Skip to main content

Privacy Policy

How BuildOS collects, uses, shares, and protects personal information.

Privacy at a Glance

Access and Control

Review your content and ask us for access, correction, a copy, or deletion

Deletion Requests

Account access ends immediately and active-system data is deleted within 30 days

No Monetary Sales

We do not sell personal information for money, and optional measurement is controllable

1. Scope and Who We Are

This Privacy Policy applies to the BuildOS website, application, communications, public pages, and related services (the Service). BuildOS is operated as a sole proprietorship based in Glen Burnie, Maryland. In this policy, “BuildOS,” “we,” “us,” and “our” refer to the operator of the Service.

This policy does not govern a third-party service or connected agent after data leaves BuildOS at your direction. Those services apply their own terms and privacy policies.

2. Information We Collect

The information we collect depends on the features you use and the choices you make.

  • Account and profile information: Your name, email address, username, profile details, authentication identifiers, and account preferences. You may register with email and password or use Google sign-in.
  • Workspace and content data: Brain dumps, projects, goals, plans, milestones, tasks, notes, documents, comments, contacts, calendar information, onboarding responses, prompts, chat messages, agent instructions, and other content you create or submit.
  • Files and media: Images, documents, attachments, voice recordings, transcripts, extracted text, file metadata, and generated audio or images when you use those features.
  • Collaboration and publishing data: Project-member information, invitee email addresses, permissions, activity records, public-page content, author information, and interactions with shared or public pages.
  • Calendar and integration data: Events, attendees, scheduling information, connector grants, approved scopes, integration settings, and the information returned by services you choose to connect.
  • Phone and notification data: Your phone number, verification status, notification preferences, push-subscription information, and delivery or response records when you enable SMS, email, or browser notifications.
  • Billing data: Subscription status, plan, trial dates, Stripe customer and subscription identifiers, invoices, and payment status. Stripe processes payment-card details; BuildOS does not store full card numbers.
  • Consent and agreement records: The versions of the Terms and Privacy Policy you accepted, the server-recorded acceptance time, acceptance method, IP address, and user agent;
  • AI and agent activity: Prompts, outputs, model and tool-call metadata, connected-agent scopes, hashed API credentials, revocation state, audit logs, and records of proposed or completed agent actions.
  • Device, security, and usage data: IP address, browser and device information, referring pages, timestamps, session and login activity, error and performance data, security events, feature interactions, and identifiers used for analytics or fraud prevention.
  • Communication engagement: Messages you send us and, where enabled, whether BuildOS emails were delivered, opened, or clicked. Open information can be imprecise because some email applications preload images.

We receive information directly from you, automatically from your device and use of the Service, from collaborators, and from services you choose to connect. Content may include personal information about other people. You are responsible for having the right to provide that information.

3. How We Use Information

We use information to:

  • Provide, personalize, maintain, and secure the Service;
  • Organize your content and generate AI-assisted outputs;
  • Process files, voice notes, searches, integrations, and connected-agent requests;
  • Manage subscriptions, trials, payments, and account access;
  • Send service, security, collaboration, and opted-in notification messages;
  • Measure reliability, diagnose errors, prevent abuse, and support users;
  • Understand product adoption and improve BuildOS; and
  • Comply with law and enforce our Terms of Service.

Where applicable law requires a legal basis, we rely on performance of our contract, our legitimate interests in operating and securing the Service, your consent, or compliance with legal obligations, depending on the activity.

4. AI Processing

Information Sent for AI Tasks

When you use an AI feature, BuildOS sends the prompt and relevant workspace context to an AI provider. That context may contain personal or sensitive information that you included in your content. Outputs and related metadata may be stored in your workspace or logs so the feature can operate and be reviewed.

AI processing may be performed by OpenRouter and model providers available through its routing service, by OpenAI, or by other providers selected for a particular AI, transcription, generation, or search function. Available models and providers may change as BuildOS improves the Service.

Providers process submitted data under their own agreements and privacy practices. For requests routed through OpenRouter, BuildOS sends a provider-routing instruction that denies data collection. Private text, structured-output, and tool routes also require Zero Data Retention by default. Some speech or media models do not support strict zero retention; those routes still deny data collection, and we may use a direct provider or local processing instead. We seek to limit the context sent to what is relevant to the requested feature, but you should not submit information that you are not authorized to share with BuildOS and its service providers.

5. Connected Agents and Third-Party Integrations

You may connect Google services, third-party AI tools, agent clients, or custom software through OAuth, agent keys, the BuildOS Connector, or similar flows.

  • Connected tools receive data within the projects, scopes, and permissions you approve. If you grant write access, they may create or change BuildOS content on your behalf.
  • We store grant metadata, scopes, encrypted OAuth credentials where required, hashed agent credentials, revocation records, and tool-call audit logs to authenticate and secure requests.
  • When you direct BuildOS to send information to a connected tool, that third party controls its own subsequent processing. Revoking access blocks future BuildOS requests but does not retrieve copies already received by the third party.

6. Service Providers and Other Disclosures

We disclose information as needed to operate the Service, including to these categories:

  • Supabase: Database, authentication, and file storage;
  • Vercel: Hosting, performance, and aggregate web measurement;
  • Stripe: Checkout, subscriptions, invoicing, and payment processing;
  • Google: Sign-in and user-enabled Calendar or other Google integrations;
  • Twilio: Phone verification and opted-in SMS delivery;
  • Email and push providers: Message delivery, suppression, and delivery diagnostics;
  • PostHog: Operational and optional browser-based product analytics;
  • Meta: Optional marketing attribution when you enable marketing measurement;
  • AI, transcription, media, and web-search providers: Processing requested features; and
  • Connected services and collaborators: At your direction or as needed to provide sharing features.

We may also disclose information when required by law, to protect rights and safety, to investigate fraud or abuse, or as part of a merger, financing, acquisition, bankruptcy, or sale of assets. We will require a successor to handle personal information consistently with applicable law.

7. Analytics, Cookies, and Tracking Choices

  • Essential storage: Authentication cookies and local preferences support sign-in, security, theme, and your tracking choices.
  • Operational analytics: BuildOS records server-side account and feature events, such as signup, onboarding, core actions, and notification delivery. We use these records to operate, secure, troubleshoot, and understand adoption of the Service. Your browser tracking choice does not disable these server-side operational records.
  • Aggregate web measurement: Vercel may collect cookie-free traffic and performance measurements that are not intentionally connected to your BuildOS user profile.
  • Optional product analytics: If you allow it, PostHog browser analytics stores state locally and measures page views and product interactions. Broad autocapture and session recording are disabled.
  • Optional marketing measurement: Meta Pixel loads only after you allow marketing measurement. Depending on applicable law, this disclosure to Meta may be considered “sharing” for targeted or cross-context advertising even though BuildOS does not sell information for money.

You can change or withdraw optional browser analytics and marketing choices through Privacy choices in the site footer. We treat a supported Global Privacy Control signal as an opt-out from optional browser analytics and marketing measurement. We also use browser Do Not Track signals to keep those optional tools off.

8. Public Pages and Communications

If you publish a page, the content and author information you designate as public can be viewed, copied, indexed, and redistributed by others. BuildOS may record a public-page view using a one-way hash derived from IP address and browser information, along with referral and timing data, to count views and prevent duplicate or abusive traffic. A supported browser Do Not Track signal prevents that view record.

Service and lifecycle emails may contain open or click measurement used to understand delivery and engagement. You may unsubscribe from optional email using the link in the message. We may still send account, security, billing, or other transactional messages needed to provide the Service.

9. SMS Notifications

SMS notifications are optional. You must enable them and verify a phone number before BuildOS sends productivity-related text messages.

  • Message frequency varies based on your settings and activity.
  • Message and data rates may apply.
  • Reply STOP to opt out and HELP for assistance.
  • SMS consent is not a condition of purchasing or using BuildOS.
  • We do not use opted-in SMS data for third-party marketing.

We disclose your phone number and delivery information to Twilio only as needed to verify the number, deliver messages, prevent abuse, and support the messaging program.

10. Google API Data

BuildOS's use and transfer of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.

We use Google data only to provide the integration you enable, maintain security, and comply with law. We do not use Google Workspace API data for advertising, sell it, or allow humans to read it except with your permission, for security or support, when legally required, or when the data has been aggregated and anonymized for internal operations in a manner permitted by Google policy.

11. Sensitive and Consumer Health Information

BuildOS is a general productivity service, not a healthcare provider, medical records system, or HIPAA-compliant service. Do not use BuildOS for emergency care, clinical decisions, or protected health information maintained for a regulated healthcare workflow.

You may choose to include health, financial, location, or other sensitive information in free-form content. We process that information only as part of the content and features you request, for security, or as required by law. We do not use the substance of your private workspace content to target advertising or build an advertising health profile.

12. Retention and Deletion

We retain account information and workspace content while your account is active and as needed to provide requested features. Retention varies by record: transient AI diagnostic artifacts may be kept for up to 14 days, and certain security-event records may be kept for approximately 180 to 400 days depending on their risk level. Billing, consent, audit, suppression, and legal records may be retained longer when needed for compliance, dispute resolution, fraud prevention, or enforcement.

You may delete individual items where the feature is available or request account deletion in the application or by emailing us. When you request account deletion, we disable account access immediately, begin cancellation of subscription renewal, and permanently delete account data from active systems within 30 days. This includes projects you solely own, user-scoped records, stored files, integration credentials, and the authentication account.

If you contributed to a project owned by someone else, the contribution may remain so deletion does not damage that person's workspace, but your actor identity is replaced with “Deleted user” and direct identifiers are removed. Limited consent, security, billing, suppression, and legal records may be retained where reasonably necessary for compliance, dispute resolution, fraud prevention, or enforcement.

Encrypted backups are not part of normal product access and may retain a limited copy until the applicable backup is overwritten under the hosting provider's rotation schedule. If a backup is restored for disaster recovery, we will reapply completed deletion requests. We may retain aggregate or de-identified information that can no longer reasonably identify you.

13. Your Privacy Rights

Access and Correction

Review and update available account or workspace information, or ask us for access, correction, or a portable copy where required by law.

Deletion and Opt-Out

Request deletion, withdraw optional consent, or opt out of covered targeted-advertising, sale, sharing, or profiling activities where applicable.

Depending on where you live, you may also have rights to know the categories and specific pieces of information collected, receive a list of certain third parties, restrict sensitive-data processing, object to processing, or appeal a denied request. We will not discriminate against you for exercising a privacy right.

Submit a request to dj@build-os.com. State the right you want to exercise and the email associated with your account. We may verify your identity and authority before acting. If we deny a request, reply with “Privacy Appeal” and your reason for appealing. We respond within the period required by applicable law, generally 45 days where a state privacy law applies.

14. Security

We use administrative, technical, and organizational safeguards designed to protect personal information, including encrypted transport, access controls, secure authentication, credential hashing or encryption where appropriate, and security monitoring. No system is completely secure, and we cannot guarantee that unauthorized access, loss, or misuse will never occur.

15. Children

BuildOS is not directed to children under 13, and we do not knowingly collect personal information from a child under 13. If you believe a child under 13 has provided personal information, contact us so we can investigate and delete it. If you are under the age of majority where you live, use BuildOS only with permission from a parent or legal guardian.

16. International Data Transfers

BuildOS is operated from the United States. If you use the Service from another country, your information may be processed in the United States and other countries where our providers operate. Those countries may have different data-protection laws. Where required, we use recognized safeguards for international transfers.

17. Changes to This Policy

We may update this policy as BuildOS, our providers, or applicable requirements change. We will post the updated policy and revise the date below. If a change materially affects how we use personal information, we will provide additional notice as required, such as an in-app message or email. If consent is required for a new use, we will request it.

18. Contact Us

For privacy questions or requests, email dj@build-os.com.
BuildOS — Glen Burnie, Maryland, United States

Effective and last updated: July 16, 2026 (version 2026-07-16)

Questions about your data?

We're here to help. Reach out anytime.

Contact Us