Privacy policy
DeepBuild is operated by its founders, Dev and Parmeet, and is not incorporated. The founding team handles privacy and support requests at parmeetabbat@getdeepbuild.com. This policy describes the current business pilot, not a promise of certified security or Canadian-only storage.
What we collect and why
- Account and sign-in information: name, email, profile image, authentication records, sessions, and session IP address and browser information. These support sign-in, account security and access control. Google sign-in supplies basic account/profile information; it does not give DeepBuild access to your Drive or Gmail.
- Project content: uploaded files and earlier versions, extracted text/model properties, folders, saved versions and project activity. These provide the shared workspace and preserve source evidence.
- Private chats: questions, answers, citations and optional good/bad ratings. We save them so you can return to conversations. Operational records such as response time, model calls and token counts support reliability and cost management.
- Optional pilot analytics: account/project-linked visits, answer outcomes, ratings and reliability/usage measures. These help us understand adoption, usefulness and performance. The internal dashboard uses counts and limited identifiers, not document contents or chat text. These records are not anonymous merely because the dashboard aggregates them.
- Support correspondence: information you choose to send us so we can respond to requests or investigate problems.
AI processing and service providers
When you ask a question, your message, bounded recent history and selected PDF content are sent to Google’s Gemini API. Small supported file sets can send the original PDF pages, including images and tables; larger sets use retrieved text. General chat messages may also be sent when no files are selected. DeepBuild stores its own chat history.
Gemini’s handling is governed by its API terms. Paid-service prompts and responses are not used to improve Google’s products, but safety/legal logging and processing outside Canada can still occur. We do not promise zero provider retention. Confidential or sensitive document use requires an agreed firm-data pilot and confirmed suitable provider configuration.
Google also processes sign-in information under its own policies. Loading a linked Google profile picture contacts Google’s image service. Storage, hosting and other technical providers may process data to operate the service; ask us about the arrangement for your pilot before submitting restricted information. Data processed abroad can be subject to that country’s lawful-access requirements.
If password-recovery email is configured, requesting a reset sends your email address and a one-use recovery link to Resend for delivery. No project files or chat content are included in that email. This email service is separate from Google sign-in and optional analytics.
The assistant can search the public web automatically when a question needs external information. Serper receives a short public-topic query, which may include public manufacturer/model identifiers or published standards mentioned in your question or documents. Gemini receives that query and selected URLs, and its URL Context tool retrieves public page content to write the web answer. Attached files and private chat history are not included in these separate lookup requests. The assistant is instructed to exclude personal and confidential details, and additional checks block recognizable sensitive query patterns; these checks cannot guarantee detection of every private detail. Avoid requesting searches involving private identities or site information. Serper processes search data under its terms and privacy policy. We have not verified a no-training guarantee for Serper. Gemini interactions disable saved interaction history with store: false; this does not disable all provider logging. We do not promise zero provider retention or Canada-only processing.
Web information is distinguished from document evidence. Serper-based answers, source titles and links are saved in your private chat history until you delete the chat or account; older Exa-based answers remain readable. We do not save full retrieved web pages, use web results as AI memory, or include their contents in usage analytics. Publisher rights still apply to excerpts and page content. Older Google Search answers retain their existing text-only, up-to-two-year expiry; their links and suggestion widgets were not stored. Opening a source visits that external website under its own policies.
Who can see your data
Current project permissions determine access to shared files, saved versions and activity. Workspace administrators can manage team access. Private chats are accessible to their author in the product. Authorized operators may access data when necessary for support, security, legal obligations or service operation; “private chat” is not a promise that no service operator can access it.
We do not sell your personal information or use it for advertising. Document/chat-content review for research or model training is not enabled. We do not publish customer names, logos, testimonials or private content without permission. Data may be disclosed where legally required or to respond to misuse or security incidents.
Your analytics choice
Optional usage analytics are on by default after the first-use notice is acknowledged. Switch them off in Settings → Pilot data use. Opt-out stops new visit collection and excludes your past account activity from pilot analytics; it does not remove product records needed for chats, reliability or security. Re-enabling analytics makes retained history eligible again. Shared project file/readiness counts may still include your contributions.
Accepting the pilot terms is not permission for marketing emails or document-content research. There is no session replay, external analytics service or advertising-cookie system in this pilot.
Cookies and local preferences
Authentication uses cookies to keep you signed in and secure the session. Browser storage remembers preferences such as appearance, sidebar size and selected file scope. These are distinct from optional visit analytics.
Retention and deletion
Active files, version history, chats and citations are retained to provide the workspace. There is currently no automatic retention-expiry job. A 30-day dashboard view is a reporting window, not a deletion deadline. Do not rely on indefinite storage as a backup.
You can delete your own chats and request account deletion through the product. Shared team files and activity can remain after an account is removed; historical activity may still name its author. Owners can permanently delete trashed files only when no saved evidence depends on them. Original-byte cleanup is queued and can be delayed by storage failures. Backups, downloaded copies and provider-retained data are not erased by those controls.
Contact us for personal-information removal requests, records protected by shared evidence, inactive data or backup questions. We will review the request, applicable retention obligations and other people’s rights. We do not claim an unlimited right to retain personal information or promise that a request can always remove every copy. Firm-specific retention and exit arrangements must be agreed before confidential-data use.
Access, correction and concerns
Email parmeetabbat@getdeepbuild.com to ask what personal information we hold about you, request access or correction, withdraw an applicable consent, request removal, or make a privacy complaint. We may verify your identity without collecting unnecessary information and must protect other people’s data. We will respond within applicable legal time limits and explain any restriction. You may also contact the relevant privacy regulator.
Protecting information and policy changes
We use authentication, current-membership permissions and controlled deletion to protect data. No system is risk-free. Report suspected unauthorized access to our support email; we will assess incidents and meet applicable notification obligations. Do not upload passwords, identity documents, health records or other highly sensitive material without an agreed suitable arrangement.
Material changes will be presented in the product before further uploads or questions. We will not treat acknowledgement of a revised notice as blanket permission for an unrelated new use of your information.