The short version
- SmartBldr is in early testing. The app isn’t open to the public yet, and some features here are still being built.
- Our website has no analytics, ads or tracking cookies. If you ask for early access, we keep the details you enter.
- Connecting a mailbox gives SmartBldr read-only access. It can’t send, change or delete your mail.
- Synced mail is private to you. Your company’s admins and your project team can’t read it, and our staff don’t read it except in the limited cases in section 04.
- We don’t sell your information, use it for advertising or use it to train AI models.
- Disconnect a mailbox and we delete its synced mail 30 days later. Section 08 lists the exceptions.
Who we are and what this covers
SmartBldr makes project management software for commercial general contractors. In this policy, “SmartBldr” (also written SmartBLDR), “we” and “us” mean the business behind smartbldr.com and the SmartBldr app.
This policy covers:
- our website, smartbldr.com, including the early-access form;
- the SmartBldr app, including mailboxes you connect from Gmail or Microsoft 365.
Where SmartBldr is today
SmartBldr is in early testing. The app isn’t open to the public yet. Only people we invite can use it, and some features in this policy are still being built. Where this policy describes a feature that isn’t available yet, it says how that feature will work. Section 06 shows which service providers we use today.
Mailbox sync is open only to test accounts we invite. During testing, their synced mail is kept on development systems that SmartBldr controls, not on the hosted services in section 06.
Some of the app’s settings screens aren’t built yet. Until they are, email info@smartbldr.com and we’ll make any change this policy offers you, such as disconnecting a mailbox, pausing its sync or turning off its AI setting.
Information we collect
On our website
The website doesn’t use analytics, advertising or tracking cookies, and it doesn’t load any third-party scripts. Its fonts are served from our own site. Because the website doesn’t track visitors over time or across other sites, and doesn’t let third parties do so, it works the same whether or not your browser sends a Do Not Track signal.
- Early-access requests. When you ask for early access, we collect your full name, work email and company. You can also choose to tell us your role, company size and annual construction volume. We note that the request came from the website.
- Emails you send us. If you write to us, we receive your email address and your message.
- Technical data. Our host, Vercel, receives the information browsers send with every web request, such as your IP address, browser type and the page requested. Vercel uses it to deliver the site and keep it secure.
In the SmartBldr app
- Account information. When your company sets you up, we store your name, work email, job title and department, who invited you, and your role in the company and on its projects. If added, we also store your phone number, time zone, language and out-of-office dates. We’ll use your work email to sign you in.
- Project information. Your team adds project records such as documents, drawings, RFIs, submittals and contacts. Project records also include email people send to a project’s SmartBldr address. These records can include the names and contact details of people your company works with, such as subcontractors, architects and owners.
- Activity records. SmartBldr records actions taken in your company’s workspace, such as who changed a record and when.
- Connected mailboxes. If you connect a Gmail or Microsoft 365 mailbox, SmartBldr copies the mail in it into SmartBldr. Section 04 explains exactly what we access and why.
How we use information
We use information to:
- provide SmartBldr and the features you and your company use;
- reply to early-access requests and messages, and contact you about early access to SmartBldr;
- keep SmartBldr secure, fix problems and prevent abuse;
- meet our legal obligations.
We don’t sell personal information, and we don’t use it for advertising. Mail you connect is used only as section 04 describes.
Gmail and Microsoft 365 data
You can connect your own work mailbox so your email comes into SmartBldr and project mail is matched to the right project. Only you can connect your mailbox. You can disconnect it at any time, in SmartBldr or by emailing us, and your company’s admins can disconnect it too.
What we ask Google and Microsoft for
SmartBldr asks only for read access. It can’t send, change, move or delete your mail, and it doesn’t ask for your calendar, contacts or files.
Gmail
https://www.googleapis.com/auth/gmail.readonly- Read-only access to your mail. We use it to copy your messages into SmartBldr and keep them up to date, and to read your address and total message count from your Gmail profile.
openidandemail- Standard Google sign-in permissions that share your email address. SmartBldr doesn’t use them today. It reads your address from your Gmail profile instead.
Microsoft 365
Mail.Read- Read-only access to the mail in your mailbox.
offline_access- Lets SmartBldr keep syncing when you’re not signed in.
User.Read- Reads your basic profile. SmartBldr uses it only to learn your mailbox’s address.
These Microsoft permissions are delegated: they cover only the mailbox of the person who connects it. Microsoft 365 connections work with work or school accounts.
What SmartBldr brings in
SmartBldr copies all the mail you send and receive from a start date you choose, in every label or folder, not only project mail. The start date is 90 days back unless you change it, and never more than 3 years back. After that, SmartBldr checks for new mail about every minute. For each message it stores:
- the sender, recipients, subject, a short preview and the time it arrived;
- the full original message, its text and HTML versions, and its attachments (any file over 50 MB is skipped);
- its Gmail labels or Outlook folder, and whether you’ve read it.
It doesn’t bring in mail that’s in Gmail’s spam, trash or drafts. In Outlook it skips Junk Email, Deleted Items, Drafts, Outbox, Conversation History and Sync Issues. When you read, label or file a message in Gmail or Outlook, SmartBldr’s copy updates. If you later move a synced message to trash, spam, Junk Email or Deleted Items, SmartBldr keeps its copy and notes the move. When you delete a message for good, SmartBldr hides it from your inbox.
How we use it
- To show your mail in your SmartBldr inbox and keep it in step with your mailbox.
- To match each message to one of your projects, using signals such as a project number in the subject, an earlier message in the same thread or a known project contact. Only projects you have access to are considered. You can change a message’s project at any time, and your choice stands.
- To show your company’s admins whether your mailbox is connected and syncing: whose mailbox it is, its address and provider, its status and sync progress, the sync start date, when it was connected or disconnected and when its mail is due to be deleted, how many messages have synced, the mailbox’s total message count, and any error. Admins never see your messages. An admin can also disconnect your mailbox, which starts the same 30-day deletion as when you disconnect it (section 08).
Who can read it
In SmartBldr, only you can read it. Matching a message to a project doesn’t share it with the project team. Your company’s owners and admins can’t read it, and SmartBldr support can’t read it, even during a support window your company approves.
SmartBldr’s mail sync service handles your mail only to store it, keep it up to date and match it to your projects. To match a message, it reads the subject, the sender and recipients, the reply details and the start of the text.
The few people who run SmartBldr’s systems have administrative access to the database and storage that hold your mail, for maintenance and security. They don’t read your mail except in the limited cases listed below.
Who handles it for us
While mailbox sync is in testing, synced mail stays on SmartBldr’s development systems, and no service provider receives it. Once sync runs on our hosted services, Supabase will store it, Render will run the jobs that sync it, and Vercel will serve the app pages where you read it. Our error and log services will receive only error codes and internal IDs from mail sync, never message content. No other provider in section 06 receives your mail, and it isn’t sent to any AI provider.
AI and your mailbox
Each mailbox has a setting that controls whether SmartBldr’s AI features may read it. The setting starts on when you connect, and you can turn it off then or at any time. Turning it off blocks AI access straight away. Today, no AI feature reads synced mail, whatever the setting, and synced mail isn’t sent to any AI provider. Before that changes, we’ll update this policy and ask for your consent.
Google API Services User Data Policy
SmartBldr’s use of information received from Google APIs will adhere to Google API Services User Data Policy, including the Limited Use requirements. It will also adhere to the Google Workspace User Data and Developer Policy.
In particular, for data we receive through Google APIs, including your Gmail:
- We use it only to provide the mail features described in this section.
- We don’t sell it.
- We don’t use it for advertising, including retargeting or personalized ads, and we don’t transfer it to advertising platforms, data brokers or information resellers.
- We don’t use it to decide creditworthiness or for lending.
- We don’t use it, or let anyone else use it, to create, train or improve any AI or machine-learning model.
- We transfer it only: to the providers named under “Who handles it for us”, to run the mail features in this section; for security purposes, such as investigating abuse; to comply with the law; or as part of a merger, acquisition or sale of assets, and then only with your explicit consent first.
- People don’t read it unless: you first give us explicit permission to view specific messages (for example, to help with a support question) and we keep a record of that permission; it’s necessary for security, such as investigating a bug or abuse; it’s necessary to comply with the law; or it’s aggregated and anonymized for internal operations, such as counting synced messages.
We apply the same rules to mail from Microsoft 365.
AI features
We’re building AI features into SmartBldr. Its agents will help with project work, such as drafting RFIs, building submittal registers and answering questions from drawings and specs. When an AI feature runs, SmartBldr will send the content that task needs to our AI model provider, Anthropic, and keep the result for your team to review.
Agents will work on your project records and on email people send to a project’s SmartBldr address. They can’t read mail synced from your Gmail or Microsoft 365 mailbox (see section 04).
We’re also building search, document reading and voice notes. Voyage AI will build search indexes from the text of project records. Amazon Textract will read the text in scanned documents and drawings your team uploads. AssemblyAI will turn voice memos into text.
We don’t use your information to train AI models. Anthropic doesn’t use data sent through its commercial API to train its models by default. None of these AI providers receives your information yet.
Storage, security and location
- Location. Our hosted database and file storage are run by Supabase in the United States (AWS US East). If you use SmartBldr from outside the United States, information we keep on these services is transferred to and stored in the United States. During testing, synced mail is kept on our development systems instead (section 01).
- Encryption. The website uses HTTPS, and the app will too. SmartBldr connects to Google and Microsoft over HTTPS. Our hosted storage provider encrypts stored data.
- Mailbox access. SmartBldr encrypts the long-lived refresh token Google or Microsoft gives it with AES-256-GCM, using a separate key for each credential. The app can’t read the token. Only SmartBldr’s mail sync service can use it.
- Private files. Synced mail and attachments are kept in private storage that browsers can’t reach directly.
- Separation. Each company’s data is kept apart by access rules enforced in the database.
- Staff access. In the app, SmartBldr staff have no standing access to your company’s workspace. To help with a support request, a company owner or admin can give one named staff member read-only access for a set time, up to 24 hours, and can end it early. Approving and ending that access are recorded in your company’s audit log. Synced mail stays out of reach even then. Separately, the few people who run SmartBldr’s systems have administrative access to the database for maintenance and security.
- Website form. The website can add early-access requests but can’t read them back. Only the SmartBldr team can view them.
No system is perfectly secure, but we work to protect your information.
Keeping and deleting information
- Early-access requests and emails to us are kept until you ask us to delete them.
- Account and project information is kept until your company asks us to delete it. You can ask us to delete your own personal information (section 09).
- Synced mail is kept while your mailbox is connected. A message you delete for good in Gmail or Outlook is hidden from your SmartBldr inbox, and its stored copy is deleted when the mailbox is purged (below). If you move your start date later, mail already copied stays until you disconnect.
When a mailbox is disconnected
When you disconnect a mailbox, an admin disconnects it, or your company removes you from SmartBldr:
- syncing stops at once, and SmartBldr stops using your Google or Microsoft access;
- for Gmail, SmartBldr also asks Google to revoke its access. SmartBldr can’t withdraw its Microsoft access on its own, so remove SmartBldr from your Microsoft account too (section 09);
- your synced mail is kept for 30 days in case you reconnect, then permanently deleted: its messages, threads, attachments, stored files and project-matching history. If you reconnect within the 30 days, your mail is kept and syncing resumes.
A few things are kept after that deletion:
- a short record of the connection: the mailbox’s address and owner, the account and permissions granted, when it was connected, disconnected and purged, and how many messages were deleted;
- the encrypted credential from Google or Microsoft, which SmartBldr no longer uses;
- notes, links and activity records that point to a deleted message. Notes and links are hidden from everyone once the message is gone;
- any message you attached to an RFI response, with its files. It stays private to you.
Removing SmartBldr’s access at Google or Microsoft stops syncing, but it doesn’t delete mail already copied. To delete that mail, disconnect the mailbox in SmartBldr or email info@smartbldr.com.
Deleted information can remain in our storage provider’s routine backups until those backups expire.
Your choices and rights
- Access, correct or delete. Email info@smartbldr.com to ask for a copy of your personal information, or to correct or delete it. We may need to confirm who you are. If a request concerns project records your company keeps in SmartBldr, we may involve your company’s admin.
- Disconnect a mailbox, or pause and resume its syncing. Email us and we’ll do it for you until you can do it yourself in SmartBldr.
- Choose whether AI features may read your mailbox, and change your choice at any time. Today, no AI feature reads synced mail either way.
- Remove SmartBldr’s access at Google. In your Google Account, open Your connections to third-party apps & services and remove SmartBldr.
- Remove SmartBldr’s access at Microsoft. In My Apps, open SmartBldr’s menu, choose Manage your application, then Revoke permissions. If your IT team approved SmartBldr for your whole company, you can’t remove it there: disconnect the mailbox in SmartBldr, email us, or ask your IT team.
- Leave the early-access list by emailing us.
Depending on where you live, you may have more rights under local privacy law. Contact us to use them.
Children
SmartBldr is a tool for businesses. It isn’t directed to children under 16, and we don’t knowingly collect their personal information. If you think a child has given us information, contact us and we’ll delete it.
Changes to this policy
When we change this policy, we’ll post the new version here and update the effective date. If we want to access new kinds of data from your Google or Microsoft account, or use your mail in a new way, we’ll update this policy and ask for your consent first.
Contact us
Questions, requests or concerns about privacy: email SmartBLDR at info@smartbldr.com.