Legal
Privacy policy
DRAFT v1, 6 October 2026. Pending lawyer review. Not reviewed by a lawyer. Not for publication or for customers until a lawyer signs off and every placeholder is filled.
Effective date: date of publication. Last updated: date.
In plain words
- Sightgrid is a work tool for construction companies. Your company decides what goes into it. Your company's job data belongs to your company.
- We collect what we need to run the tool, keep it secure, support you and bill your company. We do not sell personal information. We do not use it for advertising. We do not use your company's data to train AI models, and our AI provider does not train on it either.
- Our servers are in the United States. Our encrypted backup copies are kept in British Columbia, Canada. The founders work from the United States and Canada.
- When a job is deleted, it can be restored for 30 days. After that it is deleted for good from our live systems.
- You can delete your own account in Settings at any time.
- You have rights over your personal information. Section 13 explains them and how to use them.
1. Who we are
1.1 The company. Sightgrid is provided by SIGHTGRID LEGAL ENTITY NAME, a Oklahoma / Delaware corporation ("Sightgrid", "we", "us", "our").
1.2 Before the company is formed.
1.3 How to reach us. Privacy questions and requests: privacy@getsightgrid.com. Support: support@getsightgrid.com. Anything else: hello@getsightgrid.com. Post: SIGHTGRID LEGAL ENTITY NAME, business address.
1.4 Privacy officer. Our privacy officer is Symon Kaplan, co-founder confirm. The privacy officer is accountable for how we handle personal information and answers privacy requests and complaints.
2. What this policy covers
2.1 Covered. This policy covers personal information we handle through:
- the Sightgrid app: the web app at app address, installable on phones, tablets and computers, including shared jobs, chat, the clash workflow, the calculators and "Ask it in words",
- the Sightgrid website at getsightgrid.com, including the field-test request form,
- the Sightgrid Tools app: the calculators app sold through the Apple App Store and Google Play, and
- emails, support requests, calls and other contact with us.
2.2 Not covered. This policy does not cover how your employer or another company on your job uses information it gets through Sightgrid. That company has its own privacy duties. It also does not cover third-party websites or services we link to, or the app stores, which have their own policies.
3. Our role: controller or processor
3.1 Customer Data: we act for your company. The company that holds the Sightgrid subscription or field test (the "Customer") decides what job information goes into Sightgrid, who is invited and how long jobs are kept. For that job information ("Customer Data", described in 5.2) we process personal information on the Customer's behalf and on its instructions, set out in our Terms of Service and the Customer's agreement. In GDPR terms the Customer is the controller and we are its processor. Under Canadian law, the Customer remains accountable for that information and we handle it for the Customer. Under US state laws, we act as the Customer's service provider or processor.
3.2 Our own data: we decide. For account and sign-in data, billing data, security and rate-limit data, help requests, feedback and surveys, website visitors and field-test requests, and AI usage records, we decide why and how the information is used. In GDPR terms we are the controller of that information.
3.3 What this means for you. If you use Sightgrid through your employer or another company, ask that company first about Customer Data. We help the Customer answer your request. You may always contact us, and we will pass your request to the right Customer when the information is Customer Data.
4. Who uses Sightgrid
Sightgrid is for businesses: electrical contractors, other trades and general contractors, and the people who work for them. Users include project managers, superintendents, foremen, estimators, crew, people from other trades and general contractors' people. People who are not users also appear in Sightgrid, for example a supplier's sales representative named on a quote request, or the person who receives a view-only clash link by email.
5. What we collect
5.1 Account and profile information
| What | Where it comes from |
|---|---|
| The name you give when you join or sign in | You |
| Your email address, if you sign in by email or buy on the website | You |
| An optional notification email and an optional mobile number for alerts, and whether text alerts are off | You. Both are optional |
| Your role on each job (for example office, superintendent, foreman, estimator, crew, other trade, general contractor), your trade and your company | You, or the person who invited you |
| The name you appear under on each job | You or the inviter |
| Your company's name and its company settings (who may start jobs, invite, assign, clear items, delete jobs and so on) | The Customer's admin |
| Who invited whom, and when you joined, left or were removed | Generated by the app |
5.2 Job information (Customer Data)
Everything a Customer and its users put into a job. It can contain personal information, for example names in a model, faces in a photo or a voice in a voice note.
- building model files (IFC) and model versions, PDF drawings and imported drawing sheets, zones and levels,
- clashes, clash reports and their runs, close calls, verdicts, assignments, due dates, fixes and sign-offs, and the change report between model versions,
- photos taken for fixes, sign-offs, chat and change notes,
- job chat: text messages, photos, files and voice notes, and who has read what,
- change notes, panel schedules, one-line diagram notes, takeoffs, material requests, quote requests and supplier quotes, price files you upload, and the names, emails and phone numbers of supplier representatives you add,
- the email address of anyone you send a view-only clash link to,
- the activity log of who did what and when on the job, and the event history behind it.
5.3 Help requests, feedback and surveys
- Help requests. What you write or say, your name and role, the job, the screen and tab you were on, your device type, the app version, the last ten buttons you tapped (by button name only, never the text you typed) and the last error message on the page. If you choose to attach one, a screenshot of your screen. A screenshot can show anything that was on screen. Hidden data inside the screenshot image (such as location or camera data) is removed when it is stored.
- Weekly feedback and the after-test survey. Your answers, including anything you write or say in your own words, your name, role and job.
5.4 "Ask it in words" (the AI feature)
The words you type or say into "Ask it in words", and, if you use bulk mode, the lines you paste or the column headings and the first three rows of a spreadsheet you load. Section 7 explains how this is processed. We do not store the words themselves. We keep a usage record for each question (see 5.5).
5.5 Device, security and usage information
- Device sessions. Each signed-in device gets a session: a short description of the device, when it signed in, when it was last seen, when the session ends and whether it was signed out.
- Network address. We read your IP address on each request to apply rate limits. We do not store it in our database in readable form: we store a one-way coded key made from it, and delete the rate-limit counters after a short window. Our hosting provider records IP addresses in its own request logs (section 9).
- AI usage records. For each "Ask it in words" question: the time, a coded key for who asked and for the network address, which calculator, the mode, the AI model used, the amount of text processed and whether it worked. Kept 90 days.
- Notifications. Which alerts were created for you (assigned to you, waiting for your sign-off, invited) and whether the email was sent.
- Plan usage. Counts of seats, active jobs, storage and questions, used to apply your plan.
- Error information. Error messages from the app and server. The app contains code for an error-tracking service, set so that it does not collect personal information by default and never records your screen; it is not switched on at the date of this draft.
5.6 Billing information
When a Customer buys a plan, payment is handled by Stripe on Stripe's own checkout page. Stripe collects the billing email, billing address, tax ID if given, and card or US bank account details. We never see or store full card or bank numbers. We keep the Stripe customer and subscription references, the plan, the billing interval, the payment status, the billing email and the company name, and records of billing events.
5.7 Website and field-test requests
- Field-test request form. Your name, company, phone, email, what you want to test, your trade, whether you have a model, a short job description, the time and the page you sent it from. The request goes to Sightgrid HQ, our internal system (hosted on Vercel and Supabase), where it is saved as a contact for the founders to call back. No email is sent. The form also has a hidden spam trap, and we limit how many requests one network address can send, using a one-way coded key made from the address, not the address itself.
- Visiting the website. The website sets no cookies and has no advertising trackers. It remembers your light or dark theme choice in your browser (section 15). It uses Vercel Web Analytics and Vercel Speed Insights to count page views and measure how fast pages load. Vercel describes both as cookie-free and anonymous. For Web Analytics, Vercel records for each page view the time, the page address, the referring page, filtered query parameters, an approximate location (country, region and city), the operating system, browser and device type. It tells visits apart with a hash made from the incoming request, which it discards after 24 hours, and it does not tie data points to a person or an IP address. Speed Insights records the page, network speed, browser, device type, operating system, country and page-speed measurements. We see only aggregate figures. When the page loads, your browser fetches fonts from Google Fonts and, on pages with the 3D model, code libraries from the jsDelivr network, so those services receive your IP address and browser details (section 9).
5.8 The Tools app
The Tools app needs no account. Your calculations, saved jobs and settings stay on your device. If you use "Ask it in words" in the Tools app, the words go to our AI provider as described in section 7. You buy the Tools app from Apple or Google; they handle the payment and give us only the sales and download reports their stores provide to developers.
5.9 What we do not collect
- No location tracking. The app does not ask for or record your location. Every photo and image uploaded to the app, on every path (fixes, sign-offs, chat, change notes, drawings, quotes and help screenshots), has its hidden data removed: location (GPS), camera details, XMP data and comments.
- No contacts, calendar or other files from your device beyond what you choose to upload.
- No advertising identifiers and no cross-site tracking.
- No biometric identification. Voice notes are stored as recordings in the job chat; we do not analyse voices.
- Speaking instead of typing. Some text boxes (help, feedback, "Ask it in words", change notes and others) let you speak instead of type. This uses your browser's own speech recognition. Depending on your browser, the browser maker (for example Google for Chrome or Apple for Safari) may process the audio on its servers under its own privacy terms. Sightgrid receives only the resulting text. If you do not want that, type instead.
6. Why we use it, and our lawful bases
Where the EU or UK GDPR applies, we rely on the lawful bases shown. Where Canadian law applies, we rely on your consent, which is implied for uses a reasonable person would expect from using a work tool, and express where we say so.
| Why | What we use | Lawful basis (GDPR) |
|---|---|---|
| Run the service: show the model, your items and your chat, sync between devices, keep the job record | Account, Customer Data, device sessions | Contract with the Customer; our legitimate interest in providing the service to the Customer's users. For Customer Data, the Customer's instructions |
| Sign you in and keep accounts secure: sessions, invite links, sign-outs, rate limits, refusing changes a role may not make, the activity log | Account, sessions, coded network address, activity log | Legitimate interests (security and fraud prevention); contract |
| Notify you: assigned to you, waiting for your sign-off, invited, view-only clash links | Email, optional notification email and mobile number | Contract; legitimate interests. Text alerts only if you give a mobile number |
| Answer "Ask it in words" | The words or spreadsheet lines you send | Contract; for Customer Data, the Customer's instructions |
| Support you and fix problems | Help requests, screenshots you attach, device and error information; Customer Data only as section 8.6 allows | Legitimate interests; contract |
| Run field tests and improve Sightgrid | Feedback, surveys, help threads, usage counts | Legitimate interests (improving our product); the field test agreement |
| Bill the Customer, collect tax, keep accounts | Billing information | Contract; legal obligation |
| Answer field-test requests and business enquiries | Website form and emails | Legitimate interests (responding to business enquiries); steps before a contract |
| Comply with law, enforce our terms, defend claims | What the situation needs | Legal obligation; legitimate interests |
We use anonymous, aggregate statistics (for example, how many clashes were found per job, or how often a feature is used) to run and improve the service. They do not identify a person or a Customer.
We do not make decisions about people by automated means that have legal or similarly significant effects.
7. AI processing ("Ask it in words")
7.1 What it does. "Ask it in words" turns words into the inputs of a calculator, for example "a 30 amp circuit at 240 volts, 150 feet". The AI only fills in the form. The calculator does all the math with fixed rules. You see and can change the inputs before you rely on a result.
7.2 What is sent. Only the words you type or say into the box, or in bulk mode the lines you paste, or the column headings and the first three rows of a spreadsheet when the app cannot place the columns itself. Model files, photos, drawings, chat and other job records are never sent to the AI provider.
7.3 Who processes it. Anthropic, PBC, in the United States, through its commercial API. Anthropic's privacy centre (opened 6 October 2026) says: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models." It also says that for API users it automatically deletes inputs and outputs within 30 days, except where it must keep them longer to enforce its usage policy (up to 2 years if flagged by its automated safety systems) or to comply with law.
7.4 What we keep. We do not store the words you send. We keep the usage record described in 5.5 for 90 days.
7.5 No training by us. We do not use Customer Data or your questions to train any AI model.
7.6 Don't put sensitive personal information in a question. The feature is built for electrical quantities, not for personal information.
8. Who sees your information
8.1 People on your job. Other people on the same job see your name on that job, your role, trade and company, the items you are on, what you did in the activity log they can see, and the chat rooms you are in. What a person sees depends on their role and company, and on the Customer's settings.
8.2 Other companies on a shared job. A job can include several companies. The company that started the job (the "host", often the general contractor) invites other companies, and each company runs its own people.
- The host's people see the whole of the host's part of the job, every clash on the job, and what other companies share with the host or send to it.
- Another company's people see their own company's part of the job, and in other parts only their trade's clashes, clashes they were invited to or are on, and what is shared with their company or with them.
- A company's change notes and one-line notes stay inside that company unless it shares them.
- When the host removes a company, or deletes the job, that company's people lose access at once. Its office is given an export of its own records, kept for it for 30 days.
- What you put into another company's job stays part of that job's record, under that company's control, after you leave it. Section 11 explains how long.
8.3 View-only clash links. A user may email a view-only link to one clash to someone outside Sightgrid. The recipient sees that clash as images and text, including names on it, for 30 days by default, unless the link is cancelled sooner. The link never allows a model download.
8.4 The Customer's admin. The Customer's office users can see everything in the Customer's part of its jobs, including the activity log and who signed in on which device, and can export it.
8.5 Our service providers. The companies in section 9, each only for the work it does for us, under contract.
8.6 Our founders and staff. Our founders have administrative access to run the service. They read help requests, feedback and surveys. They do not open a Customer's models, photos or chat unless the Customer asks or agrees, or it is needed to stop a security threat, fix a serious fault or comply with law.
8.7 The law. We disclose information when we must by law, for example under a valid court order, or when needed to protect someone's safety. Where the law allows, we tell the Customer first.
8.8 A sale or reorganization of the business. If Sightgrid is sold, merges, is reorganized or is formed as a new company, information may pass to the new owner under this policy. We tell the Customer's admin.
8.9 With your consent. In any other case, only with consent.
8.10 No selling, no ad sharing. We do not sell personal information. We do not share it for cross-context behavioural advertising.
9. Service providers (subprocessors)
We use these companies to run Sightgrid. Each processes personal information only to provide its service to us.
9.1 The app
| Provider | What it does for us | What it processes | Location |
|---|---|---|---|
| Vercel, Inc. | Hosts the app and its server functions; stores files in Vercel Blob (models, drawings, photos, voice notes, chat files, exports, supplier quotes, price files); runs the daily tidy | All app traffic, stored files, request logs including IP addresses | United States |
| Supabase, Inc. | Hosts our Postgres database for the app and for our internal support desk | Account data, Customer Data records, help requests and screenshots, feedback, usage and billing records | United States (Amazon Web Services, US West, Northern California) |
| Anthropic, PBC | "Ask it in words" | Only the words or spreadsheet lines described in 7.2 | United States |
| Stripe, Inc. | Payments, subscriptions, invoices and sales tax | Billing contact, address, tax ID, payment details, subscription | United States, and Stripe's other locations |
| Resend, Inc. | Sends emails: sign-in links, invitations, alerts, view-only clash links, change note emails | Recipient email address, name and the email's content | United States |
| Telegram | Tells the founders' private group that something is waiting in Sightgrid HQ | A fixed notice (for example "New help request on Sightgrid. Open HQ.") and a link into HQ. No names, no content and no other personal information | Telegram's servers |
| Functional Software, Inc. (Sentry) | Error tracking. In the code but not switched on at the date of this draft. If switched on: error details with personal information collection off, no screen recording | Error messages, browser and device type | United States |
Text messages. The app can send urgent alerts by text message, but no text message provider is connected at the date of this draft, so none are sent. We will add the provider to this list before any are sent.
9.2 The website
| Provider | What it does | What it processes | Location |
|---|---|---|---|
| Vercel, Inc. | Hosts the website; Vercel Web Analytics and Speed Insights (cookie-free, anonymous page and speed statistics, section 5.7) | Request logs including IP addresses; for analytics, the page view data in 5.7, with visits told apart by a request hash discarded after 24 hours | United States |
| Google LLC (Google Fonts) | Supplies the website's fonts | IP address and browser details when the page loads | United States |
| jsDelivr | Supplies open-source 3D code libraries on pages with the 3D model | IP address and browser details when the page loads | Global network |
| Sightgrid HQ on Vercel, Inc. and Supabase, Inc. | Receives and stores field-test requests | The form fields in 5.7 | United States |
9.3 Others
- Apple and Google sell and deliver the Tools app under their own terms and privacy policies. They are not our processors for app store purchases; they act on their own account.
- Your browser's speech service (5.9) acts under your browser maker's terms, not ours.
- Sightgrid HQ, our own internal support desk, runs on Vercel and Supabase as above and is used only by the founders.
- Backups. In addition to our database provider's own backups, we make our own backup copies of the database, and sometimes of stored files. They are encrypted with AES-256-GCM and stored in British Columbia, Canada, on storage controlled by our founders. We keep the newest backup of each day for 14 days and the newest of each week for 8 weeks, then delete them.
9.4 Changes to providers. We tell Customers' admins by email at least 30 days before we add or replace a provider that will process Customer Data. A Customer may object on reasonable grounds as set out in the Terms of Service.
10. International transfers
10.1 Where data is. Our servers are in the United States. Our own encrypted backup copies are kept in British Columbia, Canada (9.3). Our founders work from the United States (Oklahoma) and Canada (British Columbia) and may access personal information from either country. Some of our providers process information in other countries.
10.2 What that means. Information stored or accessed in another country is subject to that country's laws, and may be accessed by its courts, law enforcement and national security authorities under those laws.
10.3 Canada. If you are in Canada, your information is transferred to and stored in the United States, with encrypted backup copies kept in British Columbia. We protect it in the United States there by contract and by the measures in section 12, to a standard comparable to Canadian law.
10.4 EU, EEA, UK and Switzerland. Where we transfer personal information from these places to the United States or Canada, we rely on: the European Commission's adequacy decision for Canada (for commercial organizations covered by PIPEDA); the EU-US Data Privacy Framework where the receiving provider is certified; and otherwise the European Commission's Standard Contractual Clauses (with the UK Addendum where the UK GDPR applies), which are part of our providers' data processing terms.
11. How long we keep information
We keep information only as long as we need it for the purposes in section 6, then delete it or make it anonymous. These periods match how the app works today.
| Information | How long |
|---|---|
| A job and its Customer Data | While the job exists. The Customer decides. |
| A job the Customer deletes | Hidden from everyone at once, and its invite links and view-only links are cancelled. The Customer's office can restore it, or export it, for 30 days. After 30 days the daily tidy deletes its stored files and then every record of it. If another company's copy of its own records from that job is still being kept (below), the final deletion waits until that copy expires. Test jobs can be deleted at once. |
| A Customer's data when its subscription ends | A 30-day export window starts: the Billing page shows the deletion date and the export of each job, and nothing is taken away during the window. After the window, once one of our founders confirms, the company's jobs, files and people are deleted, through the same steps as a deleted job (where another company is on one of its jobs, that company first gets its own 30-day copy). If the Customer pays again during the window, the window is cancelled. Stripe keeps billing records (below). |
| The copy of a company's own records when it is removed from a job, or when the host deletes the job | 30 days, for that company's office to download |
| A job export (zip) | The download is available for 1 day, then the file is deleted. Each download link works for 5 minutes. |
| Clash report runs | Runs older than 90 days are deleted, except each job's newest three. Verdicts, chat and sign-offs on a clash are kept with the job. |
| Upload pieces never finished | Deleted after 1 day (drawings and large reports) or 7 days (photos). |
| Chat messages | With the job. A message that is hidden stays in the job record, out of view, until the job is deleted. |
| Activity log and event history | With the job. These logs cannot be edited, by design, so a record of who did what stays until the job is deleted. |
| Your account (name, email, contact details) | While you are on any job or own a company, or until you delete it. You can delete your account yourself in Settings: you are taken off every job at once, every device is signed out and its sessions deleted, your help requests and your alerts are deleted, and your name, email, alert email and phone number are removed and replaced with "Former member" everywhere your name is shown. If you are the last office person of a company, you must hand office to someone else first. Records that cannot be edited stay with the job (see 13.3). Photos and voice notes you took stay with the job, which belongs to the company, with no name on them. Your account is also removed when the last job you are on is deleted for good and you own no company. |
| Device sessions | A device is signed out after 30 days without use, and 180 days after it signed in however active. The office can sign out a device at any time. |
| Invite links | Work once and expire after 7 days. |
| Notifications | Read alerts deleted after 90 days; all alerts after 180 days. |
| Rate-limit counters | Deleted after their short time window, in the daily tidy. |
| AI usage records | 90 days. |
| Help requests and screenshots | In the app: with the job they were asked from, or with your account if asked from no job. Our internal support desk keeps a copy for 24 months from the thread's last activity, then deletes it. Screenshots are deleted after 90 days. If you delete your account, your help requests are deleted from the app and from our support desk. |
| Feedback, survey answers and reports | In the app: with the job. Our internal support desk keeps a copy for 24 months from its last activity, then deletes it. |
| Billing records | As long as tax and accounting law requires. |
| Field-test requests and business emails | Kept in Sightgrid HQ as a contact. |
| Backups | Our database provider's backups roll over on its own schedule. Our own backup copies are kept as the newest of each day for 14 days and the newest of each week for 8 weeks, then deleted. So deleted data can stay in one of our backups for about 8 weeks. We do not restore deleted data from a backup except to recover from a failure. |
| Information on your device | Models, drawings, field notes, photos you saved, settings and saved calculator jobs stay on your device until you delete them or clear the app's data. Removing you from a job, or deleting a job, does not wipe your device. |
| Anonymous statistics | May be kept indefinitely. They do not identify you or the Customer. |
We may keep information longer where the law requires it, or to establish, exercise or defend legal claims.
12. How we protect information
What we actually do:
- Encryption in transit. All traffic to the app and website uses HTTPS. The connection from our servers to the database is encrypted and checks the database's certificate.
- Encryption at rest. Our providers encrypt stored data at rest under their standard controls.
- Signed, revocable sessions. Every request checks a signed device session that an office user can revoke, with idle and maximum lifetimes.
- Access checked on every request. The server checks your live membership of the job and your role on every read and write. The database checks the sign-off and visibility rules again, and its row level security lets only the app's own database role read app tables.
- Private files. Files are stored privately. Uploads use permissions limited to one file, one size and 15 minutes. Downloads use signed links that expire, normally after 10 minutes or less. Stored files are checked to be what they claim (for example a real JPEG or a real IFC file) before anything points at them.
- Invite and clash links are stored only in coded (hashed) form, work once (invites) and expire.
- Rate limits per device, per person and per network address.
- Logs that cannot be edited. The activity log and event history refuse changes.
- Least data to providers. The AI provider receives only the words in 7.2. Error reports are cleaned of invite links and signed file addresses.
- Tested backup and restore. Our restore checks counts and checksums before it completes.
No system is perfectly secure. If we learn of a breach of security that affects your personal information, we notify the Customer without undue delay, and we notify you and the authorities where the law requires.
13. Your rights and how to use them
13.1 Everyone. Whatever the law where you live, you can ask us to:
- tell you what personal information we hold about you and give you a copy,
- correct it,
- delete it,
- stop sending you non-essential emails, and
- explain how we use it.
You can change your name, contact details and alert settings yourself in the app, and delete your account yourself in Settings (section 11 explains what that does). A Customer's office can export its jobs at any time.
13.2 How to ask. Email privacy@getsightgrid.com. We may need to confirm who you are before we act, for example by replying from the email address on your account. We reply within 30 days. If the request is about Customer Data, we pass it to the Customer and help it answer, unless the law requires us to answer you directly. An authorized agent may ask for you where the law allows, with proof of authority.
13.3 Limits. Some records cannot be edited while the job exists, because the job's record of who did what is the Customer's business record (for example the activity log, the event history, clash history, verdicts, sign-offs and chat). When you delete your account, these records are not changed: every screen shows "Former member" in place of your name, but underneath the records still hold the name as it was first recorded, until the job itself is deleted. Photos and voice notes you took stay with the job. The Customer decides whether and when the job is deleted. We may also keep what the law requires and what we need to defend legal claims. We do not treat you differently for using your rights.
13.4 Canada. If you are in Canada, the Personal Information Protection and Electronic Documents Act (PIPEDA) and, in British Columbia, the Personal Information Protection Act (PIPA) may apply. You have the right to access and correct your personal information, and to withdraw consent to a use, subject to legal and contractual limits; if you withdraw consent to a use the service needs, you may no longer be able to use it. We answer access requests within 30 days, or tell you if we need more time and why. If you are not satisfied with our answer, you may complain to the Office of the Privacy Commissioner of Canada (priv.gc.ca) or, in British Columbia, the Office of the Information and Privacy Commissioner for British Columbia (oipc.bc.ca). We report breaches that create a real risk of significant harm to the Privacy Commissioner and notify affected people, as the law requires, and we keep a record of every breach.
13.5 EU, EEA, UK and Switzerland. If the GDPR, the UK GDPR or Swiss law applies to you, you also have the right to restrict or object to our processing (including processing based on legitimate interests), to data portability, and to withdraw consent at any time where we rely on consent. You may complain to your local data protection authority.
13.6 California and other US states. Several US states have consumer privacy laws, including California (CCPA as amended by the CPRA), Virginia, Colorado, Connecticut, Texas, Oregon and others. These laws apply to businesses above set thresholds. California's applies to a business with annual gross revenue above US$25 million (adjusted for inflation), or that buys, sells or shares the personal information of 100,000 or more California consumers or households a year, or that earns half or more of its revenue from selling or sharing personal information. At the date of this policy we expect to be below these thresholds. If and when a state law applies to us:
- What we collect is listed in section 5. In the categories these laws use: identifiers (name, email, phone, coded network address); commercial information (plan and billing); internet or other electronic activity (use of the app, device sessions); audio and visual information (photos, voice notes, screenshots you attach); professional or employment information (role, trade, company); and information you choose to put into the service. We do not collect sensitive personal information for the purpose of inferring characteristics about you.
- Sources, purposes and recipients are in sections 5, 6, 8 and 9. Retention is in section 11.
- We do not sell or share personal information, as those terms are defined, and have not done so in the past 12 months. We have no actual knowledge of selling or sharing the personal information of anyone under 16. We do not need a "Do Not Sell or Share" link because we do neither; we honour Global Privacy Control signals by treating them as an opt-out request, although there is nothing to opt out of.
- Your rights are to know, to access, to correct, to delete, to opt out of sale or sharing, and to limit the use of sensitive personal information, and not to be treated differently for using them. You may appeal a refusal by replying to our answer; if we still refuse, you may contact your state attorney general.
- Business contact information. Much of what we hold is business contact and work information about people acting for a company. Some state laws exclude it; where a law covers it, these rights apply to it too.
13.7 Customers' own duties. A Customer that invites people to Sightgrid is responsible for giving its own people and invitees any notice and getting any consent the law requires for what it puts into Sightgrid, for example photos of people on site.
14. Children
Sightgrid is a work tool for adults. You must be at least 18 to have an account. The service is not directed at children, and we do not knowingly collect personal information from anyone under 16. If you believe a child has given us personal information, tell us at privacy@getsightgrid.com and we will delete it.
15. Cookies and storage on your device
We do not use advertising cookies, analytics cookies or cross-site tracking, on the app or the website. The website's analytics (Vercel Web Analytics and Speed Insights) use no cookies and store nothing on your device. What we do store on your device:
15.1 The website.
| Name | Type | What it does | How long |
|---|---|---|---|
| sg-theme | Browser local storage | Remembers whether you chose the light or dark theme | Until you clear it |
The website sets no cookies. Vercel Web Analytics and Speed Insights run without cookies or device storage: Vercel tells visits apart with a hash made from the incoming request, discarded after 24 hours, and gives us only aggregate statistics (section 5.7). Google Fonts and jsDelivr receive your IP address when the page loads (section 9.2).
15.2 The app.
| What | Type | What it does | How long |
|---|---|---|---|
| Session cookie | Cookie, strictly necessary, not readable by page scripts | Keeps your device signed in | Up to 180 days; the server ends it sooner (30 days unused, or when signed out) |
| Region cookie | Cookie, functional | Remembers your region and language (United States, English; or Germany, German) so pages load in the right units | 1 year |
| Demo access cookie | Cookie, strictly necessary | Lets a demo visitor with a password see the demo | Until the demo password expires |
| The building, drawings and field notes | Browser database on your device (IndexedDB) | Lets the model and your notes open on site with no signal | Until you delete them or clear the app's data |
| Offline files | Service worker cache | Lets the app start and work offline | Until updated or cleared |
| Your choices | Browser local storage | The job you last opened, region, settings, tours you have seen, saved calculator jobs, the "prepared by" name and the contact details you entered for quotes, and similar | Until you clear them |
Because these are needed for the service to work, or only remember your own choices, we do not ask for cookie consent. You can clear them in your browser settings, but the app may then sign you out or lose offline copies.
15.3 Do Not Track. We do not track you across sites (our website analytics count page views on our own site only), so we treat every visitor the same whether or not a Do Not Track signal is sent.
16. Emails we send
We send service emails: sign-in links, invitations, alerts about items assigned to you or waiting for your sign-off, view-only clash links that another user asks us to send, and notices about your account, the service or these documents. You can turn alerts off in Settings. You cannot turn off essential account and legal notices while you have an account. We do not send marketing email without the consent the law requires, and every marketing email will have an unsubscribe link. The founders may reply personally to a field-test request or business enquiry you sent.
17. Changes to this policy
We may change this policy. For a material change, we tell Customers' admins by email and in the app at least 30 days before it takes effect, unless a change is required sooner by law. The date at the top shows the current version. We keep earlier versions and will send one on request.
18. Contact and complaints
Questions, requests and complaints: privacy@getsightgrid.com, or by post to SIGHTGRID LEGAL ENTITY NAME, attention: Privacy Officer, business address. We try to resolve every complaint directly. You also have the right to complain to a privacy regulator, as set out in section 13.

