Skip to content
Salt & Leaf
  • Flows
  • How it works
  • Pricing
App installer Request an introduction

Site menu

Salt & Leaf
  1. 01 The gap
  2. 02 Flows
  3. 03 The app
  4. 04 How it works
  5. 05 Pricing
  6. 06 Introductions
Client download Request an introduction titus@saltandleafsystems.com

Document

Privacy Policy

Salt and Leaf Systems LLC · Version 2

Salt and Leaf Systems LLC
Effective: the date this version is published in the App
Version 2

What personal information we collect, why, who we share it with, how long we keep it, and the choices you have.


On this pageHide sections
  1. 1About this Policy
  2. 2Key terms
  3. 3Our two roles
  4. 4Information we collect
  5. 5Information we do not collect
  6. 6Discovery call recordings
  7. 7How we use information
  8. 8AI processing
  9. 9Who we share information with
  10. 10We do not sell personal information
  11. 11Cookies and local storage
  12. 12Emails
  13. 13How long we keep information
  14. 14Security
  15. 15If there is a security breach
  16. 16Your privacy rights
  17. 17Clients of our Customers
  18. 18Children
  19. 19Where information is processed
  20. 20Changes to this Policy
  21. 21Contact us

1 About this Policy

1.1

Salt and Leaf Systems LLC ("Salt & Leaf", "we", "us") makes the Salt & Leaf app, a desktop app and website that runs AI automations called Flows for real-estate professionals. This Policy explains what personal information we collect, why, who we share it with, how long we keep it, and the choices you have.

1.2

This Policy covers the desktop app, the account website at app.saltandleafsystems.com, our other websites, discovery calls, and our emails and support.

1.3

This Policy works alongside the Terms of Service and the Data Protection and Confidentiality Addendum (the "Addendum"). For a Customer, the Addendum sets out our binding commitments about Customer Data. If this Policy and the Addendum differ about Customer Data, the Addendum controls.

2 Key terms

2.1

These terms have the same meaning here as in the Terms of Service, which give the full definitions. In short:

  • App means the Salt & Leaf desktop app and the account website, together.
  • Customer means the person or business that accepts the Terms of Service and holds the Account. A Customer may be a brokerage with several Users or an individual agent.
  • Account means the Customer's account in the App.
  • User means an individual with a login under a Customer's Account, whatever their role (Owner, Admin or Team member).
  • Flow means an automation a Customer adds and runs in the App. A Flow Spec describes what a Flow does and what it needs. A Run is one execution of a Flow. A Custom Flow is a Flow built for one Customer.
  • Sapling means a Customer's request for a new Flow, from the request form through the discovery call and quote to the finished build.
  • Customer Data means the data a Customer or its Users put into the App or into a Flow, including listing data, photos, documents and personal information about the Customer's own clients. It includes Sapling requests and sample files, discovery call recordings, transcripts and notes, and data we reach through an Access Authorization.
  • Output means what a Flow produces from Customer Data.
  • Subprocessor means a company we use to process personal information to deliver the App (listed in Section 9).

3 Our two roles

3.1

Customer Data. When a Customer puts data into the App, we process it on the Customer's behalf and only on its instructions. For this data we are the Customer's processor, or "service provider" as the California Consumer Privacy Act uses that term. The Customer decides what goes in and is responsible for having the right to share it and for giving its own clients any notices they need. If you are a client of one of our Customers, see Section 17.

3.2

Our own information. For account, sign-in, billing, signature, usage, support and similar information about Customers and Users, and for people who contact us or book a call, we decide how the information is used. For this information we are the controller, and this Policy describes what we do with it.

4 Information we collect

4.1

Account information. Name, email address, phone number, business name, role in the Account, and a tax ID if you give one for invoices. When a new workspace asks for access, we collect the details in the access request.

4.2

Sign-in and security information. Sign-in times, IP address, device and browser type, multi-factor authentication settings and session records. Passwords are stored by our sign-in provider in scrambled (hashed) form. We cannot see your password.

4.3

Electronic signature records. When you accept an agreement or sign a quote in the App, we record who accepted, the date and time (with time zone), the document version and a fingerprint of its text, your IP address and your browser. These are legal records of the agreement.

4.4

Billing information. Stripe processes all payments. Stripe collects your card details directly. We receive only the card brand, last four digits, expiry date, billing name and address, and records of charges and invoices. We never see or store full card numbers.

4.5

Usage and Run logs. Which Flow ran, when, which User started it, what it cost in usage, and whether it succeeded or failed, with error details when it failed.

4.6

Customer Data and Outputs. The inputs you put into Flows (such as listing data, photos, documents and client details) and the Outputs Flows produce. You control what you put in.

4.7

Sapling information. Your request form, the sample files you send, notes from our review, the quote and the build plan.

4.8

Call recordings, transcripts and notes. Discovery calls are recorded and transcribed as described in Section 6.

4.9

Support messages. Emails and other messages you send us, and our replies.

4.10

Desktop app diagnostics. App version, operating system version, device type, and error and crash reports, so we can fix problems.

5 Information we do not collect

5.1

Card numbers. Stripe holds them, not us.

5.2

Passwords for other websites. Some Flows open a third-party website (for example, a virtual tour service) in the App's browser panel. You sign in to that site yourself. The session stays on your device. We never ask for, receive or store that password.

5.3

MLS logins and shared logins. We never ask for, receive or use an MLS login, or any other personal login shared with us, including sub-logins. Where a Flow needs MLS data, we get it through a licensed data feed under our own agreement with the provider. If a build needs access to another system, the Customer creates a separate account for Salt & Leaf where that system's rules allow it. That grant is recorded in an Access Authorization and revoked at handoff.

6 Discovery call recordings

6.1

When a Customer plants a Sapling, we hold a short discovery call on Zoom. We record and transcribe the call with Fathom so we can prepare an accurate quote.

6.2

Florida law (Florida Statutes section 934.03) requires everyone on a call to agree before it is recorded. So:
(a) the booking step asks you to agree to the recording before you can book;
(b) the calendar invite says the call will be recorded and transcribed; and
(c) our specialist says so again at the start of the call.

6.3

Anyone who does not want to be recorded can ask for an unrecorded call or for written questions instead. Just tell us before or at the start of the call.

6.4

We use recordings, transcripts and call notes only to understand the request, prepare the quote and build plan, and build the Flow.

6.5

We keep them while the Sapling is open and for 12 months after it closes, then delete them. You can ask us to delete them sooner.

7 How we use information

7.1

We use personal information to:
(a) provide the App and run the Flows you choose, including sending Customer Data to Subprocessors so a Flow can produce its Output;
(b) review access requests and manage Accounts, Users and roles;
(c) scope, quote and build Custom Flows;
(d) take payments, apply credits, issue invoices and keep billing and tax records;
(e) keep records of what was agreed and when;
(f) send account and service emails (Section 12);
(g) answer support requests;
(h) keep the App secure, prevent misuse and fix errors;
(i) improve the App, using usage and Run logs and diagnostics rather than the content of Customer Data; and
(j) meet legal obligations and protect our rights.

7.2

Our staff look at Customer Data only when needed to deliver the App, to fix a problem, to build a Custom Flow, or when you ask us to.

8 AI processing

8.1

Flows use Anthropic's Claude models. When a Flow runs, the inputs it needs are sent to Anthropic, and the Output comes back to your Account.

8.2

We do not train AI models on Customer Data. Anthropic processes it under its commercial terms, which do not permit it to train its models on that data.

8.3

We choose the model and settings each Flow uses and may change them to keep quality and cost right.

9 Who we share information with

9.1

Subprocessors. We share personal information only with the Subprocessors below, which process it on our behalf to deliver the App:

Subprocessor What it does for us Information involved
Anthropic AI processing for Flow Runs Customer Data a Run needs, and the Output
Supabase Database, sign-in, file storage and server functions Account, sign-in, usage and signature records; Customer Data and Outputs stored in the Account
Vercel Hosting the website Website requests, including IP address and browser
Stripe Payments and invoices Billing information and payment records
Google Workspace Email and calendar Emails with us, call invites, names and email addresses
Zoom Discovery calls Call audio and video, and the names and emails of people on the call
Fathom Call recording and transcription Call recordings, transcripts and notes
9.2

New Subprocessors. We give Customers 30 days' notice before a new Subprocessor starts processing their data. A Customer that objects may close its Account, as the Addendum explains.

9.3

Legal reasons. We may disclose information when the law, a court order or a valid legal request requires it, or where needed to protect the rights, property or safety of Salt & Leaf, our Customers or others.

9.4

If the business changes hands. If Salt & Leaf is merged, sold or reorganized, information may pass to the new owner, who must keep honoring this Policy for the information it receives. We will tell Customers before that happens.

9.5

Nothing else. We do not share personal information with anyone else unless you ask us to.

10 We do not sell personal information

10.1

We do not sell personal information. We do not share it for targeted or cross-context behavioral advertising. We do not use it for profiling that has legal or similarly significant effects on anyone.

11 Cookies and local storage

11.1

The website and desktop app use only the cookies and local storage needed to keep you signed in, keep your session secure and remember your settings.

11.2

We use no advertising trackers and no third-party advertising cookies. If we ever add analytics, we will update this Policy first.

11.3

Because we do not track you for advertising, we have nothing to switch off when your browser sends a "Do Not Track" or Global Privacy Control signal. We treat such a signal as a request to opt out of any sale or sharing, which we do not do anyway.

12 Emails

12.1

We send account and service emails: sign-in and security messages, receipts and invoices, usage and expiry reminders, Sapling and build updates, notices of changes to our agreements, prices or Subprocessors, and replies to your messages. These are part of the service, and you cannot opt out of them while your Account is open.

12.2

If we send product news, each message will have an unsubscribe link, and unsubscribing will not affect your Account.

13 How long we keep information

13.1

While the Account is open, we keep Account information, Customer Data, Outputs and Run logs so the App works and you can see your history.

13.2

After the Account closes, we delete Customer Data and Outputs, or return them if the Owner asks before closure, within 30 days. If we closed the Account at once, the Owner may ask for that return within 14 days after closure. We delete or de-identify other Account information and Run logs within the same 30 days, except the records in 13.3.

13.3

Legal records. We keep billing, tax and payment records, electronic signature records, and signed agreements and quotes for 7 years after the Account closes, or longer if the law requires.

13.4

Call recordings follow Section 6.5.

13.5

Security logs are kept for up to 12 months, unless needed longer to investigate a security issue.

13.6

Declined requests. If we decline an access request, or a Sapling closes without a build, we delete its request details and sample files within 30 days, except any call recording, which follows Section 6.5.

13.7

Backups. Deleted data can remain in our backups until they roll off on their own schedule, within 35 days. We do not use restored backup data for anything except recovering the service.

14 Security

14.1

We protect information with:
(a) encryption in transit and at rest;
(b) least-privilege access, so only people who need data for their work can reach it;
(c) multi-factor authentication on Salt & Leaf systems; and
(d) credentials kept only in a password manager, never in code.

14.2

No system is perfectly secure. Keep your own sign-in details private, turn on multi-factor authentication, and tell us at once if you think someone has used your Account without permission.

15 If there is a security breach

15.1

If we confirm a breach of security that affects a Customer's data, we will tell that Customer within 72 hours of confirming it, explain what we know, and help it with any notices it must give.

15.2

Where Florida Statutes section 501.171 applies, affected individuals are notified within 30 days after the breach is determined, either by us or by the Customer, as the Addendum explains.

16 Your privacy rights

16.1

We offer these rights to everyone, wherever you live:
(a) Access: ask what personal information we hold about you and get a copy.
(b) Correction: ask us to fix information that is wrong. You can also edit most Account details yourself in the App.
(c) Deletion: ask us to delete your personal information. We will delete it except where we must keep it (Section 13.3) or need it to finish something you asked for.
(d) Portability: get your information in a common, machine-readable format. The Owner can also export the Account's data in the App.
(e) Opt out: of product news emails, and of any sale, sharing or targeted advertising (we do none of these).
(f) No discrimination: we will not charge you more, give you a worse service or treat you differently for using any of these rights.

16.2

How to ask. Email titus@saltandleafsystems.com and tell us what you want. We may need to confirm your identity first, usually by asking you to reply from the email address on the Account. You may use an authorized agent; we may ask for proof that the agent is acting for you.

16.3

How long it takes. We respond within 45 days. If we need more time, we will tell you why within those 45 days and take no more than another 45 days.

16.4

If we say no. We will explain why. You can ask us to reconsider by replying to our answer, and we will give you our final decision within 45 days.

16.5

Customer Data. For personal information inside a Customer's Customer Data, we act for the Customer. We pass the request to that Customer and help it respond (Section 17).

17 Clients of our Customers

17.1

If you are a client of a real-estate professional who uses Salt & Leaf, your information is in the App because that professional put it there. They decide how it is used.

17.2

To access, correct or delete that information, please contact that professional. If you contact us instead, we will pass your request to them and help them respond.

18 Children

18.1

The App is for adults using it for work. It is not for anyone under 18, and we do not knowingly collect personal information from anyone under 18. If you think we have, contact us and we will delete it.

19 Where information is processed

19.1

Salt & Leaf is based in the United States, and we and our Subprocessors process information in the United States. If you use the App from outside the United States, your information will be transferred to and processed in the United States.

20 Changes to this Policy

20.1

When we change this Policy, we publish the new version in the App with its version number and effective date.

20.2

For material changes, we email Customers at least 30 days before the change takes effect.

21 Contact us

Email: titus@saltandleafsystems.com

Mail:
Salt and Leaf Systems LLC
c/o Northwest Registered Agent LLC
7901 4th St N, Ste 300
St. Petersburg, FL 33702


Questions about this document: titus@saltandleafsystems.com

Terms of Service Privacy Policy Refund & Cancellation Policy

Salt & Leaf

Salt and Leaf Systems LLC builds prepackaged, custom AI automation, called Flows, for busy professionals, starting with real estate.

Contact

titus@saltandleafsystems.com

Billing questions: email us within 60 days of the charge.

Legal

  • Terms of Service
  • Privacy Policy
  • Refund & Cancellation Policy

Clients

  • Client download

© 2026 Salt and Leaf Systems LLC.