Privacy notice
How we handle information.
Last updated September 11, 2026
Scope
This notice describes how ProBuilder OS handles information through the public website, Founding Builder Program, authenticated web application, client portal, and mobile applications. A company using ProBuilder OS is responsible for the project and client information its authorized users place in that company's workspace.
Information we collect
We may collect information you choose to provide, including:
- Name, work email, company, role, and company type
- Project volume, current tools, and the operational problem you describe
- Messages, feedback, support requests, and Founding Builder application details
- Account, subscription, team, and onboarding information
- Workspace records such as leads, estimates, projects, schedules, tasks, daily logs, invoices, project financial records and exports, client messages, photos, videos, files, and proposal acceptance records
- Project cost details such as category budgets, committed or actual status, vendor or payee, cost and paid amounts, payment status, labor quantity and rate, transaction date, source reference, notes, and record authorship and update history
- AI scope-draft requests, generated drafts, review provenance, and usage records when an authorized contractor chooses that feature
- Plan-set files, selected drawing regions, AI-assisted takeoff suggestions, source evidence, contractor corrections, review decisions, and related usage records when an authorized contractor chooses plan analysis
We may also receive basic technical information needed to deliver and protect the site, such as request time, referring page, campaign parameters, browser or device category, and security logs. Campaign details tied to a workspace signup are stored with that company's Firebase workspace so we can understand acquisition performance. We do not sell personal information.
How we use information
- Review Founding Builder applications and contact appropriate candidates
- Create and operate company workspaces, client access, onboarding, and support
- Understand contractor workflows and prioritize product development
- Operate, secure, troubleshoot, and improve the website and application
- Meet legal obligations and prevent abuse
AI-assisted proposal drafting
When an authorized contractor chooses to generate a scope draft, ProBuilder OS may send the project description and a limited set of non-contact project characteristics to an AI service provider. We do not intentionally include the client's name, email, phone, exact street address, proposal price, payment schedule, files, messages, or unrelated workspace records in that request. AI output is a draft that the contractor must review and edit where needed before saving or sharing. Do not place sensitive personal information in the project description.
Scope drafting currently uses OpenAI's Responses API with application storage disabled for the provider request. ProBuilder OS separately stores the generated draft, its provider and review provenance, and usage information in Firebase-backed application records so the contractor can review the result and we can enforce plan limits. An abandoned private scope draft is configured to expire after seven days; scope applied to a proposal remains part of that company's workspace record.
OpenAI states that API data is not used to train its models by default unless the API customer opts in. Its abuse-monitoring logs may contain prompts and responses and are generally retained for up to 30 days, subject to approved data controls and limited legal or safety exceptions described by OpenAI.
AI-assisted plan analysis
Plan analysis is optional and starts only after an authorized contractor selects a confirmed drawing region, chooses the item categories to analyze, and confirms the disclosure shown beside the run control. ProBuilder OS sends a bounded copy of that selected plan page or region to OpenAI's Responses API. Unlike proposal-scope drafting, construction drawings may visibly contain project addresses, owner or design professional names, permit information, and other project details. Do not use plan analysis unless the company is authorized to submit that drawing to an AI provider.
Provider application storage is disabled for the request. OpenAI states that API data is not used to train its models by default unless the API customer opts in, while abuse-monitoring logs may contain submitted content and are generally retained for up to 30 days subject to approved data controls and limited legal or safety exceptions. ProBuilder OS stores the exact source revision, selected calibration, model and prompt provenance, suggested evidence, usage, corrections, and contractor review decisions in the company workspace for auditability.
AI takeoff results are suggestions, not verified construction quantities. A contractor must compare every suggestion with the source drawing and verify, correct, or reject it. Suggested or rejected quantities cannot be synchronized into estimate pricing.
Transactional email delivery
When ProBuilder OS sends an invitation, proposal notice, acceptance receipt, account notice, project-message alert, secure schedule alert, or change-order alert, it may briefly store the recipient and email content in a trusted-server delivery queue. Pending content is encrypted with authenticated encryption and cannot be read by browser or mobile clients. The encrypted content is erased after the email provider accepts the request, erased if the request requires manual review, and configured to expire no later than the message's usefulness or security deadline. A separate content-free ledger may retain recipient and content digests, provider identifiers, status, and signed delivery events for operational, security, and audit purposes.
For authenticated project-message and operational notifications, ProBuilder OS also stores a content-free event for the intended user and whether it has been opened. Project-message alerts also honor the user's choice to receive immediate email, a daily digest, or in-app notifications only; security-relevant operational notices are immediate. A pending digest item contains opaque event and recipient references, timing, status, and access-generation metadata; it does not contain message text, change-order scope or price, project or person names, email addresses, file names, or bearer access links. Current account, project, and exact resource revision access is checked before an event is shown, opened, or released for delivery. Content-free in-app events are configured to expire after 90 days. Pending and completed digest metadata is configured to expire no later than 14 days after its source event.
Electronic proposal acceptance
If a client chooses electronic proposal review, we retain the exact issued proposal, its integrity hash, the authenticated signer identity, typed or drawn electronic signature, consent choices, server-recorded acceptance time, application and platform context, and an idempotency record used to prevent duplicate acceptance. We retain these records as shared business evidence even if a user later requests account deletion. A typed signature stores the normalized typed name. A drawn signature stores normalized stroke coordinates and an integrity hash. We do not request or intentionally derive touch pressure, drawing velocity, device biometrics, or a biometric identity template from a proposal signature.
Project financial records
Authorized company users may enter operational project budgets and cost-ledger records for labor, materials, subcontractors, and miscellaneous costs. ProBuilder OS derives project and company earnings views from those user-entered records together with stored contract, approved-change, invoice, and payment information. These reports reflect the workspace data available at the time and are not independently audited or reconciled with a bank, payroll provider, tax system, accounts-payable system, or accounting ledger.
Authorized users may also record customer payments received outside ProBuilder OS, including the invoice, amount, received date, payment method, a staff-only reference, and a staff-only reconciliation note. The service derives invoice balances and recorded collections from those entries. Client views receive only an allowlisted receipt without internal references, notes, or staff identity. Voiding removes the amount from active totals while retaining the original receipt and void evidence for integrity and dispute review. ProBuilder OS does not process, settle, or independently verify the payment.
An authorized user can request a project cost-ledger CSV. The service generates that export on demand; any copy downloaded to a browser, device, email, or another system is then controlled by the company and user handling it. ProBuilder OS does not currently synchronize these records with QuickBooks or another accounting platform.
When an authorized user voids an active cost record, ProBuilder OS removes that amount from active project totals but retains an immutable server-side copy of the original record together with the voiding actor and time. This protects the integrity of the project's operational audit history and prevents a voided record identifier from being reused as a new cost.
An owner or administrator may archive a completed project's cost ledger. Archiving records a hashed aggregate financial checkpoint and immutable archive event, and makes costs and budgets read-only; it does not delete active, legacy, or voided cost history. A later reopen creates another retained event. Authorized users may also request an audit CSV that includes active, legacy-preserved, and voided records together with current archive metadata. These records remain part of the company workspace until workspace deletion, subject to shared-record, security, dispute, and legal-retention limits described below.
Analytics and preferences
The public site uses Google Analytics to understand page visits, navigation, and conversion events. Advertising storage, advertising user data, and ad personalization are disabled in our site tag. Analytics storage begins denied and is enabled only when you choose "Allow analytics." We store that choice in a first-party preference cookie; choosing "Essential only" keeps analytics storage denied. Do not enter personal information in campaign URL parameters.
Service providers and disclosure
Information may be processed by infrastructure, authentication, hosting, database, communication, analytics, and support providers used to operate the service. We may also disclose information when required by law, to protect rights or safety, or in connection with a business transaction. We do not authorize service providers to use information for their own unrelated marketing.
Workspace data
ProBuilder OS uses Firebase services for authentication, database records, file storage, and application hosting. Workspace access is tied to authenticated identities, company membership, roles, and project or client assignments. Do not submit regulated, highly sensitive, or unrelated personal information unless a written agreement explicitly places it in scope.
Retention and choices
We retain information as long as reasonably needed to provide the service, maintain business and security records, resolve disputes, or meet legal obligations. You may ask us to update or delete a Founding Builder application, request help with workspace data, or opt out of non-essential communications by emailing us. Applicable privacy rights vary by location; we will respond to verified requests as required by law.
Project cost, earnings, invoice, payment, and related source-reference records are operational company-workspace records. They are retained under the workspace and account policies described here and may remain with shared project, transaction, audit, or legally required records after an individual user's access is removed.
Client and Pro mobile users can review the authenticated request process, the data covered, and shared-record retention limits on our account deletion page.
A company owner's request may remain in review with access active until verified workspace and billing ownership is transferred, or the workspace and subscription are closed. Other authenticated client and team member deletion requests promptly revoke account access.
Security
We use reasonable technical and organizational measures appropriate to the product’s current stage. No internet service can promise absolute security. See the security page for current controls and service boundaries.
Children
ProBuilder OS is a business service and is not directed to children under 13. We do not knowingly collect personal information from children through the public site.
Contact
Questions or privacy requests can be sent to info@terrabuildr.com.