Permity

Privacy

Last updated 27 August 2026.

What Permity is

Permity reports the building-permit history of a property address — what work has been permitted, and when. It is operated by Valya AI, Colorado, USA.

What we collect

From you. Your name and email address when you create an account, and your business name if you give one. If you sign in with Google or Microsoft we receive your email, name and profile image from that provider — nothing else, and we request no other scopes.

What you look up. The property addresses you search, and the results returned. These are stored so a report can be re-opened without re-running the lookup.

Usage. Per-request records — timestamp, endpoint, outcome, and which API key was used — for billing, support and abuse prevention.

We do not collect payment card details. If you subscribe, those go directly to Stripe and never touch our servers.

What the data describes

Permit records are public records published by municipal and county authorities. They describe properties, not people, but a permit sometimes names a property owner or contractor. We do not enrich, append to, or resell that information, and we do not attempt to identify occupants.

Who we share it with

Only the processors needed to run the service:

Shovelsthe permit data itself. Receives the address being looked up.
Google Placesaddress normalisation. Receives the address text you enter.
Railwayhosting and database, US region.
Stripesubscription billing, if you subscribe.
Resendemail delivery, if you have reports emailed.

We do not sell personal information, and we do not share it for advertising.

How long we keep it

Reports are retained 90 days from generation, then deleted — including for active subscribers. Keeping documents that carry street addresses indefinitely is its own liability, so the window is deliberately bounded.

Account records and usage history are kept while the account is open and for up to seven years afterwards where tax or accounting rules require it. Cached permit data expires within 24 hours to seven days depending on type.

Your choices

Ask us to export or delete your account data at any time and we will do it within 30 days, except where we are required to keep billing records. Report links are signed and expire after seven days; you can let one lapse rather than revoking it.

Security

API keys are stored as HMAC digests and cannot be recovered from our database — a key is shown once at issue and never again. Passwords are hashed with bcrypt. Traffic is served over TLS. Report URLs are unguessable and expiring rather than permanent.

Contact

nate@valyaai.us