1. Introduction
BuilderHelp ("we," "our," or "us") is committed to protecting your privacy. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you use our construction project management platform, including the Gmail Invoice Scanner feature.
2. Google User Data (Gmail)
This section explains the Google user data we access, how we use it, whether we share it, how we store it, and how you can delete it.
2.1 Data Accessed
- Email Messages: We scan your Gmail inbox for emails containing keywords related to invoices, statements, bills, and receipts (e.g., "invoice", "statement", "bill", "receipt")
- PDF Attachments: We download PDF attachments from emails that match our search criteria
- Email Metadata: Subject lines, sender information, dates, and email IDs
- OAuth Tokens: Secure access tokens and refresh tokens to access your Gmail account (stored encrypted)
2.2 Data Usage
We use Gmail data solely to identify invoice-related emails, extract invoice details from PDF attachments, and organize those invoices inside BuilderHelp. We do not sell Google user data.
2.3 Data Sharing
We share Google user data only with service providers needed to deliver the service:
- OpenAI: To extract structured invoice data from PDF attachments
- AWS S3: To store PDF attachments securely
- Railway (PostgreSQL): To store extracted invoice data and encrypted OAuth tokens
These providers act as data processors on our behalf and are required to protect your data.
2.4 Data Storage & Protection
We store Gmail-related data in secure cloud systems and protect it with encryption in transit and at rest, access controls, and secure OAuth 2.0 authentication.
2.5 Data Retention & Deletion
Gmail data and extracted invoice data are retained only as long as needed to provide the service. You can request deletion by:
- Disconnecting Gmail inside the app (revokes access and removes OAuth tokens)
- Deleting invoices in the app (removes invoice data and schedules PDFs for deletion)
- Emailing us at support@builderhelp.com to request account or data deletion
3. Data Collection
We collect information that you provide directly, information generated by your use of the app, and information from connected services like Gmail. The specific categories of data we collect are described in detail below.
4. Data Usage
We use your data only to provide and improve BuilderHelp, including scanning for invoices, extracting invoice details, organizing project costs, and delivering account-related communications. We do not sell your personal data.
5. Data Storage
We store your data on secure cloud infrastructure and retain it only as long as necessary to provide the service or as required by law. Storage locations and retention details are listed below.
6. Information We Collect
6.1 Gmail Integration Data
When you connect your Gmail account, we collect:
- Email Messages: We scan your Gmail inbox for emails containing keywords related to invoices, statements, bills, and receipts (e.g., "invoice", "statement", "bill", "receipt")
- PDF Attachments: We download PDF attachments from emails that match our search criteria
- Email Metadata: Subject lines, sender information, dates, and email IDs
- OAuth Tokens: Secure access tokens and refresh tokens to access your Gmail account (stored encrypted)
6.2 Invoice Data
From the PDFs we process, we extract and store:
- Invoice numbers
- Vendor names
- Invoice amounts
- Invoice dates and due dates
- Line items and descriptions
- Other invoice-related information
6.3 Account Information
We collect standard account information including:
- Name and email address
- Company information
- Project data and construction information
- Usage data and preferences
7. How We Use Your Information
We use the collected information to:
- Automate Invoice Processing: Scan your Gmail inbox for invoices and automatically extract invoice data
- Project Management: Link invoices to your construction projects and track expenses
- Data Organization: Store and organize your invoices for easy access and management
- Service Improvement: Improve our services and develop new features
- Communication: Send you service-related notifications and updates
8. Data Storage and Security
4.1 Storage Locations
- Invoice Data: Stored in PostgreSQL database (hosted on Railway)
- PDF Files: Stored in AWS S3 cloud storage
- OAuth Tokens: Stored encrypted in PostgreSQL database
4.2 Security Measures
We implement industry-standard security measures including:
- Encryption of sensitive data in transit and at rest
- Secure OAuth 2.0 authentication with Google
- Access controls and authentication requirements
- Regular security audits and updates
9. Third-Party Services
We use the following third-party services:
- Google Gmail API: To access and scan your Gmail inbox
- OpenAI: To parse PDF invoices and extract data using AI vision
- AWS S3: To store PDF files securely
- Railway: To host our backend services
These services have their own privacy policies. We recommend reviewing their policies to understand how they handle your data.
10. Data Retention
- Invoice Data: Retained until you delete it or close your account
- PDF Files: Retained for 30 days after invoice deletion, then permanently removed
- OAuth Tokens: Removed immediately when you disconnect your Gmail account
- Account Data: Retained until account closure, then deleted within 30 days
11. Your Rights and Choices
You have the following rights regarding your data:
- Access: View all data we have collected about you
- Deletion: Delete invoices, disconnect Gmail accounts, or delete your entire account
- Modification: Update or correct your account information
- Disconnect: Disconnect your Gmail account at any time, which immediately revokes access
- Export: Request a copy of your data in a portable format
To exercise these rights, contact us at the email address provided in the "Contact Us" section below, or use the disconnect/delete features within the application.
12. Gmail API Scopes
Our application requests the following Gmail API permissions:
- gmail.readonly: Read your Gmail messages to scan for invoices and download PDF attachments
We only access emails that match our search criteria (invoices, statements, bills, receipts). We do not read, store, or process any other emails in your inbox. We do not modify, delete, or send any emails on your behalf.
13. Children's Privacy
Our service is not intended for users under the age of 18. We do not knowingly collect personal information from children. If you believe we have collected information from a child, please contact us immediately.
14. Changes to This Privacy Policy
We may update this Privacy Policy from time to time. We will notify you of any changes by posting the new Privacy Policy on this page and updating the "Last updated" date. You are advised to review this Privacy Policy periodically for any changes.
15. Contact Us
If you have any questions about this Privacy Policy or our data practices, please contact us: