Privacy Policy
1. Two kinds of people this policy covers
Understanding our role depends on which one you are.
Loan officers (our customers)
If you create an account, you are our customer. We collect your information directly from you, and we are responsible for how we handle it. This policy describes that handling.
Borrowers (our customers' clients)
If you are a borrower, we did not get your information from you — your loan officer entered it. We store and process it on their behalf and on their instructions, so they can build you a loan comparison. In privacy terms, your loan officer (and their company) decides what is collected and why; we are their service provider.
Practically, that means: if you want your information corrected or deleted, start with your loan officer — they control the record and can change or delete it directly. You can also contact us at support@ask.mortgage and we will help, but in most cases we will need to work through the loan officer who holds the relationship with you.
2. What we do not do
It is easier to trust a privacy policy that says what isn't happening. As of the effective date above, all of the following are true of our software:
- We do not sell personal information. Not to lenders, not to advertisers, not to lead buyers, not to data brokers, not to anyone.
- We do not use advertising or tracking technology. There is no Google Analytics, no advertising pixel, no remarketing tag, no session-replay tool, and no cross-site tracking anywhere in our product.
- We do not market to borrowers. If your loan officer entered your information, we will not email you, text you, or advertise to you.
- We do not collect borrower income. There is no income field, and no household size, assets, employment, Social Security number, or date of birth field anywhere in the Service. We designed it that way deliberately.
- We do not pull credit or obtain credit reports. We are not a consumer reporting agency. Any credit score in the Service was typed in by a loan officer.
- We do not build profiles across sites or sell insights derived from your data.
If any of this changes, we will update this policy — and, where consent is required, ask for it — before the change takes effect.
3. Information we collect
A. Loan officer account and profile information
Provided by you when you register and set up your profile:
- Name, email address, and password (stored only as a salted hash by our authentication provider — we never see or store your plaintext password).
- Business details: company name, team or DBA name, company address, company website, phone numbers, and your loan application URL.
- Licensing details: your NMLS number, your company's NMLS number, and the states you are licensed in.
- Branding images: headshot, personal logo, company logo, team/DBA logo. See the note below — these are stored publicly.
- Your default fee assumptions, scenario templates, and fee templates.
Headshots and logos are stored at public URLs so they can render on borrower reports, which are viewable without a login. Anyone with an image's direct URL can view it. Upload only images you intend to be publicly visible.
B. Borrower information — entered by loan officers
To build a comparison, a loan officer may enter, and we may store:
- Borrower name and contact information — only if the loan officer chooses to enter it. These fields are optional. They exist so a loan officer can keep their own client list organized, not because the comparison needs them. A report can be built without any borrower identity at all.
- A credit score used for pricing. See the note below — this is not what it may sound like.
- Veteran status and VA entitlement usage, where relevant to VA loan eligibility.
- Whether the borrower has an existing FHA loan.
- Subject property details: location, state, property type, and occupancy type.
- Loan assumptions and outputs: loan amounts, rates, points, fees, closing costs, cash to close, payment figures, and the resulting comparison scenarios and saved reports.
That is the complete list. It is stored so loan officers can save, revisit, and share the comparisons they build, and we use it for nothing else.
Mortgage pricing is tiered by credit score, so a loan officer has to tell the tool which tier to quote at in order to produce a rate. The number stored is the score the pricing was quoted at — an assumption the loan officer typed in to select a pricing tier.
It is not a credit report, not a score we obtained, and not a representation that a borrower's actual score is that number. We never pull credit and we have no connection to any credit bureau.
Because it is an assumption rather than a measurement, the borrower report never displays it as an exact number. It is shown only as a 20-point range — for example “740–759” — which is all the pricing actually depends on, since rate sheets price in tiers. The report labels it as the range the pricing was quoted at, states that no credit was pulled, and tells the borrower their real score may fall in a different range, which would change their pricing.
We do not collect borrower income, household size, assets, employment, Social Security number, or date of birth. Those fields do not exist in the product. A loan comparison can be built without them, so we chose not to hold them — the safest way to protect sensitive data is not to have it.
C. Technical information collected automatically
When you use the Service, our hosting and infrastructure providers generate ordinary operational records — IP address, browser and device type, timestamps, requested pages, authentication events, and error logs. We use these to keep the Service running, secure, and debuggable. We do not use them to profile, target, or track anyone across sites.
D. Information we do not receive
We do not receive credit reports, loan origination system feeds, CRM imports, pricing engine data, or other third-party financial data. If we ever add such an integration, we will update this policy before it goes live.
4. Borrower report links are public by design
When a loan officer shares a report with a borrower, the Service generates a link containing a unique, hard-to-guess token. Anyone who has that link can open the report without logging in. The link does not verify who is opening it.
This is deliberate — it is what lets a borrower open their report by tapping a link in a text message without creating an account. But it also means that anyone the link is forwarded to can see the report, including the borrower's name and the financial figures it contains.
Client report links expire 120 days after the report was last published. After that the link stops working and shows a message directing the borrower back to their loan officer, who can reissue it. Publishing a report — or publishing an update to it — starts a fresh 120 days. A loan officer editing and saving a private draft does not extend the link, because saving does not change what a borrower sees. Links expire so that one which is forwarded, or simply forgotten in an old email, does not stay open indefinitely.
Marketing comparisons are different. A loan officer can also build a general comparison with no borrower and no contact attached — for a flyer, an open house, a social post, or agent education. These contain no information about any individual, so their links do not expire and are meant to be shared publicly.
Loan officers: you choose who receives these links, and you are responsible for that choice. Send them only to the borrower and to people the borrower has authorized. Do not post them anywhere public.
Borrowers: treat your report link like a private document. Anyone you forward it to can see it, for as long as it remains live.
A report's link also stops working immediately if the loan officer archives or deletes the report. Report data is never carried inside the link itself — the link is only a reference to a stored report, which is what allows it to be expired and revoked. If you believe a link has been exposed, contact us at support@ask.mortgage and we can deactivate it.
5. How we use information
We use the information described above only to:
- Create and authenticate accounts and keep you signed in.
- Operate the Service — generate comparisons, build reports, save contacts and templates, and serve borrower report links.
- Provide support when you contact us, and send you transactional messages about your account, security, and material changes to the Service or our policies.
- Keep the Service secure, available, and working — monitoring, troubleshooting, backups, and abuse prevention.
- Investigate fraud, abuse, or violations of our Terms of Service.
- Comply with the law and respond to lawful requests.
We do not use borrower information for our own marketing, product analytics, advertising, or model training.
6. How we share information
We share information in four situations, and no others:
- Infrastructure providers. The Service runs on Supabase (database, authentication, file storage) and Cloudflare (hosting and content delivery). They process data on our behalf to run the Service. They are not permitted to use it for their own purposes.
- With the borrower's loan officer. Borrower information is visible to the loan officer who entered it — that is the entire point of the product.
- Legal and safety. We may disclose information when required by law, subpoena, court order, or legal process, or when we reasonably believe disclosure is necessary to investigate fraud, prevent harm, or enforce our agreements.
- Business transfers. If Ask Mortgage is involved in a merger, acquisition, financing, or sale of assets, information may transfer as part of that transaction, subject to confidentiality protections. We will not allow personal information to be used in ways inconsistent with this policy without giving notice first.
We do not share information with lenders, advertisers, lead buyers, or data brokers.
7. Financial privacy, GLBA, and Regulation P
Mortgage-related information — credit score, income, assets, employment, loan terms — can be “nonpublic personal information” under the Gramm-Leach-Bliley Act and Regulation P. Those rules generally require a covered financial institution to give consumers a privacy notice and to limit how it discloses their information.
Ask Mortgage is not a lender, broker, or financial institution. We are a software provider to mortgage professionals, and we process borrower information as their service provider. The obligation to give borrowers a GLBA/Regulation P privacy notice rests with the loan officer's licensed company, not with us — and using Ask Mortgage does not satisfy or replace that obligation.
8. Cookies and similar technologies
We use only what is necessary to make the Service work. Specifically, we store a login session in your browser so you stay signed in, and we remember that a borrower has acknowledged the report disclosure for the duration of their visit.
We do not use advertising cookies, marketing pixels, or third-party analytics or tracking cookies of any kind. There is no cookie banner because there is nothing to consent to beyond the strictly necessary session storage described above. If we add analytics or any tracking technology later, we will update this policy — and add any legally required consent mechanism — before turning it on.
Blocking browser storage entirely will prevent you from staying signed in.
9. Data retention
Here is exactly how long we keep things, and how to make them go away sooner.
- Your account and everything in it — profile, contacts, reports, templates — is kept for as long as your account is open.
- Closing your account permanently deletes your data within 30 days. Email support@ask.mortgage and we will close it. The 30 days is a grace period in case the closure was a mistake; after that the data is gone and cannot be recovered.
- Deleting a contact removes it immediately. No recycle bin and no grace period — when a loan officer deletes a contact, it is gone from our active systems.
- Archiving a report immediately kills its borrower link. The report itself stays in the loan officer's account so they can refer back to it. To have reports permanently deleted, email us and we will do it within 30 days.
- Borrower report links on client reports expire 120 days after the report was last published. Marketing comparisons contain no borrower information, so their links do not expire.
- Operational and security logs (IP addresses, request records, error logs) are generated by our hosting providers and kept only as long as needed to run the Service securely and investigate abuse.
- Backups. Deleted data may persist in our provider's encrypted backups for a short period before those backups rotate in the ordinary course. We do not restore a backup to recover data someone asked us to delete.
A loan officer's edits are a private draft. Nothing reaches a borrower until the loan officer deliberately publishes the report — and every publication is recorded permanently: exactly what was published, and when. If they publish a revision later, the earlier version stays frozen alongside it. These records are retained for 3 years and survive archiving, deletion, and account closure. Neither the loan officer nor Ask Mortgage can edit or delete them.
This means the figures at your link cannot change without that change being on the record. If your loan officer publishes an update, your report will tell you it was updated and when — mortgage pricing moves daily, and you should never have to wonder whether you misremembered what you were shown.
We do this because a borrower is entitled to a truthful record of what they were shown. It means a loan officer cannot quietly change the numbers under a link a borrower already relied on, and it means that if there is ever a dispute about what was represented, the answer exists. It also lets the loan officer's company meet the record-keeping rules that apply to mortgage advertising.
This is the one thing we will not delete on request, because deleting it would destroy the borrower's evidence, not just the loan officer's. It contains only what the borrower was already shown.
10. Security
We use reasonable administrative and technical safeguards appropriate to the sensitivity of the information we handle, including encryption in transit, encryption at rest through our infrastructure providers, authenticated access with row-level authorization so that loan officers can only reach their own records, and hashed password storage.
No system is perfectly secure, and we cannot guarantee absolute security. The most likely way borrower information is exposed through this Service is not a breach of our systems — it is a report share link being sent or forwarded to the wrong person. Please re-read section 4.
If you discover a vulnerability, report it to support@ask.mortgage. We will not pursue legal action against researchers who report issues in good faith and give us a reasonable chance to fix them.
11. Your choices and requests
Loan officers can view and edit profile information, contacts, reports, and templates directly in the app, and can archive or delete reports at any time. To close your account or request deletion of your data, email support@ask.mortgage.
Borrowers should contact the loan officer who prepared their report — they control the record and can correct or delete it. If you cannot reach them, or you do not know who entered your information, email us at support@ask.mortgage and we will help you identify and reach the right party.
We will honor requests as required by applicable law, subject to our need to verify identity and to retain certain records for legal, security, and backup purposes. We will never charge you or discriminate against you for making a privacy request.
12. Children's privacy
The Service is a professional tool and is not directed to children. We do not knowingly collect personal information from anyone under 18 through the Service. If we learn we have, we will delete it.
13. Third-party links
Borrower reports may link to destinations a loan officer configures, such as their own loan application page or company website. The landing page may link to other resources. We do not control those sites and are not responsible for their privacy practices. Review their policies directly.
14. Changes to this policy
We may update this policy. If we make material changes — particularly any change to what we collect, how we use it, or who we share it with — we will update the “Last updated” date, post the revised policy here, and notify account holders by email or in-product notice. We keep dated copies of prior versions.
15. Contact
Privacy questions, deletion and correction requests, support, and security reports all reach us by email. We read every message sent here.
Borrowers: if your question is about information a loan officer entered about you, contact that loan officer first — they control the record and can correct or delete it directly. If you cannot reach them, write to us and we will help.