Privacy Policy

DRAFT — UNREVIEWED. This document has not yet been reviewed by counsel. Do not publish or rely on it. Engage a US attorney with SaaS + AEC experience to finalize. Bracketed [FILL IN] markers indicate fields the operator must supply.

Version: 2026-06-16 Effective date: [FILL IN — date of public ship] Applies to: Use of the TraceBIM service at [FILL IN — production URL] and all related software, APIs, and documentation (the "Service").


1. Who we are

The Service is operated by [FILL IN — legal entity name; e.g. "Farhad Shariatzadeh" or "TraceBIM, LLC"] ("we," "us," "our"), with a registered business address at [FILL IN — US street address]. You can reach us about privacy questions at [FILL IN — privacy@domain].

2. Scope and audience

The Service is offered to users located in the United States. We do not knowingly direct the Service to, or knowingly process personal information of, residents of the European Union, United Kingdom, or other jurisdictions outside the United States. If you are outside the United States, do not use the Service.

The Service is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the Service, contact us at the address above and we will delete the account.

3. What we collect

We limit collection to what the Service needs to function. Today we collect:

3.1 Account information

Created when you register an account:

We do not store passwords in plaintext. (Authentication is currently being integrated via [FILL IN — e.g., "an external identity provider" or "bcrypt-hashed passwords"]; this section will be updated when authentication ships.)

3.2 Content you create or upload

The Service is a parametric building-information-modeling and drafting tool. To provide it, we store the project content you create or upload:

3.3 Technical information

When you use the Service we may automatically log:

These are retained for security and abuse-prevention purposes for a rolling 90-day window unless required for a longer period to investigate a specific incident.

3.4 What we do not collect today

For transparency:

4. How we use your information

We use the information described in Section 3 only to:

We do not train machine-learning models on your content, and we do not permit our sub-processors to train their models on your content (see Section 5).

5. AI features and the Anthropic sub-processor

The Service offers AI-assisted design features (redline interpretation, conversational design assistance, floor-plan vectorization, component generation, and sheet validation). When you invoke an AI feature, content you have provided is transmitted to our AI sub-processor, Anthropic, PBC, to be processed by Claude.

The content sent for each AI feature includes some or all of the following:

FeatureWhat is transmitted to Anthropic
Redline interpret (POST /ai/interpret)A rendered screenshot of your viewport and a snapshot of your element graph
Chat (POST /ai/chat)Your prompt, the conversation history, a snapshot of your element graph, and any reference images you attach
Floor-plan import (POST /ai/import-floorplan)The floor-plan image you uploaded
Component creation (POST /ai/createComponent)The text description you supplied and any reference image you attached
Sheet validation (POST /ai/validateSheet)A rendered or exported version of the sheet you are validating

Anthropic acts as our service provider under its Commercial Terms of Service. Under those terms, Anthropic does not train its models on inputs submitted through the API.

You can decline AI processing. AI features are opt-in. The first time you invoke any AI feature, the Service will display a prominent disclosure and require your explicit consent before transmitting anything to Anthropic. You can use the entire non-AI functionality of the Service without ever enabling AI features. We log a server-side record of your consent (or refusal) for audit purposes.

Confidential or restricted content. Do not submit content to AI features that you are contractually, ethically, or legally prohibited from sharing with a third-party processor. Examples include export-controlled designs, classified-program work, content subject to a non-disclosure agreement that does not permit AI subprocessing, and content subject to government clearance requirements. You are responsible for ensuring that your use of AI features complies with the obligations you owe to your own clients and regulators.

6. Cookies and similar technologies

The Service uses first-party session cookies and localStorage only — there are no third-party cookies, advertising pixels, or cross-site trackers. The session cookie keeps you logged in. LocalStorage holds non-identifying UI preferences and a record that you accepted these policies (so we don't show the acceptance prompt every time you load the app). You can clear both at any time via your browser settings; doing so will log you out and require you to accept the policies again on the next load.

7. How we share information

We do not sell your information and we do not "share" it for cross-context behavioral advertising. We disclose information only in these limited circumstances:

8. How long we keep it

After permanent deletion, residual copies may remain in encrypted backups for up to 90 days before being overwritten in normal backup rotation.

9. How we protect it

We use commercially reasonable administrative, technical, and physical safeguards to protect your information, including transport encryption (TLS), encrypted at-rest storage of database backups, row-level access controls in the database, principle-of-least-privilege access for our personnel, and periodic security reviews. No system is perfectly secure, and we cannot guarantee that unauthorized parties will never gain access. If we discover a security incident affecting your information, we will notify you in accordance with applicable US state breach-notification statutes.

10. Your rights — including California (CCPA / CPRA)

Regardless of where you live in the US, you may:

To exercise any of these rights, email [FILL IN — privacy@domain] from the email address on your account. We will respond within 45 days.

California residents have additional rights under the CCPA and CPRA:

You may use an authorized agent to submit a request; we will require verification that the agent is acting on your behalf.

CCPA disclosure table (last 12 months)

Category of personal information collectedSourceBusiness purposeDisclosed to
Identifiers (email, account ID)Directly from youAccount creation, authentication, service noticesInfrastructure providers (Section 7)
Internet activity (IP, user agent, request logs)Automatically from your deviceSecurity, abuse prevention, service operationInfrastructure providers (Section 7)
Commercial information (project content you create)Directly from youProviding the ServiceAnthropic (only when you invoke AI features)
Visual information (reference images you upload)Directly from youProviding the Service; AI processing only if you invoke AI featuresAnthropic (only when you invoke AI features)
InferencesWe do not derive inferences from your information

11. Children

The Service is not directed to or intended for use by anyone under 18. We do not knowingly collect personal information from anyone under 18, and specifically do not knowingly collect from anyone under 13 within the meaning of the Children's Online Privacy Protection Act ("COPPA").

12. Changes to this Policy

We may update this Policy from time to time. The "Version" date at the top will change, and the prior version will be archived in legal/CHANGELOG.md in the public repository. If a change materially expands the categories of information we collect, the purposes for which we use it, or the third parties to whom we disclose it, we will notify you by email at the address on your account at least fourteen (14) days before the change takes effect and, where required, will require you to re-accept this Policy before continuing to use the Service.

Your continued use of the Service after the effective date of a non-material change constitutes acceptance.

13. Contact

Privacy questions, requests, or complaints: [FILL IN — privacy@domain].

Postal mail: [FILL IN — US street address].

← Back to TraceBIM