Kalven Privacy Policy
Kalven is a Chrome extension for commercial real estate (CRE) brokers. It assists with property prospecting, prioritization, and workbook generation. This policy describes what data Kalven collects, how it is stored, and where it is sent.
What Kalven Does
Kalven runs inside your existing authenticated CoStar and TitlePro247 browser sessions. It reads property data from web pages you are already logged into, sends that data to the Anthropic Claude API for structured analysis using your own API key, and generates a downloadable Excel workbook with property prioritization and outreach recommendations.
Kalven is a CRE prospecting and prioritization tool. It does not provide lending recommendations, credit decisions, property appraisals, or investment advice.
Data Stored Locally
Kalven stores the following data in your browser using Chrome's built-in extension storage:
- Anthropic API key — stored in
chrome.storage.local(persists across sessions, encrypted at rest by Chrome, never synced to any server, never transmitted anywhere except as an authentication header to the Anthropic API atapi.anthropic.com). - UI preferences — city, state, asset type, and filter settings are stored in
chrome.storage.session(ephemeral; cleared automatically when you close your browser). - Selector schemas and page structure metadata — cached in
chrome.storage.sessionfor internal selector resolution. These contain only structural information about page layout (tag names, attributes, element positions). They never contain property data, contact data, or loan data. - Account session and entitlement tokens — when you sign in to a Kalven subscription, a short-lived signed entitlement token and account session metadata (your sign-in email, subscription status, renewal date) are stored in
chrome.storage.localalongside your profile and API key. These identify your subscription; they contain no property, contact, or loan data.
Property data, contact data, and financial data extracted from CoStar and TitlePro247 pages are held only in browser memory during your active session. They are never written to persistent storage, never synced, and never cached between sessions.
Data Sent Externally
Kalven sends data to four external services, each for a distinct and limited purpose:
- Anthropic Messages API (
https://api.anthropic.com/v1/messages) — extracted property, financial, and contact data is sent over HTTPS for AI-powered analysis. These requests are authenticated with your own Anthropic API key. You are responsible for your API usage costs and for reviewing Anthropic's terms of service and privacy policy. - Kalven backend (
api.kalven.ai) — account, billing, and entitlement metadata only: your sign-in email, subscription state, and entitlement-token requests. See "Account and Subscription Data" below for exactly what this service does and does not receive. - Stripe (
api.stripe.com, via Stripe Checkout and the Stripe Billing Portal) — payment processing for your subscription. Your card details are entered on and held by Stripe; Kalven never sees, stores, or transmits card numbers. - Resend (transactional email API) — used solely to deliver one-use sign-in links and codes to the email address you provide.
Kalven does not send data to any other third party, advertising network, analytics service, or data broker. No telemetry, usage analytics, or crash reporting is collected.
Account and Subscription Data
The Kalven backend handles only account, billing, entitlement, and operational metadata: sign-in email, Stripe customer/subscription/invoice identifiers and lifecycle state, renewal or billing dates, signed-token issuance/expiry metadata, and ordinary request/webhook logs such as timestamps, IP addresses, user agents, webhook event IDs, and error traces. It never receives, stores, logs, proxies, or transmits broker deal data, property data, owner/contact data, platform-derived records, Anthropic prompts/responses, generated reports, or Excel files.
The extension fetches an entitlement token when the popup opens or reopens, and again when you press Refresh; at those times it also tops the token up if less than two hours remain on it. It does not refresh the token in the background while the popup sits open. Before a run starts, it re-checks that token's expiry on your own machine, with no network request, and uses the cached token until it expires; after that a run is blocked until you reopen the popup or press Refresh. When a token is fetched or refreshed, the backend learns that an entitlement check happened at that time. It does not learn what property, platform, count, prompt, response, or report was involved.
Sub-processors: Vercel (hosting and database for account/billing/entitlement metadata), Stripe (billing), and Resend (sign-in email delivery). Anthropic processes per-broker API calls authenticated by your own API key and is not a sub-processor of Kalven's backend.
Data Generated Locally
Excel workbooks (.xlsx) are generated entirely within your browser using the ExcelJS library and saved to your Downloads folder via the Chrome downloads API. No workbook data leaves your browser.
Permissions
Kalven requests the following Chrome permissions:
| Permission | Purpose |
|---|---|
| tabs | Navigate and read CoStar and TitlePro247 tabs during analysis |
| storage | Store your API key and UI preferences locally |
| scripting | Execute extraction scripts on CoStar and TitlePro247 pages |
| sidePanel | Display the Kalven interface as a Chrome side panel |
| downloads | Save generated Excel workbooks to your Downloads folder |
| alarms | Keep the background service worker active during long batch analysis runs |
| tabGroups | Group platform tabs under a "Kalven" label for organization |
| debugger | Send trusted keyboard events to CoStar form fields that use strict input validation masks and reject standard programmatic DOM events |
Kalven also requests host permissions for product.costar.com, api.anthropic.com, www.titlepro247.com, and api.kalven.ai to operate within your authenticated sessions, communicate with the Anthropic API, and check your subscription status.
Your Responsibilities
- You must provide your own Anthropic API key. You are responsible for all API usage costs incurred through Kalven.
- You must comply with CoStar's and TitlePro247's respective terms of service.
- Kalven does not independently access CoStar or TitlePro247. It operates exclusively within your own authenticated browser sessions using your own credentials. Kalven does not store your platform login credentials.
Data Retention
Kalven retains no property, contact, or financial data after your browser session ends. Your API key persists in local storage until you remove it or uninstall the extension. UI preferences are cleared automatically when you close your browser.
Changes to This Policy
If this policy changes, the updated version will be posted at this URL with a revised "Last Updated" date.
Contact
For questions about this privacy policy, contact: joe@kalven.ai