Legal
Trust & Security
Last updated: 26 August 2026
BuildScope holds your scopes, your rates, your margins and your clients' details. For some customers it also holds an access token to their own accounting or job-management system. We take that seriously enough to write down exactly what we do, rather than say we take it seriously.
Everything on this page is a description of what the product does today. Where something is planned rather than built, it says so.
These documents are general draft website policies and should be reviewed by an Australian lawyer before publication.
The short version
- We do not sell your data, and we never share private project data with advertisers
- Our AI provider (Anthropic) does not train its models on your data
- Each company’s data is isolated from every other company’s, enforced by the database itself
- Card details never touch our servers
- Access keys for your connected accounts are encrypted before they are stored
- Diagnostic logs are deleted automatically on a fixed schedule
- You can delete your account and your data from inside the app
Company data isolation
Every company account has its own isolated data area. Company A cannot view, access or influence Company B’s project data.
This is not a convention we follow in our own code, which would be a promise. It is enforced by the database’s own security rules against a signed token that carries your organisation id, so a request for another company’s data is refused before it reaches our application at all.
We test it. An automated check signs in as a real organisation owner and confirms that reading another organisation’s data is refused, and that normal use still works.
Your company’s learning, templates, wording and history stay yours. Nothing one company does feeds another company’s results, and nothing private feeds the shared construction knowledge the estimator starts from.
Encryption
All traffic is encrypted in transit (TLS). All stored data is encrypted at rest by our infrastructure providers.
Connected account keys get a second layer. If you connect ServiceM8, Xero or QuickBooks, the access keys that let BuildScope act on your behalf are encrypted with AES-256-GCM before they are written down. They are never sent to your browser, never shown in the app, and never written into logs. Disconnecting deletes them rather than marking them inactive.
Who can see your data
Inside your company: the people you invite, according to the role you give them.
At BuildScope: staff access to the internal console is restricted to accounts that hold a specific administrative permission, which is currently held by the founder. Every action taken in that console against a customer account is written to an audit log.
Removing that permission, or disabling an account, takes effect on the next request rather than whenever a login session happens to expire.
Payments
BuildScope never sees or stores your card details. Card payments are handled by Stripe, and in-app purchases by Apple and Google. We hold only the identifiers needed to know that your subscription is active.
AI processing
Scope content is processed by Anthropic’s commercial API under terms that do not permit it to be used to train their models.
Where you connect an accounting system, information flows one way: BuildScope writes a draft into it. Nothing read from a connected system is sent to the AI.
More detail in our AI Use Policy.
How long we keep things
Account and project data is kept for the life of your account and deleted when you delete it.
Diagnostic logs, which we keep to fix faults and spot attacks, are deleted automatically: general notices after 14 days, warnings after 45 days, and errors after 120 days. That deletion is enforced by the database on a schedule, not by somebody remembering.
You can delete your account and its data from inside the app, at any time, without asking us.
Who else touches your data
The providers BuildScope relies on. Some hold information outside Australia.
| Provider | What for | What they receive |
|---|---|---|
| Google (Firebase, Cloud) | Accounts, database, file storage | Account and project data |
| Vercel | Hosting | Requests in transit |
| Anthropic | The AI estimator | Scope content. Not used for training |
| Stripe | Card billing | Email and billing identifiers. No card data on our side |
| Apple, Google Play | App subscriptions | Subscription identifiers |
| Klaviyo | Name, email, trial status | |
| DataFast | Website analytics | Page, referrer, country, browser. No cookie, no identifier |
| Cloudflare | Bot protection | IP address on a challenge |
| ElevenLabs | Voice features (beta) | Audio, sent via our server |
ServiceM8, Xero and QuickBooks appear only if you connect them, under your own agreement with those companies, and receive only what you choose to send.
If something goes wrong
BuildScope is covered by Australia’s Notifiable Data Breaches scheme under the Privacy Act 1988. We have a written incident response plan and a breach assessment procedure.
If a breach happens that is likely to result in serious harm, we will notify the Office of the Australian Information Commissioner and every affected person, as soon as practicable, telling you what happened, what information was involved and what we recommend you do.
We would rather tell you quickly and plainly than manage the message.
Reporting a security issue
If you believe you have found a security vulnerability in BuildScope, please tell us at admin@buildscope.app with the subject line SECURITY.
Please include enough detail to reproduce it, and give us a reasonable opportunity to fix it before disclosing it publicly. We will acknowledge your report within 3 business days and keep you updated until it is resolved.
We ask that you do not access, modify or delete data belonging to other users, do not degrade the service for others, and do not use social engineering or physical attacks. Researchers who follow that will not face legal action from us.
We do not currently run a paid bug bounty, but we will credit you if you would like us to.
Certifications
BuildScope is not currently SOC 2 attested or ISO 27001 certified. We would rather say that plainly than imply otherwise.
We are working toward both. A formal information security programme was documented in August 2026 covering incident response, access control, risk management, vendor management, secure development and business continuity, and the technical controls described on this page are already in place.
If you are evaluating BuildScope and need to complete a security questionnaire or a vendor assessment, email admin@buildscope.app and we will work through it with you.
Your part
No system is immune from risk. BuildScope takes reasonable steps to protect your information, and you are responsible for protecting your password, managing who you invite, and reviewing what access your staff have.
If you believe your account has been accessed without permission, contact admin@buildscope.app straight away.
