Policy record / Updated August 27, 2026

Your project is not our advertising inventory.

This notice describes the current product and its service providers in plain language. It avoids promises the software cannot technically prove.

Short version

Project information supports the workspace you ask us to provide. It is not sold to contractors, and projects are not publicly browsable.

Information the product handles

Account data can include your name, email address, authentication identifiers, and product access status. Project data can include scope answers, estimates, budgets, decisions, contractor records, messages, uploaded documents, photos, and closeout records that you choose to provide.

We also receive technical and usage data such as page and feature events, device or browser information, approximate campaign attribution, errors, and diagnostic context. Support requests include the contact details, category, and message you submit.

Why it is used

We use information to authenticate accounts, save and share authorized project records, provide purchased features, process payments, deliver opted-in messages, answer support requests, prevent abuse, diagnose failures, and understand whether product flows work.

Uploaded or extracted content is used for the feature you invoke. AI-assisted features may send bounded document text, project records, or—in the opted-in iMessage channel—the current message and up to twelve recent user-and-Pilot text turns to an AI provider to produce the requested extraction, comparison, summary, or conversational reply. The application requests non-persistent processing where the integration supports it, but generated output still requires your review.

Service providers and disclosures

The current product uses specialist providers for hosting and delivery: Neon for authentication and database services; Vercel for hosting, private file storage, AI Gateway routing, and short-lived integration credentials; PostHog and Google Analytics for analytics and diagnostics; Polar for checkout, orders, subscriptions, and billing portals; Resend for transactional email and support delivery; BaseHub for public Field Journal content; Linq for an explicitly opted-in iMessage sandbox; and Anthropic and Google as the default model providers, with approved OpenAI or Alibaba models also available for enabled AI-assisted features routed through Vercel AI Gateway.

Each provider receives the information needed for its role. Payment-card details are entered into the checkout provider rather than the Project Pilot workspace. We may also disclose information when legally required, to protect users or the service, or as part of a business transaction subject to appropriate safeguards.

Sharing and contractor visibility

A project is private by default. A project owner can deliberately create a public share link or invite a contractor to a project-specific portal. Anyone with the share link can see the information presented by that link. The product does not currently provide self-service share-link revocation, so create links only for the intended audience and contact support if a link must be disabled.

Contractors cannot browse unrelated homeowner projects. Project Pilot does not currently sell homeowner leads or operate an open contractor marketplace.

Retention, deletion, and choices

Information is retained while needed to provide the account, project, purchase, support, security, and recordkeeping functions described here. Different records can have different retention requirements, including payment and fraud-prevention records held by providers.

The iMessage sandbox stores a keyed digest rather than the plaintext phone handle, the final four digits for recognition, consent and status, delivery event identifiers, and aggregate usage events. Ordinary message content is excluded from Project Pilot project records, logs, analytics, and durable message tables. When you explicitly ask Pilot to submit product feedback, only that feedback and your stated contact preference are sent to the existing PostHog feedback survey. Project Pilot encrypts the complete event before Vercel Workflow durability and decrypts it only inside the bounded processing step. For conversational continuity, the processor can retrieve up to twelve recent user-and-Pilot text turns from Linq; it excludes attachments, links, and provider participant-handle fields before sending the bounded text through Vercel AI Gateway with zero-data-retention and prompt-training exclusions requested. Project Pilot does not persist that retrieved text. It may retain a short-lived canonical dialogue state containing only an assistant-action label and authorization-checked project identifiers, never message bodies or project facts; stored references expire and are reauthorized before every use. Signed project-preview links expire and reveal only the bounded project snapshot shown in their social preview before opening the authenticated project destination. Messages can remain on sender and recipient devices and are also subject to Linq, Vercel, and Apple retention behavior. Pausing clears conversational state and stops replies; unlinking removes the active handle mapping.

Export and deletion controls are available in specific parts of the product and may depend on the project’s records and entitlements. To request project- or account-level access, correction, export, or deletion, use public support and choose “Privacy or data request.” We may need to verify the account before acting.

Analytics, security, and limits

Campaign analytics are designed to retain useful attribution labels while removing raw advertising click identifiers from product events. Analytics and diagnostics can still involve identifiers, URLs without query strings, device information, and usage events.

We use access controls, private file storage, scoped project permissions, validation, and monitoring, but no internet service can promise absolute security or uninterrupted availability. Do not upload information the product does not ask for, and do not send sensitive documents through support.

Children, changes, and contact

Project Pilot Pro is intended for adults managing home projects and is not directed to children under 13. If you believe a child supplied personal information, contact support.

We may update this notice as the product or its providers change. The date above identifies the current version. Questions and privacy requests can be sent through the support form.