Effective Date: April 17, 2026 · Last Updated: October 1, 2026
LoanDeck (“LoanDeck,” “we,” “us,” or “our”) is operated by LoanDeck LLC, a company based in Long Beach, California. This Privacy Policy explains how we collect, use, disclose, and protect information when you use LoanDeck at loandeck.app (the “Service”).
By using the Service, you agree to the practices described in this policy.
This policy applies to three types of users:
Brokers — licensed mortgage professionals who create accounts and use LoanDeck to build loan comparisons.
Clients — borrowers who receive and view a shared comparison link from a broker. Clients do not create accounts.
Realtors — people whose information a loan officer saves or who use a flyer-request link to send property details and images. Realtors do not need accounts to use those links.
Account information:
Professional profile information:
Comparison data:
Data imported from a connected loan origination system:
If you connect LoanDeck to your loan origination system (LOS), either through a direct API connection or through an automation platform such as Zapier, we import a limited, allowlisted set of fields to build a comparison for you:
We do not import Social Security numbers, dates of birth, borrower contact information, employment, income, credit scores or credit data, or contact details for third parties on the file such as escrow or HOA agents — even where the connected system makes those fields available to us. The allowlist is enforced in code, not by policy alone.
Loan files you import from your device:
You can also start a comparison from a loan file exported from your loan origination system (a MISMO 3.4 XML file). The file is read inside your browser. It is never uploaded to LoanDeck, stored by us, or sent to an AI provider.
Only the fields you review and approve are sent to LoanDeck to create a draft comparison. They come from the same limited set described above: loan and property terms, closing-cost totals and credits, and borrower and co-borrower names, unless you choose to leave names out. On a refinance, they also include the balance and monthly payment of the mortgage being refinanced.
Loan files often also contain Social Security numbers, dates of birth, contact details, employment, income, assets, other debts and demographic information. Those fields are not copied into the comparison and never leave your device. The field list is enforced in code, in your browser and again on our servers.
We record that a comparison was created from an imported file, when, and which fields came from it. We do not keep the file or its name.
Realtor data:
Files you upload:
Notification preferences:
Support chat conversations:
The assistant is instructed not to ask for client information, and the chat panel asks you not to paste client statements or Social Security numbers. We store whatever you send it, so please do not send those.
Usage data:
Engagement data:
We collect this engagement data to help brokers understand how their clients are interacting with their comparisons. This data is accessible to the broker who created the comparison.
From viewing a comparison, we do not collect:
Some comparisons let you try a different purchase price or down payment and send it to your loan officer to price. Your loan officer decides whether a comparison offers this. Nothing else on the page requires it, and nothing is sent unless you press the button to send it.
What we collect: the purchase price and down payment you entered, which loan option you started from, a copy of that option as it stood when you asked, and any note you write. We also keep a record of whether you were shown an estimate and, if so, its figures — worked out again on our servers rather than taken from your browser. We do not ask for your name, email address or phone number, and we do not store your IP address or browser details with the request. Please do not put account numbers or other personal financial details in the note.
What you are shown: your down payment and loan amount, always. Where the interest rate your loan officer set for that option would still apply to your figures, or would be on the high side, you are also shown an estimated monthly payment and cash to close, worked out from the rate, fees and assumptions your loan officer entered for that option. It is an estimate, not a quote or a loan approval, and your loan officer has not reviewed it. Where your change could raise the interest rate or the mortgage insurance — a smaller down payment, for example — we show no payment and tell you why, so that your loan officer prices it rather than the page guessing.
The estimate is worked out in your browser as you type. Nothing about it is sent anywhere unless you send the request.
Why we collect it: on behalf of the loan officer who shared the comparison, to deliver your request to them.
Where it goes: your request, including any estimate you were shown, is emailed to that loan officer and shown in their LoanDeck account. If they have connected LoanDeck to other tools — a CRM, an automation platform such as Zapier, or their own webhook endpoint — it is also sent to the destination they have chosen, at their direction, and is then governed by that service's terms and privacy policy rather than ours. We do not sell your information.
Who can see that you asked: anyone who has the link to the comparison can see that a request was made, the price and down payment it asked about, and whether it has been reviewed. Your note is shown only to the loan officer.
How long we keep it: until the loan officer deletes the comparison or their account is deleted — see Section 6. You can ask us to delete it at any time using the contact details in Section 11.
Some open-house comparisons include an optional form to request a personalized quote. Nothing else on the page requires it.
Some open-house comparisons also let you try your own purchase price and down payment on an example loan option. Where the example's interest rate would still apply to your figures, or would be on the high side, you are shown an example monthly payment and cash to close. It is an example based on sample credit, not a quote or a loan approval, and no loan officer has reviewed it. Where your change could raise the interest rate or the mortgage insurance, no payment is shown and you are told why. It is worked out in your browser as you type. Seeing it never requires your name or contact details, and nothing about it is sent anywhere unless you choose to submit the request form.
What we collect: the information you enter — your name and email address, and, if you provide them, your phone number, buying timeline, and any notes — and, if you tried your own numbers first, the purchase price and down payment you were trying, which example option you started from, and a record of whether you were shown an example estimate and its figures, worked out again on our servers rather than taken from your browser — together with your IP address and browser user-agent, which we keep in order to detect abuse of the form.
Why we collect it: we collect it on behalf of the loan officer whose comparison you are viewing. We use it to deliver your request to them and to email you a confirmation that it arrived. That loan officer sees it in their LoanDeck account and can add their own notes to it.
Where it goes: your request is emailed to that loan officer, and a confirmation is emailed to you. If the loan officer has connected LoanDeck to other tools — a CRM, an automation platform such as Zapier, or their own webhook endpoint — your request is also sent to the destination they have chosen, at their direction. Once it arrives there it is governed by that service's terms and privacy policy rather than ours. We do not sell your information.
How long we keep it: until the loan officer deletes it or their account is deleted — see Section 6. You can ask us to delete it at any time using the contact details in Section 11; we may also need to ask the loan officer to remove their own copy.
What stays after the loan officer deletes it: a small reporting record, so that we can count how many requests LoanDeck delivers to each loan officer and how many different people sent them. It holds when the request was made, which comparison it came from, whether the loan officer went on to build a comparison from it, and a scrambled code made from your email address. It does not hold your name, email address, phone number, notes or the figures you tried. The code is different for every loan officer, so it cannot be used to link your requests to different loan officers, and it cannot be turned back into your email address — though if you give us your address, we can find and remove the code, which is how we act on a request to delete it. The record is deleted when the loan officer's account is deleted — see Section 6.
A loan officer may send you a general flyer-request link or a personalized link containing information they saved about you. When you start or save a request, we collect the details you enter, including your contact and brokerage information, property details, notes, and any property photos, headshot, or logo you upload. A personalized request may already contain your name, contact details, headshot, or logo from the loan officer's saved realtor record.
As you type the property address, the characters you have entered are sent to our address lookup provider (Google) to suggest matching addresses. If you pick a suggestion, we also retrieve that address's city, state, ZIP code, county and map location and save them with your request.
We use this information to save your request, email you a receipt or correction request, notify the loan officer, and help them prepare an open-house comparison and flyer. The loan officer reviews the flyer and its financing information before sending it. Your request and uploads are shown to that loan officer in their LoanDeck account; the email notifications identify the property but do not attach your photos. We do not send flyer requests to the loan officer's connected CRM or automation services.
A private request link lets anyone holding it view the details and images you supplied, so keep it private. Images you upload through this form remain in private storage while the request is being completed. If the loan officer prepares a comparison or flyer, copies may receive publicly accessible URLs for use in shared materials. See Sections 5 and 6 for image access and retention. You can request deletion using the contact details in Section 11.
If you request access to the LoanDeck beta, we collect your email address so we can tell you when your invite is ready. You can also tell us how you heard about LoanDeck; that answer is optional. When you reach our site through a campaign link or from another website, we also record the campaign details in that link (such as its source and campaign name) and the name of the website that sent you, but not the page you came from. Your browser keeps these in session storage until you close the tab, so they can be sent with your request. If you also fill in the optional follow-up form, we collect what you enter there: the states you are licensed in, the tools you use today, what you want to try first, any other notes and, if you choose to give them, a mobile number and whether you agreed to be texted.
We use this to decide when to invite you, to contact you about your invite, to help you get set up and to learn how people hear about LoanDeck. Your request, your answers and the details recorded with them are stored in our database, and your follow-up answers, including any mobile number, are also emailed to us. None of it is sent to our analytics provider. We use your mobile number only to contact you one to one about your invite and setup. We text it only if you agreed to be texted, we never use it for bulk messaging without your consent, and we never sell it. You can ask us to delete any of it using the contact details in Section 11.
We use browser sessionStorage to temporarily cache market rate data and AI entry results during your session. If you start a request to review an option on a shared comparison, or try your own numbers on an open-house comparison, what you have typed is kept the same way so that reloading the page does not lose it. A request you send is removed from it at once. This data is stored locally on your device and cleared when you close your browser tab. It is not transmitted to our servers beyond the normal course of using the Service.
To provide the Service:
To communicate with you:
To improve the Service:
We do not:
LoanDeck uses third-party services to operate. Each has its own privacy policy governing how they handle data. We use services in the following categories:
Database and authentication providers
Store your account data, comparisons, templates, realtor records, and uploaded files securely. Row-level security policies ensure brokers can only access their own data.
Email delivery services
Send transactional emails including account confirmation, password reset, comparison activity notifications, and flyer-request receipts and corrections.
AI processing services
Power AI features including the AI Loan Entry tool, mortgage statement and fees worksheet data extraction, email summary generation, and the in-app help assistant. We use two AI providers: a primary provider and a fallback provider used when the primary is unavailable. Both providers process requests via API and do not use API request content to train their models, per their respective data processing terms.
Some AI features work with your clients’ information, and only when you use them:
LoanDeck does not add Social Security numbers, dates of birth or account numbers to what it sends. They reach an AI provider only if they appear in a document you upload or text you enter. Loan files you import from your device are never sent to an AI provider.
Voice dictation uses your browser’s built-in speech recognition. LoanDeck receives only the resulting text, never the audio. Some browsers, including Chrome and Edge, send the audio to their maker (Google or Microsoft) to transcribe it, under that company’s privacy terms.
The help assistant sends your messages, and the text of our help articles, to the AI provider each time you send a message. If you paste document contents into the chat, those contents are sent to the provider along with your message.
Product analytics services
Help us understand how brokers use LoanDeck so we can improve the product. Analytics data may include usage events, feature interactions, device and browser information, IP address, and session recordings of the signed-in broker application as described in Section 2. On pages that do not require an account — including the comparison page a client opens from a shared link — nothing is sent to our analytics provider unless you accept analytics in the cookie banner, and no session recording is ever made there.
Hosting and infrastructure providers
Host the application and process web requests. May receive request logs and IP addresses.
Address lookup and mapping services
Power address autocomplete when you enter property locations.
Real estate and rental data providers
Supply market data including home price trends, rental rate estimates, and days on market displayed in location cards.
Mortgage rate data providers
Supply current mortgage rate data used to populate rate suggestions.
PDF generation services
Render comparison and flyer PDFs from your comparison data.
Video embedding services
Enable video previews when you add a YouTube, Vimeo, Loom, or similar video URL to a comparison.
Loan origination system integrations
Retrieve loan data from the LOS you connect, either directly or through an automation platform such as Zapier. Where an automation platform sits in the middle, the data passes through that platform and is subject to its privacy policy and to your own account settings there, including its record of past runs.
We do not sell your information to any third party. We share data with the service providers above only to the extent necessary to run the Service. Separately, we transmit data to services you connect, at your direction — see below.
Separately from the providers above, LoanDeck can send comparison events to services you choose to connect — a Zap, a CRM, or a webhook endpoint you supply. This is different in kind from the list above: you direct it, you choose the destination, and once the data arrives there it is governed by that service's terms and privacy policy, not ours.
When an event fires, the payload includes the comparison title, the client name you entered, the share link, the transaction type, the property address and MLS number if you added one, and for each loan option its label, loan type, rate, term, monthly payment, cash to close, and APR. It does not include uploaded documents, tax or income figures, or debt consolidation details.
Where a comparison includes an open-house request form, the event that fires when someone submits it also includes that person's name, email address, phone number, timeline and notes, and, if they tried their own numbers first, the purchase price and down payment they were trying and any example estimate they were shown. This is the one outbound event that carries a prospective borrower's contact details, and it fires only when they have filled in the form themselves.
Where you have let a client ask you to review another option, the event that fires when they send a request also includes the purchase price and down payment they asked about, the loan option they started from, and any note they wrote. It is marked as not reviewed, because nothing in it has been priced. If the client was shown an estimated payment before sending, the event says so and includes that estimated monthly payment and cash to close; otherwise it carries no payment figure. It carries no contact details, because that form does not ask for any.
We require webhook destinations to use HTTPS. We keep a log of these deliveries, including the payload sent — see Section 6 for how long.
Subprocessors: A current list of the subprocessors we use to provide the Service is available on request at hello@loandeck.app.
Your data is stored with our database provider, hosted in the United States. We implement the following security measures:
Support access: LoanDeck support can view a comparison's contents only when you explicitly grant access from within the app. Grants are limited to a single comparison, expire automatically after 7 days, and can be revoked at any time. Every support view is recorded in that comparison's activity history, visible to you. Separately, LoanDeck operators maintain infrastructure-level database access used solely for debugging, security, and operations.
Note on uploaded images: Images submitted through a realtor flyer-request link are stored privately while the request is being completed. When the loan officer prepares a comparison or flyer, copies may be stored with publicly accessible URLs so they can appear in shared materials. Other profile images, logos, and property photos you upload are stored with publicly accessible URLs for shared comparisons and PDF exports. Anyone with a public image URL can view it. Do not upload images containing sensitive personal information.
Note on pasted image URLs: Where you supply a property photo by entering a URL rather than uploading a file, we store only the URL. The image itself stays on whatever server hosts it, and your client's browser loads it from there when they open the comparison — which means that server can see that the image was requested. When we generate a PDF or flyer we fetch the image once, server-side, and embed a copy in that document.
While we take reasonable measures to protect your data, no method of transmission or storage is 100% secure. We cannot guarantee absolute security.
Account data: Retained for as long as your account is active. You may request account deletion by contacting hello@loandeck.app or using the account deletion option in Settings. Upon deletion, your data will be removed within 30 days.
Comparisons: Retained until you delete them or request account deletion.
Open-house requests: A request submitted through the form on an open-house comparison is retained until the loan officer deletes it or their account is deleted. It is not pruned automatically.
Realtor flyer requests: Requests still in draft status expire after 14 days and are scheduled for deletion about 30 days after creation, unless the loan officer extends the link. Submitted requests, uploaded images, and submission history are not automatically deleted. They remain until the loan officer's account is deleted or a deletion request is fulfilled. Images copied for a comparison or flyer may remain at publicly accessible URLs until that account deletion or a fulfilled deletion request, even if the comparison itself is deleted.
Open-house request reporting records: Each open-house request also creates the reporting record described in Section 2. It is kept after the loan officer deletes the request, until the loan officer's account is deleted. It contains no name, contact details, notes or figures; its scrambled email code is removed on request.
Requests to review an option: A request a client sends from a shared comparison is retained until that comparison is deleted or the loan officer's account is deleted. It is not pruned automatically.
Uploaded files: Retained until you delete them or request account deletion. This covers logos, headshots and property photos.
Feedback screenshots: Screenshots attached to a bug report or question through the Feedback button are stored privately and deleted automatically after 90 days. The report itself is kept, so the record of what was reported remains after its images are gone.
Session recordings: Retained for up to 30 days, then deleted. Deletion is not instantaneous, so a recording may persist for a short time past that window.
Support chat conversations: Retained for 90 days, then deleted automatically. The topic summaries described in Section 2 are deleted alongside the conversation they came from.
Usage logs: Retained for 12 months, then deleted automatically.
Digest queue: Records of client view activity queued for daily digest emails are deleted automatically 30 days after the digest is sent.
Integration activity logs: Records of events sent to services you connect are retained for 90 days, then deleted automatically. Each record includes the payload that was sent, described in Section 4, so it contains the client name and loan figures for that comparison.
Depending on where you are located, you may have the following rights:
California residents (CCPA):
All users:
To exercise any of these rights, contact us at hello@loandeck.app.
LoanDeck uses cookies and similar tracking technologies for:
Necessary cookies: Required for authentication and session management. Cannot be disabled.
Analytics: Used to understand how brokers use LoanDeck so we can improve the product. On the public site and on the comparison page a client opens from a shared link, analytics are off until you accept them in the cookie banner, and no session recording is made on those pages at any time. The banner is not shown inside the signed-in broker application, where account holders have agreed to these terms at signup; analytics and the session recording described in Section 2 run there by default.
Marketing cookies: Not currently used.
LoanDeck is a professional tool intended for licensed mortgage brokers. We do not knowingly collect information from anyone under 18 years of age. If you believe a minor has provided us with personal information, contact us at hello@loandeck.app and we will delete it.
We may update this policy from time to time. When we do, we will update the “Last Updated” date at the top of this page and, for material changes, notify you by email. Your continued use of the Service after changes are posted constitutes your acceptance of the updated policy.
If you have questions about this Privacy Policy or how we handle your data:
Email: hello@loandeck.app
Website: https://loandeck.app
LoanDeck LLC
Long Beach, California