MakeProp

Security

How we protect your data

Real estate agents trust MakeProp with property photos and client-adjacent listing data. We take that seriously. Here’s exactly how your data is protected.

Encryption in transit and at rest

All communication between your browser and MakeProp uses TLS 1.2+ encryption. Photos and data stored in our database are encrypted at rest by Supabase (AES-256).

Authentication by Supabase

Passwords are hashed using bcrypt and never stored in plaintext. Session tokens are short-lived, cryptographically signed JWTs managed by Supabase Auth.

Data hosted on AWS

Supabase runs on AWS infrastructure. Your data stays in the region where your Supabase project is provisioned. Supabase is SOC 2 Type 2 compliant.

Row-level security

Every database query is scoped to your user ID using Supabase Row Level Security policies. No query can access another user's listings or photos.

Data deletion

Deleting a listing removes its associated photos from storage. To request full account deletion, email hello@makeprop.com and we'll remove your data, subject to backups and legal obligations.

No ad tracking

MakeProp uses no third-party advertising trackers or analytics pixels. We collect only the data necessary to operate the service.

AI processing pipeline

MakeProp uses two external AI services to process your data. Here’s exactly what each one receives:

Receives: Individual listing photos (original or enhanced JPGs)

Purpose: Photo enhancement and virtual staging

Retention: Not retained beyond the processing request

Anthropic (Claude)

anthropic.com/privacy

Receives: Property text data: address, city, state, price, bedroom count, bathroom count, square footage, property type, and buyer persona

Purpose: MLS copy generation, social captions, Listing Score

Retention: Subject to Anthropic's API data policy; no photos are sent

Responsible disclosure

If you discover a security vulnerability in MakeProp, please report it responsibly to hello@makeprop.com with the subject “Security Disclosure.” We’ll acknowledge your report and work to resolve confirmed vulnerabilities as quickly as we can.

Please do not publicly disclose vulnerabilities until we’ve had a reasonable opportunity to investigate and patch them. We appreciate the security community’s help in keeping MakeProp safe.

Questions about security?

Reach us at hello@makeprop.com and we’ll get back to you.