Privacy Policy
mtge.ai provides a mortgage intelligence platform that monitors agency, investor, regulatory, and internal policy sources and returns source-backed answers to lender teams. This policy explains what we collect, how we use it, and the choices you have.
1. Information we collect
We collect information in three ways: what you give us, what our platform records as you use it, and what your organization loads into it.
- Account information: name, work email, role, company, and authentication details (or SSO identifiers supplied by your identity provider).
- Customer Content: internal policies, overlays, product matrices, and other documents your organization uploads so mtge.ai can answer against them, plus the questions your users ask.
- Usage data: pages viewed, queries run, answers opened, citations followed, device and browser type, IP address, and timestamps.
- Demo and sales inquiries: the details you submit on our Request a demo form.
2. How we use information
We use information to operate the service and keep it trustworthy.
- Retrieve, cite, and deliver answers from monitored sources and your Customer Content.
- Generate change alerts, effective-date tracking, and the audit trail your compliance team relies on.
- Authenticate users, enforce role-based permissions, and detect abuse or security incidents.
- Improve retrieval quality, source coverage, and product usability using aggregated, de-identified usage patterns.
- Communicate with you about your account, security notices, and, where permitted, product updates.
3. Customer Content and AI models
Customer Content belongs to your organization. We do not use Customer Content, or the questions your users ask, to train foundation models, and we do not share it with third-party model providers for their own training or improvement. Where a third-party model processes a request, it does so under contractual terms that prohibit retention for training.
Consumer loan-file data is not required for mtge.ai to function. If your organization chooses to include borrower information in a scenario, that information is processed solely on your instructions as a service provider and subject to our customer agreement, including any GLBA safeguards obligations.
4. How we share information
We do not sell personal information. We share it only with:
- Sub-processors that host, secure, or support the service (cloud infrastructure, email delivery, error monitoring), each bound by data-processing terms.
- Your organization: administrators can view usage and audit records for users in their workspace.
- Authorities or third parties when required by law, or to protect the rights, safety, or property of mtge.ai, our customers, or the public.
- A successor entity in a merger, acquisition, or asset sale, with notice to you.
5. Retention
Account and usage data are retained for the life of your subscription and for a limited period afterward to meet legal and contractual obligations. Audit-trail records are append-only by design and are retained for the period specified in your agreement (default seven years) because they exist to prove what guidance was in force at a given time. Customer Content is deleted or returned within 60 days of termination on request.
6. Your rights and choices
Depending on where you live, you may have rights to access, correct, delete, or port your personal information, or to object to certain processing. Because mtge.ai is deployed by your employer, we may direct requests to your organization's administrator. You can opt out of marketing email at any time using the link in any message.
7. Security
We protect information with encryption in transit and at rest, role-based access control, tenant isolation, and continuous monitoring. Our Security page describes these controls in detail.
8. International transfers and children
mtge.ai is operated from the United States. If you access the service from elsewhere, your information is transferred to and processed in the United States under appropriate safeguards. The service is intended for business users and is not directed to children under 16.
9. Changes to this policy
We will post any material changes here and notify workspace administrators before they take effect.