Keyhold Homes
Privacy
Last updated September 26, 2026.
What we collect
Viewing inquiries.
When you request a viewing we receive what you put in the form: your name, email address, phone number, preferred move-in month, number of occupants, and your message. It is stored in the property's rental portfolio so that its landlords can respond; notifications go to owners who belong to that portfolio.
Landlord accounts.
When you sign up as a landlord, we collect your name, email address, phone number and organization name to create your account and rental portfolio and, when email delivery is available, to send your account setup email. We also store the property, tenancy, rent, repair, message and document information added to that portfolio to support its rental management. Landlords can access private records in portfolios they belong to, not another landlord's private records simply because that landlord also uses Keyhold.
Tenant accounts.
For invited tenants, account records include contact details, leases, rent records and receipts, repair requests, messages with their landlord, and documents shared either way. If you give us a guarantor, we hold their name and contact details too.
Published listings.
When a landlord publishes a listing, visitors can see the property's address, description and photos. Listing pages also show rent and availability.
Repair drafting help.
If you use drafting help while reporting a repair, the repair details you enter are sent to one of the artificial intelligence providers named under Where your information lives. It returns a suggested title, category, priority, and description. The draft does not create or send a repair request. You review it and choose whether to use it, and you can complete the form without drafting help.
Rental pre-qualification references.
Before an account is created, an owner may invite an applicant to confirm their name, email and phone number and to share one or two parent or guarantor references. The applicant confirms they have permission to share each contact. Each reference receives a separate private link and confirms their own contact details, residential address and permission for us to use those details for the rental reference and, if the application is approved, onboarding. They may also answer a short set of reference questions, add an optional note and acknowledge that a separate Guarantee Agreement would follow if the application proceeds. The answers and acknowledgment are shared with owners in the same Keyhold portfolio, including by email, solely to support each owner's own reference decision. An owner may contact the reference. We do not use this process for automatic decisions or scoring.
Optional identity verification.
An applicant may be asked, through their private link, to use Plaid's hosted identity verification to compare a government-issued photo ID with a selfie. The choice is optional and can be declined without ending the application. Plaid processes the ID and selfie images and the identity details it extracts from them under its own privacy policy. Keyhold keeps the consent choice, Plaid's verification reference and status, and when the verification was completed. Keyhold does not keep the ID or selfie images, the extracted identity details, or the full document number. Identity checks recorded in person before this change keep only the type of ID, the last four characters if they were entered, whether the name matched, who checked it, and when; Keyhold holds no copy of the document, and these records follow the same 12-month deletion. The owner uses the result as one part of their review. A missing or negative result does not automatically decide an application. Consent can be withdrawn through the same private link while it remains valid. Withdrawing consent stops identity verification that is still unfinished. Keyhold deletes identity verification consent and result records 12 months after the application decision. An active privacy complaint or legal hold pauses that deletion until the matter is resolved.
Signing in and notifications.
We keep what your sign-in needs: your password (stored only as a hash, never readable), any passkeys you register, and, if you use Google to sign in, the Google email linked to your account. We also keep your notification preferences and, if you turn on push notifications, the browser subscription that delivers them.
The mobile app.
Our iPhone app signs in to the same account and shows the same records as the portal; it collects nothing beyond what this page already describes, with two additions. If you turn on notifications, Apple issues the device a delivery token and the app stores it with a random installation identifier so we can send your notifications and stop sending them when you sign out. And Apple can share anonymous crash and performance reports about the app with us; before anything is kept, the app strips every name, path, and free-form text from those reports, so they describe the app's behaviour, never yours.
Signing records.
When a lease or notice is signed through the portal, we keep the drawn signature along with the time, network address, and browser it was signed from. That record is what makes the signed document dependable, so it stays with the document.
Rent paid by e-transfer.
When rent arrives by Interac e-transfer, the bank's notification email lands in the owners' own mailbox. An owner can connect that mailbox through Google OAuth or with an IMAP app password. Google grants the gmail.readonly permission. For IMAP, Keyhold encrypts the app password before storing it. Keyhold reads matching messages from the Inbox and Archive folders, starting with no more than 24 months of history. Those messages can include the sender's name and amount or a guarantor's reply. This applies only to an owner's mailbox, never a tenant's mailbox. An IMAP connection never sends, changes, or deletes mail. A Google connection sends or manages inquiry filters only after the owner grants separate Gmail permissions. Keyhold never deletes mail.
Server logs.
Like almost every website, our server keeps routine technical logs (network address, page requested, time). We use them only to keep the site working and secure.
What we don't do
- No advertising and no analytics trackers, from us or anyone else.
- We never sell your information. Resend, Cloudflare and MapTiler may use it only to do their work for us. The same applies to what Keyhold's artificial intelligence features send to Anthropic's API, except that Anthropic keeps it for 30 days and may access it for safety and security purposes. In all other cases, each company handles your information under its own terms, as described under Where your information lives.
If an application is approved or withdrawn
If an owner approves an application, they may create a tenant account and carry the confirmed applicant and guarantor details into that account and tenancy record. A private summary is retained for the owners' file. If a request is not pursued, an owner can revoke the active request and its private links expire automatically. Identity verification consent and result records are deleted 12 months after the application decision. If there is an active privacy complaint or legal hold, those records are kept only until it is resolved and then return to that disposal schedule. Contact us using the details below if you want to ask about access, correction or deletion of information we hold.
Cookies
Keyhold uses a small number of first-party cookies. They support sign-in, account and portal functions, navigation, or appearance previews:
- kh_session keeps you signed in for up to 30 days. It holds your account id, role, and name, signed so it cannot be altered.
- kh_oauth lives for up to 10 minutes while a Google sign-in completes.
- kh_chal lives for up to 5 minutes while a passkey is registered or used.
- kh_gmail_oauth lives for up to 10 minutes while an owner connects a deposit mailbox (owners only; it is never set for tenants or visitors).
- kh-theme remembers your light or dark appearance choice for up to one year.
- kh-landing-skin is set only when you use the public-site appearance switch and remembers that choice. The home page, Homes list, individual home listings, and The family record pages read it. Support, Privacy, Terms, and sign-in pages do not read it: they stay light on larger screens. On smaller screens, the device appearance takes priority.
- kh-nav-rail remembers whether the side menu is open or closed on larger screens for up to one year.
- kh-pv-* is set while you preview appearance options and keeps those choices for up to one year.
kh-theme, kh-landing-skin, kh-nav-rail, and kh-pv-* are readable by page scripts so appearance and navigation can update immediately. The other four are not readable by page scripts, and none records what you browse.
Where your information lives
Your records live on a single private server we rent from Hetzner and run ourselves in a data centre in Ashburn, Virginia, in the United States. Encrypted backup copies of the database and uploaded documents are kept with Cloudflare, an American cloud provider: a continuously updated copy we can restore from covering the last three days, and nightly snapshots kept for about two months. Because Canadian tax law requires business records to be kept in Canada, we also refresh a weekly copy of those records onto our own machine at our home office in Ontario. The backups and that copy contain the same records as the server, so everything on this page about what we hold applies to them too. Records removed from the server age out of the backups, and because each weekly refresh mirrors the most recent nightly snapshot, a removed record leaves the Ontario copy at the first refresh after a snapshot has recorded the removal, about a week at the longest. A working copy of the database, which we use to build and test Keyhold, is also kept on a computer at the same home office. We refresh it by hand, not on a schedule, so a record removed from the server stays in it until our next refresh. We remain responsible for your information in all of those copies.
A few things also pass through outside providers, and we send each one only what its job needs: if you sign in with Google, Google handles that sign-in and confirms your email to us; if an owner connects a rental inbox, Google or the owner's email provider handles that mailbox sign-in; if an owner connects a bank account, Plaid shares that account's transactions with us so we can tell which rent has been paid; push notifications travel through your browser's push service as an encrypted payload; email notifications pass through Resend. Text message notifications are currently disabled. When you use address suggestions, the address text you type is sent to Google Maps to suggest Canadian addresses. Names, email addresses, and other form fields are not sent with it. Google handles that information under its own Privacy Policy and Maps Platform Terms.
The map on the Homes list loads in your browser from MapTiler. Some tasks use artificial intelligence from Anthropic or OpenAI: drafting help, sorting and summarizing inquiries and messages, reading receipts and lease documents, and answering owners' questions. The text or file a task works on is sent to one of them, and the result comes back to Keyhold. When owners and tenants search, the words they type can also be sent to OpenAI to help find results. We also have a phone line for spoken updates on our work: artificial intelligence from OpenAI answers our questions using a status report that can include details about tenants, applicants and owners. The calls run through Twilio, which uses ElevenLabs to speak the answers and Google to turn what we say into text. OpenAI, ElevenLabs and Google handle that data under their own terms. Plaid and Twilio may use what they receive for their own purposes, such as developing and improving their products.
We also use artificial intelligence tools from Anthropic, OpenAI, Google and xAI to build, test and run Keyhold. While they work, these tools can read our work notes and the working copy of our database, which include details about tenants, applicants and owners. Notes from that work, which can include those details, are kept with cmem.ai, a memory service the tools share; cmem.ai does not use those notes to train artificial intelligence models. OpenAI and xAI may use what their tools read to improve their own artificial intelligence. Anthropic and Google handle what their tools read under their own terms. The limit on Anthropic under What we don't do applies to Keyhold's features, not to these tools. Plaid, Twilio and Resend handle your information in the United States, and so does Apple for the iPhone app. ElevenLabs uses servers in the United States, the Netherlands and Singapore. MapTiler is based in Switzerland and delivers the map through a worldwide network. Cloudflare keeps our backups in the United States or elsewhere outside Canada. Hetzner keeps the details of our account with it in Germany. Anthropic, OpenAI, Google, xAI and cmem.ai may also handle your information outside Canada. Wherever it is handled, it may be accessible to courts, law enforcement and national security authorities of that country.
How long we keep it
A viewing inquiry is stored in Keyhold, with in-app notifications for owners in the property's portfolio and email copies when email notifications are sent. The inquiry and the notifications are deleted together by a sweep the owners run every quarter, which removes anything more than nine months old, so nothing reaches twelve months after our last contact about the home. The email copies sit in the owners' own mailboxes and are cleared by hand on the same schedule.
Identity verification consent and result records are kept for 12 months after the application decision, then deleted during the quarterly review. Identity checks recorded in person before this change keep only the type of ID, the last four characters if they were entered, whether the name matched, who checked it, and when; Keyhold holds no copy of the document, and these records follow the same 12-month deletion. An active privacy complaint or legal hold pauses that deletion only until the matter is resolved.
Tenancy, rent, and signing records are kept for the tenancy and up to 7 years after it ends, then deleted; the same quarterly sweep reviews them, so in practice they go a little earlier. Push subscriptions last until you turn them off or they stop working. Server logs are capped at 90 days, and backups expire on the rotations described above. The full schedule, including how each kind of record is disposed of, is written down in our retention procedure and followed by the owners.
Disconnecting a rental inbox immediately erases its saved Google or IMAP credential from Keyhold. The owner should also revoke the connection or app password with the email provider. Keyhold keeps nonsecret connection details and the last sync position for up to 90 days so a verified reconnect can resume safely, then removes them.
Your choices
You can ask what we hold about you, how it has been used, and who it has been shared with. You can ask us to correct it or delete it, and we will unless the record is one the law requires us to keep. Write to us:
Keyhold Homes
If you are not satisfied with our answer, you can raise it with the Office of the Privacy Commissioner of Canada.
Changes
If how we handle information changes, this page changes with it, and the date at the top moves.