Buildly is free while in beta.

Legal

Privacy Policy

What we collect, why, and who else is involved.

Draft. This describes how Buildly actually works today, but it has not been reviewed by a lawyer and is not yet a binding agreement. It will be replaced before general availability.

Two kinds of data, kept apart

Account data - organizations, members, roles, billing, site content - is held separately from data generated by visitors to your published site, such as contact form submissions and page views.

The separation is architectural, not a policy statement: they are different databases, reached by different code paths.

What we collect from you

What you give us: your name, email, business details, and anything you upload or type into the builder.

What we generate: the content and images produced from your brief, plus a record of how many sparks each generation spent.

What your site collects from its visitors

A published site captures contact form submissions, which are delivered to you and stored so a lead is never lost.

Page views are recorded in aggregate. If you connect analytics or advertising tools of your own, those tools collect data under their own terms - and a consent banner may be required on your site as a result.

Tenant isolation

One organization cannot read another organization’s data. That is enforced by the database itself, not only by application code, so a mistake in our code still cannot expose your rows.

Subprocessors

We rely on third parties to run the service: an AI gateway for content generation, an image service for generation and photo enhancement, Stripe for payments, and a CDN and bot-protection provider in front of the default subdomains.

Where you connect your own provider - your email sender, your Google account - your credentials are encrypted before storage and used only for the integration you connected them for.

Secrets and encryption

API keys and OAuth tokens are encrypted at rest. Keys you enter are masked once saved and never shown again, and are never written to logs at any level.

Your choices

You can export or delete your data by contacting us. Deleting an organization removes its sites from the public internet.

Disconnecting an integration deletes the stored credentials for it immediately and stops any background sync.