Locate.

Privacy Policy

Effective August 24, 2026 · Terms of Service · Back to the app

1. Who we are

Locate. (at locateapp.net and locator-hub.web.app, together with its companion browser extensions) is an independent tool built and operated by Jonathan Gilliam, an apartment locator working as an independent third-party contractor. It is not an official product of any brokerage, and no brokerage operates the Service or receives your data through it. Brokerage admins manage only their own members' access and market list.

2. The short version

Your clients' personal information stays in your own Google Drive, not on our servers. The shared property database is communal and visible to every authorized member. We store no passwords, sell nothing, run no ads, and use no third-party analytics.

3. What we access, and why

You sign in with Google. The Service requests these permissions and uses them only as described:

PermissionWhat it is used for
Google DriveCreating and reading the Service's own files in your Drive: your client list file, grab screenshots, and guest card PDF attachments. The Service only ever looks up files it names itself and that you own. It does not browse, index, or touch the rest of your Drive.
Send email (Gmail)Sending the guest card emails you compose, from your own address, only when you press send.
Email metadata (Gmail)Checking the status of threads the Service created for you (sent, replied, or bounced) by reading headers and labels only, never message bodies of your other mail.
Calendar eventsCreating tour events on your own calendar when you press Add to Calendar.

Locate.'s use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.

4. Where your data lives

DataWhereWho can see it
Clients: names, their property lists, grab details and screenshots, guest card PDFs, email statusYour own Google DriveYou. This data is not stored on the Service's servers and is not shown to other members through the app.
Communal property data: notes, contact details, terms, tags, regions, the search indexThe Service's database (Google Cloud, United States)Authorized members. Edits are stamped with the editing account's email address, which other members may see.
Craft documents (searches, tour sheets, cards)The Craft space they are created inWhoever has access to that Craft space. If your market uses a shared space, documents you create there, including client names in document titles, are visible to others with access to that space.
Sign-in stateYour browser's local storageYou. Clearing your browser data signs you out.

5. What our servers process

The Service's backend (Google Cloud Functions, us-central1) verifies your Google sign-in on each request, reads and writes the communal property database, reads the shared market roster, and relays Craft requests. Your Google access token passes through per request and is never stored. When you sign in on an iPhone or iPad home screen app, a one-time sign-in code may be held for up to five minutes to pass it from the Google window to the app, then deleted; it cannot be used without a key that never leaves your device. Shared Craft credentials are held server-side and are not sent to browsers. We keep no server-side copy of your client data and no passwords of any kind.

6. Retention and deletion

7. Security

Sign-in is Google OAuth only; the Service never sees or stores a password. Backend access is restricted to approved accounts and verified on every request. Client personal data deliberately stays in each member's own Google Drive so that no central database of client information exists to breach. No system is perfectly secure, so also keep your own Google account protected (strong password, two-factor).

8. What we do not do

9. Children

The Service is a professional tool for working adults and is not directed at anyone under 18.

10. Changes

This policy may change as the Service evolves; the current version is always at this page, with its effective date above. Meaningful changes will be reflected here before they take effect.

Questions or removal requests: [email protected] · Terms of Service