Legal
Privacy Policy
Last updated . Draft pending legal review. Also as Markdown.
LenDb.ai is a DGB experiment by Alon Goren and Brobot, operated by Draper Goren Blockchain ("DGB", "we", "us"). This policy explains what personal information LenDb handles, why, and what you can do about it. It covers two groups of people: visitors who use the site, API or MCP server, and loan officers whose professional information appears in the directory.
The short version: we do not track who contacts which loan officer, we do not sell leads, and we only keep what we need to run a public directory.
1. Visitors
What we collect
- Usage analytics. We use Google Analytics 4 (GA4) to understand how the site is used in aggregate: pages viewed, approximate location (city or region level), device and browser type, referring site, and similar. GA4 sets cookies or similar identifiers in your browser to do this. We do not send GA4 your name, email, or which loan officer you contacted.
- Aggregate page counts. Our own servers count page views per day, separately for people and for bots (such as GPTBot or Googlebot). These counts contain no IP addresses and no user identifiers.
- Server and security logs. Our hosting provider (Vercel) and database provider (Supabase) keep standard technical logs, which can include IP addresses and user agents, for security, abuse prevention and debugging.
- Your theme choice. If you pick light or dark mode, we store that choice in your browser's local storage (
lendb-theme). It never leaves your device. - The human check. Contact details for a loan officer are shown only after a short human check, so bots cannot harvest them. The check confirms you are a person. We do not record which profiles you unlock or what you do with the details.
What we do not collect
- We do not ask you to sign in to search or read LenDb.
- We do not record who contacts which loan officer, and we never pass your details to a loan officer or lender.
- We do not sell or rent visitor information.
The contact form
If you use the contact form (or email us), we collect what you send: your name (optional), your email address, the subject and message, the kind of request (for example a correction, removal or profile claim), the page you were on, and the NMLS ID of the profile you are writing about, if any. We may also store your browser's user agent, approximate country and a spam score. We do not store your IP address with the request.
Each message is emailed to Alon Goren and saved as a support ticket in our database so we can track and answer it. We use it only to respond to you, handle your request, keep a record that we did, and prevent abuse.
Developer accounts and API keys
If you sign up for a free API key, we collect your email address, your name if you give it, how you signed in (email link, Google or GitHub; from Google or GitHub we use only your verified email address and display name), when you accepted the Terms of Use and which version, and when you last signed in. For each key we store its name, a short visible prefix, a one-way hash of the key (never the key itself), when it was created, last used or revoked, and how many calls it made each day. If an app or AI agent asks for a key for you, we also store the email address it gave, the key name and use case it described, and its user agent and approximate country. We do not store IP addresses with any of this; per-IP rate limits are counted in memory only.
We use this to run your account and keys, enforce limits, prevent abuse, and send you sign-in and approval emails (through our email provider, Resend). We do not send marketing email. You can revoke keys at any time and ask us to delete your account through the contact form.
2. Loan officers
What we hold and why
LenDb is a directory of licensed mortgage loan officers acting in their professional capacity. Federal and state law requires much of this information to be public so consumers can check who they are dealing with. We hold:
- Professional identity: name, NMLS ID, job title, current and past employers, branch location.
- Licensing: states licensed, license numbers, status and dates, and any public regulatory actions.
- Professional details: loan programs, property types and borrower situations the loan officer works with, languages spoken, years licensed, and a short summary of the professional bio published by their employer.
- Business contact information: office phone, business email, and links to the loan officer's page at their lender. These are shown on the website only after the human check, and never through the API or MCP server.
- Headshots: where a lender publishes one, we display it from the lender's own website. We remove it on request.
- Voice or video intros: where a lender publishes one, we may describe it in a sentence of our own and link to it on the lender's site. We do not embed the recording or republish its transcript.
- Claimed-profile additions: anything a loan officer adds after claiming their profile, labeled as self-reported.
We do not collect or infer race, color, religion, national origin, sex, marital or familial status, age, disability or any other protected characteristic. See our Fair lending statement.
Where it comes from
Public pages that lenders publish about their own loan officers, public records from state regulators (for example the Florida Office of Financial Regulation's published loan officer data), and loan officers themselves. We do not scrape NMLS Consumer Access or LinkedIn. Details are in Data sources and methodology.
Why we use it
To run a free, public, neutral directory that helps borrowers, AI assistants and search engines find a licensed loan officer suited to a specific situation, and to let anyone verify who a loan officer is and where they are licensed.
Choices for loan officers
You can claim your profile to correct and add to it, ask us to remove your contact details, headshot, bio summary or media, or ask us to correct anything that is wrong. Core public licensing facts (name, NMLS ID, employer, licenses and public regulatory actions) stay, because they are public regulatory information, but we will correct them if they are wrong. See Corrections, removal and claims.
3. Who we share information with
- Everyone, by design, for directory data. Loan officer directory information is public on the site, and most of it (not contact details) is available through the API and MCP server and may be read by search engines and AI systems, including for AI training.
- Service providers that run LenDb for us: Vercel (hosting), Supabase (database), Google (GA4 analytics), Cloudflare or a similar provider (the human check), our email provider, and Anthropic (the AI models we use to extract facts and summarize public pages; we send them public web content, not visitor data).
- Legal reasons: if required by law, or to protect the rights, safety and security of users, loan officers or DGB.
- Business changes: if LenDb or DGB is reorganized or sold, information may transfer to the successor under this policy.
We do not sell visitor information. We do not sell loan officer information. If that ever changes, we will update this policy first and comply with any registration and opt-out rules that apply.
4. Your privacy rights
Depending on where you live (including California, Colorado, Connecticut, Virginia, Texas, Oregon and other states with privacy laws), you may have the right to:
- know what personal information we hold about you and get a copy;
- correct inaccurate information;
- delete your information;
- opt out of the sale or sharing of your information, and of targeted advertising;
- not be treated differently for using these rights.
We offer these rights to everyone, whether or not a state law requires it. To make a request, use the contact form on LenDb.ai or email bot@lendb.ai and say which right you want to use. We will confirm your identity in a reasonable way (for a loan officer, usually by email to an address on your lender's page or by your NMLS ID), and respond within 45 days. You can use an authorized agent; we may ask for proof of their authority. If we deny a request, you can appeal by replying to our answer, and we will review it.
Global Privacy Control. We do not sell personal information. Where a state law treats analytics cookies as "sharing," we will honor browser opt-out signals such as Global Privacy Control.
Deletion and public records. For loan officers, a deletion request removes everything we are not keeping as public regulatory information. We will tell you what we kept and why.
5. Retention
- Support tickets: kept for up to 3 years after they are resolved, so we have a record of corrections and removals, then deleted.
- Developer accounts and keys: kept while the account exists. Daily call counts are kept for up to 2 years. Sign-in links and unapproved key requests expire within a day and are deleted on a rolling basis.
- Loan officer directory records: kept while the person is licensed or appears in our sources. A loan officer who disappears from all sources is marked "status unknown" after 90 days rather than deleted at once, so links and history stay accurate. Removed contact details are not re-added from future crawls.
- Raw copies of lender pages: kept compressed so we can re-check facts without re-crawling, and deleted or refreshed on a rolling basis.
- GA4 data: kept for GA4's configured retention period (we use the shortest standard setting available).
- Server logs: kept for the provider's standard period.
6. Security
We use reasonable safeguards: encrypted connections (HTTPS), database row-level security, a read-only database role for the website, private support tickets that are never shown publicly, rate limits and the human check on contact information, and least-privilege access for our team. No system is perfectly secure. If we learn of a breach that affects you, we will tell you as the law requires.
7. Children
LenDb is for adults and is not directed to children under 13 (or under 16 where a different age applies). We do not knowingly collect information from children. If you think a child sent us information, contact us and we will delete it.
8. AI and automated processing
We use AI models (currently Claude, from Anthropic) to extract facts from public lender pages, tag specialties, summarize bios and, in future, screen reviews for spam and personal data. Rankings are computed by published rules, not by profiling visitors. See Disclosures.
9. Changes
We will update the "last updated" date when this policy changes and note material changes on the site.
10. Contact
Privacy questions or requests: use the contact form on LenDb.ai or email bot@lendb.ai.