Skip to main content

Privacy Policy

Last updated: January 2026

At Brickato ("we", "us", or "our"), we are committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our AI-powered construction document platform.

1. Information We Collect

We collect information you provide directly to us, as well as information collected automatically when you use our services.

  • Account Information: Email address, name, password, job title, and language preferences when you create an account.

  • Organization Data: Company name, registration number, contractor classification, capabilities, equipment inventory, certifications, and past project history.

  • Project Documents: Files you upload including PDFs, Word documents, Excel spreadsheets, and images. We process these documents using OCR and AI to extract text and metadata.

  • Chat Conversations: Questions you ask, AI responses, and document citations. We store conversation history to provide context-aware responses.

  • Usage Data: Page views, feature usage, session duration, and interactions with our platform collected through PostHog analytics.

  • Device Information: Browser type, operating system, IP address, and device identifiers.

2. How We Use Your Information

We use the information we collect for the following purposes:

  • Providing and maintaining our AI-powered document analysis services.

  • Processing your documents using OCR and generating searchable, queryable content.

  • Generating AI responses to your questions with relevant citations from your documents.

  • Personalizing your experience based on your organization profile and preferences.

  • Improving our services through analytics and user feedback.

  • Communicating with you about your account, updates, and support inquiries.

  • Ensuring the security and integrity of our platform.

3. Document Processing and AI

When you upload documents, we process them using advanced technologies: Optical Character Recognition (OCR): We use Google Vision API to extract text from scanned documents, including text in multiple languages and handwritten notes. Vector Embeddings: Document text is converted into mathematical representations using OpenAI's embedding models to enable semantic search. AI Analysis: We use large language models (OpenAI GPT-4 and Anthropic Claude) to analyze your documents and generate responses to your questions. Your documents are sent to these AI providers for processing. Important: While we implement security measures, AI processing involves sending document content to third-party AI providers. Do not upload documents containing sensitive personal information that should not be processed by AI systems.

4. Third-Party Services

We use the following third-party services to operate our platform:

  • Supabase: Authentication, database, and file storage services.

  • PostHog: Product analytics and user behavior tracking.

  • OpenAI: Document embeddings and AI-powered responses.

  • Anthropic: AI-powered document analysis and responses.

  • Google Cloud: OCR processing for document text extraction.

  • Render: Application hosting and deployment.

5. Data Storage and Security

We implement industry-standard security measures to protect your data: Your documents are stored in encrypted cloud storage. Database records are protected with row-level security policies. Authentication is handled through secure session tokens. We use HTTPS for all data transmission. However, no method of transmission over the Internet or electronic storage is 100% secure. We cannot guarantee absolute security.

6. Your Rights

You have the following rights regarding your personal data:

  • Access: Request a copy of the personal data we hold about you.

  • Correction: Request correction of inaccurate or incomplete data.

  • Deletion: Request deletion of your account and associated data.

  • Data Portability: Request your data in a machine-readable format.

  • Withdraw Consent: Withdraw consent for data processing where applicable.

7. Cookies and Tracking

We use cookies and similar technologies:

  • Essential Cookies: Required for authentication and session management (Supabase Auth).

  • Preference Cookies: Store your language preference (NEXT_LOCALE).

  • Analytics Cookies: Track usage patterns through PostHog to improve our services.

8. Data Retention

We retain your data for as long as your account is active or as needed to provide services. Account data is retained until you request deletion. Project documents are retained for the duration of your subscription. Chat history is retained to provide conversation context. When you delete your account, we will delete your personal data within 30 days, except where we are required to retain it for legal or regulatory purposes.

9. International Data Transfers

Our services are hosted on cloud infrastructure that may process data in various locations globally. By using our services, you consent to the transfer of your data to various countries, including the United States and European Union, where our cloud service providers operate data centers. We ensure appropriate safeguards are in place for international transfers in compliance with applicable data protection laws.

10. Children's Privacy

Our services are not intended for individuals under the age of 18. We do not knowingly collect personal information from children. If we become aware that we have collected personal data from a child, we will take steps to delete that information.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of any material changes by posting the new Privacy Policy on this page and updating the "Last updated" date. Your continued use of our services after such changes constitutes acceptance of the updated policy.

12. Contact Us

If you have questions about this Privacy Policy or our data practices, please contact us at:

For privacy-related inquiries, please contact us at support@brickato.com