Privacy
Privacy Policy
What Brokee collects to run the desk, what stays under your brokerage’s control, and the limits on our privacy commitments.
Last updated October 4, 2026
Who this policy covers
This Privacy Policy describes how KodexApps, a division of Kinetx ("KodexApps," "we," "us," and "our"), handles personal information when you use Brokee, the website at https://brokee.co, the desk application, Brok AI, and related services (together, the "Service"). KodexApps operates Brokee. More about the company is at kodexapps.com.
The Terms and Conditions govern your use of the Service. If this Policy and the Terms conflict on liability, disclaimers, or dispute resolution, the Terms control. This Policy is a notice. It is not a warranty that unauthorized access, loss, or misuse will never occur.
If you use Brokee on behalf of a brokerage or other organization, that organization is the customer ("Customer"). People whose information a Customer stores in Brokee — including clients, leads, and other parties — are not our direct customers. Their relationship is with the Customer.
Our role and the Customer’s role
Account and billing information. For account, security, billing, and site-operation data, Brokee decides why and how that information is used.
Customer Content. Contacts, leads, listings, transactions, dates, notes, messages, files, campaign content, and other records a Customer or its users submit ("Customer Content") are processed on the Customer’s instructions so we can provide the Service. The Customer is responsible for having a lawful basis to collect and use that information, for notices to those people, and for honoring their requests. We do not control the Customer’s real-estate practice.
A request about a client, lead, or other person in a workspace should be sent to the brokerage first. We will assist the Customer as needed to meet a legal duty, and we may decline a request that conflicts with the Customer’s instructions or the law.
Information we collect
Depending on how you use the Service, we collect:
- Account data. Name, email address, password (stored in a hashed form), organization membership, role, profile image if you add one, and invitations you send or receive.
- Workspace data. Brokerage name, seats, contacts, leads, listings, transactions, parties, critical dates, tasks, notes, communication logs, campaign enrollments, consent records, documents, and files you upload or connect.
- Brok AI data. Prompts, instructions you ask Brok to remember, tool actions, images you submit, voice audio, transcripts, and usage needed to run and bill the assistant.
- Messages. Text messages sent through a KIT number, and mailbox content if you connect Gmail or Microsoft mail. Message content is processed to deliver, log, and show it in the workspace.
- Billing data. Subscription status, seat count, prepaid AI balance, invoices, and billing address. Card numbers are collected by Stripe, not stored by Brokee.
- Device and log data. IP address, user agent, and similar session data; approximate location derived to suggest an MLS market; and operational logs used to secure and debug the Service.
- Preferences on your device. Theme and accessibility settings stored in this browser. They are not used to identify you across sites.
We do not require you to submit government identifiers, health records, or payment card numbers into the desk. Do not put those into notes, prompts, or files unless you have a lawful reason and accept the risk of storing them in a business system.
How we use information
We use personal information to:
- Provide, maintain, secure, and support the Service, including authentication, workspaces, and the features you turn on.
- Run Brok AI, calculate dates from the rules in a transaction, send messages you initiate, and import data from services you connect.
- Bill seats and prepaid usage, prevent fraud, and collect amounts due.
- Send service messages, such as invitations, password resets, billing notices, and security alerts. These are part of the Service, not optional marketing.
- Investigate abuse, enforce the Terms, and comply with law, legal process, and valid requests from public authorities.
- Understand aggregate reliability and cost, including de-identified or aggregated statistics that do not identify a person.
We do not sell personal information. We do not share personal information for cross-context behavioral advertising. We do not use Customer Content to market third-party products to the people in your contacts.
Brok AI and voice
When you use Brok, the prompt and the workspace context needed to answer it — which can include contact, listing, transaction, and document details — are sent to a model provider (currently OpenAI or Anthropic, depending on the model) to generate a response. Voice is processed through OpenAI’s realtime voice service. Audio and a transcript may be retained with the workspace so the desk has a record of the request and the change.
Model providers process that content under their API terms to provide the response. We do not authorize those providers to use Customer Content to train their general models. Provider terms can change. Do not submit information you are not allowed to share with a processor, and do not treat a model’s output as verified fact.
Outputs can be wrong, incomplete, or out of date. Review every change before you rely on it. The limits in the Terms, including the disclaimers and the cap on liability, apply to Brok.
Customer Content and your instructions
You instruct us to host, display, back up, transmit, and otherwise process Customer Content to provide the features you use, including search, import, critical dates, campaigns, e-sign, and Brok actions you confirm. That instruction is the basis on which we handle Customer Content.
You represent that you have provided any notice, and obtained any consent, the law requires before you upload a person’s information or message them. You will not upload information you do not have rights to process. We may remove Customer Content, or suspend access, if we believe it violates the Terms or the law. We have no duty to monitor Customer Content.
Email, calls, and texts
Campaigns and one-to-one messages are sent because a user of the Customer asked for them. The Customer must have the consent required by the Telephone Consumer Protection Act, the CAN-SPAM Act, state telemarketing and texting laws, and carrier rules before a text or marketing email goes out. Brokee records consent status you enter. We do not independently verify that a recipient agreed to be contacted.
You are solely responsible for message content, quiet hours, honor of opt-outs, and the legal basis for each send. If a recipient opts out, you must stop. We may block sending that we believe is unlawful or abusive. Liability for a message a user sends sits with the Customer, as stated in the Terms.
Payments
Subscriptions and prepaid balances are billed by Stripe. Stripe collects payment card details under its own privacy notice and PCI obligations. We receive limited billing details, such as customer id, subscription status, last four digits where Stripe provides them, invoices, and the billing address you submit. We use that information to charge the plan, apply tax where we must, and keep accounting records.
How long we keep information
We keep account and Customer Content for as long as the workspace is active and you have not deleted it. After you close a workspace or we terminate it, we delete or de-identify Customer Content within a reasonable period, except for copies we must keep for security, dispute, tax, or legal reasons, and residual copies in backups that expire on a rolling cycle.
Billing and tax records are kept for the period the law requires, often several years. Security logs are kept for a shorter operational period. Session records expire when the session ends or is revoked. Accessibility and theme settings stay in your browser until you clear them.
We do not promise that a deletion is instantaneous across every backup. After the retention window, we have no duty to recover deleted content.
Security
We use administrative, technical, and organizational measures appropriate to a business software service, including access control by workspace and role, hashed passwords, and transport encryption. No method of transmission or storage is perfectly secure. We do not guarantee that the Service will be uninterrupted, that unauthorized access will never happen, or that a particular control meets a certification you did not receive in a signed writing.
You are responsible for your password, the people you invite, the devices you use, and the integrations you connect. Tell us promptly at privacy@brokee.co if you believe an account was compromised. Our notification of a security incident, if any is required, will follow applicable law and will not, by itself, admit liability.
International processing
We operate the Service from the United States. Service providers may process information in the United States and other countries where they operate. Those countries may not provide the same privacy protections as your home country. By using the Service, you understand that your information will be processed in the United States. Where a transfer mechanism is required and available, we use it. We do not represent that the Service is established in the EU, the UK, or any other specific country.
Your choices and rights
Subject to verification and to exceptions in the law, you may:
- Access and update your profile in Settings.
- Ask us to correct account information, or delete your account, by emailing privacy@brokee.co.
- Export or delete workspace records with the tools in the product, or ask the workspace owner to do it.
- Opt out of promotional email if we ever send it. Service and billing messages will continue while you have an account.
- Clear cookies and site data in your browser to remove the session, theme, and accessibility settings on that device.
We may deny or limit a request when we cannot verify you, when the request is excessive or unfounded, when disclosure would reveal another person’s information or a trade secret, when we must keep the information for legal, security, or billing reasons, or when the Customer, not Brokee, controls the record. We will not discriminate against you for making a lawful privacy request. We may charge a fee where the law allows.
If you are an authorized agent, we may require proof of authority and verification of the person. Appeals of a denied request may be sent to privacy@brokee.co with the subject line "Privacy appeal."
US state privacy notices
Residents of California, Colorado, Connecticut, Virginia, Utah, Texas, Oregon, and other states with consumer privacy laws may have rights to know, access, correct, delete, and obtain a copy of certain personal information, and to appeal a denial. California residents may also designate an authorized agent.
Brokee does not sell personal information and does not share it for cross-context behavioral advertising, as those terms are used in the California Consumer Privacy Act. We do not knowingly process sensitive personal information for the purpose of inferring characteristics. Categories we collect and the purposes for using them are listed above in "Information we collect" and "How we use information." We retain each category as described in "How long we keep information."
To exercise a state right, email privacy@brokee.co. We will respond within the time the applicable law requires.
Children
The Service is for brokerage businesses and their adult users. It is not directed to anyone under 18, and we do not knowingly collect personal information from children under 13. If you believe a child has given us personal information, email privacy@brokee.co and we will delete it, subject to any legal hold.
Changes to this policy
We may update this Policy as the Service, the law, or our practices change. We will post the new Policy and change the "Last updated" date. If we make a material change to how we use personal information we already hold, we will provide a more prominent notice, such as an email to the account address, where we still have one. Continued use after the effective date is acceptance of the updated Policy, to the extent the law allows. If you do not agree, stop using the Service and close the account.
Contact
Privacy questions and requests: privacy@brokee.co. Other legal notices: legal@brokee.co.
This Policy does not create a fiduciary duty, a special relationship, or any warranty beyond what the Terms expressly state. Disputes about privacy are resolved under the Terms, including the limitation of liability and the dispute-resolution section.
Related: Privacy Policy · Terms and Conditions · Accessibility