This Privacy Policy explains what information Rook (operated by Aximon) collects, how we use it, who we share it with, and the choices you have. Rook is a business tool used by real estate acquisition teams. Your deal flow, your documents, and your model are yours. We help you underwrite faster; we do not sell your data, and we do not use your private deal documents to train shared or public models.
Scope and who we are
This Policy applies to the Rook web application, our website and product pages, and related services (together, the "Service"), operated by Aximon ("we", "us", "Rook"). It applies to the people who sign up for and use the Service on behalf of a real estate firm or team ("you").
Rook is a business-to-business product intended for use by professionals. It is not directed to consumers or to children, and we do not knowingly collect information from anyone under 18.
Information we collect
We collect only what we need to run the Service. Specifically:
- Account information you provide when you sign up or are invited, such as your name, work email address, and the organization you belong to. Authentication is handled through Supabase Auth.
- Documents and files you upload or import, such as offering memorandums, rent rolls, T-12 operating statements, Excel underwriting models, and related deal materials brought in from systems you use (for example, CoStar, Yardi, or Excel), so the Service can read, extract, and underwrite them.
- Content connected through an email inbox you choose to link (via Google or Microsoft/Outlook authorization), including message metadata, message bodies, and attachments, used to detect and ingest deals sent to you. You control which inbox is connected and can disconnect it at any time.
- Voice notes or audio you submit to the assistant, which are transcribed to text so we can act on them.
- Property and deal data you enter or generate in the product, including addresses, financial assumptions, and the analyses, comps, and memos the Service produces.
- Usage and device data, such as which features you use and basic technical logs, used to operate, secure, and improve the Service.
How we use your information
We use the information above to:
- Provide the Service: parse your documents, extract facts, generate underwrites, comps, pro formas, and investment memos, and return them to you.
- Enrich analyses with public and licensed market data (for example, comparable sales, rents, demographics, and market signals) so your underwrites are grounded in real numbers.
- Authenticate you, operate and secure the platform, prevent abuse, and provide support.
- Improve the Service, including debugging and measuring which features are useful. We do not use your private deal documents to train shared or public models, and we do not share your pipeline with other customers.
How your documents are processed
We use OpenAI to process relevant document, email, and audio content for deal detection, analysis, and transcription. For connected inboxes, this can include sender information, subjects, message snippets and body text, attachment metadata, and extracted attachment text. Our infrastructure providers are listed under "Service providers" below.
We do not use your content, including Google user data and information derived from it, to develop, improve, or train shared, public, or general-purpose AI models. Our large-language-model provider processes API inputs and outputs to deliver the service and does not use them to train its models.
Connected email accounts
If you connect a Google (Gmail) or Microsoft (Outlook) inbox, we request permission to read messages and attachments to identify and import deal opportunities, and to send emails you explicitly submit through the Service. Relevant message and attachment contents are processed using OpenAI as described under "How your documents are processed" and "Service providers". We do not use connected email data for advertising or transfer it except as needed to provide the Service to you.
Connecting a mailbox makes it available to your workspace. Workspace members can view imported deal and email review information, manage the connection, and send messages they explicitly submit from that mailbox. You can disconnect the mailbox in Settings.
Rook's use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements. Our use of information received from Microsoft APIs is likewise limited to providing the Service.
For Google user data, these limits take precedence over broader provisions in this Policy: personnel may read specific content only with your documented, explicit permission, when necessary for security purposes or to comply with applicable law, or when the data is aggregated and anonymized for internal operations. We obtain your explicit prior consent before transferring Google user data as part of a merger, acquisition, or sale of assets, and your consent before using it for a newly disclosed purpose.
Data about property owners and other third parties
To help our customers evaluate and pursue real estate, the Service collects and compiles business-context information about properties and the people connected to them, such as property owners, brokers, and their firms. This can include names, business contact details, firm affiliation, and property ownership records, drawn from documents our customers provide and from publicly available or licensed sources.
This information is used only to support legitimate commercial real estate activity for the customer whose account it appears in, not for advertising and not for sale. If you are an owner or broker and want to know what information we hold about you, or to have it corrected or removed, contact us at support@aximon.ai.
Email you send through a connected account
If you use the Service to email contacts from an email account you connect, those messages are sent from your own mailbox and your own address. You are the sender and, for the personal data of the people you contact, you are the controller. We process that data on your behalf to carry out the send you asked for.
You select the recipients and submit the message before sending starts. Submitted messages are queued and sent separately to each recipient in the background, so sending can continue after you close the page.
We store what is needed to run and account for the send: the recipient's name, firm and address as they exist in your list, the message you wrote, and a per-recipient record of what happened to it — queued, sent, failed, or skipped, and why. That record is what stops the same person being emailed twice and is retained with your workspace data.
Deciding who may lawfully be contacted, having a lawful basis for contacting them, and honoring their opt-outs and data-subject requests are your responsibilities as the sender. See the Email outreach section of our Terms of Use.
If you received an email sent through Rook from one of our customers and want it to stop, reply to that message directly — it goes to the sender's own inbox, because they sent it from their own account. You can also contact us at support@aximon.ai and we will record the address so it is not contacted again from that workspace.
Service providers and subprocessors
We share information with a limited set of vendors who process it on our behalf to deliver the Service, under agreements that require appropriate confidentiality and security. We do not sell your information, and we do not share it for advertising. Our current categories of providers are:
- Cloud database, storage, and authentication: Supabase, which hosts your account, documents, and generated artifacts.
- AI processing: OpenAI, for document understanding, generation, and voice transcription via API.
- Market and property data enrichment: RentCast, plus public or government data sources such as the U.S. Census Bureau, Bureau of Labor Statistics, Bureau of Economic Analysis, the Federal Reserve (FRED), and SEC EDGAR.
- Email connectivity: Google (Gmail) and Microsoft (Outlook) authorization, for inboxes you choose to connect, used to read messages and attachments for deal intake and send messages explicitly submitted by workspace members.
We will keep this list current as our providers change. If you need a formal, up-to-date subprocessor list for a security or vendor review, email support@aximon.ai.
Security
Your data is encrypted in transit (TLS) and at rest, and is stored in a secured database. When you connect an inbox, the Service processes your messages and attachments automatically to detect and pull in deals; this is done by software, and we do not human-read your inbox for any other purpose. We do not monetize your documents or use them to train shared or public models.
In normal operation, our personnel do not access the content of your documents or deals. Limited access may occur when reasonably necessary to provide support you request, investigate a security or service issue, comply with applicable law, or protect the Service, and is restricted to authorized personnel with a legitimate need.
Authorization tokens for connected inboxes are encrypted at rest; Rook does not receive or store your Google or Microsoft account password. Your documents and data are logically isolated per organization, so one customer cannot see another customer's pipeline. No method of transmission or storage is perfectly secure, but we work to protect your information using industry-standard safeguards.
Compliance
We plan to undergo a SOC 2 Type II examination. No report is available yet.
Where your data is stored
Rook is built for real estate firms in the United States, and your data is stored on cloud infrastructure located in the United States.
For the documents and deal data you put into the Service, we act on your behalf and process that content to provide the Service to you. A data processing agreement is available on request for customers who need one for a security or vendor review; email support@aximon.ai.
Data retention
We retain your documents and the artifacts we generate for as long as your account is active or as needed to provide the Service. You can delete individual deals, files, chats, and connected inboxes from within the product at any time; deleting a deal removes its files and derived data from active production systems, subject to limited processing time and residual encrypted backup copies.
Disconnecting an inbox does not delete previously imported deals or documents; use the deletion options described here.
You can also request deletion of all of your data at any time by emailing support@aximon.ai. We will remove it within 30 days, except where we must retain limited information to comply with legal obligations or resolve disputes. Residual copies may persist in routine backups for a limited period before being overwritten.
Your choices and rights
You can access, correct, export, or delete your information, and you can disconnect a linked inbox, at any time from within the product or by contacting us. Depending on where you live, you may have additional rights over your personal information under applicable law, including the right to request access or deletion; we honor these requests.
To make a request, email support@aximon.ai. We may need to verify your identity before acting on a request.
Changes and contact
We may update this Policy from time to time. When we make material changes, we will update the "Last updated" date above and, where appropriate, notify you. Your continued use of the Service after an update takes effect means you accept the revised Policy.
Questions, requests, or a security review? Email us at support@aximon.ai.