance for marketplace and Find a Pro features, and verify that a typed or selected address can be geocoded.
The current address provider is Geoapify. Autocomplete and place-details requests send the address text you type or select. The product is configured for United States addresses.
Latitude and longitude are stored on the property or project record after a successful lookup. They are not a legal survey.
6. Business Credential Information
License numbers, insurance documents, and related uploads are collected so Staff can review a Business. They are not shown as public profile trivia and are not included in a user's self-serve data export.
Staff review is limited to what was submitted. A Verified or Insurance/License Verified label is not proof that a credential remains valid.
7. Communications
We store in-app messages for the conversation types the product supports. We send transactional email through Resend when a feature is wired to do so (for example, a new bid, a support reply, a password change, or a required legal update).
Optional reminder categories can be turned off in Settings. Required security and legal notices are not marketing and do not use the marketing-consent path.
Marketing/audience tools that exist in the Staff product are separate from transactional mail. We do not treat a legal-update email as marketing consent.
8. AI Feature Data
If you use Kasa AI, project analysis, or Visualization Studio, we send the text, structured project context, and (for visualization) images/masks needed to produce the result you asked for to the configured AI provider. The current provider is OpenAI (Responses API for structured analysis/chat; Images API for visualization edits).
We store the resulting Project Intelligence Record, chat messages, visualization versions, and usage/cost metadata in KasaTool.
We do not assert, from application code alone, that the provider will or will not train on that data. That depends on the provider contract and account settings in force at the time. Treat provider training/retention as an item for counsel and vendor-term verification before public launch.
9. Payment / Transaction Metadata
Stripe receives the information needed to start Checkout, manage a subscription, add Lead Balance or Ad Wallet funds, or process a Connect-related event if that feature is used.
KasaTool stores subscription status, customer references, ledger entries, and webhook event ids. We do not store full card numbers.
During the current invited beta, paid lead charging and paid advertising are off, and B2B posting charging is off. Wallet and subscription tables may still exist.
10. Analytics / Cookies / Similar Technologies
KasaTool uses:
- Essential cookies / local storage for authentication and ordinary app function
- First-party analytics events stored in KasaTool for Staff metrics
- PostHog (when a key is configured and Staff has enabled analytics) for product analytics and, if separately enabled, session replay
Session replay is configured to mask all inputs. Additional private regions (message bubbles, tenancy document details, license/insurance numbers) are marked not to capture.
Staff accounts and accounts marked as test accounts are opted out of PostHog capture. The first-party analytics row may still be written and tagged.
There is no cookie-consent banner in the current product. Whether one is required depends on the launch jurisdictions and on whether PostHog is treated as a sale/share/targeted-advertising cookie under those laws. We are not adding a banner in this version solely as decoration.
11. How We Use Information
We use personal information to:
- create and secure accounts
- operate property, project, marketplace, messaging, rental, and Business features
- generate AI analysis or visualizations you request
- match or recommend Businesses, send bid opportunities, and open conversations you start
- review Business verification materials
- send transactional notices and, if you have not disabled them, optional reminders
- prevent fraud and abuse
- understand product usage
- comply with law and enforce these Terms
- record the exact legal-document versions you accepted
12. How We Disclose Information
We disclose information in these situations:
- To the other party in a relationship you create. Examples: a Business you Connect with on Find a Pro can see the search details and messages; Businesses who receive a Get Bids opportunity can see the bid-request information needed to respond; a landlord and renter can see tenancy-scoped records; a reviewer and Business can see a review.
- To processors listed in the processor inventory (hosting, database, email, AI, address lookup, payments, analytics, video search).
- To Staff who have the permission required for that record.
- For legal or safety reasons if we reasonably believe we must.
- In a business transfer if KasaTool is sold or reorganized.
We do not operate a data-broker business or sell mailing lists as a product. We also do not make a blanket statutory claim that personal information is never sold or shared. Sharing project and contact details with Businesses so they can respond to a lead, and using PostHog, can raise "sale" or "share" questions under some state privacy laws. Those questions are flagged for counsel.
Paid advertising targeting is off in the current invited beta. Insurance answers, private rental records, and private AI chat content are not used as advertising targeting inputs.
13. Service Providers / Processors
Current processors evidenced in the product configuration include:
- Supabase — authentication, database, file storage
- Vercel — application hosting
- OpenAI — AI text/image features
- Resend — transactional email
- PostHog — product analytics / optional session replay
- Geoapify — address autocomplete and geocoding
- Stripe — subscriptions and one-time wallet top-ups when those flows run
- YouTube Data API — video discovery when that provider is enabled
A processor is not always "active" in a given environment. Empty credentials fail closed and do not pretend the vendor is connected.
14. Public Information
Public Business profiles, opt-in personal profiles, Discover posts you make public, and public reviews can be seen by other people, including people who are not signed in.
Do not put information on a public surface if you do not want it public.
15. Business Transfers
If we are involved in a merger, acquisition, financing, or sale of assets, personal information may be transferred as part of that transaction. We will continue to treat it under this Policy unless a new Policy is published.
16. Legal / Safety Disclosures
We may disclose information to comply with law, respond to lawful process, protect users, investigate fraud or abuse, or protect KasaTool's rights.
17. Retention
We keep information for as long as needed for the purpose it was collected, including:
- account and profile data while the account is open
- project, message, tenancy, and job history that another party still needs after you leave
- legal-acceptance records as evidence of the version you agreed to
- ledger, billing, and audit records for financial and security integrity
- email delivery logs and lifecycle job records used to operate and debug notices
- backups and logs for a limited additional period
We do not promise immediate deletion from every backup or log. We do not currently publish a complete per-table retention schedule. That is a known gap for a later operations pass.
18. Security
We use reasonable administrative, technical, and organizational safeguards, including access control, RLS on user data, private buckets for sensitive uploads, and re-authentication before account deletion.
No method of transmission or storage is perfectly secure. We do not promise that unauthorized access can never occur.
19. Your Privacy Choices
You can:
- edit most profile and property fields in the product
- close a public personal profile
- turn off optional notification/email categories
- export a copy of selected account data
- request account deletion
- contact hello@kasatool.com for a privacy question or correction we cannot complete in Settings
Marketing consent, if collected later, will be separate from the Terms/Privacy checkbox.
20. Access / Correction / Deletion
Most corrections can be made in Settings, profile, property, and Business screens.
For access or correction we cannot complete in the product, email hello@kasatool.com. We may need to verify that the request is from the account holder.
Deletion is described in the Terms and in Settings. Some shared or legally retained records are not erased.
21. Data Export
Settings includes a self-serve export of selected account data (profile, properties, projects, your own messages, reviews you wrote, notification preferences, support requests you opened, subscription summary, memberships, and owned Business profile fields).
The export does not include Staff internal notes, license/insurance documents, or other users' bids. That is intentional.
22. Marketing Communications
Transactional mail about your account, security, legal updates, bids, and projects is not marketing.
We do not use the signup legal checkbox as marketing opt-in.
23. State Privacy Rights
Depending on where you live and whether a particular state privacy law applies to KasaTool, you may have rights to request access, correction, deletion, a copy of data, an appeal of a denied request, and to be free from discrimination for exercising a privacy right.
Some laws also create rights to opt out of "sale," "sharing," or targeted advertising. Whether those definitions apply to lead delivery or PostHog is a counsel question. We do not silently answer it with a blanket non-sale slogan.
If you want to make a rights request, email hello@kasatool.com. If we deny a request, you may reply to ask for a review.
24. California notices
If California privacy law applies, the categories above are the categories of personal information we collect and the business/commercial purposes we use them for. We collect them from you, from your use of the service, and from processors listed in this Policy.
We do not use or disclose sensitive personal information for purposes that California law treats as requiring a separate limit-use right, beyond providing the features you asked for (for example, storing an address or a license document for verification).
25. Texas notices
KasaTool's launch market includes Texas. If the Texas Data Privacy and Security Act or other Texas consumer law applies, you may have rights consistent with Section 23. Email hello@kasatool.com to exercise them.
26. Children's Privacy
KasaTool is not directed to children. You must be at least 18 years old to create an account. We do not knowingly collect personal information from anyone under 18. If you believe a child created an account, contact hello@kasatool.com.
27. International Users
The product is built for United States use, including US-only address filtering. If you access KasaTool from another country, your information may be processed in the United States. We do not currently offer a region-specific international transfer addendum.
28. Changes
We may publish a new Privacy Policy version. If Staff marks it as requiring re-acceptance, we will block ordinary product use until you accept, and we will try to notify you in-app and by email. We will not treat silence as acceptance of a required new version.
29. Contact
Privacy questions, correction requests, deletion questions, and state-rights requests:
KasaTool is operated by Leonardo Gomez under the KasaTool name.
Operator: Leonardo Gomez
Product / operating name: KasaTool
Email: hello@kasatool.com
Mailing address:
6675 S Custer Rd
Suite 500, PMB 1027
McKinney, TX 75070
United States