mtge.aiMortgage Intelligence
Privacy

Privacy Policy

Last updated September 1, 2026

mtge.ai provides a mortgage intelligence platform that monitors agency, investor, regulatory, and internal policy sources and returns source-backed answers to lender teams. This policy explains what we collect, how we use it, and the choices you have.

1. Information we collect

We collect information in three ways: what you give us, what our platform records as you use it, and what your organization loads into it.

  • Account information: name, work email, role, company, and authentication details (or SSO identifiers supplied by your identity provider).
  • Customer Content: internal policies, overlays, product matrices, and other documents your organization uploads so mtge.ai can answer against them, plus the questions your users ask.
  • Usage data: pages viewed, queries run, answers opened, citations followed, device and browser type, IP address, and timestamps.
  • Demo and sales inquiries: the details you submit on our Request a demo form.

2. How we use information

We use information to operate the service and keep it trustworthy.

  • Retrieve, cite, and deliver answers from monitored sources and your Customer Content.
  • Generate change alerts, effective-date tracking, and the audit trail your compliance team relies on.
  • Authenticate users, enforce role-based permissions, and detect abuse or security incidents.
  • Improve retrieval quality, source coverage, and product usability using aggregated, de-identified usage patterns.
  • Communicate with you about your account, security notices, and, where permitted, product updates.

3. Customer Content and AI models

Customer Content belongs to your organization. We do not use Customer Content, or the questions your users ask, to train foundation models, and we do not share it with third-party model providers for their own training or improvement. Where a third-party model processes a request, it does so under contractual terms that prohibit retention for training.

Consumer loan-file data is not required for mtge.ai to function. If your organization chooses to include borrower information in a scenario, that information is processed solely on your instructions as a service provider and subject to our customer agreement, including any GLBA safeguards obligations.

4. How we share information

We do not sell personal information. We share it only with:

  • Sub-processors that host, secure, or support the service (cloud infrastructure, email delivery, error monitoring), each bound by data-processing terms.
  • Your organization: administrators can view usage and audit records for users in their workspace.
  • Authorities or third parties when required by law, or to protect the rights, safety, or property of mtge.ai, our customers, or the public.
  • A successor entity in a merger, acquisition, or asset sale, with notice to you.

5. Retention

Account and usage data are retained for the life of your subscription and for a limited period afterward to meet legal and contractual obligations. Audit-trail records are append-only by design and are retained for the period specified in your agreement (default seven years) because they exist to prove what guidance was in force at a given time. Customer Content is deleted or returned within 60 days of termination on request.

6. Your rights and choices

Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. Because mtge.ai is deployed by your employer, we may direct requests to your organization's administrator. You can opt out of marketing email at any time using the link in any message.

7. Security

We protect information with encryption in transit and at rest, role-based access control, tenant isolation, and continuous monitoring. Our Security page describes these controls in detail.

8. International transfers and children

mtge.ai is operated from the United States. If you access the service from elsewhere, your information is transferred to and processed in the United States under appropriate safeguards. The service is intended for business users and is not directed to children under 16.

9. Changes to this policy

We will post any material changes here and notify workspace administrators before they take effect.