Privacy Notice
LoanBot AI privacy practices
This notice explains the categories of information LoanBot AI may process, why it is used, when providers or business customers may receive it, and how requests are handled. LoanBot AI does collect and process personally identifiable information (PII) and, when that information is associated with a mortgage inquiry, financial service, or identifiable consumer, nonpublic personal information (NPI). A customer agreement or a financial institution's privacy notice may provide additional or controlling terms for customer-directed processing.
1. Information we may process
- Account and profile information: name, business contact details, professional role, company, licensing/profile information, and account settings.
- Consumer inquiry and relationship information: name, contact information, property or transaction interests, assigned professional, communications, tasks, and workflow status.
- Borrower-provided financial and eligibility information: income, debts, assets, reserves, down-payment estimates, borrower-provided credit ranges, self-employment, bankruptcy indicators, veteran or military eligibility, and related preliminary qualification inputs when a user chooses to enter them.
- Mortgage scenario and property information: payment and balance estimates, loan purpose, transaction type, occupancy, property information, timeline, pipeline status, and hypothetical or preliminary scenario details.
- Application and device information: authentication/session information, feature use, error and security events, browser/device details, and similar operational data made available by the platform.
- Integration information: data necessary to use an approved connected service, such as source documents, email delivery, subscriptions, media, or listing data.
- Support and compliance information: support requests, consent/acknowledgement records, vendor-review material, and incident or privacy-request records.
When these categories are associated or reasonably linkable to an identifiable consumer in a mortgage-service context, LoanBot treats the combined record as nonpublic personal information (NPI). This includes self-reported estimates and ranges, property information linked to a consumer, communications, and scores, matches, recommendations, or other information derived from the consumer's profile or activity.
2. Information you must not submit
During the PMR vendor-approval period, LoanBot policy prohibits intentional submission of:
- Social Security numbers, taxpayer identification numbers, or ITINs;
- Dates of birth;
- Bank account, routing, ABA, checking, or savings account numbers;
- Payment-card numbers, CVV/CVC, or PIN data;
- Government identification numbers or images;
- Consumer passwords, login credentials, or recovery codes;
- Exact credit scores obtained from a consumer report.
The prohibited categories include Social Security numbers, date of birth information, bank account or routing information, payment-card data, government identification, credentials, and exact consumer credit scores.
Do not place prohibited information in free text, messages, attachments, imports, support requests, or field labels. Borrower-provided credit may be represented only as an approved range.
PMR boundary: Until Premier Mortgage Resources approves LoanBot for the specific data categories and workflows, PMR borrower/customer information must not be intentionally entered or uploaded into LoanBot. A technical feature, policy document, or provider certification does not by itself authorize PMR production-data use.
3. Why information is used
- provide, secure, administer, support, and improve the requested service;
- connect authorized users and display approved role-based workflow information;
- generate educational calculations, content, or scenario assistance at the user's request;
- send service communications and approved user-directed messages;
- manage subscriptions, prevent abuse, investigate incidents, and enforce agreements;
- meet contractual, legal, privacy, security, audit, and recordkeeping obligations.
4. Business customers and financial institutions
LoanBot may process information for PMR or another business customer. In that situation, the customer may determine the purpose and permitted use of the information, and LoanBot may be required to follow the customer's instructions and contract. Privacy requests concerning customer-controlled information may be routed to that customer.
LoanBot does not treat information received from a financial institution as available for unrelated marketing, sale, or redisclosure. Use is limited by the service purpose, agreement, approved access, and applicable requirements.
5. Service providers and integrations
LoanBot uses providers for cloud application services, storage, transactional email, payments, AI-assisted features, source documents, listing information, domains, and related operations. A provider may receive account, recipient, operational, mortgage-profile, property, message, media, or other information only when needed for the enabled function and permitted by the applicable relationship.
Routine new-lead and loan-stage emails are designed to direct an authorized recipient back to LoanBot rather than reproduce borrower identity or detailed financial profiles in email. A user-directed email or video share may include the selected recipient, sender, optional message, title, and link. Higher-risk borrower-document or restricted-data processing is not enabled merely because a technical integration exists. The data flow, provider retention/training terms, logging, deletion, contract, and PMR approval must first be satisfied.
6. AI-assisted features
Some features use AI to analyze user-provided inputs or generate educational content. Profile-aware affordability and mortgage-education features may use selected mortgage intent, borrower-provided credit range, income, debt, down payment, target price, property state, veteran status, calculated results, and the user's prompt. AI output may be incomplete or inaccurate and is not a credit decision, underwriting approval, commitment to lend, legal advice, or substitute for current lender guidance and professional review.
Do not submit prohibited information to AI features. PMR NPI and other Restricted-data use requires a specifically approved data flow, identified model/provider path, applicable retention and training terms, logging and deletion review, contract/DPA review, and customer approval.
7. Security
LoanBot uses a risk-based security program that includes an NPI inventory, role/ownership/assignment controls, limited role projections, server-side authorization for selected sensitive functions, data minimization, secure development, provider oversight, incident response, retention, and continuity requirements. Platform-level encryption, logging, backups, and infrastructure controls are treated as provider controls and require current evidence.
No internet service is risk-free. Report suspected unauthorized access promptly through the security contact in the applicable agreement or authenticated support channel. See the Security Overview and Incident Response Commitment.
8. Retention and deletion
LoanBot retains information only for an approved service, security, contractual, or legal purpose. Retention differs by category. PMR/customer data is subject to the applicable agreement and instructions. Temporary restricted-document staging, when specifically approved, must be deleted after processing with a short failure backstop.
After a verified termination or approved deletion instruction, LoanBot addresses production records, files, access, approved subprocessors, exports, and backup-aging treatment. Data subject to a legal, regulatory, security, audit, or litigation hold may be retained only for the hold's scope and duration.
9. Privacy requests
Depending on the relationship and applicable law, a person may request access, correction, export, or deletion. LoanBot verifies identity and authority, determines whether a business customer controls the response, searches relevant systems, documents exceptions, and uses secure delivery for exports.
Submit requests through the privacy or security contact identified in the applicable agreement or through the authenticated support channel. Do not send prohibited identifiers to verify a request unless specifically instructed through an approved secure method.
10. Children and international use
LoanBot is not intended for children under 13 and does not knowingly solicit their personal information. Users are responsible for ensuring they have authority to provide information and that use is permitted in their jurisdiction. International use may require additional contractual and legal review before restricted data is processed.
11. Changes
LoanBot may update this notice to reflect service, provider, legal, or security changes. The version and effective date identify the current notice. Material changes are communicated as required by the applicable agreement or law.