Monitored company
Smartrent
clause.watch tracks 2 legal documents published by Smartrent, re-reading each one every six hours. Below is what each document covers, in plain English.
Security & Data Privacy
SmartRent Security & Data Privacy Overview
> Scope note: This document primarily describes SmartRent’s security practices and the categories of information it collects. It is not a complete privacy policy or terms-of-service agreement. Several important topics—such as formal privacy rights, AI training, dispute procedures, and policy changes—are not addressed.
1. Data Collection & Usage
Information collected
SmartRent says it collects three broad categories:
- User-provided information: Email address, mobile number, and similar registration details.
- Home information: Address and information about the home, including room names assigned in the app.
- Device and app activity: Interactions with connected devices and use of the app, including:
- Changing thermostat settings
- Locking or unlocking doors
- Granting visitor or service-provider access
- Other connected-device interactions
How information is used
The stated purposes are to:
- Register and authenticate users
- Send registration links and access codes
- Operate and support SmartRent devices and services
- Provide the user experience and manage app functionality
Retention
SmartRent states that device-activity data is encrypted and deleted after 30 days, with a full deletion when a resident moves out.
However, the document does not specify:
- How long account, contact, address, or home information is retained
- Whether data may be retained for legal, fraud-prevention, backup, or billing purposes
- How “move out” is determined or how quickly deletion occurs
2. User Rights
The document does not identify formal rights to:
- Access or receive a copy of personal data
- Correct inaccurate data
- Delete account or personal information
- Restrict or object to processing
- Port data to another provider
- Withdraw consent
- Appeal a privacy decision
- File a complaint with a regulator
It does state that device-activity data is deleted after 30 days and fully deleted upon move-out. This is a specific retention commitment, but it is not the same as a comprehensive data-rights process. Users would need to consult SmartRent’s broader privacy policy or contact SmartRent to determine whether additional rights apply under laws such as state privacy laws or the GDPR.
3. Third-Party Sharing
SmartRent says it does not sell personal information and does not sell it to third-party affiliates.
Nevertheless, information is processed by third parties involved in providing the service, including:
- Amazon Web Services (AWS), which hosts the platform and data
- Cloud, security, infrastructure, and other service providers
- Potentially SmartRent personnel and authorized contractors who require access
The document does not provide a full list of vendors, explain whether data is transferred internationally, or describe disclosures required by law. It also does not clearly explain what information property managers or landlords can access beyond stating that device-activity data is not visible to them in the platform.
4. AI/ML Training
The document is silent on artificial intelligence and machine-learning training. It does not say whether personal information, device data, or de-identified information is used to train SmartRent or third-party AI models. Users should not assume that the absence of a statement means data is excluded from AI training.
5. Key User Obligations
Users are instructed to:
- Protect their phones with a passcode or biometric security
- Secure the SmartRent mobile app
- Never share phones or personal access codes
- Reset door codes if they may be compromised
Users may also be subject to permissions and identity-verification requirements established by local property or community administrators. A practical risk is that anyone with access to the user’s phone, app credentials, or door code may potentially access the home or connected devices.
6. Liability & Disputes
The document describes safeguards, including encryption, firewalls, access controls, vulnerability scanning, penetration testing, MFA, and incident-response procedures. It also references ISO 27001 certification and SOC 2 Type II audits.
However, it contains no express provisions addressing:
- Liability for security incidents or unauthorized access
- Service interruptions or device failures
- Indemnification
- Arbitration or court jurisdiction
- Class-action waivers
- Notice requirements for claims
- Available remedies or damages caps
Security certifications and encryption reduce risk but do not guarantee that breaches or operational failures cannot occur.
7. Changes
The document does not explain:
- How SmartRent will notify users of updates
- Whether notice will be sent by email, app notification, or website posting
- When changes become effective
- Whether continued use constitutes acceptance
Users should look for a separate privacy policy or terms of service containing these provisions.
Terms
Change history
2026-09-05 · Security & Data Privacy
Yes
2026-09-05 · Terms
No
2026-09-05 · Security & Data Privacy
Summary
Scope of the Diff
- The diff states only: “Added approximately 16 words to the document.”
- The actual 16-word addition is not provided.
- No deletions or replacement language is shown.
Legal Impact
- The legal effect cannot be reliably assessed without the exact added wording.
- It is not possible to determine whether the addition changes:
- Customer obligations or rights
- Data ownership or licensing
- Confidentiality or privacy protections
- Liability, indemnification, or termination rights
- Service functionality or permitted uses
AI Training and Customer Data
- The provided diff does not identify whether customer data may be used to train, fine-tune, evaluate, or improve AI models.
- No conclusion can be drawn about:
- Whether customer data is used for model training
- Whether usage is opt-in, opt-out, or automatic
- Whether de-identified, aggregated, or identifiable data is used
- Whether customer prompts, outputs, files, or metadata are included
- Whether data is retained after termination
- Whether third-party AI providers may access the data
Risk Assessment
- Unassessable based on the information provided.
- The exact 16-word addition should be reviewed before accepting the amended terms, particularly for language granting broad rights to use, reproduce, analyze, retain, or train models on customer data.
Information Needed
Please provide the actual text of the addition, using the stated markup format.
2026-09-04 · Terms
No
2026-09-04 · Terms
2026-09-03 · Terms
2026-09-03 · Terms
2026-09-02 · Terms
2026-09-02 · Terms
2026-09-01 · Terms
2026-08-31 · Terms
No
2026-08-29 · Terms
2026-08-28 · Terms
2026-08-26 · Terms
2026-08-25 · Terms
2026-08-24 · Terms
2026-08-24 · Terms
2026-08-21 · Terms
2026-08-20 · Terms
2026-08-19 · Terms
2025-09-15 · Terms
The publisher records this document as revised on this date (“Last Modified: September 15, 2025”).
Between 2023-06-22 and 2024-07-29 · Terms
No
Between 2023-05-24 and 2024-07-18 · Security & Data Privacy
Summary of Important Changes
Overall assessment
The diff appears to be primarily a formatting and punctuation cleanup, not a substantive change to SmartRent’s privacy, security, or data-use obligations. Most changes replace typographic apostrophes with straight apostrophes, such as “that’s” → “that's” and “SmartRent’s” → “SmartRent's.”
No new contractual permissions, restrictions, warranties, or liability provisions are apparent in the provided text.
Potentially substantive or notable changes
1. Document heading appears to change
- The opening text changes from “Resident Data Security and Privacy” to a malformed or duplicated version resembling “Resident Data Security and PrivacyResident Data Security and Privacy.”
- This may be a diff or formatting artifact, but it should be checked in the final document to ensure the title is not duplicated or corrupted.
2. Security descriptions remain substantially the same
The revised text continues to describe:
- Cloud-security protocols
- AWS security services
- Multi-factor authentication for production access
- A 24/7 security team
- Incident escalation procedures
- Security architecture zones
- Application code review and testing
- Separation of testing, staging, and production environments
- A responsible-disclosure policy
- MFA for certain platform administrators
These statements describe security practices but generally do not create detailed security commitments, service levels, breach-notification deadlines, indemnities, or guarantees. If this document is intended to function as a contractual security commitment, the language remains relatively high-level.
3. Possible terminology or formatting issue
The text refers to “P2-Factor Authentication (2FA)”. This may be a typographical error for “Two-Factor Authentication (2FA)” or may conflict with the preceding use of MFA. The final document should use consistent terminology and clarify whether MFA is enabled by default for all relevant users or only platform administrators.
4. Data categories remain referenced
The text continues to refer to information about a resident’s home, including:
- Address
- Room names assigned through the SmartRent app
- Sensor data from connected devices
These references indicate that the service may process location, household, and device-generated data. The excerpt does not clarify retention periods, sharing practices, ownership, deletion rights, or whether sensor data is considered personal information.
AI model training and data use
No changes addressing AI training or model development are visible in this diff. The excerpt does not state whether customer or resident data:
- Is used to train, fine-tune, or evaluate AI models;
- Is shared with AI providers;
- Is anonymized or aggregated before such use;
- Is excluded from model training by default; or
- Can be used for product improvement or analytics.
Accordingly, the diff provides no new authorization or restriction concerning AI training. Any AI-related terms may appear elsewhere in the privacy policy, terms of service, or data-processing agreement and should be reviewed separately.
Between 2019-11-13 and 2023-05-24 · Security & Data Privacy
Summary of Important Changes
Overall assessment
The diff appears to contain no substantive changes to data practices, security obligations, or customer rights. Most edits correct punctuation, spacing, or formatting, particularly replacing straight apostrophes with typographic apostrophes (for example, “SmartRent's” → “SmartRent’s” and “Here's” → “Here’s”).
Changes identified
1. Document title and formatting
- The opening title was reformatted from:
> “Resident Data Security and PrivacyResident”
to:
> “Resident Data Security and PrivacyAt SmartRent…”
- Several headings and paragraphs appear to have been concatenated or have line-break changes, including:
- “Your Privacy and Security”
- “Incident response”
- “Secure architecture zones”
- “Quality assurance”
- “P2-Factor Authentication (2FA)”
These appear to be presentation or extraction changes rather than changes in legal meaning. However, the final document should be checked to ensure headings and paragraphs remain clearly separated.
2. Grammar and punctuation
Examples include:
- “that's” → “that’s”
- “Here's” → “Here’s”
- “SmartRent's” → “SmartRent’s”
- “you've” → “you’ve”
- Minor insertion of punctuation and spacing around headings and sentences.
These edits do not appear to alter contractual rights, duties, or limitations.
3. Security representations
The described security measures remain materially the same, including:
- AWS security services and network protections
- Multi-factor authentication for production access
- 24/7 security monitoring and incident escalation
- Segmented security architecture
- Quality assurance and software development lifecycle controls
- Separation of testing/staging and production environments
- Responsible disclosure procedures
- MFA for platform administrators
No new security warranty, breach-notification obligation, liability commitment, or compliance obligation is added in the shown diff.
AI training and data use
No changes related to AI or machine-learning training are visible in this diff.
Specifically, the diff does not add or remove language addressing:
- Use of customer, resident, sensor, or home data to train AI models
- Whether data may be used to improve algorithms or services
- Sharing data with AI vendors or other processors
- Opt-out or consent rights relating to AI training
- Retention or deletion of data used for model training
- Restrictions on using confidential or personal data in AI systems
Accordingly, this diff does not appear to create a new AI-training authorization or remove an existing one. A review of the complete privacy policy or surrounding provisions would still be necessary to confirm whether AI-related terms exist elsewhere.