Privacy Policy
Last updated 26 September 2026
Vetta is a product of Aeolus Consulting. In this policy, "we", "us" and "our" mean Aeolus Consulting, operating as Vetta. You can reach us at team@aeolusconsulting.ai.
This policy is written to be read, not filed. If anything here is unclear, write to us and ask.
The short version
- Two different people are covered by this policy. The customer is the leasing agent, brokerage or landlord who signs up and pays. The applicant is the person whose rental application documents get forwarded to us. Applicants never signed up with us. Most of the sensitive information we handle belongs to them.
- What we handle. Account and billing details for customers. For applicants, the rental application email a customer forwards to us and everything attached to it, which is usually pay stubs, bank statements, employment letters, government identification, credit reports the applicant supplied, and the application form itself.
- Why. To read those documents, pull out the figures, check them against the rent for that listing, and produce one ranked report for the customer, with each finding cited back to the page it came from.
- Who else sees it. Amazon Web Services hosts everything. Amazon Bedrock, which is also Amazon, runs the AI that reads the documents, and it currently runs in the United States. It also reads part of some arriving emails before anyone presses Process. Stripe handles payments and never receives applicant information. Cloudflare serves our public website and never receives applicant information.
- How long. Documents and reports are deleted 30 days after we receive them. The raw forwarded email, with every attachment still inside it, is deleted after 90 days. A few records last longer and we list them below.
- The main risks you should know about. These documents are sensitive. A forwarded rental application can contain enough information to impersonate someone or open credit in their name. The reading of the documents crosses the border into the United States, where American courts and authorities can compel access. The report a landlord receives opens from a link without a sign-in, and we do not record who opens it. No system is perfectly secure and we do not claim ours is.
- The ranking is a calculation, and it is not neutral. Silence in a package costs points. The rent as a percentage of income is one of the scored factors. Both are set out in full below, and the section written for applicants says it as plainly as this one does.
- We do not sell personal information. Ever. We do not use applicant documents for anything except producing the report the customer asked for.
- You can complain. To us first, and then to the Office of the Privacy Commissioner of Canada. Details at the end.
Who this policy covers
It covers three groups.
Visitors to our public website at usevetta.app.
Customers who create an account at app.usevetta.app, and the people who use the service under that account.
Applicants whose documents reach us because a customer forwarded them. If that is you, the section written for you is below. You did not agree to anything with us, and we think that makes your section the most important one here. It is written to be read on its own. Read the rest of the policy too, because it applies to you as much as it applies to our customers, and the last section tells you how to complain.
If you are a customer
What we collect from you and why
Your account. Your email address, your name if you give it, your password, and an authenticator app secret if you turn on two-factor sign-in. Sign-up runs through Amazon Cognito. We need this to give you an account, to let you sign in, and to send you the emails the service has to send you.
Your organization record. An organization identifier we create, the email address you signed up with, and the display name you set. The display name is what a landlord sees on a report you share.
Your listings. The property address, the unit, the monthly rent, and the forwarding address we mint for that listing. We need these to route forwarded mail to the right listing and to check applicants' figures against the right rent.
Your billing details. Your Stripe customer and subscription identifiers, your plan, your status, and a record of each completed analysis so we can bill for it. While you use the free allowance, we keep a count of the applicants it has covered and, for each applicant reviewed on it (counted, or reviewed before and so not counted), the same kind of opaque identifier derived from file fingerprints, so the same documents on the same listing count at most once; these are kept with your organization record. Your card details never reach our servers. You enter them on a page hosted by Stripe, and Stripe holds them.
Your sign-in session. When you sign in we set one cookie in your browser holding your session tokens. We re-check that token against Amazon Cognito on every request.
Job records. When you press Process, we record which emails you selected, which applicants resulted, and whether the job succeeded. This is an audit trail so you can see what was run and when.
What you write to us. If you email us for support, or about a privacy request, or about a brokerage plan, we keep that correspondence.
Operational logs. Our systems write logs. They are deliberately built to record identifiers, error types and counts rather than people's words or names. A test in our codebase fails the build if a logging call looks like it is about to write personal content.
We do not use any of this to build a profile of you, and we do not share it with anyone for their own purposes.
Emails we send you
The service itself sends two: a notification when a report is ready, and a notification when a landlord records a decision on a link you shared. Amazon Cognito sends your sign-up verification and password reset messages. Stripe sends your invoices and receipts directly, because Stripe is the merchant of record for your subscription. We will also email you about your account when we have to, for example a change to our prices, a change to our Terms or to this policy, a change to the service, or a reply to something you wrote to us.
The report-ready and decision emails come with the service and are not marketing, so we do not need your separate permission to send them. If you would rather not receive either one, write to us and we will turn it off for your account. We do not send marketing email. If we ever start, we will ask you first, and every message will carry an unsubscribe link and our contact details.
One thing to be aware of: the decision email names the applicant the landlord chose. Once that email is in your inbox it is in your mail provider's system, not ours. Our 30 day deletion clock and our encryption do not reach it. That is worth knowing if your brokerage has its own retention rules.
If you are a rental applicant
You are reading this because you applied to rent a home and the agent or landlord forwarded your application to us. You did not sign up for Vetta and you may never have heard of us. This section is for you, and it is written so you can read it on its own. Nothing in the rest of this policy is softer than what is written here.
How we got your documents
A landlord or leasing agent gave each of their listings a forwarding address. When your application arrived by email, they forwarded it to that address. Everything attached came with it.
What happens the moment it arrives. We store the message and every attachment, and we label what arrived so the agent's inbox is useful. Our own rules do that labelling by reading the subject, the sender, the attachment filenames and the start of the message text. Those rules handle most mail on their own. Two cases go to an AI service run by Amazon, which currently runs this work in the United States. The first is mail that arrives with attachments our rules cannot recognise as an application package, which includes the case where you send a further document after your application. The second is an application whose applicant our rules cannot tell apart from the person who forwarded the mail. In either case what is sent is the listing address, the sender's name and email address, the subject, how many times the message has been forwarded, the attachment filenames, and the first 8,000 characters of the message text.
What the labelling step writes down. Whichever route was taken, we store the label, how confident it was, the names it worked out for you and for the agent, and one sentence of its reasoning, on the email record. Where the AI step ran, we also store what your covering message claims about you, where it claims anything: an income figure, a credit score, an employer, and whether an offer is mentioned. That is what the message says, not what your documents show, and nobody checks it at that point. All of it goes on the same 30 day clock as the email it was read from.
Your documents themselves are not opened at this stage. No attachment is read, no figures are pulled out of your documents, and no report is produced until the agent selects that email and starts a job.
The landlord or agent decided to collect your documents, and they are the organization responsible for having told you that and for having your consent. Under Canadian privacy law they are supposed to explain what they are collecting, why, and who will see it, including that a third party service like us will read the documents. We require our customers to have named Vetta to you, and to have pointed you to this page, before they collected your documents. We are not in a position to verify that for every application, and we do not contact applicants to check.
If nobody told you about us, we want to know. Write to us at the address below. We will answer you, and we will take it up with the customer who sent us your file.
We read your documents only on that customer's instructions, and only to produce their report. We do not use them for anything else. We do not sell them. We never send anything to you. We never send your file to another landlord, another agent, or any tenant list or database. The agent who forwarded your application decides who receives the link to the shared copy.
We do not use your documents to train AI models and we never will. We should be precise about what that covers. An AI service run by Amazon reads your documents for us, and Amazon publishes the position that it does not store the content of those requests and does not use it to train models. That is Amazon's statement about Amazon's own service. We rely on it and we pass it on. We do not guarantee it ourselves, and we hold no separately negotiated agreement of our own that promises it.
If you did not know your documents would be read by a service like ours, raise it with the landlord or agent first, because they made that decision. But you can also come straight to us, and we will answer. What we hold is our responsibility to protect, and your rights below apply to us as well as to them.
What we hold about you
Not everything below is in every file. It depends on what you sent.
Your email and the forward chain. The subject line, the sender and recipient names and addresses along the whole chain of forwards, the timestamps, and the text of the message including anything you wrote in it.
What the labelling step recorded. The label, its confidence, the names it worked out, and one sentence of reasoning. Where the AI step ran, also the income figure, the credit score and the employer your covering message claims, and whether it mentions an offer.
Your documents, exactly as you sent them. Pay stubs, bank statements, employment and offer letters, government identification, credit reports you obtained yourself, enrolment letters, and the rental application form. We also keep the filename as it was written, the file type, the size, and a fingerprint of the file.
The figures we read out of those documents. Your employer, your gross and net pay, how often you are paid, your annualized income, the credit bureau and score shown on a report you supplied, tradelines, balances, collections, previous addresses, your date of birth where it is printed on a bureau report or on identification, a masked bank account number with closing balances and transaction descriptions, and from the application form your date of birth, occupants, pets, and whether the form was signed.
Identification numbers. We transcribe the type of identification you supplied and, where the document shows them, the identification number and the driver's licence number from the application form. These are used to check that the documents in a package describe the same person. They are not part of the score. Being straight with you: a driver's licence number written in Ontario's format is withheld from the landlord's copy, in both of the places that render a report, along with a birth date worked out from it. It is not withheld from the agent's copy. An identification number in any other format, a passport number for example, has no rule at all, so it can reach the landlord's copy if it appears in a finding. If you would rather we did not hold these, ask us and we will delete what we hold about you on the terms set out under your rights below.
People you named. If your application form lists a previous landlord, a personal reference, an employer contact or an emergency contact, we transcribe those names and contact details too. Those people are not party to anything either, and this policy covers them as well.
If you are one of those people. You can write to us too, on the same terms as an applicant. Because we store files by listing rather than by person, tell us your name, the name of the person who gave us your details if you know it, and anything else that would help us find the file, such as the city or the approximate date. If we can find you we will tell you what we hold and delete it on request. If we cannot find you from what you can give us, we will say so plainly rather than leaving the request open, and we will tell you what we would need.
The report. What we found, each finding quoted from the document it came from with a page number, the checks we ran, a score out of ten and a band of Shortlist, Consider or Decline, or Needs review where nothing could be read.
A shareable copy. A link the agent can send to the landlord who is making the decision. It holds back more than the agent's own copy does.
How your file is ranked
An AI model reads each document and transcribes what it says into a fixed set of fields. It is instructed to transcribe, not to judge. It does not decide your score, your rank or your band. Ordinary code does that, with fixed numbers that are the same for every applicant.
Six factors are scored, out of 105 points in total:
| Factor | Most it can score |
|---|---|
| Income shown in documents | 30 |
| Credit information you supplied | 25 |
| Savings, and rent tendered in advance | 25 |
| How long you have been with your current employer | 15 |
| The terms of the offer | 5 |
| Rent as a percentage of your income | 5 |
Those points become a score out of ten, and the score sets the band. 6.5 or higher is Shortlist. 4.5 or higher is Consider. Below that is Decline.
A gap counts as uncertainty, and it is not free. If your package says nothing either way about one of those factors, that factor is scored at one third of its weight rather than at zero. It is not dropped. With no credit report, the credit factor scores 8.33 of its 25 points, so the gap costs you up to 16.67 points out of 105 against an applicant who supplied one. The same arithmetic applies to each of the others. We would rather tell you that than tell you a gap costs nothing. What a gap cannot do is put you below someone whose documents were read and found wanting.
Three situations set the label whatever the points say. A file where a document was mechanically shown to be fabricated is scored 1 out of 10, which lands it in Decline. A file with unpaid collections totalling $1,000 or more is labelled Decline whatever its score. A file where nothing at all could be established, meaning no income from stubs or from a letter, no credit score, no savings and no rent tendered, is labelled Needs review, is given no score at all, and is ranked above the unpaid-collections group, because it may be the strongest application in the set.
What the calculation does not use, and what it cannot promise
No factor in the calculation is a protected ground. Nothing scores your age, family status, citizenship, disability, ethnicity or receipt of public assistance, and no such field exists in the figures the score is computed from. Being precise rather than flattering, there are three things this does not mean.
One. It does not mean protected ground information is never present. You chose what to send, a bureau report carries a date of birth, and a bank statement shows where money came from. What we promise is that none of it is an input to the calculation, and that dates of birth do not reach the landlord's copy.
Two. It does not mean the method is neutral in its effect. Income annualized from your pay stubs starts at 21 of the 30 income points. The same income stated in an employment letter starts at 10. If your income arrives as ODSP, as Ontario Works, as a pension, as child benefits, as self-employment income, or as anything else that does not produce pay stubs, you cannot reach the higher tier however real and sufficient that income is, and if you have no employment letter either the whole income factor falls to the one third rule at 10 of 30. The calculation also scores how long you have been with your current employer, so a recent return to work or a recent change of jobs scores lower there. You may score lower than someone with identical money in the bank. We think that is a real limitation rather than a detail. It is one reason the report is decision support and not a decision.
Three. The rent as a percentage of your income is one of the scored factors. We are telling you that because it is the part of our method Ontario law is most critical of, and you are entitled to know it is in there. The figure is worth 5 points of the 105: 5 points where the rent is 30 percent or less of the income shown in your documents, 3 points at 35 percent or less, 1 point at 40 percent or less, and none above that. Those steps feed the points, the points feed the score, and the score sets the band the landlord acts on. The figure also appears in the report and in the copy the landlord sees.
What that means if your income is a benefit, a pension or self-employment. We work the percentage out from your pay stubs, or from an employment letter if there are no stubs. If your income arrives in any other way there is usually nothing for us to work it out from, so the factor cannot be answered and it is scored at one third, which is 1.67 of its 5 points. You lose 3.33 points out of 105 on a factor that had nothing to do with whether you can afford the rent, on top of the income tier described above. That is the arithmetic. We are not going to describe it as anything better than it is.
We tell landlords not to use that figure as a cut-off. Ontario's Board of Inquiry declared in Kearney v. Bramalea Ltd. that rent-to-income ratios and minimum income criteria breach the Human Rights Code, whether used on their own or alongside other selection criteria, and held in Vander Schaaf v. M & R Property Management that letting a landlord obtain income information does not let the landlord apply a ratio to it. The Ontario Human Rights Commission takes the same position about minimum income rules. Our Terms tell every customer, in the strongest words we have, that they must not use this figure or any minimum income rule as a cut-off. If a landlord sets one, that is their decision and their liability, and you can take it to the Human Rights Tribunal of Ontario.
One line in the report today goes further than that, and you should know about it. Where the rent is 33 percent or less of the income in your documents, the report can carry a short strength reading that the rent is inside a 33 percent guideline commonly applied, and that line can appear in the landlord's copy. It is not our position that such a guideline should be applied. It is in the product today and we would rather name it here than let you find it in a report about you.
What you can do about any of this. Tell the agent, and tell us, how your income arrives and what documents show it, and ask us for the reasons behind your result. We will look again, and where it changes the result we will produce a corrected report and tell the agent it exists.
We do not pull credit. We have no relationship with any credit bureau. We do not order credit reports or credit checks, and we never contact a bureau about you. We obtain nothing about you from anyone except the customer who forwarded your application. We keep no standing file on you that outlives the report we produced for that customer. Any credit information in a report came out of a document you obtained yourself and gave to the agent.
What the landlord's copy holds back, and what it does not
Social Insurance Numbers. We do not need one and we ask customers not to send one. If a nine digit number that passes the SIN checksum appears in a document, we strip it out of the report before anyone reads it, in both the agent's copy and the landlord's copy. The original document you sent still sits in storage until it expires on the schedule below, so the safest thing is still not to send a SIN at all.
Your date of birth, from the shared copy. Dates of birth are extracted from documents so we can cross-check them. Before the landlord's copy is rendered we strip any date that sits next to a date-of-birth label, in both of the places that render a report. Like the Social Insurance Number rule above, that is a filter rather than a guarantee.
Personal email addresses, in part. In the landlord's copy the name half of an email address is replaced and the domain is kept, because findings reason about the domain.
Anything we cannot back up. If our checks produce a finding that is not supported by a quote from one of your documents, it is dropped from the shared copy rather than softened. Quotes in the shared copy are capped in length and number, and the language is checked so a finding describes a document rather than accusing a person.
What is not held back. The short list of strengths on your card carries no citation of its own and is not dropped for want of one, and it appears in the landlord's copy. The rent-to-income figure appears there. A driver's licence number is withheld, as described above, but an identification number in another format is not.
Who can open that link
The link is a long random web address. Anyone who has it can open the report without signing in, and we do not record who opens it. We built it that way so the landlord making the decision does not need an account. It does mean that if the agent forwards the link on, whoever receives it can read the report.
Against that: the agent can switch the link off at any time, and it stops working 30 days after it is created. The shared copy holds back what is listed above.
How long we keep it
Most of it, 30 days from the day your documents reach us: the documents themselves, the figures read out of them, the email record, and the report.
One thing lasts longer. The forwarded email exactly as it arrived, with every attachment inside it, is kept for 90 days. That is the longest-lived complete copy of your package, and we would rather say so than let you assume one clock covers everything.
The timer is not to the minute, and the full list is in "How long we keep things" below.
Your rights, and how to use them
You can ask us for the following, and you do not need a lawyer or a form.
- Access. What we hold about you, where it came from, how it has been used, and who we have disclosed it to.
- Correction. If a figure is wrong, tell us. We will check it against the document it was read from, correct what we hold, and produce a corrected report where that is what fixes it. Two honest limits. A link the agent has already shared shows the version it was created against, so a correction does not change what a landlord has already seen. We will tell the agent that a corrected report exists and ask them to re-share it, and we will tell you that we have done so. And if the landlord has already made their choice, a correction cannot undo it. If we do not agree that something is wrong, we will record what you say on the file, tell you our reasons in writing, and tell the customer who received the report that you dispute its accuracy.
- An explanation, and a second look. You can ask us what figures were used for your file, which factors drove the result, and why you were put where you were. We will tell you in plain terms. You can also tell us anything you think the documents did not show, such as that your income arrives another way, that a collection was settled, or that a figure was misread. We will look again, and where it changes the result we will produce a corrected report and tell the agent it exists. This is done by a person. Quebec law gives a person the right to be told about a decision made by automated processing alone, and to ask for it to be reviewed. We make no decision, so that right runs against the landlord or agent rather than against us. We will answer you anyway.
- Deletion. Ask us to delete what we hold about you. In most cases we will, because the customer's report is theirs and our copy exists only to serve it. We will refuse only where the law requires us to keep something, or where a complaint, a challenge or a proceeding about the very decision your documents were used for is already under way and the record is needed for it. We will not refuse simply because a customer would prefer us to keep it. If we refuse, we will tell you in writing which of those grounds applies, tell you what we are keeping and for how long, delete everything not covered by the ground, and tell you that you can complain to us and then to the Privacy Commissioner of Canada.
- Withdrawal of consent. This one is mostly directed at the landlord or agent, because they collected the documents. Tell them, and tell us, and we will act on their instruction and can delete our copy. Withdrawing consent may mean the landlord cannot complete their assessment of your application, and that is their decision to explain, not ours.
How to make a request. Email team@aeolusconsulting.ai with "Privacy request" in the subject. Tell us your name, the address of the property you applied for, and the agent or brokerage you applied through. We need the property address because we store files by listing, not by person, and without it we may not be able to find you.
We stop the clock when you ask. From the moment your request or your complaint reaches us, we hold the information it concerns out of the automatic deletion schedule, so it is not erased while we are dealing with your request or while you still have the right to challenge our answer. Holding information out means moving a copy of it somewhere the timers do not reach, and a person does that by hand, so the sooner you tell us the better. If the information had already expired before your request reached us, we will tell you exactly that rather than leaving you guessing.
How we confirm who you are. We will confirm who you are before we hand anything over, because giving your file to the wrong person would be the worse mistake. We will ask for the least we can manage with, normally the email address the application was sent from plus one detail from it that only you would know. We will not ask you to send us a copy of your identification unless there is no other way. If we do ask, we delete it as soon as the request is closed, and we never add it to your file.
How we send it back. We will not send a file of this kind back to you by ordinary email. Once we have confirmed who you are, we will agree a secure way to give you the information, and we will tell you what that will be before we send anything.
What happens next. We will answer within 30 days. If we need longer we will tell you inside those 30 days, explain why, take no more than 30 extra days, and tell you that you may complain to the Privacy Commissioner about the delay. Access is free or at minimal cost, and if there would be any cost we will tell you what it is and get your agreement before we do the work. We will explain any codes or shorthand in the file so the answer makes sense. If we refuse all or part of a request, we will tell you in writing, give our reasons, and tell you how to challenge that.
If your request is really for the landlord. Some things only they can answer, such as why they chose someone else. We will say so plainly and pass your request on to them rather than leaving you to start again. We will not use their silence as a reason to leave you without an answer. If they do not come back to us, we will answer you with what we hold, tell you that we asked and did not hear back, and give you their details so you can go to them yourself.
A note on timing. If more than 30 days have passed since your application was forwarded, and you have not already asked us for anything, we have probably deleted your documents and your report. If that is the case we will tell you exactly that, and tell you what, if anything, is left.
How this is handled. Requests are handled by a person, not by a portal or an automated tool. We do not have a self-serve deletion button and we are not going to pretend otherwise.
Three more things you should know
Your documents are read in the United States. The text of your documents, plus images of pages, are sent to an AI service run by Amazon, which currently runs this work in United States regions. Every page of your identification, your bank statements and your application form is sent as an image, because the meaning of those pages is in their layout, and so is every page of anything we could not read as text. For pay stubs, credit reports and employment, offer and enrolment letters we send the first page and the signature page, and nothing else. At most six page images per document. While your information is in another country it is subject to that country's laws, and American courts, law enforcement and national security authorities may be able to compel access to it. There is more in "Where your information is, and where it goes" below.
We describe our security. We do not guarantee it. The section "How we protect this" below sets out what we actually do, including what we have not done. No method of transmitting or storing information is completely secure, and we do not claim ours is.
When a landlord records a choice, an email naming the person chosen goes to the agent's ordinary mailbox. Once it is there it is in their mail provider's system, not ours, and our deletion clock and our encryption do not reach it.
Keep reading
The rest of this policy is for you as well as for our customers: how the ranking is calculated in full, which other companies handle your information and where they are, how long we keep everything, how we protect it, what happens if there is a breach, and how to complain to us or to the Privacy Commissioner of Canada. You can also complain to us or to the Commissioner without reading another word. Write to team@aeolusconsulting.ai.
How the ranking works
We think you are entitled to know this whether you are the customer or the applicant. The section above says the same thing for applicants; this one adds the detail.
What happens on arrival, and what waits for the customer. A forwarded email is stored and labelled when it arrives. Our own rules do the labelling from the subject, the sender, the attachment filenames and the start of the text, and they handle most mail on their own. Two cases go to the AI service named below, which runs in the United States: mail that carries attachments our rules cannot recognise as an application package, and an application whose applicant our rules cannot tell apart from the person who forwarded it. In either case what is sent is the listing address, the sender's name and email address, the subject, how many times the message has been forwarded, the attachment filenames, and the first 8,000 characters of the message text. Where that step runs, what it returns is stored on the email record, including any income figure, credit score or employer the covering message itself claims. The documents themselves are not opened, no figures are extracted from them and no report is produced until a customer selects specific emails and asks for them to be analysed.
A model reads. Code decides. An AI model reads each document and transcribes what it says into a fixed set of fields. It is instructed to transcribe, not to judge. It does not decide the score, the rank or the band.
The score and the band are calculated by ordinary code with fixed numbers. Files are first sorted into groups. A file with a mechanically proven fabrication is set aside. A file with unpaid collections of $1,000 or more is placed below files without them. A file nothing could be established from is marked "Needs review" rather than guessed at, and is placed above the unpaid-collections group, because it may be the strongest application in the set. Then six bounded factors are scored over the figures we extracted: documented income up to 30 points, the credit information the applicant supplied up to 25, savings and rent already tendered up to 25, how long the current employment has lasted up to 15, the terms of any offer up to 5, and the rent as a percentage of the income shown in the documents up to 5. That is 105 points in total, converted to a score out of ten. A score of 6.5 or higher is Shortlist. 4.5 or higher is Consider. Below that is Decline.
Three of the groups above set the label as well as the position. A file with a mechanically proven fabrication is scored 1 out of 10, which lands it in Decline. A file held back because unpaid collections reach $1,000 is labelled Decline whatever its points. A file nothing could be established from is labelled Needs review and given no score at all.
Those thresholds are fixed constants in our code. They do not move between one applicant and the next. That is deliberate, and the reason is worth stating: an order a leasing agent cannot reproduce is an order they cannot defend to the person they turned down.
A gap counts as uncertainty, not as failure, and it is not free. If a package says nothing either way about something, such as no bank statement, no credit file or no employment document, that factor is scored at one third of its weight rather than at zero. It is not dropped from the calculation. An applicant with no credit file scores 8.33 of the 25 credit points, so the gap costs up to 16.67 points out of 105 against an applicant who supplied one. We would rather say that than tell you a gap is free. What it cannot do is put a file below one whose documents were read and found wanting. And if nothing at all could be established from a package, it is labelled "Needs review" and sent to a person rather than given a band, because a band there would be a judgement on a file nobody has read.
Income is never the whole story. Income is worth up to 30 points, and income annualized from pay stubs starts at 21 of them while the same income stated in an employment letter starts at 10. Income is never scored on its own. It is always counted alongside credit information, savings, how long the employment has lasted, the offer and the rent-to-income figure.
The rent-to-income figure is scored, and it must not be used as a cut-off. Our own calculation gives it 5 points of the 105, on fixed steps: 5 points at 30 percent or less, 3 at 35 percent or less, 1 at 40 percent or less, and none above that. So a band already carries a rent-to-income judgement inside it. That is a limit on what a band is worth, not a licence to add a threshold of your own. Ontario's Board of Inquiry declared in Kearney v. Bramalea Ltd. that rent-to-income ratios and minimum income criteria breach the Human Rights Code, whether used on their own or alongside other selection criteria, and held in Vander Schaaf v. M & R Property Management that letting a landlord obtain income information does not let the landlord apply a ratio to it. The Ontario Human Rights Commission takes the same position about minimum income rules. A score that uses no protected ground can still produce an effect the Code treats as discrimination, and a band is not evidence that a screening decision complies with the Code. Where the rent is 33 percent or less of the supplied income, the report can also carry a short strength saying the file sits inside a 33 percent guideline commonly applied, and that line reaches the landlord's copy. It is not our position that such a guideline should be applied.
Findings are cited. Two things in the report are not. Every finding in the report names the document and the page it was read from, and a finding whose citation does not resolve is marked for a person to check rather than presented as settled. The summary paragraphs, and the short list of strengths on each applicant's card, are written from those findings and are not separately cited, so the citations are the place to check a number. Those strengths appear in the landlord's copy too.
A person decides. Vetta is decision support. It is not automated decision-making and it is not legal advice. The report is not sent anywhere automatically. The customer reviews it and chooses whether to share it. The selection of a tenant is made by a person pressing a button, and our own emails say so in as many words. We never send anything to an applicant.
If a landlord turns you down partly because of a report, section 10(7) of Ontario's Consumer Reporting Act requires them to tell you, at the time they give you their decision, that information from another source was part of it, and to tell you the nature and source of that information if you ask within 60 days. We do not send that notice for you or for them. Ask them.
Documents can be misread. Transcription is not perfect and we do not authenticate documents or promise to detect a forgery. Customers are told to check cited figures against the underlying documents before deciding anything.
Who else handles this information
These are the only companies that receive personal information from us, and what each one gets.
Amazon Web Services. Hosting, file storage, the database, the compute that runs the analysis, inbound and outbound email, and customer sign-in. AWS receives everything described in this policy. This runs in the AWS Canada (Central) region in Montreal.
Amazon Bedrock, which is part of AWS. This is the AI service that reads the documents. It receives the labelling payload described above when we are labelling an arriving email. When we are analysing documents it receives the text of each document, plus page images: every page of identification, bank statements and application forms, every page of anything we could not read as text, and the first and signature pages of pay stubs, credit reports and employment, offer and enrolment letters, capped at six page images per document. Bedrock currently runs this work in United States regions. Amazon publishes the position that it does not store the content of these requests and does not use them to train models. That is Amazon's statement about Amazon's own service. We rely on it and we pass it on rather than guaranteeing it ourselves, and we hold no separately negotiated agreement of our own that promises it.
Stripe. Payments, subscriptions, the billing portal and usage metering. Stripe receives customer information only: the customer's email address, an organization identifier, the plan, and one metering event per completed analysis carrying the Stripe customer identifier, a quantity of one, a timestamp, and a one-way hash we use so the same analysis cannot be billed twice. It also collects the customer's card and billing details directly through its own checkout pages. No applicant information of any kind goes to Stripe. We do not state where Stripe processes this, because we have not pinned a region with them and we are not going to guess.
Cloudflare. DNS for usevetta.app and delivery of our public marketing page. Cloudflare sees every request to the public page, including the visitor's IP address, as part of delivering it. No customer or applicant information goes to Cloudflare. The signed-in application is not served through Cloudflare. We do not state where Cloudflare processes this either, for the same reason.
rdap.org. When an employment letter names an employer's website or email domain, we look up when that domain was registered, to compare it against the hire date the letter claims. Only the domain name is sent. Personal mail domains such as gmail.com and outlook.com are excluded, so a personal email address is not sent. No name and no document content is sent.
Google. Our contact address is a Gmail address, so anything you write to us arrives in Google's mail service. That includes privacy requests, which by their nature identify you.
What binds them. Each of these companies handles this information as our service provider. We use each of them on the standard terms they publish for their own service, which carry their own security and data-handling commitments. Amazon publishes a data processing addendum as part of those terms, which applies to an AWS account without anyone signing it. Beyond that we have not negotiated or signed anything further with any of them, and we are not going to describe published terms as something stronger than they are. Canadian privacy law makes us responsible for this information wherever it goes, including while one of these companies is processing it. That responsibility does not move.
We will keep this list current. If we add a company that handles personal information, we will update this page.
Where your information is, and where it goes
This is the part people ask about most, so here is exactly what is true today.
Documents, reports and records are currently stored in Canada, in the AWS Canada (Central) region in Montreal, encrypted with a key we control.
The reading of those documents currently happens in the United States. Both the labelling of an arriving email, in the two cases described above, and the analysis of the documents are done by Amazon Bedrock in US regions. The text and images are transmitted there to be read, and the result comes back to Canada. This is not a preference. There is no Canadian endpoint for the models this work needs, and we would rather tell you that than run an older model so we can print a nicer sentence.
While information is in another country, it is subject to that country's laws. United States courts, law enforcement and national security authorities may be able to compel access to it under United States law, regardless of where we are or what we have agreed with anyone.
We do not claim that your information never leaves Canada, because that would not be true.
We may change providers and locations. We choose the companies and the regions we use, and those choices can change as the service grows or as better options become available. What is written above describes our current arrangements. It is not a promise that they will stay the same forever. If we make a material change to where personal information is stored or read, we will update this page and email customers before the change takes effect. What we will not do is change the reason we hold information. If we ever want to use personal information for a genuinely new purpose, we will ask for consent for that purpose rather than relying on this policy.
How long we keep things
For applicant material, deletion is enforced by our storage providers on a timer, not by a cleanup job somebody has to remember to run. Records are created with an expiry stamped on them by default, so forgetting to set one is the safe direction rather than the dangerous one. The timer is not to the minute. Our database sweeps expired records on its own schedule, so a record can outlive its date by up to about two days before it is erased. A shared link is the exception: the page checks its expiry on every view and refuses an expired one.
- Applicants' documents, and the records describing them: 30 days from the day we receive them. Both the files themselves and the database records go on the same clock. Thirty days is the period our storage enforces, and it is the same for every listing. Nobody can set a longer one, because the storage rule that deletes the files is fixed for the whole service. If you want something gone sooner than that, ask us and we will delete it.
- Reports, in every form we store them: 30 days. This is deliberately the same clock as the documents they were drawn from. A summary of someone's bank statements is not a lesser copy of it.
- The email record, including the message text, the forward chain and what the labelling step wrote down: 30 days.
- The raw forwarded email as it arrived, including the attachments: 90 days. This is the longest-lived complete copy of an applicant's package and we would rather say so than let you assume one 30 day clock covers everything.
- Share links: 30 days, and they can be revoked earlier. A revoked link and a link that never existed look identical to whoever holds it.
- A landlord's recorded decision: expires with the link it was made on.
- Job records: 90 days. These hold identifiers, not names.
- Storage access logs: 90 days. These hold file paths, not names.
- Operational logs: one to three months depending on the system.
- Your organization record and your listing records: kept while your account is open, and deleted twelve months after you close it, except for anything a tax record needs. These are your business records and hold no applicant documents. The organization record also holds your free-allowance count and, for each applicant reviewed on the allowance, an opaque identifier derived from file fingerprints; neither has a timer, and both are deleted with the organization record. Note the consequence while your account is open: an applicant's file under a listing expires at 30 days, but the listing and its forwarding address stay live.
- Billing and tax records: seven years from the end of the calendar year the charge falls in, then deleted. We keep them because tax law requires us to. Each row holds an organization, a job identifier, an opaque applicant identifier derived from file fingerprints, a count and a date. It does not hold an applicant's name, although it can be re-linked to a listing while that listing exists. Stripe keeps its own records under its own policy.
- Your session cookie: up to 30 days, and it stops working when your sign-in expires.
Two of those periods are kept by hand, not by a timer. The account and listing period, and the billing and tax period, are our own rule, and a person carries them out. Every other clock in the list is enforced by our storage. We are telling you which is which so you know how much to rely on each.
If you ask us for access, or for a correction, or for deletion, or you complain to us, we stop the clock. From the moment your request reaches us we hold the information it concerns out of the automatic deletion schedule, so it is not erased while we are dealing with your request or while you still have the right to challenge our answer. Holding information out means moving a copy of it somewhere the timers do not reach, and a person does that by hand, so the sooner you tell us the better.
Deletion is not instant and not absolute. Our database keeps continuous backups for recovery, and file storage keeps previous versions briefly. Information that has been deleted can still exist inside a backup or recovery window for a short time afterwards. We are telling you this rather than describing deletion as a clean, immediate erasure, because it is not.
Account cancellation. Cancelling your subscription stops billing. It does not by itself delete your organization record or your listings, because we do not have a self-serve account deletion feature. If you want your account and its contents removed, email us and we will do it by hand. Applicant documents under your listings will already have expired on the schedule above.
How we protect this
Here is what we actually do. We are describing our practices, not warranting an outcome.
Start with the limitation that matters most. Shared report links open without a sign-in, so anyone holding the link can read the report, and we do not record who opened it. That is the trade we made so a landlord does not need an account. Against it: the link is a 128 bit random token, it is served by our application rather than handed out as a direct storage link so that expiry and revocation are enforced on every view, it is marked not to be indexed or cached, it expires after 30 days, and it is pinned to the version of the report it was created against so a later re-analysis cannot silently change what a landlord was sent.
The rest:
- Information is encrypted in transit. Our storage refuses unencrypted connections, and our inbound mail server requires TLS.
- Information is encrypted at rest with a key we manage ourselves, which rotates every year. That covers the document storage, the database and the database's backups.
- Every applicant document is written with the owning organization cryptographically bound to the stored file, and a rule in our infrastructure refuses any write that does not use our own key, so a silent fallback to a weaker key cannot happen.
- Keeping one organization's files away from another's is enforced in our application code, from a verified sign-in token, not by our cloud provider's own permissions. We would rather tell you that than let the word "isolation" do work it has not earned.
- No file storage is publicly accessible. Public access is blocked at the bucket level.
- Sign-in requires a password of at least 12 characters with upper case, lower case and digits. Our sign-in provider can take an authenticator app as a second factor. Account recovery is by email only.
- Your session cookie is restricted to secure, same-site, server-only access. Your token's signature, issuer, audience and expiry are re-verified on every single request, and which organization you belong to is read only from inside that verified token, never from anything a browser could set. A user cannot change their own organization: our identity provider refuses the write before any of our code runs.
- Each part of the system runs with its own narrow permissions. The part that receives mail cannot read reports or share links.
- Logs are built to avoid personal content. Errors are recorded by type rather than by message, because an error message can quote the thing that caused it. Workflow data is excluded from logging for the same reason. An automated test blocks any new logging call that looks like it would write a person's words or identity.
- Credentials are held in a managed secrets service and read at run time. There are no passwords in our code.
- We run an automated daily check of the whole pipeline against a synthetic test file, so a silent failure in the analysis is caught rather than discovered by a customer.
- Our code repository is scanned before every commit and before every push for personal information, so real applicant material cannot be committed by accident.
What we do not claim. We have not had an independent security audit or a penetration test, and we do not hold SOC 2, ISO 27001 or any other certification. We are not going to imply otherwise by pointing at our hosting provider's certifications, which are theirs and not ours.
No method of transmitting or storing information is completely secure, and we cannot guarantee absolute security. What we can tell you is what we do, which is written above, and that we will keep working at it.
If something goes wrong. Canadian privacy law requires that if a breach of our security safeguards creates a real risk of significant harm to someone, we report it to the Privacy Commissioner of Canada and notify the people affected as soon as feasible, tell them what happened and what they can do about it, notify any organization that could reduce the harm, and keep a record of breaches whether or not they meet that threshold, for at least two years. We will do that. Where a breach affects an applicant's documents, we will also tell the customer who sent them, because they have their own obligations to the applicant.
To be as plain here as we were about our security testing: we have no automated system that watches for unauthorised access. We would learn of a breach from a provider's notice, from an alarm on our own systems, or from you. That is why the measures above and the short retention matter more to us than a promise about what happens afterwards.
Cookies, analytics and tracking
Our public website at usevetta.app is built to load nothing. The file we publish sets no cookies, loads no external scripts, no external fonts and no tracking pixels, and its Content-Security-Policy allows no script to be loaded from any address at all. We have never added an analytics product to that file ourselves. Read the next paragraph before you take that as the whole answer.
Cloudflare sits in front of that page. Every request to usevetta.app passes through Cloudflare, including your IP address, because that is how the page is delivered. Cloudflare can measure traffic to the domain at its own network level, and it can add its own measurement script to a page it serves without any change to the file we publish. It has done exactly that on this domain: Cloudflare Web Analytics was injecting a beacon into responses sent to browsers, from a setting outside the file we publish. Those are counts, not profiles, and we do not connect them to any person. We are switching that measurement off at the Cloudflare end, and until we can show you it is off we would rather describe it than deny it.
The signed-in application at app.usevetta.app sets one cookie, which holds your session so you stay signed in. It is strictly necessary and the product does not work without it. Two more cookies exist only for the sign-in exchange itself. They are deleted the moment you land back in the app, and if you do not finish signing in they expire on their own after ten minutes.
We use no advertising cookies, no cross-site tracking, and no third-party analytics product of our own. There is no Google Analytics, no tag manager, no session recording and no advertising pixel in our website or in our application.
If that changes, we will choose a tool that does not use cookies to follow people between sites and does not build profiles of individuals, we will name it in this section, and we will update this page before or when we start using it. We would rather write that sentence now than quietly add a tracker later.
Who can look at this information, and when
We do not read applicant documents as a matter of course. A person at Vetta may look at stored content only in a small number of situations: when a customer asks us for help with a specific problem and gives us permission, when an error has stopped the automated process and someone has to intervene to complete or clear the job, when we are investigating suspected misuse of the service, and when the law requires it. Where a bug can be fixed at the root instead of by looking at the affected file, we fix it at the root.
Legal requests. We will not hand over personal information in response to a request from law enforcement or anybody else unless we are legally required to. Where we are permitted to tell the affected person or customer that a request was made, we will.
Business transfer. If the business is ever sold or transferred, we will tell customers before personal information is transferred or becomes subject to a different privacy policy.
Aggregate information. We may use and publish counts and statistics that cannot identify any person or organization, for example how many analyses ran in a month.
Who is accountable, and how to complain
Aeolus Consulting is the organization accountable for the personal information described in this policy. Vetta is its product. Being accountable means it stays responsible for this information even while one of the companies named above is processing it, and even while it is outside Canada.
One role is accountable for this policy: our Privacy Officer. That role is accountable for how we handle personal information, for answering access, correction and deletion requests, and for answering complaints. It is held by a person, not by an inbox, and we will give you the name of the individual holding it if you ask.
Write to team@aeolusconsulting.ai. Put "Privacy request" or "Privacy complaint" in the subject line. That address reaches the Privacy Officer, it is read by a person, and it is the address to use for everything in this policy, whether you are a customer, an applicant, or someone an applicant named.
About our address. We publish the name of the business behind Vetta, Aeolus Consulting, and an email address that reaches a person who reads it. We do not publish a postal address or a telephone number on this page. If you would rather write on paper, or you need our registered details before you send us anything, ask at the address above and we will give them to you.
Complaints. If you think we have handled personal information wrongly, tell us. We will acknowledge your complaint within five business days and give you our answer within 30 days. If we need longer we will tell you inside those 30 days and why. Our answer will be in writing, will say what we found, and will say what we did about it. Every complaint gets looked at. If we were wrong, we will say so and fix it.
If our answer does not satisfy you, you can complain to the Office of the Privacy Commissioner of Canada:
- Online at priv.gc.ca, using the complaint form on that site
- By telephone at 1-800-282-1376, toll free in Canada
- By mail at Office of the Privacy Commissioner of Canada, 30 Victoria Street, Gatineau, Quebec, K1A 1H3
You can go to the Commissioner directly. The Commissioner may ask you to raise the matter with us first, and may decline a complaint brought long after the events it concerns, so it is better to bring it early either way.
If you are in Alberta, British Columbia or Quebec, your province has its own private-sector privacy law and its own regulator, and you may be able to complain to them instead. The Office of the Privacy Commissioner of Canada can point you to the right one.
If you believe a screening decision discriminated against you, that is a matter for the Human Rights Tribunal of Ontario rather than for a privacy regulator, and it is a matter for the landlord or agent who made the decision rather than for us. You can bring both if both apply.
Changes to this policy
We may update this policy. This version took effect on 26 September 2026, which is the date shown at the top of this page.
If we make a significant change, we will refresh that date and email customers. Where the change materially affects how personal information is handled, including a change to where it is stored or read or a change to the companies that handle it, we will give that notice before the change takes effect rather than after.
A change of provider is not a change of purpose. If we ever want to use personal information for a genuinely new purpose, or disclose it to a new kind of recipient for their own purposes, we will ask for consent for that, not rely on a quiet edit to this page.
Contact
Questions, requests and complaints: team@aeolusconsulting.ai
Parts of this policy are adapted from the Basecamp open-source policies by 37signals LLC, used under CC BY 4.0, and have been modified for Vetta by Aeolus Consulting.
Adapted from the Basecamp open-source policies / CC BY 4.0.