BrokyBrokyBeta

Privacy Policy

Last updated: 21 July 2026 · GDPR-first
1. Who we are2. Your account data3. Public-record data in the platform 4. Cookies & storage5. Processors & transfers6. Retention 7. Your rights8. US users9. Changes & contact

1. Who we are

Broky ("we") operates this property-intelligence platform. The data controller is the Broky operator, contactable at andreasvourkos@gmail.com (a legal entity name and address will replace this notice at incorporation). We are established in Greece; the GDPR and Greek law 4624/2019 govern our processing.

2. Data we process about you

DataPurposeLegal basis
Email, name, avatar (from Google or your registration)Your account and sign-inContract — Art. 6(1)(b)
Immutable authentication subject and verified-email aliasesKeeping your account available after a verified email change while preventing recycled addresses from taking over account, team, billing or referral recordsContract — Art. 6(1)(b); legitimate interest for account security — Art. 6(1)(f)
Sign-in activity (when you last used the platform, request counts)Security and service administrationLegitimate interest — Art. 6(1)(f)
Waitlist email + languageThe early access you requestedConsent — Art. 6(1)(a)
Alert subscriptions (email + your saved search)Email digests you request (double opt-in, unsubscribe in every email)Consent — Art. 6(1)(a)
Pending first-party referral touch, accepted referral-offer decision (declines are cleared), referral code and attribution, snapshotted billing workspace, paid-qualification queue, reward status and credit historyShowing the offer before attribution, recording acceptance, operating the referral programme, applying the refund hold and preventing duplicate or same-workspace rewardsContract — Art. 6(1)(b); legitimate interest for fraud prevention — Art. 6(1)(f)
Keyed referral anti-fraud fingerprint derived from IPShort-window abuse and velocity review; the raw IP is not stored in the referral recordLegitimate interest — Art. 6(1)(f)
Opaque referral click ID, keyed browser-touch/consumer fingerprints and server timestampsEnforcing first-touch attribution, expiry and single-account consumption without storing the browser identifier in readable formContract — Art. 6(1)(b); legitimate interest for fraud prevention — Art. 6(1)(f)
Technical logs (IP address, browser) at our hosting edgeSecurity, abuse prevention, operationsLegitimate interest — Art. 6(1)(f)
Your country (from IP, at the network edge)Opening the map on your region — not storedLegitimate interest — Art. 6(1)(f)
AI-chat prompts, responses, selected country, attached files you choose to submit, and the database filters or records needed to answerAnswering your request, preserving the conversation you save, recovering an interrupted response, and preventing the AI from using data outside the active country or your permissionsContract — Art. 6(1)(b); legitimate interest for service security and reliability — Art. 6(1)(f)
Optional thumbs-up/down feedback and the bounded question/answer excerpt connected to itHuman-reviewed quality evaluation and regression testing; it is not used for automatic or online model trainingLegitimate interest in improving the service — Art. 6(1)(f)

We do not sell personal data, show ads, or run third-party marketing/analytics trackers.

3. Personal data inside the platform content (public records)

The platform republishes records that the law already makes public: Greek permits and decisions (Διαύγεια, published under law 3861/2010), public tenders (ΚΗΜΔΗΣ), company registries (ΓΕΜΗ), US public records (NYC Open Data — permits, deeds, property data), and servicers' own public property catalogues. Where these records name natural persons — for example the engineer on a building permit, or a buyer/seller on a recorded deed — that personal data appears on the platform exactly as published by the official source.

4. Cookies & local storage

We set no tracking or advertising cookies. We use first-party browser storage strictly to make the product work: your sign-in session (Supabase), theme, language and map preferences. If you arrive through a referral link, first-party storage keeps the referral code, signed attribution token and expiry for the displayed attribution window (normally 30 days and never more than 90 days). It is removed after attribution, expiry or a terminal rejection. Because this is functional/strictly-necessary storage, no consent banner is required; if we ever add analytics we will ask first.

5. Processors & international transfers

ProcessorWhat forTransfers
CloudflareHosting, edge network, databaseSCCs / EU-US Data Privacy Framework
Cloudflare Workers AI / AI GatewayAI inference and secure routing to the selected model providerSCCs / EU-US Data Privacy Framework
SupabaseAuthenticationSCCs / DPF
GoogleSign-in with Google (identity provider) and, when selected by Broky's governed model router, Gemini AI inferenceSCCs / DPF
OpenAIAI-chat inference when selected by Broky's governed model routerSCCs / DPF
AnthropicAI-chat inference when selected by Broky's governed model routerSCCs / DPF
ResendTransactional team invitations and alert email delivery you requestSCCs / DPF
StripeSubscription payments, billing status and paid-referral qualificationSCCs / DPF

We share personal data with no one else, unless required by law.

6. Retention

7. Your rights (GDPR)

You have the right of access, rectification, erasure, restriction, portability, and objection (including to any legitimate-interest processing), and the right to withdraw consent at any time without affecting prior processing. Write to andreasvourkos@gmail.com — we respond within 30 days. This includes requests concerning saved AI chats and AI answer feedback. You may also lodge a complaint with the Hellenic Data Protection Authority (dpa.gr) or your local EU supervisory authority.

8. US users

We are not currently subject to the CCPA/CPRA or similar US state privacy laws (we do not meet their thresholds and do not sell or share personal information). We nevertheless extend the same rights described above to all users, wherever located. US public-record content (e.g. NYC Open Data) is governed by the publishing agency's terms.

9. Google user data (connected Google account)

If you connect your Google account (Connectors → Gmail / Calendar / Drive), Broky's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

ScopeWhat Broky does with it
gmail.sendSends a report or message from your own Gmail account, only after you approve an on-screen approval card showing the recipient, subject and content. Broky never reads, lists, or modifies your mailbox.
calendar.eventsCreates an event you explicitly asked for, after you approve the card. Broky does not read your other calendars or events.
drive.fileWrites a report file Broky itself creates. This scope grants access only to files the app creates — never to your existing Drive content.
spreadsheetsWrites a spreadsheet Broky itself creates as part of an export you approved.

We never sell or transfer Google user data, never use it for advertising, and never use it to train generalized AI/ML models. Google user data is used solely to provide the user-facing feature that requested it. Access tokens are stored encrypted (AES-GCM) and are deleted when you disconnect the connector (Connectors → Disconnect) or delete your account. You can also revoke Broky's access at any time at myaccount.google.com/permissions.

10. Changes & contact

We will announce material changes in-app or by email. Questions and privacy requests: andreasvourkos@gmail.com.