Version: 2026-09-18 Effective date: September 18, 2026 Applies to: the TraceBIM service at https://www.tracebimai.com, the TraceBIM app for iPhone and iPad, and all related software, APIs, and documentation (the "Service").
The Service is operated by TraceBIM, LLC ("we," "us," "our"), a United States limited liability company. You can reach us about privacy questions, requests, or complaints at [email protected]. We respond to every request from the email address on your account.
The Service is offered to users located in the United States. We do not knowingly direct the Service to, or knowingly process personal information of, residents of the European Union, United Kingdom, or other jurisdictions outside the United States. If you are outside the United States, do not use the Service.
The Service is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the Service, contact us at the address above and we will delete the account.
We limit collection to what the Service needs to function, to bill you, and to keep the Service secure. Today we collect:
Created when you register an account:
The Service is a parametric building-information-modeling and drafting tool. To provide it, we store the project content you create or upload:
When you use an AI feature we keep, in addition to the content above:
When you use the Issue for Permit feature we permanently record the attestation you make: your account identity, your stated role, the jurisdiction and property address you enter, each confirmation you check, the sheet list, a cryptographic fingerprint of the exported file, your network (IP) address, and the date and time. Each issued export carries an issuance number that identifies this record. See Section 5.2a of the Terms of Service.
Payments are handled by Stripe, Inc. on hosted checkout and billing-portal pages. Stripe collects your payment-card details, name, and billing address directly; we never receive or store your full card number. We store the Stripe customer and subscription identifiers for your workspace, your subscription status and billing period, and a record of each AI-credit purchase (amount, price, tax collected, status, and a link to the Stripe receipt).
When you use the in-app Feedback button we store the sentiment you picked, the message you typed, the screenshot you chose to attach, the app version, your browser or device, and the time. For feedback that reports a bug or frustration, the sentiment, message, and app version (never the screenshot) are copied into the private issue tracker we use to fix problems; that tracker is hosted by GitHub, Inc.
We use the information described in Section 3 only to:
We do not send marketing email without your separate consent.
The Service offers AI-assisted design features (redline interpretation, conversational design assistance, floor-plan vectorization, component generation, and sheet validation). When you invoke an AI feature, content you have provided is transmitted to our AI sub-processor, Anthropic, PBC, to be processed by its Claude models.
The content sent for each AI feature includes some or all of the following:
| Feature | What is transmitted to Anthropic |
|---|---|
| Redline interpret | A rendered screenshot of your viewport, your redline strokes, and a snapshot of your element graph |
| Chat | Your prompt, the conversation history, a snapshot of your element graph, and any reference images you attach |
| Floor-plan import | The floor-plan image or photo you uploaded |
| Component creation | The text description you supplied and any reference image you attached |
| Sheet validation | A rendered or exported version of the sheet you are validating |
Anthropic acts as our service provider under its Commercial Terms of Service. Under those terms, Anthropic does not train its models on inputs submitted through the API.
You can decline AI processing. AI features are opt-in. The first time you invoke any AI feature, the Service displays a disclosure and requires your explicit consent before transmitting anything to Anthropic. You can use the entire non-AI functionality of the Service without ever enabling AI features. We keep a server-side record of your consent for audit purposes.
Confidential or restricted content. Do not submit content to AI features that you are contractually, ethically, or legally prohibited from sharing with a third-party processor. Examples include export-controlled designs, classified-program work, content subject to a non-disclosure agreement that does not permit AI subprocessing, and content subject to government clearance requirements. You are responsible for ensuring that your use of AI features complies with the obligations you owe to your own clients and regulators.
The Service uses first-party browser storage only — there are no third-party cookies, advertising pixels, or cross-site trackers. Your browser's local storage holds your sign-in session, non-identifying interface preferences, a record that you accepted these policies (so we don't show the acceptance prompt on every load), your AI-consent choice, and the random visitor token used by our page-view analytics. Stripe's hosted checkout pages set their own cookies under Stripe's privacy policy. You can clear browser storage at any time via your browser settings; doing so signs you out.
We honor the Global Privacy Control signal as confirmation that we do not sell or share your personal information; because we never do, there is nothing further for it to switch off.
We do not sell your information and we do not "share" it for cross-context behavioral advertising. We disclose information only in these limited circumstances:
These companies process data on our instructions, under written terms requiring confidentiality and security, and only to provide their service to us:
| Provider | What it processes | Purpose |
|---|---|---|
| Anthropic, PBC | Content you submit through AI features (Section 5) | AI features |
| Stripe, Inc. | Payment details, billing address, purchase and subscription records | Payments, subscriptions, sales tax |
| Cloudflare, Inc. | Web traffic to https://www.tracebimai.com, including your network address | Hosting and delivery of the web app; protection against abuse |
| Fly.io, Inc. | All API traffic and, where used, uploaded image files on server disk | Hosting of the API |
| Supabase, Inc. (on Amazon Web Services, US West) | All data described in Section 3 | Application database and backups |
| Google LLC (Google Cloud Storage) | Uploaded reference images, where configured | File storage |
| Resend, Inc. | Your email address and the content of transactional emails | Sending verification codes, password resets, and billing and policy notices |
| GitHub, Inc. | Feedback text, sentiment, and app version (Section 3.6) | Private bug tracking |
| Apple Inc. | App distribution; aggregated diagnostics if you opted in on your device | Distribution of the iPhone and iPad app |
We will update this table before adding a provider that processes personal information.
Our staff can view the data described in Section 3 through an administrative console, gated by separate credentials, in order to debug problems you report, monitor service health and AI cost, and produce aggregate metrics. We do not use that access to look at your projects for any other purpose.
| Data | Retention |
|---|---|
| Account information (active accounts) | For as long as your account exists |
| Account information (deleted accounts) | Your account is deactivated immediately; email, display name, and password hash are kept for a 30-day grace period during which you can ask us to restore the account, then overwritten with non-identifying values |
| Pending signups (unverified email + code) | 48 hours |
| Project content | For as long as the project exists. A project you move to the trash can be restored for 30 days, then it is permanently deleted |
| Mutation log (edit history) | Seven (7) years after a project's final modification, reflecting the professional standard of care for architectural records |
| Uploaded and captured image files | Deleted within 30 days after the parent project is permanently deleted |
| AI usage ledger | 13 months, for billing records |
| AI provenance ledger | As long as the element it describes exists; deleted with the element or project |
| Issue for Permit attestation records | Permanent (see Section 3.4) |
| Billing and purchase records | As long as your account exists plus seven (7) years, as tax and accounting law requires |
| Feedback submissions | Until you ask us to delete them |
| Page-view analytics | 365 days |
| Server logs | Rolling 90 days, unless retained longer to investigate a specific security incident |
| Acceptance records (Terms / Privacy / AUP / AI consent) | As long as your account exists plus seven (7) years, so that we can demonstrate which version of each policy you accepted |
After permanent deletion, residual copies may remain in encrypted backups for up to 90 days before being overwritten in normal backup rotation.
We use commercially reasonable administrative, technical, and physical safeguards to protect your information, including transport encryption (TLS) for every connection, encryption of the database and its backups at rest, row-level access controls in the database that isolate each workspace's data, Argon2id password hashing, signature-verified payment webhooks, principle-of-least-privilege access for our personnel, and periodic security reviews. No system is perfectly secure, and we cannot guarantee that unauthorized parties will never gain access. If we discover a security incident affecting your information, we will notify you in accordance with applicable US state breach-notification statutes. Report a security concern to [email protected].
Regardless of where you live in the US, you may:
To exercise any of these rights, email [email protected] from the email address on your account, or use the Feedback button in the Service. We will confirm receipt within 10 business days and respond within 45 days. We will verify your identity by confirming that the request comes from the email address on the account, and we may ask you to confirm from within the Service.
California residents have additional rights under the CCPA and CPRA:
You may use an authorized agent to submit a request; we will require verification that the agent is acting on your behalf.
| Category of personal information collected | Source | Business purpose | Disclosed to |
|---|---|---|---|
| Identifiers (email, name, account ID, IP address) | Directly from you; automatically from your device | Account creation, authentication, service notices, security, acceptance and attestation records | Infrastructure providers and email provider (Section 7.1) |
| Commercial information (plan, subscription status, purchase records) | Directly from you; from our payment processor | Billing, tax, and accounting | Stripe; infrastructure providers |
| Internet activity (page views, request logs) | Automatically from your device | Security, abuse prevention, service operation, first-party analytics | Infrastructure providers |
| Geolocation (country derived from IP address) | Automatically from your device | First-party analytics | Infrastructure providers |
| Customer content (project content, images, feedback) | Directly from you | Providing the Service; AI processing only if you invoke AI features; bug fixing for feedback | Anthropic (only when you invoke AI features); GitHub (feedback text only); infrastructure providers |
| Inferences | — | We do not derive inferences from your information | — |
The Service is not directed to or intended for use by anyone under 18. We do not knowingly collect personal information from anyone under 18, and specifically do not knowingly collect from anyone under 13 within the meaning of the Children's Online Privacy Protection Act ("COPPA").
We may update this Policy from time to time. The "Version" date at the top will change, each change is recorded in our legal changelog, and prior versions are available on request. If a change materially expands the categories of information we collect, the purposes for which we use it, or the third parties to whom we disclose it, we will notify you by email at the address on your account at least fourteen (14) days before the change takes effect, and the Service will ask you to accept the updated Policy before you continue.
Your continued use of the Service after the effective date of a non-material change constitutes acceptance.
Privacy questions, requests, or complaints: [email protected].
Security reports: [email protected].
Legal notices: [email protected].
← Back to TraceBIM