Privacy
How we handle data
- Saving or sharing a build stores the configuration and the generated estimate needed to reproduce its permalink. A saved build may also include the reason notes and interview answers submitted through the build flow.
- A saved build has a randomized share ID and no account — there is no list of your builds and no owner lookup. Anyone who has the permalink can open that saved build. The randomized share ID is the only access barrier; there is no login or owner authentication.
- There are no user accounts tied to saved builds, and builds are not managed through an account dashboard.
- The current product does not accept bill, invoice, or document uploads, and performs no automatic redaction — there is no upload workflow.
- The app runs on third-party hosting and database providers, which necessarily handle operational and network metadata to serve requests. The application itself does not write your IP address or request headers into a saved build.
- When the approved site-specific script is configured, the app uses Plausible for aggregate page views and a small allowlist of product events: Builder entry, package/path and step progression, review and share completion, provider-link exits, empty catalog-filter results, and an optional yes/no estimate-usefulness response.
- Product analytics does not receive build contents, custom resource names or notes, interview answers, saved-build or share identifiers, or catalog search text. Shared-build paths are grouped under a redacted route and query strings are removed before analytics. Plausible uses no analytics cookies; it receives the remaining page and network/browser metadata needed to aggregate visits.
For privacy questions, or to ask about or request deletion of a saved build, email hello@aistackpicker.com. Include the build’s permalink or share id so the record can be found. Please do not email full bills, invoices, passwords, or API keys.