Skip to content
RelivoHelp
Esc
↑↓navigate↵open⌘Jpreview
On this page

Privacy policy

The Relivo privacy policy.

Effective: 13 October 2026
Last updated: 6 October 2026

Who we are

Relivo is a customer relationship manager for solo real estate agents, operated by SiteonWP LLC, a New Mexico limited liability company. In this policy, “Relivo”, “we” and “us” mean SiteonWP LLC. “You” means the agent who holds a Relivo account.

This policy covers the Relivo application at my.relivoapp.com, the Relivo phone app for iPhone and Android, the website at relivoapp.com, the property microsites Relivo publishes on your behalf, and the lead capture forms and tracking script you install on your own website.

Account Data and Customer Data

Relivo handles two different kinds of personal data, and our role is different for each. This distinction decides who is accountable for what.

Account Data is information about you, the agent: your name, email address, phone number, billing details and how you use the product. We decide how this is handled, so for Account Data we act as the controller.

Customer Data is information about your clients and leads: the contacts, notes, emails, tasks, deals and enquiries you store in Relivo. You decide what goes in and why. We only process it to run the service for you, so for Customer Data you are the controller and we are the processor acting on your instructions.

What this means in practice: if one of your clients asks to see or delete the data you hold about them, that request is yours to answer, not ours. We will help you carry it out, but we will not act on your clients’ data without your instruction, except where the law requires it.

What we collect

Information you give us

  • Account details: name, email address, and password. Passwords are stored hashed by our authentication provider, never in readable form.
  • Profile and business details: phone number, company name, licence details, default commission rate, signature, and branding you add for your property microsites.
  • Billing details: handled by Stripe. We receive your plan, subscription status and the last four digits of your card. We never see or store full card numbers.
  • Support messages: the content of support tickets you open, so we can answer them.

Customer Data you put in

  • Contacts and leads: names, email addresses, phone numbers, postal addresses, budget ranges, lead source, tags, stage and any notes you write.
  • Deals, listings and showings: property addresses, prices, commission figures, stages and dates.
  • Messages: the subject, body, sender and recipient of emails in a contact’s timeline, along with notes and any calls or texts you log by hand.
  • Enquiries: submissions from your lead capture forms, property microsite enquiry forms, and any inbound webhook you connect.
  • Voice notes: recordings you make in the phone app, their transcripts, and the updates you confirm from them. See “Voice notes in the phone app” below.
  • Photos and files: photos you add to a listing or a contact, and files you attach to an email.

Information we collect automatically

  • Usage and device data, in the web app: pages visited inside the app, browser type, approximate performance timings, and error reports when something breaks.
  • Log data: our hosting and security providers process IP addresses to serve requests, apply rate limits and block abuse. Our authentication provider records the IP address and the browser or app details of each signed-in session, to keep your account secure.
  • Phone app, device data: the phone’s name or model, its platform, the app version, when it was last used and a push notification token, so that we can show you which phones are signed in and send alerts to them. The app contains no analytics, advertising or crash reporting tools.
  • Phone app, camera, photos and files: the camera scans the sign-in code shown on your computer. That image is read on the phone and is not stored or sent to us. When you choose, the camera also takes photos for a listing, a contact or an email. Photos you take or choose, and files you attach, are uploaded only when you add them. Location data is removed from photos.
  • Phone app, phone contacts: when you add a contact from your phone’s contacts, the app reads only the person you pick: their name, a phone number and an email address. It does not read or upload the rest of your address book.

How we use it

We use personal data to provide and operate Relivo, and for nothing else. Specifically:

  • To run the product: store your records, rank your day on the Today screen, send and receive email on your behalf, and publish your property microsites.
  • To alert you to new leads and enquiries, client replies and task reminders, by email, by text message to your own phone, or by push notification in the phone app, as you choose in Settings.
  • To turn your voice notes into text and suggest the updates they describe, which change nothing until you confirm them. See “Voice notes in the phone app” below.
  • To take payment, manage your subscription, and tell you about billing events such as a trial ending.
  • To answer your support requests.
  • To keep the service secure and available: rate limiting, bot protection, error monitoring and fraud prevention.
  • To send you service messages about your account, and product news, tips and offers. See “Email we send you” section below.

What we never do

  • We do not sell personal data.
  • We do not share it with advertisers.
  • We do not use your Customer Data, your email content, or anything received from Google APIs to develop, improve or train generalised artificial intelligence or machine learning models. The one feature that uses AI models, voice notes in the phone app, is described in “Voice notes in the phone app” below.

Email we send you

There are two kinds, and you can control one of them.

Service email is part of running your account: password resets, billing receipts, trial reminders, new lead alerts, and notices about changes to this policy or our terms. You cannot opt out of these while your account is open, because they are how we tell you things you need to know.

Marketing email is our newsletter, product news, tips and offers. You get it in one of two ways. Either you asked for it, by ticking the box when you created your account, which is never ticked for you. Or you are a current customer or a recent trial user, where the law allows us to tell you about the product you are using or trying.

Either way your name and email address are on our mailing list, which is run by MailerLite, and every message carries an unsubscribe link. Unsubscribing takes effect immediately, applies whichever of the two routes brought you here, and does not affect your account or your service email. You can also ask us to remove you at any time by writing to support@relivoapp.com.

If you neither opted in nor have a current relationship with us, we do not send you marketing at all.

Your clients are never added to this list. MailerLite receives only your own name and email address as the account holder. It never receives your Customer Data.

Mailbox access

Relivo can connect to your mailbox so that client emails appear in the contact timeline. What we can access depends entirely on how you connect, and the differences are real. The connection itself is handled by Aurinko, a mailbox integration provider acting as our processor.

Gmail and Google Workspace, connected in one click: send only. Relivo requests permission to send mail as you. It does not request, receive or read the contents of your Gmail inbox. Replies stay in Gmail and are not logged in Relivo.

Outlook and Microsoft 365, connected in one click: read and send. Relivo syncs both directions, so mail you send outside the CRM also appears in the timeline.

IMAP and SMTP, any provider: read and send. The credentials you supply carry read access inherently, so Relivo syncs both directions.

Where Relivo does sync your mailbox, it reads messages in order to match them to the right contact and show them in that contact’s timeline. It does not scan your mail for advertising, profiling or model training. You can disconnect a mailbox at any time from Settings.

If you have not connected a mailbox, Relivo can still send on your behalf from a shared Relivo address and route replies back into the right thread.

Google API services

Relivo’s use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including its Limited Use requirements. That policy is published at https://developers.google.com/terms/api-services-user-data-policy

Concretely, for Google accounts Relivo requests permission to send mail only. It does not request read access to Gmail. Information received from Google APIs is used solely to send email you compose in Relivo, is never transferred to third parties except as needed to provide that feature or where required by law, is never used for advertising, and is never used to develop, improve or train generalised AI or ML models. No human reads this data except with your explicit consent, for security purposes, to comply with applicable law, or where the data has been aggregated and anonymised.

Voice notes in the phone app

The phone app can record a voice note. You talk, and Relivo saves your words as a note and suggests the updates they describe, such as a reminder, a stage change or new contact details. Nothing in your CRM changes until you review the summary and confirm it. This is Relivo’s only AI feature. The Today ranking is a fixed formula, not a model.

Before your first voice note, the app explains how it works and asks for your permission. Until you allow it, nothing is recorded or sent.

How it works:

  • The recording is uploaded to our private storage and sent through OpenRouter to a speech-to-text model, currently OpenAI’s. With it we send a short list of your contact names and listing streets, so that names are spelled correctly.
  • The transcript is then sent through OpenRouter to a language model, currently Google’s Gemini with Anthropic’s Claude as a fallback, together with today’s date, your time zone, your pipeline stage names and, when you record from a contact’s page, that contact’s name. It returns suggested updates, which our own code checks against your contacts, listings and stages before showing them to you.
  • The speech-to-text provider keeps nothing from the request and does not train on it. For the summary we use only model providers that keep nothing once they have answered and do not train on it. OpenRouter does not train on it either, and keeps it no longer than it needs to route the request, except where abuse detection, security, billing or the law require.
  • We keep the recording for 30 days, then delete it. The transcript stays as a note on the contact until you delete it or your account.

Record only your own dictation. Do not use voice notes to record conversations with other people. In some states, recording a conversation requires everyone’s consent.

Website visitor tracking

Relivo gives you an optional script to install on your own website. When a visitor browses a page carrying that script, Relivo records the visit so that if the visitor later fills in one of your forms, their earlier browsing can be attached to the new contact.

What is recorded: a randomly generated visitor identifier, the pages viewed, page titles, the referring URL, UTM campaign parameters, the browser user agent string, and timestamps.

Relivo does not store visitor IP addresses. An IP address is used momentarily to apply a rate limit and is then discarded. It is never written to the visitor, session or event records.

Because this script runs on your website and collects data about your visitors, you are the controller for it. You are responsible for disclosing it in your own website privacy notice and for collecting any consent your jurisdiction requires. The same applies to the lead capture forms you embed, each of which includes a consent checkbox.

Cookies and analytics

We use different tools on the app and on our marketing website, so we list them separately.

In the Relivo app at my.relivoapp.com, we use only what is necessary to run the product. There is no advertising or cross-site tracking.

  • Authentication cookies set by our authentication provider, to keep you signed in.
  • Short-lived flow cookies used while you connect a mailbox, to remember which provider you chose and where to return you afterwards.
  • A support session cookie, set only if a Relivo administrator accesses your account for support. See “Security and support access” below.
  • Bot protection from Cloudflare Turnstile on sign-up, sign-in and password reset, to block automated abuse.
  • Product analytics and performance measurement from Vercel, used in aggregate to understand which parts of the app are used and how fast pages load.

On our marketing website at relivoapp.com, we also use Google Analytics to understand how visitors find and move around the site, which pages are read, and which lead to a sign-up. Google Analytics sets its own cookies and processes information including your device type, browser, approximate location and the pages you view. We use this in aggregate, to improve the site. You can opt out across all sites using Google’s browser add-on at https://tools.google.com/dlpage/gaoptout

Most browsers let you block or delete cookies. Blocking the necessary cookies listed above will stop parts of the app from working, in particular staying signed in.

The phone app uses no cookies. It keeps your sign-in in the phone’s secure storage (the Keychain on iPhone, the Keystore on Android), and a copy of the screens you last loaded so that it opens without signal. Signing out removes both. Voice notes recorded without signal wait on the phone until they can be sent, and signing out deletes any that have not been sent. Photos and files you pick sit in the phone’s temporary storage while they upload.

Service providers

Relivo is built on a small number of providers. Each processes personal data only to provide its service to us, under contract. We do not add providers casually, and this list is kept current.

  • Supabase: database, authentication and file storage. Involves all Account Data and Customer Data.
  • Vercel: application hosting, product analytics and performance measurement. Involves request data, usage and device data.
  • Aurinko: mailbox connection for Gmail, Outlook and IMAP. Involves mailbox credentials or tokens, and message content where two-way sync is enabled.
  • Resend: system email, sending on your behalf when no mailbox is connected, and routing inbound replies. Involves email addresses and message content.
  • MailerLite: our newsletter and product marketing email. Involves your name and email address as the account holder, and no Customer Data.
  • Telnyx: text message alerts to your own phone. Involves your phone number and the alert content.
  • Stripe: payments and subscription billing. Involves billing details and payment information.
  • Upstash: background jobs and rate limiting. Involves job payloads and transient request identifiers.
  • Cloudflare: media storage for listing photos and video, contact photos, and email attachments until they are sent, and bot protection. Involves uploaded media and attachments, and sign-up and sign-in requests.
  • Sentry: error monitoring. Involves technical error reports, which may incidentally include identifiers.
  • Google Analytics: visitor analytics on relivoapp.com only. Involves device, browser, approximate location and pages viewed.
  • Follow Up Boss: optional, and only if you choose to import your contacts. Involves the contacts, notes, tasks and appointments you import.
  • Expo: delivers push notifications to the phone app, through Apple’s and Google’s notification services, and delivers app updates. Involves a push token, an installation identifier, the phone’s platform, reports on whether each app update started correctly, and the text of each notification, which can include a contact’s name, the first words of an enquiry or new lead’s message, and the subject of an email reply.
  • OpenRouter: routes voice note requests to AI model providers. Involves voice recordings, transcripts, and the contact names, listing streets and stage names sent with them.
  • OpenAI, Google and Anthropic: speech-to-text and summaries for voice notes, reached through OpenRouter. Google’s Gemini runs on Google Cloud, and Anthropic’s Claude on Amazon Web Services or Google Cloud. Involves the same data, under the limits described in “Voice notes in the phone app”.
  • Slack: internal notices to us about accounts, such as a new sign-up, a plan change or a deletion. Involves your name, email address and plan, and no Customer Data.

We may also disclose personal data where the law requires it, to enforce our terms, to protect the rights and safety of people or property, or to a successor in connection with a merger or sale of the business. If ownership ever changes, we will say so before your data moves.

How long we keep data

  • Your account and everything in it: as long as your account is open.
  • After you delete your account: 30 days, then permanently deleted. Access ends and billing stops immediately, and you can cancel the deletion during the hold.
  • Voice note recordings: 30 days, then deleted. Their transcripts are notes, kept with the contact.
  • Listing photos and video: kept with the listing. A photo you remove from a listing is also taken off its property microsites and deleted from storage within a day.
  • Contact photos: until you replace or remove the photo, then deleted within a day.
  • Email attachments: deleted once the email is sent, or within a day if it is not.
  • Phone app sign-in codes: until used, and they expire within 10 minutes.
  • Phones signed in to your account: until you sign that phone out, from the phone or from Settings on the web, or delete your account.
  • Website tracking events and sessions: 90 days.
  • Anonymous visitors who never became a contact: 180 days.
  • Visitors who did become a contact: kept with that contact as attribution history, for as long as the contact exists.
  • Marketing list: until you unsubscribe, after which we keep a record that you unsubscribed so we do not add you again.
  • Billing and tax records: as long as the law requires, typically seven years.
  • Backups: deleted data may persist briefly in encrypted backups before being overwritten on the normal cycle.

Security and support access

We take security seriously because the alternative is unacceptable for a product holding an agent’s entire client book. Measures in place include encryption in transit and at rest at the storage layer, row level security in the database so one account cannot read another’s records, rate limiting on public endpoints, bot protection on sign-up, sign-in and password reset, a check against known breached passwords, integration keys and mailbox tokens stored separately from your profile so they cannot be read by the browser, and error monitoring so failures are noticed rather than discovered by you. The phone app signs in with a single-use code, from the QR code on your computer or sent to your email, and we email you whenever a new phone signs in to your account.

Photos and video on a published property microsite are public, like the microsite itself. Until then, listing photos and video, like contact photos, are stored at long, unguessable addresses that are never published. Email attachments are private.

No service can promise perfect security. If a breach affects your personal data, we will notify you and any regulator that applicable law requires, without undue delay.

A Relivo administrator can sign into your account to investigate a problem you have reported. We disclose this because most products do not, and you should know it is possible. Every such session is recorded, including who started it, when it started and ended, and the originating IP address. During a support session, access to the administrative console and to sensitive account pages is blocked. We use this only to provide support, to investigate abuse, or where the law requires it.

Your responsibilities

Relivo holds personal data about people who never signed up with us: your clients and leads. You are responsible for that relationship.

  • Make sure you have a lawful basis to store and use the contact data you put into Relivo.
  • Give your own privacy notice to the people whose data you collect, including through your website forms, tracking script and property microsites.
  • Obtain any consent your jurisdiction requires before contacting a lead by email, phone or text message.
  • Honour requests from your own clients to access, correct or delete their data.
  • Only add a photo of a client if they are happy for you to.
  • Keep your password to yourself. A Relivo account is for one person.

Your rights

Depending on where you live, you may have the right to access, correct, delete or port your personal data, to object to or restrict processing, and to withdraw consent. You will not be discriminated against for exercising any of them.

Several of these you can exercise yourself, immediately, without asking us:

  • Access and correct your profile information in Settings.
  • Export your contacts to a CSV file from Settings, using the column names another CRM’s importer expects.
  • Delete your account from Settings, on the web or in the phone app. Access ends at once, billing stops, and everything is permanently deleted after a 30 day hold during which you can change your mind. The steps are at my.relivoapp.com/delete-account.
  • Disconnect a mailbox or an integration at any time from Settings.
  • Unsubscribe from marketing email using the link in any such message.

For anything else, write to support@relivoapp.com. We will respond within the time applicable law allows, normally within 30 days. We may need to verify your identity first. If you are in the EEA or UK and are unhappy with our answer, you may complain to your local data protection authority.

International transfers

Relivo is operated from the United States and our providers process data there. If you use Relivo from outside the United States, your personal data will be transferred to and processed in the United States, which may have different data protection laws from your own country. Where required, our providers rely on recognised transfer mechanisms such as the European Commission’s Standard Contractual Clauses.

Some of the AI model hosts used for voice notes may answer a request from a data centre outside the United States. They keep nothing once they have answered.

Children

Relivo is a business tool and is not directed at children. We do not knowingly collect personal data from anyone under 18. If you believe a child’s data has reached us, write to hello@relivoapp.com and we will delete it.

Changes

We will update this policy when the product changes. The effective date at the top always reflects the current version. If a change materially affects how we handle your personal data, we will tell you by email or in the app before it takes effect, rather than relying on you to notice.

Contact

SiteonWP LLC, trading as Relivo
1209 Mountain Road Place Northeast, STE N
Albuquerque, NM 87110
United States

General enquiries: hello@relivoapp.com
Privacy and product support: support@relivoapp.com