Outview LLC · Last updated: June 2026
Privacy Policy
1. Introduction and Data Controller
This Privacy Policy describes how Outview LLC (“we”, “us”, “our”) collects, uses, stores, and protects personal data in connection with the Rielto platform (“Platform”) accessible at rielto.io and rielto.app.
Data Controller: Outview LLC
5830 East 2nd St, Ste 7000
Casper, Wyoming 82609 — US
Email: privacy@rielto.io
EU Representative (GDPR Art. 27): For matters related to EU data subjects, you may also contact us at privacy@rielto.io. We are in the process of appointing a formal EU representative and will update this policy when complete.
This policy applies to:
- Visitors to rielto.io (marketing site)
- Registered users of rielto.app (Platform)
- Waitlist applicants
This policy complies with:
- The EU General Data Protection Regulation (GDPR) — Regulation (EU) 2016/679
- The California Consumer Privacy Act (CCPA) and California Privacy Rights Act (CPRA), where applicable
- Applicable US federal and Wyoming state privacy laws
2. Data We Collect
2.1 Data You Provide Directly
Account registration and waitlist:
- First and last name
- Professional email address
- Company or business name
- Country
- Professional activity type (real estate agent, vacation rental, hotel, etc.)
- Monthly volume of properties managed
- Link to professional activity (optional)
- How you heard about Rielto (optional)
Payment information:
- Billing name and address
- Payment card details (processed directly by Stripe — we do not store full card numbers)
- VAT number (where applicable)
Platform use:
- Property photographs you upload for generation
- Wizard inputs (property type, location, tone, language preferences, voice selection, video duration)
- Copy edits and approvals you make during the generation process
- Communications with our support team
2.2 Data Collected Automatically
Technical data:
- IP address
- Browser type and version
- Device type and operating system
- Pages visited and time spent
- Referring URL
- Session identifiers and cookies
Usage data:
- Feature usage patterns and interaction events (via PostHog analytics)
- Generation history, credit usage, and account activity
- Error logs and performance data
2.3 Data We Do Not Collect
We do not collect:
- Sensitive personal data (health, religion, political opinions, biometric data) — unless you choose to upload content depicting such information, in which case you are responsible for the appropriate legal basis
- Data from persons under 18 years of age
- Financial account numbers (beyond what Stripe requires for payment processing)
3. How We Use Your Data
We process your personal data for the following purposes and legal bases:
| Purpose | Legal Basis (GDPR) | Legal Basis (US) |
|---|---|---|
| Providing and operating the Platform | Performance of contract (Art. 6(1)(b)) | Contractual necessity |
| Processing payments and managing subscriptions | Performance of contract (Art. 6(1)(b)) | Contractual necessity |
| Reviewing waitlist applications | Legitimate interests (Art. 6(1)(f)) | Legitimate business interest |
| Sending transactional emails (generation complete, approval, billing) | Performance of contract (Art. 6(1)(b)) | Contractual necessity |
| Sending product updates and marketing communications | Consent (Art. 6(1)(a)) — you may opt out at any time | Consent / opt-out right |
| Improving the Platform through analytics | Legitimate interests (Art. 6(1)(f)) | Legitimate business interest |
| Fraud prevention and security | Legitimate interests (Art. 6(1)(f)) | Legitimate business interest |
| Compliance with legal obligations | Legal obligation (Art. 6(1)(c)) | Legal obligation |
| Processing AI generations from your uploaded photos | Performance of contract (Art. 6(1)(b)) | Contractual necessity |
We do not use your personal data for automated individual decision-making or profiling that produces significant legal effects.
4. Data Retention
We retain your personal data for the following periods:
| Data Category | Retention Period |
|---|---|
| Account data (name, email, company) | Duration of account + 3 years after deletion |
| Generated content (videos, photos, copies) | Duration of account + 30 days after deletion |
| Payment records | 7 years (tax and legal compliance) |
| Waitlist applications (not approved) | 12 months from submission |
| Analytics and usage logs | 24 months |
| Support communications | 3 years from last interaction |
| Legal hold data | As required by applicable law |
When you delete your account, we initiate deletion of your personal data and generated assets within 30 days, except where retention is required by law or legitimate business interest (e.g., billing records).
5. Your Rights
5.1 Rights Under GDPR (EU Users)
If you are located in the European Union or European Economic Area, you have the following rights:
- Right of access (Art. 15): request a copy of the personal data we hold about you
- Right to rectification (Art. 16): request correction of inaccurate or incomplete data
- Right to erasure (Art. 17): request deletion of your personal data, subject to legal retention obligations
- Right to restriction (Art. 18): request that we limit processing of your data in certain circumstances
- Right to data portability (Art. 20): receive your data in a structured, machine-readable format
- Right to object (Art. 21): object to processing based on legitimate interests or for direct marketing
- Right to withdraw consent: where processing is based on consent, withdraw it at any time without affecting the lawfulness of prior processing
- Right to lodge a complaint: file a complaint with your national data protection authority. For Spain: Agencia Española de Protección de Datos (aepd.es). For Italy: Garante per la protezione dei dati personali (garanteprivacy.it). For EU generally: https://edpb.europa.eu
5.2 Rights Under California Law (CCPA/CPRA)
If you are a California resident, you have the right to:
- Know what personal information we collect, use, disclose, or sell
- Delete your personal information (subject to exceptions)
- Correct inaccurate personal information
- Opt out of the sale or sharing of your personal information — we do not sell personal information
- Non-discrimination for exercising your privacy rights
5.3 How to Exercise Your Rights
Submit requests to: privacy@rielto.io
We will respond within 30 days (GDPR) or 45 days (CCPA/CPRA). We may verify your identity before processing requests. Requests are free of charge unless manifestly unfounded or excessive.
6. Sharing and Sub-Processors
We share your data only as necessary to operate the Platform. We do not sell your personal data. We do not share your data with advertisers or data brokers.
6.1 Sub-Processors
The following third-party services process personal data on our behalf. All sub-processors are contractually bound to process data only on our instructions and to maintain appropriate security measures.
| Sub-Processor | Country | Data Processed | Purpose |
|---|---|---|---|
| Supabase | US (AWS us-east-1) | Account data, generation metadata, authentication tokens | Database, authentication, and file metadata |
| Stripe | US | Name, email, billing address, payment card data | Payment processing and subscription management |
| Cloudflare (R2) | Global CDN | Uploaded photos, generated videos, generated audio | Asset storage and delivery |
| Anthropic (Claude API) | US | Property descriptions and wizard inputs (used to generate copy) | AI copy generation |
| Google (Gemini API) | US | Uploaded property photos (processed for enhancement and analysis) | AI photo enhancement and visual analysis |
| FAL.AI / Kling | US | Enhanced property photos (used to generate video) | AI video generation |
| ElevenLabs | US | Voiceover script text | AI voice synthesis |
| Resend | US | Email address, name | Transactional email delivery |
| PostHog | US (US region) | Usage events, IP address (anonymized), device data | Product analytics |
| Vercel | US (AWS/GCP) | IP address, request logs | Hosting and edge delivery |
| Railway | US | Server logs | API and worker hosting |
6.2 International Data Transfers
Some sub-processors are located outside the European Economic Area. Where we transfer personal data to third countries, we ensure adequate safeguards are in place through:
- EU Standard Contractual Clauses (SCCs) as updated by Commission Decision 2021/914
- The EU-US Data Privacy Framework, where applicable
7. Cookies and Tracking
7.1 Cookies We Use
| Cookie | Type | Purpose | Duration |
|---|---|---|---|
sb-auth-token | Essential | Supabase authentication session | Session |
ph_session | Analytics | PostHog session tracking | 24 hours |
ph_distinct_id | Analytics | PostHog user identification (anonymized) | 1 year |
locale | Functional | Stores language preference | 1 year |
7.2 Cookie Management
You can control cookie settings through your browser settings. Disabling essential cookies may affect Platform functionality. We do not use advertising or third-party tracking cookies.
8. Data Security
We implement industry-standard technical and organizational measures to protect your personal data, including:
- Encryption in transit: all data transmitted between your browser and our services uses TLS 1.2 or higher
- Encryption at rest: sensitive data is encrypted at rest in our database
- Access controls: production data is accessible only to authorized personnel on a need-to-know basis
- Authentication: multi-factor authentication required for all internal system access
- Row-level security: database-level isolation between tenant accounts
- Signed URLs: generated assets are accessible only via time-limited signed URLs
Despite these measures, no security system is impenetrable. In the event of a personal data breach affecting your rights and freedoms, we will notify relevant supervisory authorities within 72 hours and affected users without undue delay, as required by GDPR Art. 33-34.
9. Children’s Privacy
The Platform is intended exclusively for professional use by adults. We do not knowingly collect personal data from persons under 18 years of age. If we become aware that we have collected data from a minor, we will delete it promptly. If you believe we have inadvertently collected data from a minor, please contact us at privacy@rielto.io.
10. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes via email or Platform notification at least 14 days before the changes take effect. The “Last updated” date at the top of this policy reflects the most recent revision. Your continued use of the Platform after the effective date constitutes acceptance of the updated policy.
11. Contact
For privacy-related questions, requests, or complaints:
Outview LLC — Privacy
5830 East 2nd St, Ste 7000
Casper, Wyoming 82609 — US
Email: privacy@rielto.io
For urgent data protection matters related to EU users, please mark your email subject line: [GDPR REQUEST]