Privacy Policy

Last updated: September 10, 2026

1. Overview

This Policy explains what data BuildBot Systems ("BuildBot," "we," "us") collects through the BuildBot web application, backend API, and companion camera application (together, the "Service"), and how it is used, stored, and shared. The Service is invite-only and used by facility managers, building owners, drone operators, and insurance adjusters performing facade inspections.

2. Data we collect

  • Account data: email address and role, managed via Supabase Auth. We do not support self-signup — accounts are created by BuildBot administrators.
  • Inspection imagery and video: RGB photos/video, infrared (IR) photos/video you submit for processing.
  • Embedded image/flight metadata: EXIF GPS coordinates, altitude, gimbal angle, and capture timestamp, when present in uploaded files — used to compute ground sample distance (GSD) and reverse-geocode a building address.
  • Inspection metadata you provide: building name, address, company name, drone model, and flight parameters (altitude, distance, camera intrinsics) entered on the upload form.
  • Generated outputs: defect segmentation masks, crack measurements, thermal analysis, and the resulting PDF reports.

3. Google Drive access

If you choose to connect a Google account, we request only the minimum access needed for the specific feature you use, and always ask you to explicitly grant it via Google's own consent screen:

  • Web import (read-only): used only when you choose to import files from Drive on the inspection upload page. This runs entirely in your browser — the access it obtains is used directly from your device to list and download the files you explicitly pick, and is never transmitted to or stored on our servers. Files you pick are then submitted as part of your inspection, the same as a direct upload.
  • Companion app backup (app-created files only): used by our companion mobile app, if you sign in, to back up captures and recordings you create with it to a folder it creates in your Drive. This access only ever covers files the app itself created — never your existing Drive contents.

We do not use Google user data to train generalized or non-personalized AI/ML models. Our use of Google APIs complies with the Google API Services User Data Policy, including its Limited Use requirements.

4. How we use data

  • To run defect detection and thermal analysis on submitted imagery;
  • To generate inspection reports (PDF);
  • To display your inspection portfolio, results, and share links back to you;
  • To operate account authentication and role-based access control;
  • To maintain and improve Service reliability (error logs, rate-limit enforcement).

5. Third-party processors

We use a small number of vetted infrastructure providers to operate the Service — for authentication, application hosting, cloud compute used to run defect-detection processing, AI-assisted report text generation, and file storage. Each is bound by its own data processing terms and only processes the minimum data needed to perform its function; none are permitted to use your data for their own purposes.

We do not sell your data, and we do not share inspection imagery or reports with third parties except the infrastructure providers above (to operate the Service) or when you explicitly generate a public share link for a specific result. A full list of subprocessors is available on request.

6. Data retention and deletion

Inspection data is retained for as long as your account is active, so you can access your inspection history. You can request deletion of your account and associated data at any time by contacting us — we will delete uploaded imagery, generated outputs, and account records within a reasonable period, except where retention is required by law.

7. Security

Access to the Service requires authentication; sensitive routes are role-gated. API requests are authenticated via JWT. We apply standard security headers, path/input validation on uploads, and do not expose storage credentials to the client — uploads and Drive imports either go through the backend directly or use short-lived, scope-limited tokens issued client-side.

8. Children's privacy

The Service is intended for professional use by adults in the building inspection industry and is not directed at children. We do not knowingly collect data from anyone under 18.

9. Changes to this policy

We may update this Policy as the Service evolves. Material changes will be reflected by updating the "Last updated" date above.

10. Contact

Questions about this Policy, or requests to access/delete your data, can be sent to buildbotsystems@gmail.com.