DRAFT — UNREVIEWED. This document has not yet been reviewed by counsel. Do not publish or rely on it. Engage a US attorney with SaaS + AEC experience to finalize. Bracketed
[FILL IN]markers indicate fields the operator must supply.
Version: 2026-06-16 Effective date: [FILL IN — date of public ship] Applies to: Use of the TraceBIM service at [FILL IN — production URL] and all related software, APIs, and documentation (the "Service").
The Service is operated by [FILL IN — legal entity name; e.g. "Farhad Shariatzadeh" or "TraceBIM, LLC"] ("we," "us," "our"), with a registered business address at [FILL IN — US street address]. You can reach us about privacy questions at [FILL IN — privacy@domain].
The Service is offered to users located in the United States. We do not knowingly direct the Service to, or knowingly process personal information of, residents of the European Union, United Kingdom, or other jurisdictions outside the United States. If you are outside the United States, do not use the Service.
The Service is not directed to children. We do not knowingly collect personal information from anyone under 18. If you believe a minor has used the Service, contact us at the address above and we will delete the account.
We limit collection to what the Service needs to function. Today we collect:
Created when you register an account:
We do not store passwords in plaintext. (Authentication is currently being integrated via [FILL IN — e.g., "an external identity provider" or "bcrypt-hashed passwords"]; this section will be updated when authentication ships.)
The Service is a parametric building-information-modeling and drafting tool. To provide it, we store the project content you create or upload:
When you use the Service we may automatically log:
These are retained for security and abuse-prevention purposes for a rolling 90-day window unless required for a longer period to investigate a specific incident.
For transparency:
We use the information described in Section 3 only to:
We do not train machine-learning models on your content, and we do not permit our sub-processors to train their models on your content (see Section 5).
The Service offers AI-assisted design features (redline interpretation, conversational design assistance, floor-plan vectorization, component generation, and sheet validation). When you invoke an AI feature, content you have provided is transmitted to our AI sub-processor, Anthropic, PBC, to be processed by Claude.
The content sent for each AI feature includes some or all of the following:
| Feature | What is transmitted to Anthropic |
|---|---|
Redline interpret (POST /ai/interpret) | A rendered screenshot of your viewport and a snapshot of your element graph |
Chat (POST /ai/chat) | Your prompt, the conversation history, a snapshot of your element graph, and any reference images you attach |
Floor-plan import (POST /ai/import-floorplan) | The floor-plan image you uploaded |
Component creation (POST /ai/createComponent) | The text description you supplied and any reference image you attached |
Sheet validation (POST /ai/validateSheet) | A rendered or exported version of the sheet you are validating |
Anthropic acts as our service provider under its Commercial Terms of Service. Under those terms, Anthropic does not train its models on inputs submitted through the API.
You can decline AI processing. AI features are opt-in. The first time you invoke any AI feature, the Service will display a prominent disclosure and require your explicit consent before transmitting anything to Anthropic. You can use the entire non-AI functionality of the Service without ever enabling AI features. We log a server-side record of your consent (or refusal) for audit purposes.
Confidential or restricted content. Do not submit content to AI features that you are contractually, ethically, or legally prohibited from sharing with a third-party processor. Examples include export-controlled designs, classified-program work, content subject to a non-disclosure agreement that does not permit AI subprocessing, and content subject to government clearance requirements. You are responsible for ensuring that your use of AI features complies with the obligations you owe to your own clients and regulators.
The Service uses first-party session cookies and localStorage only — there are no third-party cookies, advertising pixels, or cross-site trackers. The session cookie keeps you logged in. LocalStorage holds non-identifying UI preferences and a record that you accepted these policies (so we don't show the acceptance prompt every time you load the app). You can clear both at any time via your browser settings; doing so will log you out and require you to accept the policies again on the next load.
We do not sell your information and we do not "share" it for cross-context behavioral advertising. We disclose information only in these limited circumstances:
After permanent deletion, residual copies may remain in encrypted backups for up to 90 days before being overwritten in normal backup rotation.
We use commercially reasonable administrative, technical, and physical safeguards to protect your information, including transport encryption (TLS), encrypted at-rest storage of database backups, row-level access controls in the database, principle-of-least-privilege access for our personnel, and periodic security reviews. No system is perfectly secure, and we cannot guarantee that unauthorized parties will never gain access. If we discover a security incident affecting your information, we will notify you in accordance with applicable US state breach-notification statutes.
Regardless of where you live in the US, you may:
To exercise any of these rights, email [FILL IN — privacy@domain] from the email address on your account. We will respond within 45 days.
California residents have additional rights under the CCPA and CPRA:
You may use an authorized agent to submit a request; we will require verification that the agent is acting on your behalf.
| Category of personal information collected | Source | Business purpose | Disclosed to |
|---|---|---|---|
| Identifiers (email, account ID) | Directly from you | Account creation, authentication, service notices | Infrastructure providers (Section 7) |
| Internet activity (IP, user agent, request logs) | Automatically from your device | Security, abuse prevention, service operation | Infrastructure providers (Section 7) |
| Commercial information (project content you create) | Directly from you | Providing the Service | Anthropic (only when you invoke AI features) |
| Visual information (reference images you upload) | Directly from you | Providing the Service; AI processing only if you invoke AI features | Anthropic (only when you invoke AI features) |
| Inferences | — | We do not derive inferences from your information |
The Service is not directed to or intended for use by anyone under 18. We do not knowingly collect personal information from anyone under 18, and specifically do not knowingly collect from anyone under 13 within the meaning of the Children's Online Privacy Protection Act ("COPPA").
We may update this Policy from time to time. The "Version" date at the top will change, and the prior version will be archived in legal/CHANGELOG.md in the public repository. If a change materially expands the categories of information we collect, the purposes for which we use it, or the third parties to whom we disclose it, we will notify you by email at the address on your account at least fourteen (14) days before the change takes effect and, where required, will require you to re-accept this Policy before continuing to use the Service.
Your continued use of the Service after the effective date of a non-material change constitutes acceptance.
Privacy questions, requests, or complaints: [FILL IN — privacy@domain].
Postal mail: [FILL IN — US street address].
← Back to TraceBIM