The same 10-item "getting sued" checklist we just ran on ourselves, run against the five competitors on the tracking list — EliseAI, Alven, Uniti, Lette, Fonio — from public evidence only (sites, policies, terms, trust centers). Companion to the PropFlow internal audit. 2026-08-13.
| Item | PropFlow | EliseAI | Alven | Uniti | Lette | Fonio |
|---|---|---|---|---|---|---|
| 1 · Privacy policy exists | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| 2 · Data collection disclosed | ✅ | ✅ | ✅ | ✅ | ✅ | ✅ |
| 3 · AI / automated decisions disclosed | ✅ | ✅ | ✅ | ⚠️ | ✅ | ⚠️ |
| 4 · Third-party processors named | ⚠️ 3 named | ✅ categories | ✅ 19 in DPA | ❌ none | ✅ 143 listed | ✅ by name+city |
| 5 · Deletion / retention rights | ❌ unenforced | ✅ portal+phone | ✅ 2-stage DPA | ✅ 24mo cap | ✅ | ✅ GDPR |
| 6 · Storage exposure | ✅ verified | ✅ | ✅ | unknown | ✅ | ✅ |
| 7 · Testimonials genuine | ⚠️ blog claims | ✅ named majors | ⚠️ first names | ⚠️ no people | ✅ verifiable | ⚠️ split |
| 8 · Cancellation path | ❌ 403 bug | ⚠️ B2B private | ⚠️ thin | ⚠️ term lock-in | ⚠️ none stated | unknown |
| 9 · Auto-renewal disclosed | ⚠️ terms silent | n/a public | ❌ | ✅ 30-day notice | ❌ | unknown |
| 10 · AI crisis / self-harm stance | ⚠️ none | ⚠️ ops only | ⚠️ none | ⚠️ marketing | ⚠️ none | ⚠️ none |
Everyone has a privacy policy that says they collect data. After that it splits: the Europeans (Lette, Fonio) and Alven publish detailed vendor lists because GDPR makes them; EliseAI has the most grown-up privacy operation (a request portal and a toll-free number); and nobody — not one of six companies — has published a plan for what their AI does when a tenant says something alarming. That last one is an open lane.
Posture: high/mature, multi-state. CCPA-category-style disclosure (down to biometrics and keystroke monitoring — unusually candid), profiling opt-out covering "provision or denial of housing," a live privacy-rights portal, a toll-free rights line, biometric-specific retention (BIPA-aware), Texas AG complaint routing. Policy refreshed Feb 2026. Testimonials fully attributed to verifiable majors (Equity Residential, LeFrak).
Citable gaps: no public subprocessor list (Trust Center is a JS-gated portal), no published AI-safety/crisis policy (only an ops article on emergency-maintenance call escalation), legal pages are embedded Google Docs that render empty without JS, and B2B cancellation terms aren't public. Retention default is "as long as we deem necessary."
Posture: unusually strong paper trail for its size. Public DPA with SCCs + UK addendum naming 19 subprocessors (Anthropic, Vapi, Telnyx, Twilio, OpenRouter…), two-stage deletion (soft at 6mo inactivity, hard on request, delete-or-return within 30 days of termination), public security annex, BC/DR contacts page. Clearly built for enterprise procurement via Vanta.
Citable gaps: the homepage badges "SOC 2 (Type I & II), ISO27001" while their own DPA says SOC 2 Type I is "Planned Q4 2026," Type II early 2027, ISO 27001 planned 2027 — the marketing overstates their own document. Testimonials are first-name-only against big brand names (unverifiable). No auto-renewal disclosure despite $10/unit/mo + free trial. Customer-side termination is "simply discontinue using the Service" — no refunds, no notice terms.
Posture: mid. Fresh privacy policy (July 2026), 24-month retention cap, deletion via ops@ email. Auto-renewal properly disclosed (12-month renewals, 30-day non-renewal notice). 11 named customer companies.
Citable gaps: zero third-party processors named (categories only — thin for a company claiming GDPR/CCPA/HIPAA readiness), no ADM rights section, no named individuals in testimonials, anonymous ROI metrics ("214% ROI, 170 sites"). And the B2B service terms say the service "may not be cancelled or terminated by Client during the Subscription Term" except for Uniti's own uncured breach — the hardest lock-in in the set. Their consumer T&C is two years stale with no billing terms.
Posture: strong on privacy, weak on commercial terms. GDPR-native (Dublin), trust center with 143 subprocessors, ISO 27001 claimed, explicit Art. 22 posture ("our AI does not make autonomous decisions that produce legal effects"), tenant-data categories disclosed, real verifiable testimonials (Grayling Properties MD confirmed via press).
Citable gaps: terms have no user-initiated cancellation procedure and no auto-renewal language ("payments are non-refundable"); no published crisis/AI-safety policy; the 143-entry subprocessor list looks auto-generated from an OAuth app inventory (includes Reddit and Pocket — sloppy hygiene). Marketing says "autonomous" while the policy says the opposite — a tension a buyer could poke.
Posture: complete legal stack, thin specifics. Vienna GmbH, German-law contracts, servers in Nuremberg, processors named with cities, EU-US DPF + SCCs, separate app privacy notice + public DPA + Swiss addendum.
Citable gaps: no Art. 22 ADM section and no explicit transcription disclosure despite being a voice-AI company; no concrete retention periods for call recordings; homepage EN testimonials ("Dr. Amanda Reyes, Family Medicine Practice") are generic US personas absent from their real (strong, named) customer-stories page — plausibly invented for the English market; binding terms are German-only and JS-rendered. No crisis protocol despite selling to medical practices.
Where we're ahead:
Where we're behind the pack:
The open lane nobody owns: a published AI safety & crisis protocol — what Clara does on emergencies AND on a distressed-tenant message (988, human escalation, business-flow stop). Zero of six companies have one. We already have the strongest real emergency handling in the set (deterministic gas/CO guard, emergency-relay agent); writing the crisis half and publishing the whole thing as a trust page makes us the only vendor a risk-averse operator can point their counsel at. Cheap to build, differentiating to publish.
We're not behind on the scary stuff — our security is the only independently checked one in the group. We're behind on paperwork transparency: competitors show their vendor lists and deletion processes; we say "email us." And there's one thing nobody in the industry has done — publish what their AI does when a conversation turns into a crisis — that we're actually best positioned to do first.