Legal

Privacy policy

Last updated 6 September 2026

BuildFlow holds contracts, drawings, photographs of people's homes and the record of how a job was run. This says what we collect, why, who can see it, and how to get it back or have it deleted — in the plainest English we can manage.

Who we are

BuildFlow is provided by [YOUR COMPANY NAME LTD], [YOUR REGISTERED ADDRESS]. For UK GDPR purposes we are the data controller for account data, and a data processor for the project content our customers put into the product.

If you are a homeowner using BuildFlow because your builder invited you, your builder is the controller of that project's content and we process it on their behalf. Questions about what is held on your job are best put to them; questions about the software are for us.

What we collect

Account data. Your name, email address, phone number if you give one, job title, avatar, and the password hash produced when you set a password. We never see your password itself.

Company data. For builders: company name, address, contact details, logo, brand colour, registration and VAT numbers, and the insurance and qualification entries you add.

Project content. Everything you put into a job — the programme, tasks, site diary entries, photographs, snags, messages, documents, certificates and inspection records — including anything you happen to include inside those.

Technical data. IP address and browser or device type in server and security logs, and the device description stored against a push-notification subscription so you can tell your phone from your tablet.

Usage data. When AI features are used, we record the number of tokens and the cost of each request against the company, so spend can be shown and capped.

What we do not collect

We do not use advertising trackers, we do not sell data to anyone, and we do not build a profile of you for marketing. There are no third-party analytics or advertising SDKs in the app.

We do not ask for or hold payment card details. If and when card payment is added, it will be through a payment processor that holds them instead of us.

The mobile app requests no device permissions beyond notifications, and the camera and photo library when you choose to add a photograph.

Why we hold it, and on what basis

To provide the service — the whole of the project content, on the basis of performing our contract with you or your builder.

To keep accounts secure — authentication and security logs, on the basis of our legitimate interest in preventing unauthorised access.

To send you notifications — in-app and, where you have switched it on, push. Push is on the basis of your consent, given per device, and withdrawable in the app or your phone's settings.

To answer questions with FlowAI — project data is sent to our AI provider only when somebody asks a question, and only what is needed to answer it. See below.

To bill and support — company and contact details, on the basis of contract and our legitimate interest in running the business.

Who can see your data

Access inside BuildFlow is enforced by the database, not by hiding parts of the interface. Company staff see the projects they are put on; clients see only their own project, and never the site diary, costs, or internal notes.

Outside BuildFlow, data is shared only with the suppliers that run it:

  • Supabase — database, authentication and file storage. Hosted in the region chosen when the account was set up.
  • Vercel — application hosting and serving.
  • OpenRouter and the model provider it routes to — only when an AI feature is used, and only the project content needed for that request. Your data is not used to train their models.
  • Google, Apple, Mozilla and Microsoft push services — the encrypted contents of a push notification, if you have turned notifications on.

We will disclose data if we are legally required to. We will tell the account owner unless we are prohibited from doing so.

FlowAI and your project data

When somebody asks FlowAI a question, a bounded summary of that project plus any records the assistant looks up are sent to the model provider to answer it. Nothing is sent when the feature is not used, and turning it off stops it entirely.

The assistant runs on the asking person's own permissions, so it cannot see anything that person could not already see. It never makes changes without an explicit confirmation.

Project data is not used to train models. Requests are not retained by us beyond the token and cost figures used for the spend cap.

Where data is held

In the Supabase region chosen when the account was set up, with application hosting on Vercel's global network. Where a supplier processes data outside the UK or EEA, that transfer relies on the UK International Data Transfer Addendum or Standard Contractual Clauses.

If you have a specific data residency requirement, tell us before you sign up rather than after.

How long we keep it

Project content is kept for as long as the account exists. Dropping to a smaller plan never deletes anything; it only stops you adding more.

Completed and archived projects are kept, deliberately — the record of a job is the thing you want years later when a question comes up about it.

Audit logs are append-only and are kept for the life of the account. They cannot be edited by your team or by us; that is what makes them worth having.

On account deletion, project content is removed within 30 days, other than anything we must keep for legal or accounting reasons.

Your rights

Under UK GDPR you can ask for a copy of your data, correct it, have it deleted, restrict or object to how it is used, and ask for it in a portable form. Most of this is available in the product: profile data is editable, documents and photographs download as the files you uploaded, and the handover pack gathers a project into a single PDF.

For anything the product does not cover, email hello@example.com and we will respond within one month.

If you are unhappy with how we have handled it, you can complain to the Information Commissioner's Office at ico.org.uk.

Security

Row Level Security on every table, so access is decided by the database rather than the application. Files in private storage with short-lived signed links and no public URLs. Server-side session verification on every request. An append-only audit trail of who changed what.

We are not certified to ISO 27001 or SOC 2, and we would rather say so than imply otherwise with a badge.

If you believe you have found a security issue, email hello@example.com with enough detail to reproduce it. We will not take issue with anyone reporting one in good faith.

Children

BuildFlow is a tool for businesses and their customers. It is not directed at children and we do not knowingly collect data from anyone under 16.

Changes

If we change this policy in a way that materially affects you, we will tell account owners by email or in the app before it takes effect. The date at the top always reflects the current version.

Contact

Questions about this policy, or a request about your own data: hello@example.com.

See also our terms of service and security overview.

Privacy policy · BuildFlow