Skip to content

Cribfolio Privacy Policy

Effective Date: May 27, 2026 Last Updated: September 2, 2026 Version: 1.5

Summary of v1.5 update: Three corrections, all of them making this Policy match what the code actually does. (1) It now names the controller: Cribfolio is a trade name, and the company is Monkeyhead, LLC. (2) Section 6.1 now discloses every third party our website actually talks to — Google Analytics, the TikTok advertising pixel, Stripe, the QR-code renderer, and, in a new Section 6.1a, the hosting, font and library services that necessarily see your IP address. Section 5 explains what the advertising pixel means under state privacy law and how to opt out. (3) The Global Privacy Control commitment in Section 15 is now enforced in code before any tag loads, rather than stated here alone.

Summary of v1.4 update: Privacy requests now route to a dedicated monitored address — privacy@cribfolio.com — separate from product support. This makes CCPA / CPRA / state-privacy-law requests easier to process within statutory deadlines.

Summary of v1.3 update: Added Section 4.8 — explicit non-collection of sensitive personal information under CPRA and similar state laws. Added Section 9.5 — explicit third-party AI service disclosure (Apple Guideline 5.1.2(i)) documenting what is sent to Anthropic Claude, what is never sent, and the one-time in-app consent flow.



1. Introduction

This Privacy Policy ("Policy") explains how Monkeyhead, LLC, a limited liability company doing business as Cribfolio ("Cribfolio," "we," "our," or "us"), collects, uses, shares, retains, and protects personal information when you access or use our mobile applications, websites, application programming interfaces, and related services (collectively, the "Services"). Monkeyhead, LLC is the controller of that personal information.

By creating an account, signing in, or otherwise using the Services, you acknowledge that you have read and understood this Policy. If you do not agree with our practices as described here, please do not use the Services.

We have written this Policy in plain language wherever possible. If any section is unclear to you, please contact us before you rely on the Services — your understanding matters to us.

2. Who We Are

Cribfolio is a product of Monkeyhead, LLC, and is a personal property-intelligence application that helps owners of residential real estate track properties, estimate rental pricing, organize maintenance and financial information, and plan upgrades. We operate primarily as a consumer mobile application available through the Apple App Store and Google Play, and as a set of supporting cloud services.

The legal entity responsible for the Services, and the party to contact about them, is Monkeyhead, LLC (d/b/a Cribfolio), 1321 Sartori Ave, Suite A, Torrance, CA 90501, USA.

Contact information for all privacy matters is listed in the Contact Us section at the end of this Policy.

3. Scope of This Policy

This Policy applies to personal information we collect through the Services. It does not apply to information collected by third parties, such as partner businesses, service vendors, or other landlords or property owners you may interact with through our referral features. When we link to or integrate with third-party services, those services operate under their own privacy policies and we encourage you to review them separately.

4. Information We Collect

We collect only the information we genuinely need to provide and improve the Services. We have grouped the categories below to align with the personal information classifications recognized under the CCPA/CPRA so that you can match each category to the rights you hold under applicable law.

4.1 Identifiers

4.2 Customer records

4.3 Property-related information you enter or import

You control what property information you enter. If you do not enter a figure, we do not have it. If you do enter it, we store it so we can display it back to you across sessions and devices.

4.4 Usage information

4.5 AI-interaction information

4.6 Pricing feedback information (data moat)

If you consent via the data-sharing toggle in your signup flow or in Settings, we collect paired snapshots of the pricing recommendations we display to you alongside the actual rental rates you ultimately set. These snapshots include property characteristics, comp source, amenity configuration, and algorithm version at the time of recommendation. This information trains our pricing model to make more accurate recommendations for every user over time. It is linked to your account identifier so that we can honor deletion requests. You may withdraw this consent at any time from Settings, after which no further snapshots are collected.

4.7 Information we do NOT collect

To be explicit about what we avoid:

4.8 Sensitive personal information (CPRA-defined categories)

Under the California Privacy Rights Act (CPRA) and similar state laws, "sensitive personal information" includes categories such as government identifiers, account log-in credentials in combination with passwords, precise geolocation, racial or ethnic origin, religious or philosophical beliefs, union membership, contents of mail / email / text messages where Cribfolio is not the intended recipient, genetic data, biometric identifiers processed for identification purposes, health information, and information about sex life or sexual orientation.

Cribfolio does not knowingly collect or process any category of sensitive personal information as defined above, with three narrow operational exceptions: (a) account passwords, which are processed only via our authentication provider's one-way hashing as described in Section 4.2 and are never visible to us in plaintext; (b) any sensitive information you voluntarily type into the AI assistant or display on a photo you choose to scan, which is processed solely to fulfill your request and is governed by Sections 9.5 and 4.5 of this Policy; and (c) documents you choose to store in the Document Vault — mortgage statements, insurance policies, closing paperwork and the like — which routinely contain government identifiers and financial account numbers. We do not read, index, or train on Vault documents. Our AI assistant is built to refuse to repeat a government identifier or a financial account number back to you even when one appears in a document you uploaded, and it redacts such values from anything it does say. You choose what goes into the Vault, and you can delete any document at any time. We do not use sensitive personal information for purposes beyond providing the Services you requested, and we do not sell or share it.

5. How We Use Your Information

We use the information we collect for the following purposes:

We do not sell your personal information for monetary consideration, and we do not display third-party advertising inside the Cribfolio app.

Our website is different from our app, and you should know exactly how. The Cribfolio website carries a Google Analytics tag, and our public home page additionally carries a TikTok advertising pixel. These set first-party cookies and let us measure which campaigns bring people to the site. Under the CCPA/CPRA and similar state laws, an advertising pixel of this kind may constitute "sharing" personal information for cross-context behavioral advertising. Neither tag runs inside the Cribfolio mobile app. Section 6.1 lists exactly where each one appears.

How to opt out. If your browser sends the Global Privacy Control signal, we treat it as an opt-out and neither tag loads — this is enforced in code before either tag is requested, not merely promised here. You may also block these tags with any standard browser or extension setting.

6. How We Share Your Information

We share personal information only in the limited circumstances described below.

6.1 Service providers (processors)

We contract with the following vendors to provide parts of the Services. Each is bound by a written agreement requiring them to process your information only on our instructions and to maintain security controls appropriate to the data.

6.1a Infrastructure that necessarily sees your IP address

Loading any web page reveals your IP address and browser details to whoever serves the files. On our website that includes Vercel (hosting), Google Fonts and jsDelivr (typefaces and shared libraries). These receive no account information from us — only what any web request necessarily carries. We list them because "we do not share your data" should not quietly exclude the parties your browser is required to talk to in order to render our pages.

6.2 Data sources we query about your property

The following third-party services provide data we use to produce comp analyses and location signals. To return results for your specific home, we send the property’s address — and, for walkability and transit scores, its map coordinates — along with non-identifying details such as bedroom and bathroom counts, square footage, and property type. We do not transmit your name, email address, or account identifier to these sources, and none of them is told whose home the address is.

6.3 Compelled or legal disclosures

We may disclose your information if we believe in good faith that disclosure is required to comply with a subpoena, court order, or other legal obligation; to protect the safety of any person; to enforce our Terms of Service; to investigate fraud, security, or technical issues; or in connection with a merger, acquisition, or asset sale provided that any successor is bound by terms at least as protective of your information.

6.4 Anonymous aggregate data

We may publish or share statistical reports that do not identify any individual user — for example, median rental rates by market, common upgrade patterns, or subscription conversion rates. These reports do not contain your personal information.

6.5 If a real-estate agent, loan officer, or brokerage gave you Cribfolio

Some people receive Cribfolio from a real-estate agent, loan officer, or brokerage who pays for a co-branded version of the app. If that is how you joined, their name, photo, and contact details appear inside your app, and a limited, defined set of information is available to them. This section describes all of it.

What they can see

What they never see

Your rooms, room ratings, photos, documents, receipts, items, appliances, warranties, serial numbers, stored passwords, utility bills, insurance policies, mortgage details, your home’s estimated value, the questions you ask our AI assistant, which screens you open, how long you spend in them, or any record of what you looked at inside the app. The one exception is the brief-open date described above, and only while you have chosen to share it. Beyond that we do not collect per-client usage analytics for partners and we do not provide them.

Turning off sharing does not remove the app, your data, or a membership you were given. If you would prefer to have no partner attached to your account at all, contact us using the details at the end of this policy and we will help you remove it.

6.6 What we do not do

We do not sell your personal information for monetary consideration. We do not display targeted advertising inside the Services. We do not rent your email address to marketing partners. We do not share your property address with referral partners (referrals are triggered by non-identifying signals such as zip code + property type). We do not tell a real-estate or lending partner which screens you open, what you read, or how long you spend in the app; apart from the consent-gated brief-open date in 6.5, we do not provide partners with any usage analytics about you.

7. Third-Party Links and Referral Partners

The Services may display referral cards or links to third-party home services, insurance providers, contractors, and retailers. When you tap one of these links, you leave the Cribfolio Services and the third party's own privacy policy applies. We may receive a commission if you make a purchase from a referred partner. Our receipt of a commission does not influence the safety or objectivity of recommendations; we surface partners based on the actual condition and characteristics of your property.

8. Legal Bases for Processing

For users located in jurisdictions that require us to state a legal basis for processing personal information (such as the United Kingdom or European Economic Area, if we accept users from those regions), our legal bases are:

9. AI and Automated Decision-Making

Parts of the Services use automated systems to produce estimates, recommendations, and other outputs. We want you to know when this is happening and how to respond.

No automated system used by the Services produces decisions that have legal or similarly significant effects on you without human review. You retain full control over every decision you make based on our outputs.

If you prefer not to receive AI-generated outputs, you can avoid those features. Disabling AI features does not limit your ability to use the non-AI parts of the Services.

9.5 Third-Party AI Service Disclosure

Some AI features in Cribfolio are powered by Anthropic's Claude, a third-party AI service. This section explains exactly what is sent, what is never sent, and how to control it.

Before any data is sent to Anthropic, Cribfolio displays an in-app consent screen the first time you attempt to use an AI feature. The consent screen identifies the third party (Anthropic), summarizes what data will be transmitted, and requires you to tap "I Agree" before any AI call is made. Tapping "Not Now" blocks AI features until you turn them on later from Settings → AI & Privacy. You are asked only once — after you grant consent, AI features work normally without any further prompts. This consent flow is governed by Apple App Store Guideline 5.1.2(i) and is in addition to this Policy.

What is sent to Anthropic when you use an AI feature:

What is never sent to Anthropic — your personal information stays private:

The only nuance: if you choose to scan a document or photo that visibly contains a name, address, or other identifier (for example, scanning a utility bill that has the billing address printed on it), that image content reaches Anthropic's vision model because that is the content you submitted. We do not separately add or augment identifiers — what you see in the photo is what is sent.

Anthropic's treatment of submitted data:

Your controls:

If we add additional AI vendors or change what categories of data we send, we will require you to grant fresh consent through a new in-app prompt before the change takes effect for your account.

10. Your Privacy Rights

Depending on where you live, you may have the following rights with respect to personal information we hold about you. Regardless of your jurisdiction, we offer the core rights of access, correction, and deletion to all users.

10.1 Rights we offer all users

10.2 California residents (CCPA/CPRA)

In addition to the rights above, California residents have:

10.3 Colorado, Connecticut, Virginia, Utah, Texas, Florida residents

You have rights similar to those described for California residents, including the right to access, correct, delete, and obtain a portable copy of your personal information. You also have the right to opt out of targeted advertising, though we do not engage in targeted advertising within the Services. Where applicable, you have the right to appeal a refusal of a privacy request.

10.4 How to exercise your rights

To exercise any of the rights above, contact us using the information in Section 18 (Contact Us). We will respond within the timeframes required by the applicable law (generally 45 days in the United States; 30 days for some EU/UK requests), with one extension period available for complex requests.

We will verify your identity before responding to a request. For sensitive requests such as deletion, we may require you to sign in to the Services or confirm via an email link to prevent unauthorized requests.

Account deletion is also available to you directly within the Services from the Settings menu. In-app deletion triggers the same deletion workflow as a written request and is usually faster.

11. Children's Privacy

The Services are intended only for users aged eighteen (18) and older. We do not knowingly collect personal information from anyone under the age of 18. If we learn that we have collected personal information from a minor, we will promptly delete it. If you believe a minor has provided us with personal information, please contact us using the information in Section 18 and we will take prompt action.

12. Data Security

We use technical and organizational measures designed to protect your information against unauthorized access, loss, misuse, or alteration. These include:

No security system is perfect. In the event of a data incident affecting your personal information, we will notify you and applicable authorities as required by law.

13. Data Retention

We retain personal information only for as long as necessary to provide the Services and to fulfill the purposes described in this Policy.

14. International Data Transfers

We store and process personal information in the United States. If you are accessing the Services from outside the United States, please be aware that your information may be transferred to, stored in, and processed in the United States, where data-protection laws may differ from those in your country. By using the Services, you consent to such transfer. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses.

15. Cookies, Tracking Technologies, and Do Not Track

Our mobile application does not use web cookies in the traditional sense but does use similar local storage mechanisms (such as persistent tokens for keeping you signed in and cached property data for offline-first rendering). These are strictly necessary for the app to function.

Our website uses essential cookies, plus the analytics and advertising cookies set by the two tags named in Section 6.1. Neither is present in the mobile app. The analytics tag runs across cribfolio.com; the advertising pixel runs on the public home page only.

We honor the Global Privacy Control (GPC) signal as a valid opt-out. This is enforced in code: a small script runs before any tag on every page, and when it sees GPC it withholds both the analytics tag and the advertising pixel entirely rather than merely limiting them. If that script fails to load for any reason, the tags are withheld as well — the safe direction is not tracking you. We do not respond to traditional Do Not Track headers, because no consistent industry standard has emerged.

Third parties collecting information across sites. Yes — on our website only. The Google Analytics tag and, on our public home page, the TikTok advertising pixel are operated by those companies, and they may collect personally identifiable information about your online activities over time and across different websites when you use our site. Neither runs inside the Cribfolio mobile app. Withholding the Global Privacy Control signal, or blocking those domains in your browser, stops both. We do not permit any other third party to collect information about you across sites, and we do not allow third parties to collect information about your activity in the mobile app at all.

15a. Nevada Residents — Designated Request Address

Nevada law (NRS 603A.340) lets a Nevada consumer direct a website operator not to sell certain covered information. We do not sell covered information as Nevada defines it, and we have no plans to. Nevada also requires every website operator to designate an address where a request may be submitted, regardless of whether it sells anything. Ours is privacy@cribfolio.com. We will acknowledge a verified request within 60 days, as the statute requires, and we will tell you plainly that there was nothing to stop.

16. Changes to This Policy

We may update this Policy from time to time. When we make material changes, we will notify you by an in-app notice, by email to the address on file, or by posting the updated Policy with a new "Last Updated" date and a summary of the most significant changes. Where required by law, we will seek your renewed consent before applying a material change to your data.

Minor, non-material changes (such as formatting, typo fixes, or expansion of a list of examples) may be made without notice. We encourage you to review this Policy periodically.

17. No Rights to Third Parties

This Policy does not create any rights for any person other than you as a user of the Services. No other individual or entity may enforce any term of this Policy.

18. Contact Us

For questions about this Policy, to exercise any privacy right, or to report a concern:

We aim to respond to every privacy inquiry within five (5) business days and to resolve every request within the timeframes required by applicable law.


End of Privacy Policy — v1.5 — 2026-05-27