Legal

Privacy Policy

Last updated July 14, 2026
Gridline works on the confidential heart of an architecture practice: its models, its drawings, and its judgment. This Policy explains what we collect, how we use it, and the line we will not cross: your project data is never used to train AI models.
In plain terms
  • Your data is not training data.We never use your project content or prompts to train AI models, ours or anyone else’s.
  • You stay the owner. For the content you put into Gridline, your firm is in control and we act only as your processor.
  • We do not sell your information, and we keep cookies to the essentials.
  • Security by design: encryption in transit and at rest, single sign-on, and least-privilege access.

Scope and who we are

This Privacy Policy explains how Gridline, Inc.(“Gridline”, “we”, “us”), a Delaware corporation, handles information in connection with our website at gridlineos.com (the “Site”) and the Gridline software, plugins, and services we provide to architecture, engineering, and construction firms (together, the “Service”).

It applies to visitors to the Site, people who book a demo or request access, and the authorized users of firms that use the Service. It does not apply to third-party products or websites that we link to but do not control.

Our two roles: controller and processor

The way we treat information depends on which kind of information it is, and we are deliberate about the distinction:

  • As a controller. For information about the Site, marketing, account administration, and access requests, we decide why and how the information is processed. This Policy is our notice for that activity.
  • As a processor.For the models, drawings, documents, prompts, and other content a firm puts into the Service (“Customer Data”), the firm is the controller and we process that content only on the firm’s behalf and on its instructions, under our Terms of Service and Data Processing Addendum. If you are an individual user at a firm, please direct questions about Customer Data to your firm in the first instance.

Information we collect

Information you provide

  • Access requests. When you book a demo or request access, we collect your name, work email, firm name, role, and any optional project or workflow context you choose to share for the demo.
  • Account and authentication. When your firm is onboarded, we create accounts for authorized users. Authentication is handled by our identity provider; we receive your name, email, and the authentication and session signals needed to keep your account secure.
  • Customer Data. The content you and your firm submit to the Service so that Gridline can do its work, including building-model data, drawing sets, project documents, and the questions or prompts you ask. We process Customer Data as a processor (see above).
  • Support and communications. Messages you send us, and the contents of those exchanges.

Information we collect automatically

  • Usage and device data. Standard log information such as IP address, browser and device type, pages and features used, and timestamps, which we use to operate, secure, and improve the Service.
  • Cookies. We use a small number of cookies, described in the Cookies section below.

Slack and Microsoft Teams integrations

When a firm connects Slack or Microsoft Teams, Gridline receives the workspace or tenant identifiers, the requesting user's provider identifiers, and the messages or commands that users intentionally direct to Gridline. We also receive the conversation, thread, activity, and delivery metadata needed to reply, preserve context, prevent replay, and maintain the firm's audit trail. During account linking, a provider-supplied name or work email may be used to suggest the likely Gridline account, but it never grants access.

Gridline uses this information only to authenticate the external request, connect the correct firm and user, answer the directed request, perform an authorized action, secure the integration, and provide support. Gridline does not crawl unrelated Slack channels, direct messages, or Teams conversations, and it does not use chat-platform data to train AI models or for advertising.

Workspace credentials are encrypted. A firm owner can disconnect the integration, and an individual can unlink their provider identity without disconnecting the firm. On disconnect, uninstall, or token revocation, Gridline disables the connection and removes retained provider credentials. Directed message content and audit records follow the Customer Data retention terms described below. Users can request access, export, or deletion through their firm or by contacting privacy@gridlineos.com.

Slack and Microsoft process information under their own agreements and privacy notices when users interact with their platforms.

How we use information

We use information to:

  • provide, maintain, secure, and improve the Service and the Site;
  • authenticate users, administer accounts, and prevent fraud and abuse;
  • review and respond to access requests and support inquiries;
  • generate the answers, citations, and analysis you ask the Service to produce;
  • understand how the Service is used in aggregate so we can make it more useful and reliable;
  • comply with law, enforce our agreements, and protect the rights, safety, and property of Gridline, our customers, and others.

We process Customer Data only to provide the Service to your firm and on your firm’s documented instructions, not for our own independent purposes.

AI models, inference, and training

We do not use your Customer Data, prompts, or the answers generated for you to train, fine-tune, or improve foundation models, whether ours or a third party’s. Your firm’s work is not a training set.

To answer a question, the Service may send the relevant context to a third-party model provider to run inference and return a result to you. We work to ensure those providers are engaged on enterprise terms that prohibit training on your content and that apply zero or short data retention where the provider offers it. Inference is performed to serve your request, and for no other purpose.

We may use aggregated and de-identified operational metrics (for example, latency, error rates, and which features are used) to improve the Service. Such metrics do not identify you or your firm and do not contain Customer Data.

How we share information

We do not sell personal information. We share information only as follows:

  • Subprocessors and service providers. Vendors that host, store, secure, and operate the Service on our behalf, under contracts that limit them to providing those services (see Subprocessors below).
  • Within your firm. Customer Data and account activity are accessible to the authorized users and administrators of your firm, as your firm configures.
  • Legal and safety. Where we reasonably believe disclosure is required by law or legal process, or is necessary to protect rights, safety, or the integrity of the Service.
  • Business transfers. In connection with a merger, acquisition, financing, or sale of assets, subject to the protections of this Policy.

Subprocessors

We rely on a small set of established infrastructure providers to deliver the Service. Current categories include:

  • Cloud hosting and application delivery, for running the Site and Service.
  • Managed database, for storing application and project data.
  • Identity and authentication, for secure sign-in and single sign-on.
  • AI model inference, for generating answers and analysis, under terms that prohibit training on your content as described above.

We maintain a current list of subprocessors and will make it available to customers on request. Where required by the Data Processing Addendum, we will give notice of material changes to our subprocessors so a customer can object.

International data transfers

We are based in the United States and may process information there and in other countries where we or our subprocessors operate. Where we transfer personal data across borders, we rely on appropriate safeguards, such as the European Commission’s Standard Contractual Clauses (and the UK Addendum where applicable), to protect the information consistent with this Policy and applicable law.

Data retention

We keep personal information for as long as needed to provide the Service and for the legitimate and lawful purposes described in this Policy, then delete or de-identify it.

Customer Data is retained for the duration of your firm’s use of the Service. On termination, we make Customer Data available for export for a limited window and then delete it from active systems, with residual copies removed from backups in the ordinary course, as described in our Terms and Data Processing Addendum.

Security

We take security seriously and design the Service to keep your firm’s work confidential. Our measures include:

  • encryption of data in transit and at rest;
  • authentication and single sign-on through a dedicated identity provider, with least-privilege access controls;
  • network, application, and infrastructure controls with our cloud providers;
  • internal access to Customer Data limited to what is needed to operate and support the Service.

We are building toward formal third-party certification of our security program. No system is perfectly secure, but we work continuously to protect your information and will notify affected parties of a personal-data breach as required by law.

Your privacy rights

Depending on where you live, you may have rights to access, correct, delete, port, or restrict the processing of your personal information, and to object to certain processing. Where we rely on consent, you may withdraw it at any time. We do not discriminate against you for exercising these rights.

To exercise a right with respect to information we hold as a controller, contact us at privacy@gridlineos.com. Where your request concerns Customer Data we process on behalf of a firm, we will refer the request to that firm and support them in responding. We may need to verify your identity before acting.

Cookies

We keep cookies to a minimum and do not use third-party advertising cookies. We use:

  • Essential cookies, such as a signed session cookie that keeps you logged in securely. The Service does not work without these.
  • Preference cookies, such as the one that remembers your light or dark theme.

You can block or delete cookies in your browser, but essential cookies are required to use the Service.

Children

The Service is a professional tool intended for businesses and is not directed to children. We do not knowingly collect personal information from anyone under 16. If you believe a child has provided us information, contact us and we will delete it.

Changes to this Policy

We may update this Policy as the Service evolves or as law requires. When we make material changes, we will update the date above and, where appropriate, give additional notice. Your continued use of the Service after an update means you accept the revised Policy.

Contact us

Questions about this Policy or our privacy practices? Reach our privacy team at privacy@gridlineos.com, or write to Gridline, Inc., Attn: Privacy, Delaware, USA. For security matters, contact security@gridlineos.com.

If you are in the EEA or UK and have a concern we have not resolved, you have the right to lodge a complaint with your local data protection authority.