Comps Cache
MethodPricingSecurity
Sign inGet started
Legal

Privacy Policy

Last updated: September 16, 2026

This Privacy Policy explains what Comps Cache collects, how we use it, how we share it, and the choices available to users and affected individuals.

United States only. Comps Cache is offered and directed solely to users located in the United States. The service analyzes United States real estate. Our application and its database are hosted in the United States; two of the service providers named below, Plausible Analytics and the Photon geocoding service, operate from the European Union and receive only the limited data described in their entries. We do not offer the service to individuals located outside the United States and do not knowingly open accounts for them; a visit to our application pages from anywhere records the analytics described under Cookies below (this Privacy Policy and the Terms pages load no analytics).

Comps Cache is a hosted, web-based decision-support tool for hard-money, bridge, fix-and-flip, and private lenders. It parses property comparables and related property documents and returns a defensible value range. Comps Cache is not an appraisal service. Comps Cache does not approve, deny, price, fund, or make loans. The lender using the service owns the lending decision.

Comps Cache is operated by Bloom Craft Reserve LLC, doing business as CompsCache, with a mailing address at PMB 700, 11150 W Olympic Blvd, Suite 1050, Los Angeles, CA 90064. References to "Comps Cache," "we," "us," and "our" mean Bloom Craft Reserve LLC.

Questions: hello@compscache.com

1. Information we collect

Account and authentication information

We collect information needed to create and secure your account, including:

  • email address;
  • sign-in credentials or authentication information;
  • account status, plan, and related account records.

Access to Comps Cache requires sign-in. Passwords are stored only as salted cryptographic hashes, and sessions are managed server-side.

Uploaded documents and submitted analysis content

Users may upload or submit documents and text for analysis, including:

  • property profiles;
  • title-company files;
  • comp sheets;
  • pasted text;
  • user-entered comparable sales, including address, price, and sale date.

We call this "Customer Content."

Customer Content may include personal, financial, property, title, ownership, loan, or transaction information about people who are not Comps Cache users, such as borrowers, guarantors, property owners, buyers, sellers, tenants, agents, title/escrow personnel, or other third parties.

Do not submit personal information beyond what is reasonably needed for collateral analysis. Where practical, redact information that is not needed, such as full Social Security numbers, government ID numbers, bank account numbers, or unrelated personal financial details.

Generated reports and analysis records

We store reports generated on your account, including selected comparable information, narratives, value ranges, LTV calculations, $/SF calculations, and related analysis outputs.

All computed values, including ranges, LTV, and $/SF, are produced deterministically in code. The AI may help select, summarize, or narrate information, but it does not compute the numbers.

Billing and payment information

If you purchase a subscription or prepaid credit pack, payment processing is handled by Stripe.

Comps Cache receives and stores billing records needed to manage your account, such as plan type, subscription status, prepaid credit balance, invoice and transaction identifiers, and payment status.

Payment-card details are entered with and handled by Stripe, not directly by Comps Cache. Comps Cache does not receive or store full payment-card numbers.

Technical and usage data

We collect standard technical and usage information needed to operate, secure, troubleshoot, and improve the service, such as:

  • log entries;
  • request metadata;
  • timestamps;
  • session and sign-in events;
  • report-generation events;
  • error and diagnostic information;
  • Our application does not store IP address, browser/device fingerprint, referrer, or IP-derived location in its own database — our access logs record only account/tenant ID, resource type, action, and timestamp. We do use your IP address transiently for rate limiting and abuse prevention; the IP address used at signup is included in the account-review notice sent to our operator; and our analytics provider receives it as described under Cookies below. Our hosting provider's infrastructure may log IP addresses transiently for security and abuse-prevention purposes, consistent with standard web-server practice.

Cookies and similar technologies

We use cookies or similar technologies that are necessary for sign-in, server-side sessions, CSRF protection, and account security.

We use Plausible Analytics, a cookieless, privacy-focused analytics service, loaded through our own domain. For each page view it receives the page URL, the referrer, your browser and operating-system type, your screen size, and your IP address (relayed through our server), plus a small number of product events such as account signup. Plausible's published data policy (plausible.io/data-policy) states that its script sets no cookies and does not track visitors across sites. We do not use advertising cookies or tracking pixels.

Communications

If you contact us, we collect the information you provide in that communication, including your email address and the contents of your message.

2. How we use information

We use information to:

  • create, authenticate, and secure user accounts;
  • provide the document parsing and valuation-range reports users request;
  • store generated reports on the user's account;
  • process user-entered comps and uploaded property documents;
  • operate the deterministic calculations used for ranges, LTV, and $/SF;
  • use AI to assist with selection, summarization, and narration;
  • process billing for subscriptions and prepaid credit packs;
  • provide support and respond to user requests;
  • monitor, troubleshoot, secure, and improve the service;
  • prevent abuse, fraud, unauthorized access, and misuse;
  • comply with legal, accounting, tax, and security obligations.

Use of Customer Content for training or product improvement: We do not use uploaded documents or generated reports to train or fine-tune AI models. Anthropic's handling of submitted text is described in Section 4.

We do not use Comps Cache to approve, deny, price, or fund loans.

3. Uploaded information about borrowers, owners, and other third parties

Comps Cache is used by lenders and lender-side users. Customer Content uploaded by those users may describe people who do not have an account with Comps Cache.

The user or account holder is responsible for ensuring that they have the right to upload and process Customer Content through Comps Cache, including providing any required notices or obtaining any required consents from borrowers, property owners, or other affected individuals.

If you are a borrower, property owner, or other person whose information was uploaded by a Comps Cache customer, the lender or account holder may be the party that controls that information. You should contact that lender or account holder directly with privacy requests. If you contact us at hello@compscache.com, we may ask for information to verify the request and may refer or forward the request to the relevant account holder where appropriate or required.

4. AI processing

Comps Cache performs analysis in part through the Anthropic API.

When you request an analysis, we may send Anthropic information needed to perform that analysis, such as:

  • text extracted from uploaded documents;
  • pasted text;
  • user-entered comparable information;
  • prompts, instructions, and context needed to process the request;
  • related generated text or analysis context.

Comps Cache currently operates under Anthropic's standard API data-retention policy. No zero-data-retention agreement is in place. You should assume that submitted document text may be retained by Anthropic according to Anthropic's applicable standard policy. If we put a zero-retention agreement in place in the future, we will update this policy.

Anthropic's standard retention period (absent a zero-retention agreement) is 30 days: Anthropic automatically deletes inputs and outputs from its backend within 30 days of receipt or generation, except where a longer period applies under law, Usage Policy enforcement, or a separately agreed arrangement. See Anthropic's data retention policy.

Comps Cache's computed values are not generated by the AI. Value ranges, LTV, $/SF, and other numeric outputs are calculated deterministically in Comps Cache code. The AI may help select, summarize, and narrate; it does not compute the valuation numbers.

5. How we share information

We share information only as needed for the purposes described in this policy.

Service providers

We share information with vendors that help us operate the service, including:

  • Anthropic, for AI processing (see Section 4);
  • Stripe, for subscriptions, invoices, and prepaid credit packs;
  • RentCast, a property-data provider: to retrieve comparable listings and property records, we send RentCast the subject property address (and related search parameters) for the analysis you request, and, when you ask us to enrich a comparable you entered yourself, that comparable's address;
  • U.S. Census Bureau geocoding and data services (geocoding.geo.census.gov, api.census.gov): we send the subject property address — and, as you type into the address field, the text typed so far — to resolve coordinates and census geography used in the analysis and to suggest matching addresses;
  • U.S. Census Bureau TIGERweb (tigerweb.geo.census.gov): when a report is generated we send the map area covering the subject and its comparable sales, expressed as coordinates, to retrieve the public-domain street and railroad centrelines drawn as the basemap on the report's comparables map. No address, account, or personal information is sent;
  • Render (render.com), our cloud hosting and database provider;
  • Plausible Analytics (plausible.io), our website analytics provider, which receives the page-view data described under Cookies above;
  • Google (Places API): as you type into the address field, our server sends the characters typed so far to Google to suggest matching addresses and, when you pick a suggestion, that suggestion's identifier to retrieve its full address and coordinates; the browser never talks to Google for this;
  • Photon geocoding service (photon.komoot.io): our server also sends the text you type to Photon for street-level address suggestions;
  • Resend (resend.com), our transactional email provider, which delivers sign-in confirmation, password-reset, account-review, contact-form and other service email; contact-form email can be routed through an alternative SMTP relay in place of Resend where we configure one, and such a relay would receive the same fields;
  • Cloudflare: our network edge — every request to our site passes through Cloudflare's network on its way to our hosting provider, so Cloudflare sees your IP address and request metadata; and Email Routing, which forwards mail sent to our support address, including contact-form submissions, to the mailbox our team reads, hosted by Google (Gmail).

These providers process information under their applicable terms, data-processing agreements, or service agreements.

Third-party services your browser connects to directly

Some features load from or send requests to third-party services directly from your browser. Those services receive your IP address and standard request metadata as part of any such request:

  • Stripe (checkout.stripe.com, billing.stripe.com) — when you buy a plan or credits, or open the billing portal, your browser is sent to pages hosted by Stripe, where you enter payment details directly with Stripe. Stripe receives your IP address and what you type there; we never see full card numbers.
  • Google Maps embed (www.google.com, maps.google.com) — when you view a report, a map of the subject property is loaded directly from Google, which receives your IP address and the subject location.
  • OpenStreetMap tile servers (tile.openstreetmap.org) — serve the map images on the report's comparables map. The tile requests reveal the approximate map area being viewed.
  • cdnjs (cdnjs.cloudflare.com) — serves the Leaflet map library files used to render the map.

These services are operated by third parties under their own privacy policies. Comps Cache does not send them your account information, with one exception: when our server creates a Stripe checkout or billing-portal session it passes your Stripe customer identifier and an internal account reference so the payment can be matched to your account.

Legal, security, and compliance

We may disclose information if we believe disclosure is reasonably necessary to:

  • comply with law, legal process, subpoenas, court orders, or government requests;
  • enforce our terms or protect our rights;
  • investigate fraud, abuse, security incidents, or unauthorized access;
  • protect users, third parties, or the service.

Business transfers

If Comps Cache is involved in a merger, acquisition, financing, reorganization, bankruptcy, sale of assets, or similar transaction, information may be transferred as part of that transaction, subject to appropriate confidentiality or transfer restrictions where applicable.

Aggregated or de-identified information

We may use or share aggregated statistics — such as counts of reports generated or overall usage volumes — that do not identify, and cannot reasonably be linked to, a user, borrower, property owner, or other individual.

Sale or advertising sharing

We do not sell personal information, uploaded documents, or generated reports, and we do not share personal information for cross-context behavioral advertising.

6. Data retention

We retain information only for as long as needed for the purposes described in this policy, unless a longer period is required for legal, accounting, tax, security, backup, dispute-resolution, or compliance reasons.

Specific retention periods:

Data categoryRetention period
Account and authentication recordsKept while your account is active; deleted within 30 days of account closure, subject to the legal, accounting, tax, security, and dispute-resolution exceptions noted above
Uploaded documents / Customer ContentDocument text is purged 72 hours after processing
Generated reports10 days on the free tier; 60 days on any current paid plan (Solo, Pro, or Desk). Reports you save (pin) are kept until you delete them.
Technical and usage logs365 days
Billing, invoice, subscription, and prepaid credit records7 years (retained for tax and accounting compliance)
Support communications2 years from the last message in the thread
BackupsRetained for at least as long as generated reports (up to 60 days); residual copies purged on the backup rotation cycle
Anthropic API-retained content30 days (Anthropic's standard API retention period, absent a zero-retention agreement) — see Section 4

If you close your account, you will lose access to the service. Deletion of account data, uploaded documents, and reports will follow the periods above. Residual copies may remain in backups for a limited period and may be retained longer if required for legal, security, accounting, or dispute-resolution reasons.

7. Security

We use reasonable safeguards designed to protect information submitted to Comps Cache.

Known safeguards include:

  • salted, hashed password storage (passwords are never stored in plaintext);
  • server-side sessions;
  • CSRF protections;
  • standard technical and usage logs for security and troubleshooting.

We also apply:

  • encryption in transit (HTTPS/TLS) for connections to the service;
  • per-account data isolation so accounts cannot access one another's documents or reports;
  • structured audit logging of security-relevant events.
  • encryption at rest for the production database, provided through our managed hosting provider;
  • administrative and billing functions restricted to owner-level accounts; analyst API sessions are capability-limited and cannot access billing or administration;
  • secrets and API keys held in environment configuration, not in application code;
  • backups protected with the same access restrictions as production data.

No method of transmission or storage is completely secure. We cannot guarantee absolute security.

8. Your choices and privacy requests

You may request access to, correction of, or deletion of account data by contacting hello@compscache.com.

We may need to verify your identity and account authority before responding. Some information may be retained where required for legal, accounting, tax, security, backup, fraud-prevention, or dispute-resolution reasons.

If your information was uploaded by a lender or another Comps Cache customer, we may direct your request to that customer because they may control the relevant documents and reports.

Cookie choices: you may be able to block cookies through your browser, but necessary session/security cookies are required for the service to function.

Payment choices: subscription and payment settings may be managed through your account's billing settings, which are processed through Stripe.

9. US state privacy rights

Comps Cache is a United States–only service. Privacy rights vary by state.

California (CCPA/CPRA): Comps Cache does not currently meet the CCPA/CPRA applicability thresholds (annual gross revenue, volume of consumers' personal information, or revenue from selling/sharing personal information). Regardless of statutory applicability, we extend the same core choices to California residents: you may request to know, correct, or delete the personal information we hold about you by emailing hello@compscache.com. We do not sell personal information or share it for cross-context behavioral advertising, so there is nothing to opt out of on that front, and we will not discriminate against you for making a privacy request. If our business grows to meet the statutory thresholds, we will update this section with the full required disclosures.

Other US states: Comps Cache does not currently meet the applicability thresholds of other state privacy laws (such as those of Virginia, Colorado, Connecticut, or Texas). Residents of any state may nevertheless submit access, correction, or deletion requests to hello@compscache.com, and we will honor them as described in Section 8.

EU / UK / EEA: Comps Cache is not offered to, marketed to, or intended for individuals located in the European Union, United Kingdom, or European Economic Area, and we do not profile or target individuals located there. Our website analytics (Plausible Analytics, Section 5) records a page view for any visitor to our application pages regardless of location, without cookies or cross-site tracking, and is not used to profile individuals.

10. Children

Comps Cache is intended for business use by lenders and authorized professionals. It is not intended for children.

Minimum age: 18.

We do not knowingly collect information from children under 18. If you believe a child has provided information to us, contact hello@compscache.com.

11. United States processing

Comps Cache's own application and database are hosted in the United States. The service providers named in Section 5 process data under their own terms and in their own locations; two of them, Plausible Analytics and the Photon geocoding service, operate from the European Union.

The service is offered only to users located in the United States. If you nevertheless access Comps Cache from outside the United States, you do so on your own initiative, and your information will be transferred to the United States and processed as described in Section 5 and this Section, where privacy laws may differ from those of your location.

12. Changes to this policy

We may update this Privacy Policy from time to time. The "Last updated" date above shows when it was last revised.

For material changes, we will provide notice by posting the updated policy on this page and revising the "Last updated" date, and, where appropriate, by email or in-app notice before or when the changes take effect.

13. Contact

Questions or privacy requests:

Comps Cache
Bloom Craft Reserve LLC, dba CompsCache
PMB 700
11150 W Olympic Blvd, Suite 1050
Los Angeles, CA 90064
Email: hello@compscache.com

Comps Cache
TermsPrivacyContacthello@compscache.com