Privacy & Data
Privacy Policy
Effective date: September 6, 2026. This policy applies to every member of a workspace — owners, admins, members, and read-only viewers alike.
On this page
- 1. Who we are
- 2. Who this applies to
- 3. What we collect
- 4. How AI features process your data
- 5. How we use your data
- 6. Our legal bases (EU/UK)
- 7. Who we share data with
- 8. International data transfers
- 9. Data retention
- 10. Your privacy rights (EU/UK, US, GCC)
- 11. Cookies & similar technologies
- 12. Data security
- 13. Children's privacy
- 14. Changes to this policy
- 15. Contact us
1. Who we are
Builder Kopilot ("Builder Kopilot", "we", "us") is the data controller responsible for your personal data under this policy.
Before publishing this policy: replace the placeholders below with your registered legal entity name, registered address, and privacy contact — these fields must reflect a real, verifiable entity to satisfy GDPR Art. 13, UK GDPR, and CCPA/CPRA disclosure requirements.
- Legal entity name: [Company Legal Name]
- Registered address: [Registered Address, Country]
- Privacy contact: [privacy@yourdomain.com]
- EU/UK representative (if applicable): [Name & contact, if you have no EU/UK establishment]
2. Who this applies to
This policy covers everyone who uses Builder Kopilot within a workspace — regardless of your role. Whether you are a workspace owner, admin, member, or read-only viewer, the same protections and rights described here apply to your personal data. Roles determine what you can do inside a workspace — they do not change how we handle your data as a person.
3. What we collect
We collect the following categories of data:
- Account & authentication data — name, email address, password hash or OAuth identity, and workspace/organisation membership and role.
- Workspace content you create — PRDs, personas, roadmap items, tasks, brainstorm sessions, notes, research sessions, and product specs. This is the core content you and your team author inside the product.
- Uploaded files — screenshots, screen recordings, and task attachments you upload for analysis.
- Product usage & analytics data — feature usage, activity logs, and metrics you connect or enter, used to power in-app analytics and the weekly digest.
- AI chat & assistant interactions — messages you send to the in-app chat assistant, and metadata about AI feature usage (token counts, which feature was used) for billing accuracy and abuse prevention.
- Third-party integration data — if you connect Jira, we store the connection token and the minimum data needed to push tasks and read project lists. We do not access Jira data beyond what you explicitly push or request.
- Device & log data — IP address, browser type, and basic request logs, collected automatically for security and reliability.
We do not currently collect payment or billing information through this product.
4. How AI features process your data
Builder Kopilot's core features — PRD generation, persona synthesis, roadmap scoring, brainstorming, screenshot analysis, and the chat assistant — work by sending relevant workspace content to third-party AI model providers so they can generate a response. This is a fundamental part of how the product works, and we want to be direct about it:
- Content you submit to an AI feature (for example, a PRD brief, a screenshot, or a chat message) is transmitted to our AI infrastructure provider and, in turn, to the underlying model provider (for example, OpenAI, Google, or Anthropic models accessed via OpenRouter) solely to generate the requested output.
- We do not permit our model providers to use your workspace content to train their general-purpose models, where that provider offers a no-training / zero-retention option — and we select providers accordingly.
- Generated outputs (PRD text, persona profiles, scores, chat replies) are stored in your workspace like any other content, governed by the same access controls as the rest of the product.
- Screen recordings and screenshots you submit for AI analysis are processed as extracted image frames only — raw video is discarded after frames are extracted and is never transmitted to a model provider.
5. How we use your data
- To provide, operate, and maintain the product and the workspace you belong to.
- To generate AI-assisted content you request (PRDs, personas, roadmap scores, chat responses, analysis).
- To power in-product analytics, dashboards, and the weekly digest.
- To send transactional and, where you've opted in, digest emails.
- To maintain security, detect abuse, and enforce our terms.
- To respond to support requests and feedback you submit.
- To comply with legal obligations.
6. Our legal bases for processing (EU / UK users)
If you are located in the European Economic Area or the United Kingdom, we rely on the following legal bases under the GDPR and UK GDPR:
- Performance of a contract — processing needed to provide the product you or your organisation signed up for.
- Legitimate interests — for security, fraud prevention, product analytics, and improving the service, balanced against your rights.
- Consent — for optional communications (for example, marketing emails), which you may withdraw at any time.
- Legal obligation — where we must retain or disclose data to comply with the law.
7. Who we share data with
We do not sell your personal data. We share data only with service providers who process it on our behalf, under contractual confidentiality and data-protection commitments:
- Cloudflare — hosting, database (D1), file storage (R2), and Workers AI, which power the application infrastructure and screenshot storage.
- AI model providers (via OpenRouter and direct integrations) — process content you submit to AI features solely to generate the response you requested, as described in Section 4.
- Jira (Atlassian) — only if you explicitly connect your Jira account, to push tasks and read project data at your direction.
- Email delivery provider — to send transactional and digest emails.
We may also disclose data if required by law, to protect our rights, or in connection with a merger, acquisition, or sale of assets — in which case we will notify affected users where required.
8. International data transfers
Our infrastructure and service providers operate globally, including in the United States. Where we transfer personal data of EU, EEA, or UK users outside those regions, we rely on recognised safeguards — such as the EU Standard Contractual Clauses and the UK International Data Transfer Addendum — with our service providers.
If you are located in the Gulf Cooperation Council region (United Arab Emirates, Saudi Arabia, Qatar, Bahrain, Kuwait, or Oman), several of these jurisdictions' data protection laws restrict transferring personal data outside the country unless the destination provides an adequate level of protection, or appropriate contractual safeguards and, where required, regulatory notice or consent are in place. We apply the same contractual safeguards described above to transfers of GCC-region personal data, and we rely on your consent to this policy, given at sign-up, as the basis for cross-border processing where a specific adequacy mechanism is not yet formally recognised by the relevant authority.
9. Data retention
We retain your workspace content for as long as your account or workspace remains active. If you delete a workspace, its content, uploaded files, and associated AI-generated outputs are deleted from active systems; residual copies may persist briefly in backups before being purged on our standard backup rotation schedule. If you delete your account, we delete or anonymise your personal account data within a reasonable period, except where we must retain it to comply with a legal obligation or resolve disputes.
10. Your privacy rights (EU/UK, US, GCC)
If you are in the EU, EEA, or UK (GDPR / UK GDPR)
You have the right to:
- Access the personal data we hold about you.
- Correct inaccurate or incomplete data.
- Request erasure of your personal data ("right to be forgotten").
- Restrict or object to certain processing, including processing based on legitimate interests.
- Receive your data in a portable format.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your local supervisory authority — in the UK, the Information Commissioner's Office (ico.org.uk); in the EU, your national Data Protection Authority.
If you are a California resident (CCPA / CPRA) or in another US state with a comprehensive privacy law
You have the right to:
- Know what personal information we collect, use, and disclose about you.
- Request deletion of your personal information, subject to certain exceptions.
- Correct inaccurate personal information.
- Opt out of the sale or sharing of personal information — we do not sell personal information, and we do not share it for cross-context behavioural advertising.
- Non-discrimination for exercising any of these rights.
Residents of Virginia, Colorado, Connecticut, Utah, and other states with comprehensive privacy laws have substantially similar rights, which we honour on the same basis described above.
If you are in the Gulf Cooperation Council region (UAE, Saudi Arabia, Qatar, Bahrain, Kuwait, or Oman)
Your data is protected under the applicable national personal data protection law — including the UAE Federal Decree-Law No. 45 of 2021 (and the DIFC and ADGM data protection regimes in their respective free zones), the Saudi Personal Data Protection Law (PDPL, enforced by SDAIA), the Qatar Law No. 13 of 2016, the Bahrain Personal Data Protection Law, the Kuwait Data Privacy Protection Regulation, and the Oman Personal Data Protection Law. Across these frameworks, you generally have the right to:
- Be informed about how your personal data is collected and used (this policy).
- Access the personal data we hold about you.
- Request correction of inaccurate data.
- Request destruction or erasure of your personal data, subject to legal exceptions.
- Object to or restrict certain processing.
- Withdraw consent at any time, where processing is based on consent.
- Lodge a complaint with your national regulator — for example, the UAE Data Office, the Saudi Data & Artificial Intelligence Authority (SDAIA), Qatar's Compliance and Data Protection Department, the Bahrain Personal Data Protection Authority (PDPA), Kuwait's Communication and Information Technology Regulatory Authority (CITRA), or Oman's Ministry of Transport, Communications and Information Technology.
To exercise any of these rights, contact us using the details in Section 15. We will verify your request and respond within the timeframe required by applicable law.
11. Cookies & similar technologies
We use essential cookies to keep you signed in and remember your active workspace. We do not use third-party advertising cookies. Where we introduce optional analytics cookies in the future, we will request consent where required by law and update this section accordingly.
12. Data security
We use industry-standard technical and organisational measures — encryption in transit, access controls scoped to your workspace, and role-based permissions — to protect your data. No method of transmission or storage is 100% secure, and we cannot guarantee absolute security.
13. Children's privacy
Builder Kopilot is intended for business use by adults and is not directed at children. We do not knowingly collect personal data from anyone under 16. If you believe a child has provided us with personal data, contact us and we will delete it.
14. Changes to this policy
We may update this policy from time to time. We will update the effective date above when we do, and for material changes, we will provide additional notice (such as an in-app banner or email) before the change takes effect.
15. Contact us
Questions about this policy or your data? Contact us at [privacy@yourdomain.com], or email hello@builderkopilot.com.