buildable
Menu
Build in studio

Privacy policy

Effective 7 September 2026.

Buildable Technology Oy operates Buildable at buildable.sh and app.buildable.sh. We are the controller for account administration, service operation and our own support communications. Contact: privacy@buildable.sh. Postal address: Makasiinitie 9b, 02780 Espoo, Finland.

Information we use

Account information. When you choose Google sign-in, we receive your Google account identifier, verified email address and profile name. We request only OpenID, email and profile access. Signing in does not give Buildable access to your Gmail, Drive, contacts or calendar. We store an account record, sign-in events and a secure session identifier to recognize you and protect your workspace.

Design work. Cloud features store the projects, revision inputs, briefs, selected context packages, uploaded files, comments and review information you deliberately submit. We also record generated outputs, job progress, failures and usage counters. Local projects can remain in your browser until you choose cloud synchronization. Clearing browser storage may remove local-only work.

Collaboration. Invitation email addresses, permissions, acceptance and expiry records determine access. Comments retain the author's identity and source revision. Files are shared with a review when you explicitly select them. Company membership does not automatically make your private projects visible to everyone in the company.

Service and support information. Our infrastructure processes connection and security information, such as IP addresses and request logs. If you contact us, we use your message and contact details to respond. Please avoid sending unnecessary sensitive personal information in briefs, uploads or support messages.

Why we process information

We process account, project, collaboration and requested generation data to provide the service you request and perform our agreement with you. We use necessary security and operational records for our legitimate interests in protecting the service, preventing misuse and diagnosing failures. Where applicable, we retain records to meet legal obligations. Optional processing that requires consent is explained when offered; you may withdraw consent without affecting earlier lawful processing.

Providers and AI features

Cloudflare hosts the application, database, private file storage and job infrastructure. Google provides sign-in. Requested design generation uses Cloudflare Workers AI and a bounded Fabro workflow; the deterministic design kernel produces supported geometry and exports. These providers receive the information needed to perform the requested operation.

An optional Gemini decorated-render feature, when enabled, sends a rendered preview image and a selected scene instruction to Google only after the disclosure in that feature is accepted. It does not upload your original documents as part of that render request. Generated decoration can differ from the design and is a derived illustration.

Our PostHog integration uses the EU endpoint for a limited app-open event. Its current configuration disables session recording, automatic interaction capture and person profiles, and uses memory-only persistence. It does not include your name, email, brief, file names or design contents in that event. Providers may still process connection information when receiving requests.

We use Slack for internal operational notifications such as build results and enrollment counts. The notification integration excludes design contents and original documents. Authorized operators may access service records to maintain and support Buildable. We do not sell personal information or use Google account information for advertising.

Some providers may process information outside Finland or the EEA. An EU storage location does not guarantee that every support, security or AI operation occurs only in the EU. Applicable provider agreements and lawful transfer safeguards govern such processing. Contact us for information about the safeguards relevant to your use.

Storage, retention and deletion

We keep cloud project information while needed to provide your workspace, maintain revision history and support the reviews you request. Archiving a project is not deletion. Session and invitation credentials expire; some security, audit and usage records may need to remain after access ends. Retention depends on the purpose, applicable legal obligations and unresolved disputes rather than a single period for every record.

You can remove supported files using the product controls. For account deletion, project deletion, an export or questions about retained records, email privacy@buildable.sh. We may verify your identity before acting. We will explain any information that must be retained and why. Removing access cannot recall copies another authorized recipient has already downloaded.

Your rights

Depending on the applicable law, you can request access, correction, erasure, restriction or portability of your personal data, and object to processing based on legitimate interests. You can withdraw consent where processing relies on it. You may complain to the Finnish Office of the Data Protection Ombudsman, or another competent supervisory authority.

You can revoke Google's connection through your Google Account settings; that does not itself delete a Buildable account or its saved projects. Buildable does not make decisions producing legal or similarly significant effects about you solely through automated processing.

Changes and contact

We will update this page as the service changes and provide notice of material changes where required. Questions and privacy requests: privacy@buildable.sh.

Explore Buildable ↗