Privacy

This describes what Walkthrough collects, who can see it, who we share it with, and how long we keep it. It is written to be read, not skimmed past.

Effective August 15, 2026

The short version

  • A tenant never creates an account, is never charged, and is never asked for payment details.
  • Both parties to a tenancy receive the identical record. We do not show one side something the other cannot see.
  • We do not sell personal information, and we do not use anyone’s photographs or tenancy data to train machine-learning models.
  • We do not run advertising trackers, and nothing here follows you around the web. We do keep our own record of how the product is used, described below.

Who we are to you

A landlord or property manager signs up for Walkthrough and enters their properties, units and tenancies. In data-protection terms they decide what is collected about their tenancy and we process it on their behalf. If you are a tenant and want something changed or removed, the landlord who sent you the link is the first place to ask; you can also write to us at agallee36@gmail.com and we will help.

What we collect from landlords

  • An email address, used to sign in. We send a one-time link rather than storing a password.
  • Business or trading name, and a contact email shown to tenants.
  • Property addresses, unit labels and room layouts.
  • Tenancy details entered by the landlord: tenant name, tenant email, start and end dates, rent amount and due day where recorded.
  • Subscription status. Card details are entered on Stripe’s own pages and are never sent to or stored by us — we hold an identifier for the subscription and nothing more.

What we collect from tenants

A tenant opens a link, photographs the unit, and signs. There is no account and no password. From that we hold:

  • The name and email address the landlord entered, and any correction the tenant makes to it.
  • The photographs taken, and any notes typed alongside them.
  • Details the phone attaches to each photograph: the time the camera recorded, camera make and model, exposure settings, and the location coordinates, where the phone includes them. Phone cameras often embed GPS coordinates in a photo. Where they are present we keep them, because a photograph that can be placed at the unit is worth more than one that cannot. Where the phone or browser has stripped them, nothing is inferred and none is added. If you would rather not include them, turn off location access for the camera before you start.
  • Browser and device information — user agent string, platform, and window size — recorded with each photograph and with anything signed.
  • When a report or a notice is signed or acknowledged: the time, the IP address, and the browser user agent. These are recorded alongside the signature so that both parties can see the circumstances in which it was made.
  • Anything a tenant chooses to add afterwards: reported problems and their photographs, uploaded documents, and rent payment entries.

Times and fingerprints

Every photograph is fingerprinted with SHA-256 in the browser before it is uploaded, and the fingerprint is re-checked against the received bytes on our side. The time a record was received is taken from our database clock. Times reported by a phone are stored too, and are always labeled “device-reported” wherever they appear, because a phone’s clock can be wrong or changed.

Photographs cannot be deleted from a walkthrough

The capture history is append-only by design and is enforced that way in the database, not merely in the interface. Retaking a photograph adds a new one; it does not overwrite or erase the earlier one. Nobody — not the tenant, not the landlord, not us through the application — can quietly remove a photograph from a walkthrough after it has been taken. That is the property that makes the record worth anything to either side, and it is the trade-off for it.

This does not override your rights below. It means a deletion request is handled by us directly, on the record as a whole, rather than by a button that silently rewrites history.

Who can see what

  • A landlord sees only their own properties, units, tenancies and reports.
  • A tenant link opens only that tenancy. It does not reach any other tenancy, unit or landlord.
  • Signed reports are held identically by both parties, and each party’s copy carries the same document fingerprint.

These boundaries are enforced by row-level security in the database rather than by checks in application code alone.

Who we share it with

We use a small number of service providers, each for one job, all processing data in the United States:

  • Supabase — database, file storage and sign-in links.
  • Vercel — hosting and request logs.
  • Stripe — subscription payments for landlords. Tenants never reach Stripe.
  • Resend — sending the emails described above.
  • GrowthDesk — our own tool for seeing how Walkthrough is used. It receives the name of an action and an account identifier — that a unit was created, that a report was completed — and, when a landlord first sets up their account, the business name and contact details they entered. No tenant’s name or email address is ever sent to it, and no photograph, note, document or report ever leaves Walkthrough for it.

We do not sell personal information and we do not share it for cross-context behavioral advertising. Beyond the providers above, we disclose data only where the law requires it, and only to the extent it requires.

How long we keep it

A tenancy record is kept for as long as the landlord’s account holds it. The whole point of a move-in record is that it is still there at move-out, which can be years later, and deposit disputes and the statutes governing them run past the end of a tenancy. If a landlord closes their account we delete their properties, units, tenancies and the media attached to them within 90 days, other than anything we are required to keep for tax or legal reasons.

Error logs and email delivery records are kept for 12 months. Billing records are kept for as long as tax law requires.

Your rights

Depending on where you live you may have the right to ask for a copy of your data, to have it corrected, to have it deleted, or to object to how it is handled. California residents have these rights under the CCPA as amended, and residents of the EU and UK under the GDPR.

Write to agallee36@gmail.com and we will respond within 30 days. Requests are handled by a person rather than a form. If a request would require us to alter a signed record that the other party to the tenancy also holds, we will tell you plainly what we can and cannot do and why, rather than either refusing outright or quietly changing a document someone else is relying on.

We will never charge you, degrade the service, or treat you differently for exercising any of these rights.

Cookies and local storage

A landlord’s session cookie keeps them signed in; your browser also stores whether you prefer the light or dark appearance. On the tenant side, photographs waiting to upload are held in your browser’s own storage on your phone so that a dropped signal does not lose a photograph you have already taken; they are cleared once they have been sent.

There are no advertising cookies and no behavioral advertising trackers anywhere on this site. Our own record of how the product is used is described under the providers above.

Children

Walkthrough is for adults entering into or managing a tenancy. We do not knowingly collect information from anyone under 13.

Changes

If this policy changes in a way that affects what we collect or who we share it with, we will change the effective date at the top and email account holders before it takes effect.

Contact