Back to Home
AECify

Privacy Policy

Last Updated: September 2026

1. Introduction

AECify ("we," "our," or "us") provides an AI-powered construction inspection and project management platform for the Architecture, Engineering, and Construction (AEC) industry. This Privacy Policy describes how we collect, use, disclose, and protect your personal information when you use our services at aecify.com (the "Service").

By using the Service, you agree to the collection and use of information in accordance with this policy.

2. Information We Collect

2.1 Information You Provide

  • Account information: Name, email address, phone number, company name, job title
  • Project data: Project names, addresses, inspection records, documents, photos
  • Communications: Messages sent through the platform, form submissions
  • Payment information: Processed securely by Stripe — we never store credit card numbers on our servers

2.2 Information Collected Automatically

  • Usage data: Pages visited, features used, timestamps (via PostHog product analytics)
  • Device information: Browser type, operating system, screen resolution
  • Location data: GPS coordinates when you use location features (with your permission)
  • Log and error data: Application logs and crash reports (Sentry), with email and IP stripped where configured

3. How We Use Your Information

  • Provide, maintain, and improve the Service
  • Process transactions and manage your subscription
  • Send transactional emails (account confirmations, password resets, project notifications)
  • Provide AI-powered features (photo analysis, code compliance, document analysis)
  • Monitor and improve security, detect fraud and abuse
  • Comply with legal obligations

4. How We Share Your Information

We do not sell your personal information. We share data with service providers who help us operate the Service:

  • Supabase: Database, authentication, file storage, and edge functions
  • Stripe: Payments and subscription billing (card data stays with Stripe)
  • Vercel: Web application hosting
  • Resend: Transactional and product email delivery
  • OpenAI: AI features. When you run photo analysis or document conformity checks, we send jobsite photos and relevant drawing/specification excerpts to OpenAI so the model can compare them. We do not train our own model on your data. OpenAI's retention of API inputs is governed by OpenAI's terms and our OpenAI organization settings (we request store: false where the API supports it). We do not claim zero-data-retention unless separately contracted.
  • PostHog: Product analytics (identified user id and email after login, pageviews, feature usage). Session replay, when enabled, masks text and media by default.
  • Sentry: Error monitoring; replay-on-error with text/media masked; we strip email and IP from client reports where configured
  • Mapbox: Map tiles and address geocoding
  • Google Places: Address autocomplete suggestions
  • OpenWeatherMap: Weather for project coordinates
  • Open-Meteo: Precipitation and historical weather for project coordinates (supplemental to OpenWeatherMap)
  • Regrid: Parcel boundary lookups at project coordinates
  • USGS: Elevation queries for map measurement tools
  • Esri ArcGIS Online: Satellite/basemap imagery tiles for project map views (coordinates and IP as part of normal tile requests)
  • IP lookup providers (ipify, seeip, ipinfo): When someone signs an electronic form or document, we capture their public IP address for the signature audit trail. These providers receive the signer's browser request in order to return that IP.
  • Have I Been Pwned (HIBP): Password leak checks via k-anonymity (only a partial SHA-1 hash prefix of the password is sent; the full password is never transmitted)
  • CDN providers (cdnjs / unpkg): Deliver open-source libraries (e.g. PDF.js) to the browser; they receive IP and referrer as part of normal CDN requests
  • Intuit QuickBooks: Invoice customer and line-item data when you choose to sync invoices
  • Your organization: Other members can see shared project data according to their permission level
  • Project collaborators: Stakeholders you invite can access project-specific data
  • Legal requirements: When required by law, court order, or to protect our rights

5. Data Security

We implement industry-standard security measures including:

  • Encryption in transit (TLS 1.2+) and at rest (AES-256)
  • Row Level Security (RLS) on all database tables for multi-tenant isolation
  • Multi-factor authentication (TOTP) support
  • Regular security audits and vulnerability scanning
  • Strict access controls and principle of least privilege
  • SOC 2 compliance program

6. Data Retention

  • Active accounts: We retain personal and project data while your organization's subscription (or trial) is active.
  • After cancellation: The organization becomes read-only. We send warning emails and permanently delete organization data 45 days after cancellation unless you resubscribe.
  • Personal Delete Account: Removes your login and personal profile data. Organization-owned projects, inspections, and photos remain for remaining team members. The last owner cannot wipe the company via personal Delete Account — they must cancel the plan (45-day retention) or use Delete Organization in Plan Settings.
  • Immediate organization deletion: Available to the last owner from Plan Settings; deletes company data and member logins after password confirmation.
  • Stripe: We cancel the subscription and detach payment methods on org wipe, but keep the Stripe customer record so invoice/tax history remains available to our payment processor.
  • Deletion audit: We retain a minimal organization_deletions record (company name, admin email, Stripe customer id) to prove a wipe occurred.
  • Audit events: Security/compliance audit logs are retained for up to 2 years, then purged.

7. Your Rights

Depending on your location, you may have the right to:

  • Access: Request a copy of your personal data (Profile → Data & Privacy → Export Your Data)
  • Deletion: Delete your personal account, or (as last owner) delete the organization from Plan Settings
  • Correction: Update your personal information via your profile settings
  • Portability: Export your data in machine-readable JSON; use Project → Export for full photo/document archives
  • Objection: Object to certain processing activities by contacting us

To exercise these rights, use the self-service tools in your account settings or contact us at privacy@aecify.com.

8. Cookies and Tracking

AECify uses essential cookies and local storage for authentication and session management. We use PostHog for product analytics (pageviews, feature usage, and optionally masked session replay). We do not use third-party advertising cookies or advertising tracking pixels.

9. Children's Privacy

The Service is not directed to individuals under 16 years of age. We do not knowingly collect personal information from children. If you believe a child has provided us with personal data, please contact us.

10. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email or through an in-app notification. Continued use of the Service after changes constitutes acceptance of the updated policy.

11. Contact Us

If you have questions about this Privacy Policy or our data practices, contact us at: