Find a sublease

Privacy notice

Version listing-discovery-2026-10-01 · Effective September 28, 2026

Sublyst is operated by Brick Oven Holdings LLC, 895 Aurora Avenue, Boulder, CO 80302, United States. Contact: Sublyst contact form.

Current free service

Accounts, listing publication and applications are currently free. No purchase or payment-card details are required for these activities. Historical test-payment records are described below. Before introducing paid listing services, we will update this notice to explain any additional payment information, processors and retention practices. See the terms for future purchase consent.

What we collect and why

We store account names, account emails, optional school-verification emails, password hashes, verification status, optional phone details, self-reported birth year and required 18+ confirmation, reusable profile answers, private profile photos, sessions, listings, photos, favorites, private blocked-listing choices, public Host introductions, community ratings, application drafts and submissions, support messages, school-domain requests, reports, acceptance records and administrative activity. We also retain test-payment references and email-delivery records. Providers may process IP addresses and technical logs.

We use this information to operate the service, verify inbox access, publish listings, deliver applications, respond to requests and protect the service. Do not submit IDs, Social Security numbers, bank statements, payment credentials or other sensitive documents. Optional contact details are optional.

Who can see it

Published listing addresses, descriptions, prices, dates, home types, bedroom and bathroom details, approximate entire-home square footage, amenities, household answers and photos are visible to the public, including people without accounts. A private photo-storage bucket is not a promise that published photos stay private: displayed photos can be downloaded or copied. Do not put private documents or someone else’s personal contact details in a public listing.

Reusable profiles remain private until shared through an application; there is no people directory. Application drafts are not shown to the lister. A submitted application, including your account email, saved profile snapshot (including birth year and supplied housing preferences), optional photo and included phone details, is available to that lister inside Sublyst. Notification emails contain a general notice and a link to sign in, not application messages, photos, phone numbers or profile answers. Withdrawal changes the application status but does not immediately hide its details from the lister. The lister can continue to view those details until they are erased under the retention schedule below or removed through account deletion. Withdrawal cancels queued application notices where sending has not already begun. It cannot recall an in-flight or delivered email or erase a copy the lister saved. Editing your profile does not rewrite previously submitted applications.

Authorized operators can access information needed for support, safety and service operation. Providers include Render (hosting and scheduled backup processing), Supabase (database and photo storage), Cloudflare R2 (encrypted photo backups), Resend (service email) and Stripe (historical test transaction records). Sublyst does not store full payment-card numbers or security codes. We do not currently sell personal information or use it for targeted advertising.

We may disclose information when required by law or reasonably necessary to investigate misuse, protect rights or safety, or respond to legal claims. Copyright notices and counter-notices contain contact details. We share information needed to process a notice with affected parties; a valid counter-notice, including its required contact details, is forwarded to the original complainant. See the copyright policy. Copyright correspondence handled in our agent’s email inbox is separate from the website’s support records. We manually review resolved copyright emails and case notes for deletion 180 days after resolution. We retain only records still needed for an active dispute, a legal obligation or repeat-infringer enforcement, with the reason reviewed periodically. This is a manual review, not automatic inbox deletion.

Google sign-in and optional school verification

If you choose Google sign-in, Google provides your account identifier, verified email, school-domain information and basic profile name. We use these to authenticate your account and store the identifier linking it to Sublyst. Previously, school verification could use a separate school-managed Google account. School verification now sends a link to your school email, tied to the requesting Sublyst account. Verification links expire after 24 hours. We store the verified school address, domain and verification date; this does not change your sign-in email. Any older school account identifier is retained only with the existing verification record. The school email is visible to you and authorized operators, not other users. Hosts see only the badge through your application; your optional school-verification status can also appear on your own listings. Your school email address is not publicly displayed. School verification alone does not add another way to log in; it can be removed in Account settings and is deleted with your account. We do not request access to Gmail, Drive, contacts or calendars, and do not retain Google access or refresh tokens. Google’s own privacy notice also applies. You can continue to use email/password sign-in where available.

Optional Microsoft school sign-in

If you choose Microsoft sign-in, Microsoft provides your school sign-in address, basic profile name, and account and organization identifiers. We verify that the sign-in address belongs to an approved school domain and that Microsoft associates that domain with the organization issuing your identity. We store the account identifier to connect your Sublyst account. We do not request access to your mailbox, contacts, files or calendar, and do not retain Microsoft access or refresh tokens. Microsoft’s privacy notice also applies.

Cookies and protections

The site uses a session cookie to keep you signed in. It currently has no integrated advertising trackers and does not use browser Do Not Track signals to change its functional cookies or the on-site interest counting described below. Provider websites have their own notices. We use password hashing, access controls and secure connections on the hosted site. Uploaded photos are decoded and re-encoded to remove image metadata. Older stored uploads are checked in batches; unchecked stored photos are temporarily unavailable until processed, and invalid images are removed. No service can guarantee absolute security.

Contact without an account

Our contact form and homepage feedback form store your topic, subject and message. It provides a private link for checking status and reading the team’s reply; it does not send email notifications. Anyone with that link can read the status and a general reply, so keep it private. Public replies are limited to standard messages; the link does not expose your submitted message or private account records. Do not submit passwords or sensitive documents. Submitting feedback does not subscribe you to marketing. The form does not verify your identity; staff must verify account control before disclosing private account information.

18+ access and application profiles

Public listings can be browsed without an account or age confirmation. Creating or using an account requires confirmation that you are at least 18. Profile setup requires your self-reported birth year; users in the youngest eligible birth year must also confirm that they have already turned 18. We do not collect a birth month or day or verify age using identity documents. We display the birth year as provided, not an exact age calculated from that year. Older application snapshots may retain an exact age supplied under an earlier flow until the normal application retention period ends.

Sending an application copies your saved profile, including birth year, any saved phone number and photo, housing preferences, your account email and optional message. You can preview it before sending. The receiving Host and authorized operators can see this snapshot. Your roommate-gender search preference is not sent to Hosts. Birth year is not a public people-directory field, search filter or automated applicant-ranking input. Profile changes do not rewrite submitted applications; application edits change that application only. These fields follow the existing profile and application retention/deletion rules.

Household profiles and comparisons

Optional household answers are public listing content. Describe shared living habits without identifying roommates or sharing their private information. Applicants can privately compare their saved preferences with a listing; viewing this comparison does not send their profile to the lister. Roommate-gender filters use the lister’s description of other people who will remain in the same home and share living areas with the incoming renter, excluding the person moving out. A positive roommate count is required to add gender; unknown counts do not match a specific gender preference. No preference includes all households; homes with no other roommates appear under either gender choice. These search preferences do not restrict who can apply. Listers can compare submitted application snapshots in their private dashboard. These comparisons use stated living preferences, budgets and dates, do not rank people, and are not a verification or compatibility guarantee. Household answers follow listing retention and are included in the lister’s data export.

Opening a published listing can contribute to its recent-interest ranking. We count at most one view per browser session per listing in a rolling seven-day period, excluding signed-in owners. We store a protected session identifier with the listing and time, not an email or IP address in the view records. Records expire after seven days and are removed during hourly cleanup. Clearing cookies or using another browser can count separately. Trending reflects recent interest, not verification or trust. Public listing pages also show aggregate recent views and first-publication dates. Visitor identities are not shown. Temporary search preferences affect that search only and do not update your rental profile.

Retention

These periods apply to Sublyst’s working database and photo storage for the current free service. Cleanup runs hourly, retries failures, and records its progress. An ordinary open support ticket or listing report does not block account deletion or unrelated cleanup. Authorized administrators can preserve an encrypted copy of one selected record for a documented reason and at most 90 days per hold, with access logged. These copies exclude photo files and do not block deletion of the rest of an account. Expired copies are removed by hourly cleanup. Legacy broad preservation holds require review and replacement before affected deletion can proceed; unresolved test billing can also require resolution. Records without a reliable historical date receive a full retention window when this system is introduced.

A copyright hold hides the affected listing and freezes edits while a notice is reviewed. Its current photos remain in private working storage for up to 90 days per documented preservation period, which an administrator may extend for a continuing case. If that period expires, the listing stays hidden and ordinary closure cleanup begins. Closing or deleting the listing or account still starts ordinary deletion; a hold does not preserve a separate photo archive or block deletion of unrelated data.

Website copyright-case records are deleted 180 days after case resolution. Account-restriction records include a limited hash of the account email so deleting and recreating an account with the same email does not bypass an active restriction. Active restrictions and their reasons are reviewed at least every 180 days; released restriction records are deleted after 180 days. These records may remain after account deletion when needed to enforce the restriction. Administrative decision logs follow the one-year schedule above. These website records are separate from copyright emails reviewed manually in the agent’s inbox.

Backups and provider copies

Supabase maintains daily database backups with seven days of history. Listing-photo backups run separately each day and are encrypted in private Cloudflare R2 storage with a 30-day expiration rule. Deletion from working records does not immediately remove older backup copies. Provider processing delays can affect expiry. Before restoring backups to service, we reconcile recent account deletions so erased accounts are not simply brought back.

Providers also retain their own service records. Render and our Supabase plan currently provide seven days of dashboard log history. Resend retains email content and logs for 30 days and its backups for seven days. These windows describe the relevant service records, not a guarantee that every provider record or legally required record disappears at that time. We do not promise immediate deletion from every provider or from copies independently saved by recipients.

Your choices and deletion

In Account settings, download your data or submit a tracked deletion request. A recent sign-in is required. Your download includes your own applications, not private information submitted by other applicants. You can also edit profile details, withdraw applications, close listings, or delete your account from My account. Account deletion removes your profile, listings, favorites and applications from the working database and queues stored photos for removal. It also removes applications to your deleted listings. Limited test-payment, report, administrative and privacy-request records can remain for the periods above.

If an unresolved issue prevents deletion, use the contact form for review. You can request access, correction, export or deletion without signing in, but the form alone does not prove identity: we must verify account control before disclosing or deleting private data. Do not send identity documents; they are not part of ordinary support. We cannot recall delivered emails or delete copies independently retained by listers.

Depending on the law that applies to you, you may have additional privacy rights, including using an authorized agent or appealing a request decision. Use the contact form or signed-in support and identify the request you want reviewed. We may verify your identity and an agent’s authority. We will not discriminate against you for exercising applicable privacy rights.

School requests currently provide a private status link instead of emailing a decision. Keep that link private. We post updates to this notice with a version and effective date. For material changes to this policy bundle, the site prompts account holders to review it before new posting, saving or application activity. You may still browse, contact support or request deletion without accepting new terms.

Public Host introductions and community ratings

Your optional public Host name and introduction are separate from your private applicant profile. On your listings we show this public introduction, membership month, first-listing month and account/school verification labels. These dates do not establish completed hosting experience. You can edit or clear your introduction in Account settings. Clearing it changes our display but cannot erase copies saved by others.

A community rating records the rating account, listing, half-star score from 0.5 to 5 and update time. Public pages show the aggregate average and count, not reviewer names, contact details or a public reviewer profile. Signed-in users can see their own rating. Authorized administrators can inspect account-linked ratings to handle moderation. Ratings are open to accounts without proof of an application or stay and are not verified guest reviews. You can change or remove your rating. Ratings and Host introductions are included in your private data export and are removed with account deletion; administrative moderation logs follow the existing audit retention period.

Property preferences and private blocking

Home type, amenities, bedroom and bathroom counts, bathroom access and approximate square footage describe the Host’s listing. Square footage refers to the entire home, including shared rooms, even when only a room is offered. Household size and minimum space preferences supplied in your renter profile are private until included in an application. They are not guarantees about occupancy, suitability or accessibility.

Blocking a listing stores a private link between your account and the listing and hides it from your browsing, search and saved-listing results. It does not block communications or applications already sent. You can unblock it from Account settings. Blocking choices are included in your private export and removed with your account.

Back to top ↑