Privacy notice
Last updated 10 October 2026
Who we are
CheckMyRental is a service of Neurova AI (sole proprietorship), Heideveldstraat 6, 5643 CH Eindhoven, Netherlands, KvK 94328900, VAT NL005076610B08. We decide why and how your data is used, so we are the controller under data protection law.
Questions about your data: support@checkmyrental.nl, +31 6 19919544.
What we collect and why
- Data
- Your answers to the 7 questions
- Why
- To apply the rules that fit your situation
- Legal basis
- Performing our agreement with you
- Kept
- Deleted with your order after 7 days (at the end of the 14th day after a payment, or 8 days after a re-check if that is later)
- Data
- The masked contract text you approve
- Why
- To check it against the rules
- Legal basis
- Performing our agreement with you
- Kept
- We delete it 24 hours after upload. Our AI provider deletes what it received within 30 days by default and may keep it longer where the law requires or to deal with misuse of its service (see the processors below)
- Data
- Findings and your report, with short quotes from the masked text (at most 300 characters each)
- Why
- To show your report
- Legal basis
- Performing our agreement with you
- Kept
- Findings: deleted 7 days after the analysis, or with their report. Report: deleted 7 days after it is delivered, and never later than your order
- Data
- Your email address, only if you give it for your link, your report or your order
- Why
- To send your link, your report or the order confirmation
- Legal basis
- Performing our agreement with you
- Kept
- Deleted with your order after 7 days (at the end of the 14th day after a payment, or 8 days after a re-check if that is later)
- Data
- Your email address for the scam checklist or the waitlist and, for the checklist, your six yes or no answers and the score
- Why
- To send the checklist you asked for, or to tell you when we support your language
- Legal basis
- Your request; tips and offers only with your separate consent, which you confirm by email before we send any
- Kept
- Checklist without consent to tips: 7 days. With consent to tips (after you confirmed it by email): until you unsubscribe, at most 24 months. Waitlist: 12 months. Deleted when you unsubscribe
- Data
- A keyed hash of your email address, with the time you asked for tips, the time you confirmed by email and the wording you agreed to
- Why
- To prove that you agreed. The Dutch consumer authority ACM expects us to be able to prove consent for up to 5 years after we send a message
- Legal basis
- Legal obligation; legitimate interest
- Kept
- Until 5 years after the last message we could send you, which is at most about 7 years after you agreed. It holds no readable email address, but it is still personal data, because we can check whether an address matches it
- Data
- Your account: your email address, your language, and the dates of your sign-ins
- Why
- To sign you in and to keep your report credits
- Legal basis
- Performing our agreement with you
- Kept
- Until you delete your account, or until 24 months after you last signed in, bought or used a credit, unless you still have credits you can use
- Data
- Report bundles you bought: the date, the price, the credits used and left, the end date, the version of the terms, and a one-way hash of the token in the withdrawal link of your order confirmation
- Why
- To deliver the reports you paid for, to handle a withdrawal and to remind you before credits expire
- Legal basis
- Performing our agreement; legal obligation (tax records)
- Kept
- With your account (24 months after a bundle ends); the payment record for 7 years, without your email address
- Data
- Sign-in links (your email address, and the link itself only as a one-way hash) and sign-in sessions (one-way hash)
- Why
- To sign you in securely
- Legal basis
- Performing our agreement; legitimate interest (security)
- Kept
- A link works for 15 minutes and a session for 12 hours; both are deleted a day after they end
- Data
- A keyed hash of your IP address, and counters made from a keyed hash of your email address or from the random number of your order or account (not the data itself)
- Why
- Rate limits and preventing abuse
- Legal basis
- Legitimate interest
- Kept
- Up to 2 days for the counters, 7 days with an order (to the end of the 14th day after a payment)
- Data
- The campaign tags in the address you came from (utm_source and similar), if there were any
- Why
- To see which advertising works
- Legal basis
- Legitimate interest
- Kept
- With your order; in the usage events without a link to you once your order is deleted
- Data
- What you type in the feedback box or when you flag a finding (up to 1,000 characters)
- Why
- To improve the rules and to correct errors
- Legal basis
- Legitimate interest
- Kept
- Deleted with your order
- Data
- The number of each payment message from Stripe and the order it was about
- Why
- To handle every payment message once
- Legal basis
- Performing our agreement; legitimate interest
- Kept
- 35 days
- Data
- Usage events (page and step counts, never contract text, names or email addresses)
- Why
- To see which steps work
- Legal basis
- Legitimate interest
- Kept
- Kept, without a link to you once your order is deleted
- Data
- Our hosting provider's request logs: your IP address, your browser type and the page address (not your report code, which browsers do not send to servers)
- Why
- To run the service and keep it secure
- Legal basis
- Legitimate interest
- Kept
- Up to 7 days on our current hosting plan (Railway's own retention)
- Data
- Payment and invoice data (amount, date, package, a Stripe payment reference, a keyed hash of your email address) and, as evidence if a payment is disputed, the time and version of your withdrawal waiver, the version of the terms and the time of delivery
- Why
- To take payment, handle refunds and keep our tax records
- Legal basis
- Performing our agreement; legal obligation (tax records)
- Kept
- Card or bank details are handled by Stripe, not by us. We keep a minimal invoice record until the end of the seventh year after the payment, the period Dutch tax rules require for business records. The waiver and delivery record of a report started with a bundle credit is kept until the end of the seventh year after that credit was used. Once a month we also download a copy of the payment, bundle and consent records to our own computer, and delete each file once its rows are past their keep date
- Data
- Messages you send us, for example by email
- Why
- To answer you
- Legal basis
- Legitimate interest; performing our agreement
- Kept
- 12 months after the last message in the conversation, then deleted (longer only while a complaint, refund or dispute is open)
| Data | Why | Legal basis | Kept |
|---|---|---|---|
| Your answers to the 7 questions | To apply the rules that fit your situation | Performing our agreement with you | Deleted with your order after 7 days (at the end of the 14th day after a payment, or 8 days after a re-check if that is later) |
| The masked contract text you approve | To check it against the rules | Performing our agreement with you | We delete it 24 hours after upload. Our AI provider deletes what it received within 30 days by default and may keep it longer where the law requires or to deal with misuse of its service (see the processors below) |
| Findings and your report, with short quotes from the masked text (at most 300 characters each) | To show your report | Performing our agreement with you | Findings: deleted 7 days after the analysis, or with their report. Report: deleted 7 days after it is delivered, and never later than your order |
| Your email address, only if you give it for your link, your report or your order | To send your link, your report or the order confirmation | Performing our agreement with you | Deleted with your order after 7 days (at the end of the 14th day after a payment, or 8 days after a re-check if that is later) |
| Your email address for the scam checklist or the waitlist and, for the checklist, your six yes or no answers and the score | To send the checklist you asked for, or to tell you when we support your language | Your request; tips and offers only with your separate consent, which you confirm by email before we send any | Checklist without consent to tips: 7 days. With consent to tips (after you confirmed it by email): until you unsubscribe, at most 24 months. Waitlist: 12 months. Deleted when you unsubscribe |
| A keyed hash of your email address, with the time you asked for tips, the time you confirmed by email and the wording you agreed to | To prove that you agreed. The Dutch consumer authority ACM expects us to be able to prove consent for up to 5 years after we send a message | Legal obligation; legitimate interest | Until 5 years after the last message we could send you, which is at most about 7 years after you agreed. It holds no readable email address, but it is still personal data, because we can check whether an address matches it |
| Your account: your email address, your language, and the dates of your sign-ins | To sign you in and to keep your report credits | Performing our agreement with you | Until you delete your account, or until 24 months after you last signed in, bought or used a credit, unless you still have credits you can use |
| Report bundles you bought: the date, the price, the credits used and left, the end date, the version of the terms, and a one-way hash of the token in the withdrawal link of your order confirmation | To deliver the reports you paid for, to handle a withdrawal and to remind you before credits expire | Performing our agreement; legal obligation (tax records) | With your account (24 months after a bundle ends); the payment record for 7 years, without your email address |
| Sign-in links (your email address, and the link itself only as a one-way hash) and sign-in sessions (one-way hash) | To sign you in securely | Performing our agreement; legitimate interest (security) | A link works for 15 minutes and a session for 12 hours; both are deleted a day after they end |
| A keyed hash of your IP address, and counters made from a keyed hash of your email address or from the random number of your order or account (not the data itself) | Rate limits and preventing abuse | Legitimate interest | Up to 2 days for the counters, 7 days with an order (to the end of the 14th day after a payment) |
| The campaign tags in the address you came from (utm_source and similar), if there were any | To see which advertising works | Legitimate interest | With your order; in the usage events without a link to you once your order is deleted |
| What you type in the feedback box or when you flag a finding (up to 1,000 characters) | To improve the rules and to correct errors | Legitimate interest | Deleted with your order |
| The number of each payment message from Stripe and the order it was about | To handle every payment message once | Performing our agreement; legitimate interest | 35 days |
| Usage events (page and step counts, never contract text, names or email addresses) | To see which steps work | Legitimate interest | Kept, without a link to you once your order is deleted |
| Our hosting provider's request logs: your IP address, your browser type and the page address (not your report code, which browsers do not send to servers) | To run the service and keep it secure | Legitimate interest | Up to 7 days on our current hosting plan (Railway's own retention) |
| Payment and invoice data (amount, date, package, a Stripe payment reference, a keyed hash of your email address) and, as evidence if a payment is disputed, the time and version of your withdrawal waiver, the version of the terms and the time of delivery | To take payment, handle refunds and keep our tax records | Performing our agreement; legal obligation (tax records) | Card or bank details are handled by Stripe, not by us. We keep a minimal invoice record until the end of the seventh year after the payment, the period Dutch tax rules require for business records. The waiver and delivery record of a report started with a bundle credit is kept until the end of the seventh year after that credit was used. Once a month we also download a copy of the payment, bundle and consent records to our own computer, and delete each file once its rows are past their keep date |
| Messages you send us, for example by email | To answer you | Legitimate interest; performing our agreement | 12 months after the last message in the conversation, then deleted (longer only while a complaint, refund or dispute is open) |
If you do not give us your data
You do not have to give us your email address to check a contract and read the free result. To pay, Stripe asks for one, so that the confirmation and your report link can reach you, and an account needs one. Without your answers and the masked contract text we cannot produce your report, because the rules we apply depend on them.
Masking in your browser
Your original file stays in your browser. Only the masked text you approve is sent; our AI provider (Anthropic) processes it outside the EU. We delete our copy 24 hours after upload; Anthropic deletes what it received within 30 days by default, and may keep it longer where the law requires or to deal with misuse of its service.
We read the text and mask names after labels such as Landlord or Huurder, addresses, bank account numbers, phone numbers, email addresses, dates of birth and ID numbers in your browser. You check the masked text, can mask more, and can unmask a name or an address that was masked by mistake, before you send it; bank account numbers, email addresses, phone numbers, ID numbers and dates of birth stay masked. Our server checks again and refuses text with an unmasked bank account number, email address, phone number, ID number or date of birth.
Masking is automatic and can miss a name or detail that is written in an unusual way. That is why you check the masked text before it is sent.
A contract can name other people, such as a landlord, an agent or co-tenants. Their details are masked in your browser before anything is sent (unless you unmask a name or an address yourself), and we cannot identify or contact them. If you think your own details were processed, write to support@checkmyrental.nl.
If you are a consumer, we are the controller of everything you send us, including other people's details in your lease. If you let out a home for income or otherwise use the service for your business, the lease holds your tenants' details: you decide why and how they are used, and we process them for you under the processing terms (the page Processing terms for business users, linked at the end of every legal page).
Who receives data (processors)
- Processor
- Anthropic
- Purpose
- AI model that finds and quotes clauses
- Data
- Only the masked contract text you approve. Never your answers, your email address or the original file
- Where and safeguards
- United States or worldwide: Anthropic's API offers no EU-only option (checked 8 October 2026). Transfers use the EU Standard Contractual Clauses in Anthropic's data processing addendum. Anthropic deletes API inputs and outputs within 30 days by default, may keep them longer where the law requires or to deal with misuse of its service, and may not train its models on them
- Processor
- Resend
- Purpose
- Sending email
- Data
- Your email address and the email (never contract text). A report link in an email opens your report, so keep your mailbox safe
- Where and safeguards
- United States. Resend's data processing addendum uses the EU Standard Contractual Clauses, and Resend states that it is certified under the EU-US Data Privacy Framework. Resend keeps sent emails and their logs for 30 days
- Processor
- Stripe
- Purpose
- Payments
- Data
- Email address and payment data. Stripe also decides for itself how to use some data, for example to prevent fraud and to meet its legal duties
- Where and safeguards
- Worldwide, as Stripe's agreement and privacy policy describe. Transfers to Stripe in the United States rely on the EU-US Data Privacy Framework and, if that fails, on the Standard Contractual Clauses in Stripe's data transfer addendum
- Processor
- Cloudflare Turnstile
- Purpose
- Bot check, only when switched on
- Data
- IP address and technical browser signals
- Where and safeguards
- United States. Cloudflare acts as our processor for the check, and decides for itself how to improve its bot detection. Its data processing addendum uses the EU Standard Contractual Clauses and the EU-US Data Privacy Framework
- Processor
- Hosting (Railway)
- Purpose
- Running the app and the database
- Data
- Everything above
- Where and safeguards
- Our servers and database run in Railway's Amsterdam region. Railway is a United States company that says its main processing is in the United States: for any access from outside the EU, its data processing addendum applies the EU Standard Contractual Clauses or the EU-US Data Privacy Framework
| Processor | Purpose | Data | Where and safeguards |
|---|---|---|---|
| Anthropic | AI model that finds and quotes clauses | Only the masked contract text you approve. Never your answers, your email address or the original file | United States or worldwide: Anthropic's API offers no EU-only option (checked 8 October 2026). Transfers use the EU Standard Contractual Clauses in Anthropic's data processing addendum. Anthropic deletes API inputs and outputs within 30 days by default, may keep them longer where the law requires or to deal with misuse of its service, and may not train its models on them |
| Resend | Sending email | Your email address and the email (never contract text). A report link in an email opens your report, so keep your mailbox safe | United States. Resend's data processing addendum uses the EU Standard Contractual Clauses, and Resend states that it is certified under the EU-US Data Privacy Framework. Resend keeps sent emails and their logs for 30 days |
| Stripe | Payments | Email address and payment data. Stripe also decides for itself how to use some data, for example to prevent fraud and to meet its legal duties | Worldwide, as Stripe's agreement and privacy policy describe. Transfers to Stripe in the United States rely on the EU-US Data Privacy Framework and, if that fails, on the Standard Contractual Clauses in Stripe's data transfer addendum |
| Cloudflare Turnstile | Bot check, only when switched on | IP address and technical browser signals | United States. Cloudflare acts as our processor for the check, and decides for itself how to improve its bot detection. Its data processing addendum uses the EU Standard Contractual Clauses and the EU-US Data Privacy Framework |
| Hosting (Railway) | Running the app and the database | Everything above | Our servers and database run in Railway's Amsterdam region. Railway is a United States company that says its main processing is in the United States: for any access from outside the EU, its data processing addendum applies the EU Standard Contractual Clauses or the EU-US Data Privacy Framework |
Transfers outside the EU
The masked contract text is processed by Anthropic outside the EU. Anthropic acts as our processor under its data processing addendum, which includes the European Commission's Standard Contractual Clauses for transfers outside the EU. We send Anthropic only the masked text you approve, never your name, email address, answers or original file.
The other providers in the table above are also based in the United States or process data there. The safeguard for each one is in the table. The EU-US Data Privacy Framework is in force; if a court ended it, the Standard Contractual Clauses in each provider's agreement remain our safeguard.
You can read these agreements on the providers' own websites: Anthropic https://anthropic.com/legal/data-processing-addendum, Resend https://resend.com/legal/dpa, Stripe https://stripe.com/legal/dpa, Cloudflare https://www.cloudflare.com/cloudflare-customer-dpa/ and Railway https://railway.com/legal/dpa.
Your rights
You can ask us to show you the data we hold about you, to correct it, to delete it, to limit how we use it, to give you a copy in a usable format, and to stop using it where we rely on our legitimate interest. Where we rely on your consent (tips and offers), you can withdraw it at any time; this does not affect what we did before.
Use "Download my data" and "Delete my data now" on your report to see and delete your order at once (until you unlock the full report, the download holds your answers, the masked text and the free preview, and the findings follow with the report). If you have an account, its page has "Download my account data" and "Delete my account". For anything else, or for data that is not linked to an order such as an email list entry, write to support@checkmyrental.nl. We answer within one month. We may ask you for the link to your report or to write from the email address we hold, so that we do not give your data to someone else.
Deleting your order or account does not reach the copies our providers keep for a short time under their own terms: Anthropic (what it received, 30 days by default, longer in the cases named above), Resend (sent emails and logs, 30 days) and Stripe (its own payment records, which it must keep by law). If you want the findings of an order that is not unlocked as part of a request for access under the GDPR, write to us and we answer within one month.
You can complain to the Autoriteit Persoonsgegevens, the Dutch data protection authority (https://autoriteitpersoonsgegevens.nl).
Cookies and analytics
We set no cookies. We use no advertising or tracking scripts, and the site loads its fonts and images from its own server. We count visits and steps ourselves, without cookies and without names, email addresses or contract text.
Your browser's session storage keeps your report link for the current tab while you pay, so you can come back from the payment page. While you answer the questions it also keeps what you typed (only your answers, never contract text), so a reload does not lose them: they stay for this tab for up to 24 hours and are removed when you send the check, press Start over or close the tab. Session storage is cleared when you close the tab.
If you sign in to an account, your browser's session storage keeps a sign-in token for this tab. It ends when you close the tab, when you sign out, after an hour without use, or after 12 hours at most. A new tab or window starts signed out; a sign-in you finish in another tab is passed on to the tabs of this site that are waiting for it. It is needed for the sign-in you asked for. It holds your email address and a sign-in code, and is removed when it ends. A report you open from your account page is kept for this tab in the same way and is forgotten when you sign out.
When the bot check is on, Cloudflare Turnstile runs on the page where you send your text and on the sign-in form: Cloudflare sees your IP address and technical browser signals, and keeps one small item in your browser (in its own storage area, not a cookie) to tell people from bots. Cloudflare does not publish what that item holds or for how long. We do not use it for advertising. On Stripe's payment page, Stripe's own cookie rules apply.
Security
Your file is read and masked in your browser. We never write contract text to our logs, and we delete data on a fixed schedule (see the table above). Connections to this site use HTTPS.
Automated processing
Your report is produced by software. It has no legal effect on you; you decide what to do with it.
An AI model (Claude, from Anthropic) finds and quotes the clauses in your masked contract text and checks every red quote, which can only lower a result. Fixed rules in our code decide every colour, and the explanations and the email draft are texts we wrote from official sources.
Changes
We will update this notice when something changes and show the date at the top.