Privacy Policy
Effective 10 September 2026
The short version
We collect what the product needs to work: your account details, the projects you build, and what you type into the AI. We do not sell any of it, and we do not use your project data to train models.
Two things are easy to miss, so they are stated plainly below: property addresses you enter are sent to a mapping service to be turned into coordinates, and if you add subcontractor contact details you are giving us information about someone else.
This summary is for orientation only. The numbered sections below are the agreement.
1. Who this covers
This policy describes how Construct PM (“we”) handles personal information in Construct PM, including the website, the web application, and the API. It applies to everyone who visits the site or holds an account.
If you use Construct PM as part of your job, your employer may also have its own obligations regarding the data you put in. This policy covers our side.
2. What you give us directly
When you create an account, we store:
- Your email address, which identifies the account and is how we reach you about it.
- A one-way hash of your password. We do not store the password itself and cannot recover it — only reset it.
- A display name, if you set one.
When you use the product, we store what you create:
- Projects — the name, the property address if you supply one, the generated plan and takeoff, and the estimated totals.
- AI conversations — the prompts you send and the replies you receive, kept so that a conversation survives a page reload and you can return to it later.
- API tokens, stored only as a one-way hash. A token is displayed once, at creation, and cannot be shown again.
3. Information about other people
Construct PM lets you record subcontractor and trade contacts — company name, contact name, and an email address or phone number — so the product can notify them about schedule changes.
That is personal information about someone who is not our user and has no account with us. By entering it you confirm you are entitled to share it and to have them contacted about the project. We use it only to send the notifications the project generates; we do not market to these contacts, add them to any list, or use their details for anything else.
If one of those contacts wants their details removed, either the project owner can delete them in the app or they can write to us at support@construct-pm.com.
4. What we collect automatically
We keep counts of the actions that meter against your plan — how many plans or estimates you have generated in the current period — because those limits cannot be enforced without them.
Our hosting provider processes standard server logs, including IP address and browser user-agent, as a normal part of serving the site and protecting it from abuse. We use a session cookie to keep you signed in. We do not use advertising or cross-site tracking cookies.
5. Payment information
Payments are handled by Stripe. Card numbers are entered directly with Stripe and never reach our servers — we cannot see them.
What we store is the Stripe customer and subscription identifier, your plan tier, the subscription status Stripe reports, and when the current period ends. That is enough to know what you are entitled to, and no more. Stripe’s own privacy notice governs what it does with payment data.
6. How the AI features work
When you use a feature that generates a plan, an estimate, or an explanation, the text of your request is sent to a language model running on infrastructure we operate, and the reply is stored with your conversation.
We do not use your projects or conversations to train models. If we ever route these features through a third-party model provider, we will name that provider in this policy before doing so.
7. Who else receives your data
We do not sell personal information and we do not share it for advertising. We use a small number of service providers, each receiving only what its job requires:
- Stripe — payments and subscription billing.
- Our hosting and database providers — running the site and storing your account and project data.
- Resend — delivering notification emails, which means the recipient address and message content.
- OpenStreetMap Nominatim — turning a property address into coordinates. This means a project address you enter is sent to them when a feature needs its location.
- The US National Weather Service (NOAA) — weather forecasts for those coordinates, used to flag weather-sensitive work. It receives the coordinates, not your identity.
We may also disclose information where the law requires it, or where it is necessary to investigate abuse or protect someone’s safety. If the business is ever sold or merged, account data may transfer with it; this policy continues to apply until you are told otherwise.
8. How long we keep it
Account and project data is kept while your account is open. When you delete your account we delete your account record, projects, conversations, and trade contacts.
Two exceptions, both deliberate. Billing records are retained as long as tax and accounting rules require. And the log of notifications actually sent is not deleted: it exists so that a dispute about whether a subcontractor was told about a change can be settled, and a record that can be erased by one party cannot do that. It holds the message and the address it went to, and nothing further.
9. Your choices
You can view and change your account details, and edit or delete any project or conversation, from within the app. To have your account and its data deleted entirely, write to support@construct-pm.com from the address on the account.
Depending on where you live you may have rights to access, correct, export, or delete your personal information, or to object to some processing. Ask us using the same address and we will act on it — we do not require you to invoke a particular statute to be taken seriously, and we will not charge you or degrade your service for asking.
10. Security
Passwords are stored only as one-way hashes, as are API tokens. Traffic is encrypted in transit. Access to production data is limited to those who need it to operate the service.
No system is perfectly secure, and we would rather say so than imply otherwise. If we discover a breach affecting your personal information, we will notify affected users and any regulator that the law requires, without unnecessary delay.
11. Children
Construct PM is a business tool and is not directed to children. You must be at least 18 to hold an account. If we learn we have collected information from a child, we will delete it.
12. Where your data is processed
We operate from the United States and process data there. If you use the service from outside the United States, you are sending your information to the United States, where privacy laws differ from those in your country.
13. Changes to this policy
If we change this policy in a way that materially affects how we handle your information, we will update the effective date above and tell account holders by email before the change takes effect. We will not apply a materially different policy to information already collected without asking you first.
14. Contact us
Questions, requests, or complaints about privacy go to support@construct-pm.com. See also our Terms of Service.
