Do Our Competitors Do This?

The same 10-item "getting sued" checklist we just ran on ourselves, run against the five competitors on the tracking list — EliseAI, Alven, Uniti, Lette, Fonio — from public evidence only (sites, policies, terms, trust centers). Companion to the PropFlow internal audit. 2026-08-13.

The matrix

ItemPropFlowEliseAIAlvenUnitiLetteFonio
1 · Privacy policy exists
2 · Data collection disclosed
3 · AI / automated decisions disclosed⚠️⚠️
4 · Third-party processors named⚠️ 3 named✅ categories✅ 19 in DPA❌ none✅ 143 listed✅ by name+city
5 · Deletion / retention rights❌ unenforced✅ portal+phone✅ 2-stage DPA✅ 24mo cap✅ GDPR
6 · Storage exposure✅ verifiedunknown
7 · Testimonials genuine⚠️ blog claims✅ named majors⚠️ first names⚠️ no people✅ verifiable⚠️ split
8 · Cancellation path❌ 403 bug⚠️ B2B private⚠️ thin⚠️ term lock-in⚠️ none statedunknown
9 · Auto-renewal disclosed⚠️ terms silentn/a public✅ 30-day noticeunknown
10 · AI crisis / self-harm stance⚠️ none⚠️ ops only⚠️ none⚠️ marketing⚠️ none⚠️ none
In plain terms

Everyone has a privacy policy that says they collect data. After that it splits: the Europeans (Lette, Fonio) and Alven publish detailed vendor lists because GDPR makes them; EliseAI has the most grown-up privacy operation (a request portal and a toll-free number); and nobody — not one of six companies — has published a plan for what their AI does when a tenant says something alarming. That last one is an open lane.

Company by company

EliseAI — the mature one

Posture: high/mature, multi-state. CCPA-category-style disclosure (down to biometrics and keystroke monitoring — unusually candid), profiling opt-out covering "provision or denial of housing," a live privacy-rights portal, a toll-free rights line, biometric-specific retention (BIPA-aware), Texas AG complaint routing. Policy refreshed Feb 2026. Testimonials fully attributed to verifiable majors (Equity Residential, LeFrak).

Citable gaps: no public subprocessor list (Trust Center is a JS-gated portal), no published AI-safety/crisis policy (only an ops article on emergency-maintenance call escalation), legal pages are embedded Google Docs that render empty without JS, and B2B cancellation terms aren't public. Retention default is "as long as we deem necessary."

Alven — the procurement-ready one (with a badge problem)

Posture: unusually strong paper trail for its size. Public DPA with SCCs + UK addendum naming 19 subprocessors (Anthropic, Vapi, Telnyx, Twilio, OpenRouter…), two-stage deletion (soft at 6mo inactivity, hard on request, delete-or-return within 30 days of termination), public security annex, BC/DR contacts page. Clearly built for enterprise procurement via Vanta.

Citable gaps: the homepage badges "SOC 2 (Type I & II), ISO27001" while their own DPA says SOC 2 Type I is "Planned Q4 2026," Type II early 2027, ISO 27001 planned 2027 — the marketing overstates their own document. Testimonials are first-name-only against big brand names (unverifiable). No auto-renewal disclosure despite $10/unit/mo + free trial. Customer-side termination is "simply discontinue using the Service" — no refunds, no notice terms.

Uniti — the lock-in one

Posture: mid. Fresh privacy policy (July 2026), 24-month retention cap, deletion via ops@ email. Auto-renewal properly disclosed (12-month renewals, 30-day non-renewal notice). 11 named customer companies.

Citable gaps: zero third-party processors named (categories only — thin for a company claiming GDPR/CCPA/HIPAA readiness), no ADM rights section, no named individuals in testimonials, anonymous ROI metrics ("214% ROI, 170 sites"). And the B2B service terms say the service "may not be cancelled or terminated by Client during the Subscription Term" except for Uniti's own uncured breach — the hardest lock-in in the set. Their consumer T&C is two years stale with no billing terms.

Lette — the EU-native one

Posture: strong on privacy, weak on commercial terms. GDPR-native (Dublin), trust center with 143 subprocessors, ISO 27001 claimed, explicit Art. 22 posture ("our AI does not make autonomous decisions that produce legal effects"), tenant-data categories disclosed, real verifiable testimonials (Grayling Properties MD confirmed via press).

Citable gaps: terms have no user-initiated cancellation procedure and no auto-renewal language ("payments are non-refundable"); no published crisis/AI-safety policy; the 143-entry subprocessor list looks auto-generated from an OAuth app inventory (includes Reddit and Pocket — sloppy hygiene). Marketing says "autonomous" while the policy says the opposite — a tension a buyer could poke.

Fonio — the GDPR-boilerplate one

Posture: complete legal stack, thin specifics. Vienna GmbH, German-law contracts, servers in Nuremberg, processors named with cities, EU-US DPF + SCCs, separate app privacy notice + public DPA + Swiss addendum.

Citable gaps: no Art. 22 ADM section and no explicit transcription disclosure despite being a voice-AI company; no concrete retention periods for call recordings; homepage EN testimonials ("Dr. Amanda Reyes, Family Medicine Practice") are generic US personas absent from their real (strong, named) customer-stories page — plausibly invented for the English market; binding terms are German-only and JS-rendered. No crisis protocol despite selling to medical practices.

What this means for us

Where we're ahead:

Where we're behind the pack:

The open lane nobody owns: a published AI safety & crisis protocol — what Clara does on emergencies AND on a distressed-tenant message (988, human escalation, business-flow stop). Zero of six companies have one. We already have the strongest real emergency handling in the set (deterministic gas/CO guard, emergency-relay agent); writing the crisis half and publishing the whole thing as a trust page makes us the only vendor a risk-averse operator can point their counsel at. Cheap to build, differentiating to publish.

In plain terms

We're not behind on the scary stuff — our security is the only independently checked one in the group. We're behind on paperwork transparency: competitors show their vendor lists and deletion processes; we say "email us." And there's one thing nobody in the industry has done — publish what their AI does when a conversation turns into a crisis — that we're actually best positioned to do first.

Method

Five parallel research agents, one per competitor, public evidence only (marketing sites, privacy policies, terms, DPAs, trust centers, press). No logins, no probing beyond public pages. Statuses reflect what is publicly verifiable — a "❌/unknown" means not published, not proven absent internally. PropFlow column reflects the internal audit (repo + live AWS + live site), which is a deeper standard than the public-only lens applied to competitors — bias noted. Fetched 2026-08-13.

PropFlow Docs