Legal
Privacy Policy
Effective: September 8, 2026
1. Introduction
EASYBUILDS LLC, a Delaware limited liability company doing business as LODE ("LODE," "we," "us," or "our") respects your privacy. This Privacy Policy explains how we collect, use, disclose, and retain information when you use our website and web application available at lode.build (collectively, the "Services").
This Privacy Policy is intended for users in the United States. The Services are not directed to individuals located in the European Union (EU) or European Economic Area (EEA), and we do not market the Services to the EU/EEA at this time.
By accessing or using the Services, you agree to this Privacy Policy and our Terms of Service. Capitalized terms not defined in this Privacy Policy have the meanings given to them in our Terms of Service.
2. Information We Collect
We collect information to provide and improve the Services, process subscriptions, support users, and protect the security and integrity of the Services.
2.1 Information You Provide to Us
Depending on how you use the Services, you may provide:
- Account information (required): your name and email address.
- Project and document data (optional): construction drawings, specifications, revision issuances, PDFs, photos and other files, markups and comments, sheet metadata, project names, and the names, companies, roles, email addresses and phone numbers of project team members, consultants, contractors and other contacts you enter.
- Communications: messages you send to customer support, survey responses, and feedback you submit.
You can choose not to provide optional information, but some features may not work without it.
2.2 Payment and Billing Information
If you purchase a subscription, payments are processed by our payment processor, Stripe. Stripe collects and processes your payment information (such as payment card details and billing address) in accordance with Stripe's terms and privacy policy. We typically receive limited information from Stripe, such as your billing status, the last four digits of a payment card, expiration date, and transaction identifiers, which we use for billing records, fraud prevention, and customer support.
2.3 Third-Party Sign-In (Optional)
If you choose to sign in with Google or Microsoft, we receive information from those providers such as your basic profile information (for example, name and email) as permitted by your account settings and the permissions you grant. You can revoke access at any time through your third-party account settings.
LODE's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
2.4 DOC (AI features)
DOC is our optional AI assistant. What DOC may read is set at the account level by the account Owner as separate permissions: a master switch, the general assistant, project information, phase documents (submittals, RFIs, change proposals), drawing information (sheet numbers, titles, disciplines, revisions), specifications (specification text), and full drawings (extracted drawing text and images). Any project can also have DOC turned off entirely. New accounts start with the general assistant and phase documents on, and project information, drawing information, specifications and full drawings off. Nothing from a class you have not enabled is sent to our AI provider. DOC is provided as a beta feature and will change.
When you use a DOC feature, we send Anthropic what that feature needs, limited to the classes you have enabled. Depending on the feature this can include: your question and the conversation so far; text extracted from drawing sheets (and, for change annotations, the previous and new text); a rendered image of a drawing region you select and ask about; images you attach to a question; specification section text; excerpts of submittal documents for DOC Review; project details such as project names, numbers, phases, client names, issuance names and dates, sheet numbers and titles; the project's team and contacts directory (names, companies, roles, email addresses and phone numbers you entered), contract data, decision and phone logs and your firm's lessons learned with their authors' names; and schedule, permit, bidding, construction-administration and financial records when you ask about them. When DOC uses web search, your question or a search derived from it is sent to a search service through Anthropic. We do not send your login credentials or payment information, and we do not send whole PDF files.
We do not train any AI model on your content. LODE uses Anthropic's API under Anthropic's API terms, which do not use customer data for model training. Anthropic's own retention and safety practices are described in its terms. AI output may be inaccurate or incomplete and is not a substitute for professional judgment; see our Terms of Service for details.
We store your DOC conversations so you can return to them; they are personal to the member who had them and are not part of the account's record. If your account does not belong to an organization, they are deleted with it. If it does, they are retained as described in Section 6.2, and they remain private: no other member of the organization can read them, then or afterwards. We also keep usage records to meter your monthly DOC allowance and to investigate errors or abuse.
2.5 Information Collected Automatically
Like most web services, we automatically collect certain information when you use the Services, such as:
- Log and device data: IP address, browser type, device identifiers, operating system, and referral URLs.
- Usage data: how you interact with the Services (for example, pages visited, features used, and actions taken). We collect product usage analytics (PostHog) and error reports (Sentry). We do not use session replay or screen recording.
- Approximate location information inferred from your IP address (for example, city/region).
2.6 Cookies and Similar Technologies
We use cookies and similar technologies for authentication, security, and to remember your preferences. We may also use cookies and similar technologies for product usage analytics and performance monitoring (PostHog, Vercel Analytics and Vercel Speed Insights) to understand how the Services are used and to improve them. We do not use session replay.
You can control cookies through your browser settings. If you disable cookies, some features of the Services may not function properly.
2.7 Do Not Track Signals
We do not use the Services to track you across third-party websites for targeted advertising and therefore do not respond to "Do Not Track" (DNT) signals.
2.8 Information About Recipients of Shared Documents
When an account holder shares documents or workflows through the Services (for example, a transmittal, a share link, a guest review room, a bid room, a contractor portal or a punch list), we collect information about the people who receive, open or use them, even if they do not have a LODE account. This may include a recipient's name and email address (when provided at the time of access), IP address, browser and device (user-agent) information, and open and download activity. Files a guest uploads through a contractor portal or punch list become part of the sharing account's project record. We use this information to deliver the shared documents, provide delivery and access confirmation, and maintain the sharing account holder's transmittal and audit records. This information is part of the sharing account's project records and is deleted when those records are permanently deleted, as described in Section 6.
3. How We Use Information
We use the information we collect to:
- Provide, operate, maintain, and improve the Services;
- Compile and manage your drawing sets, process revision issuances, and generate outputs you request;
- Create and manage accounts;
- Process subscriptions, payments, and billing;
- Provide collaboration features you enable (for example, sharing projects with team members you invite);
- Provide customer support and communicate with you about the Services;
- Monitor, detect, prevent, and address fraud, abuse, security incidents, and technical issues;
- Conduct analytics and product research, including aggregated and de-identified analytics;
- Comply with legal obligations and enforce our Terms of Service; and
- Provide optional AI-assisted document analysis features.
We may de-identify or aggregate information so it can no longer reasonably be used to identify you. We may use de-identified or aggregated information for product improvement, analytics, and research purposes.
4. How We Share Information
We do not sell your personal information. We also do not share personal information for cross-context behavioral advertising (also called "targeted advertising") as those terms are defined under many U.S. state privacy laws.
4.1 With Service Providers
We use third-party service providers to help operate the Services. These providers process information on our behalf and subject to contractual confidentiality and security obligations. Our service providers are listed below and at lode.build/security; we give notice before a new provider begins handling your project content:
- Web hosting and infrastructure providers (Vercel for our website and web application, and Railway for our application backend and processing services).
- Database, authentication and file storage (Supabase) for accounts, project metadata, uploaded sheets and outputs.
- Document storage providers (Amazon Web Services (AWS) S3, and in some cases Cloudflare R2) for uploaded and compiled documents.
- Long-term archival storage providers (AWS S3 Glacier) for cold-storage copies.
- Job-queue hosting (Railway) used to process uploads and generate outputs, and rate-limiting infrastructure (Upstash).
- Product usage analytics and performance providers (PostHog; Vercel Analytics and Speed Insights), and error reporting (Sentry). None of these records your session or screen.
- Real-time collaboration provider (Liveblocks) for live presence, cursors and shared review rooms; it receives display names, company names for guest reviewers, presence and cursor positions, not your files.
- Payment processors (Stripe), including sales-tax calculation.
- AI provider (Anthropic) for DOC, receiving only what your AI permissions allow (Section 2.4).
- Email and communications providers (Resend).
- Sign-in providers (Google, Microsoft) if you choose to sign in with them.
Office-document conversion runs on software we host ourselves and is not a third-party service.
4.2 With People You Share With
If you invite collaborators to a project or otherwise share information through the Services, those people will be able to access the information you share with them, subject to the permissions you set.
4.3 For Legal and Safety Reasons
We may disclose information if we believe in good faith that disclosure is necessary to comply with law; respond to lawful requests; protect the rights, safety, and security of LODE, our users, or others; or investigate fraud or security issues.
4.4 Business Transfers
If we are involved in a merger, acquisition, financing, reorganization, bankruptcy, or sale of assets, information may be transferred as part of that transaction, subject to appropriate protections.
5. Document Ownership
Your documents are yours, always. All construction drawings, revision issuances, PDFs, and other files you upload to the Services remain your exclusive property. LODE processes your files solely to provide the Services you use: compiling and managing your record, sharing what you choose to share, and DOC as your AI permissions allow. We do not claim any ownership interest in your documents. We do not train AI models on your documents, and our AI provider's API terms do not use them for model training. We do not sell or monetize your document data.
6. Data Retention and Deletion
We retain information for as long as necessary to provide the Services and for other legitimate business purposes, such as complying with legal obligations, resolving disputes, and enforcing our agreements. The Terms of Service set specific retention windows: 30 days after a deletion, 30 days after a cancelled trial ends, 30 days after a paid plan ends or a subscription becomes unpaid, and for as long as an Archive plan is paid. After a window ends we permanently delete the data as described in Section 6.1.
6.1 Deletion of Projects and Documents
When you delete a project or document, it enters a 30-day grace period during which you may restore it. After the 30-day grace period expires, all associated files, including uploaded PDFs, processed sheets, compiled sets, and AI-generated summaries, are permanently and irreversibly deleted from our storage systems. No copies of your documents are retained after permanent deletion, other than in the routine backups LODE maintains of its databases and file storage, which are replaced in the normal course; we do not restore deleted data from them.
While a project is active, LODE's document control intentionally preserves your revision history. Superseded and voided documents are not silently discarded; they are retained with full provenance as a core feature of the Services so you keep a complete, auditable record of how your set evolved. This retained history is permanently deleted together with the project or account under this Section when the grace period expires.
Projects owned by an organization are the organization's records. If you delete your individual account, projects that belong to an organization are not deleted along with your personal account; they remain with the organization and are subject to deletion by the organization.
6.2 Account Deletion
If you request account deletion, your subscription is cancelled and the data described below enters the same 30-day grace period, during which you can cancel the deletion from the link we email you. What is deleted depends on the account and on what it has contributed to.
An individual account that does not belong to an organization. Your login, your profile, your projects, your documents and their revision history, and all other personal information associated with your account are deleted, except where retention is required for legal, tax, security, or billing purposes. One thing is kept. Where an account has contributed to a project, we retain the contributor's display name on that work as part of the project record, including after the account is deleted. We do this because who did what on a construction project can matter in a professional or legal dispute years later. Note that having no organization does not by itself mean no other party is involved: an account that belongs to no organization can still be assigned to, and work on, a project owned by one. If the project belongs to an organization, requests to remove attribution are directed to that organization. Other requests are considered individually.
An organization's account. When an organization deletes its account, or its plan ends and is not renewed, the organization's entire record is deleted after the grace period: every project and document belonging to the organization, and the work of every member in it. Members are notified before this happens.
An individual account that belongs to an organization. We delete your login, your profile, your personal information and anything personal to you, and you are removed from the organization. We do not delete the work you contributed to the organization's projects. That work is the organization's record, and it stays with the organization along with the attribution that identifies who did it: your name and an internal account identifier remain attached to the documents, comments, markups and revision entries you created, so that the organization keeps a complete and auditable record of how its project developed. Requests to remove that attribution should be directed to the organization, which controls its own project records; we will act on the organization's instruction.
6.3 Anonymized Data for System Performance
We retain anonymized, non-identifiable metrics about how the Services are used, for example how many sheets were in a typical issuance, how long processing took, and what types of errors occurred. This data contains no names, no document titles, no file content, and cannot be linked back to you or your projects. We use it solely to improve LODE's performance and reliability for all users.
6.4 Audit Records
A record that your account existed and was deleted is retained permanently for legal and compliance purposes. This record contains no names, no email addresses, and no file content, only the fact that a deletion occurred and when.
6.5 Data After a Trial or Plan Ends
The trial requires no payment method to start. When a cancelled trial ends or a paid plan is cancelled, the account is locked and its data is kept for 30 days so you can subscribe, buy Archive, or export it. If you do none of these within 30 days, the account's projects and documents are permanently deleted as described in Section 6.1. A subscription that becomes unpaid is different: the account is locked in the same way, but no deletion clock starts and we do not delete an account for non-payment — the data stays until the account is cancelled or deleted. Archive keeps the data for as long as the Archive fee is paid; it is download-only.
7. Security and Data Breach
We use reasonable administrative, technical, and physical safeguards designed to protect information. We store and process information in the United States. Passwords are hashed, data is encrypted in transit and at rest, and access is restricted using least-privilege permissions and row-level security. Application data such as accounts and project metadata is managed and stored through Supabase; uploaded and compiled documents are stored in Supabase Storage and on Amazon Web Services (AWS) S3 (and in some cases Cloudflare R2), with cold-storage copies in AWS S3 Glacier. However, no method of transmission or storage is completely secure, and we cannot guarantee absolute security.
In the event of a data breach affecting your personal information, we will notify you as required by applicable law.
8. Your Choices and Privacy Rights
8.1 Access, Correction, Deletion, and Export
You may update certain information directly in the Services. You may also request to access, correct, or delete your personal information by contacting us at support@easybuilds.com. We may need to verify your identity before responding to your request.
The account Owner can export the whole account from Settings at any time while on a plan, during a retention window, or on Archive. The export includes every project, file, compiled set, annotation, markup, comment and revision-history record the account owns, with records and metadata in machine-readable form and a manifest of its contents. Individual projects, sheets, compiled sets and files can also be downloaded from the app.
8.2 Marketing Communications
We may send you marketing emails or other promotional communications in the future. You can unsubscribe from marketing emails using the unsubscribe link included in the emails. You may also manage notification preferences within the Services.
8.3 State Privacy Rights
Depending on your state of residence (such as California, Colorado, Connecticut, Virginia, Utah, and other states with comprehensive privacy laws), you may have additional rights regarding your personal information. These rights vary by state, but may include:
- The right to know/access: confirm whether we process personal information and access it;
- The right to correction: request that we correct inaccuracies;
- The right to deletion: request that we delete personal information (subject to exceptions);
- The right to data portability: obtain a copy of certain personal information in a usable format;
- The right to opt out of certain processing, such as targeted advertising, certain profiling, or the sale of personal information (as defined by applicable law).
To exercise your rights, contact support@easybuilds.com. In some states, you may also have the right to appeal a decision we make regarding your request. To submit an appeal, please reply to our response or contact support@easybuilds.com with the subject line "Privacy Rights Appeal." We will not discriminate against you for exercising your privacy rights.
Authorized Agents (California): If you are a California resident, you may use an authorized agent to submit a request on your behalf, subject to verification requirements under applicable law.
9. Children's Privacy
The Services are not intended for individuals under 18. We do not knowingly collect personal information from children under 13. If you believe a child has provided us personal information, please contact us and we will take appropriate steps to delete it.
10. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. If we make material changes, we will give at least 30 days' notice by email to the account Owner and in the app before they take effect, post the updated policy, and update the effective date.
11. Contact Us
If you have questions about this Privacy Policy or our privacy practices, please contact us at support@easybuilds.com.