Privacy Policy
Effective Date & Last Revised: August 16, 2026//Version 2.1
The Short Version
Blueprint Nexus Inc. ("Blueprint Nexus", "we", "us", or "our") operates the Blueprint Nexus web application, iOS application, and API.
We do not sell or share your personal information for cross-context behavioral advertising. Your workspace content stays yours. We process data to run your workspace, execute the agents you start, bill you, and keep the platform secure — and we contract with our AI providers so that your content is not used to train their models.
This summary is for orientation only; the sections below govern.
01.Scope & Who We Are
Blueprint Nexus Inc. is the data controller for personal information processed through Blueprint Nexus. This policy applies to our website, the Blueprint Nexus web application, our iOS application, and our public API and MCP endpoints (together, the Service).
Where you use Blueprint Nexus through an organization or workspace administered by someone else, that organization is the controller of the workspace content and we process it as their processor under our customer agreement. Their internal policies govern their access to that content; direct requests about it to them.
02.Information We Collect
We collect information you provide, information generated as you use the Service, and information from services you choose to connect.
- Account & profile data: name, username, email address, avatar, and authentication records. If you register with a password we store a salted hash, not the password. If you sign in with Google or GitHub we receive your basic profile and email from that provider.
- Workspace content: blueprints, architecture nodes and edges, documents, notes, literature indices, standup logs, chat messages, tasks, and any files you upload into your Blueprint Knowledge Network (BKN).
- AI prompt context: the prompts you submit, the workspace content selected as context for a request, agent instructions and run history, tool calls, and model outputs.
- Sandbox execution data: code, files, commands, and logs produced when you or your agents run workloads in an isolated sandbox VM.
- Connected integration data: where you authorize a connection, the data that connection is scoped to — for example calendar events, repository and commit metadata, issue-tracker records, or data from third-party apps you connect. We request the narrowest scopes the feature needs, and you can revoke access at any time.
- Payment data: billing name, email, billing address, plan selection, and transaction history. Card numbers are collected and stored by Stripe or Apple, not by us; we receive only transaction results and the last four digits.
- Your own provider API keys (BYOK): if you supply keys for your own AI provider accounts, we store them encrypted and use them only to make the requests you initiate.
- Technical & usage data: IP address, browser and OS version, device and app identifiers, timestamps, referring pages, feature usage, token and credit consumption, error traces, and security logs.
- Support communications: messages you send us and the contents of bug reports you choose to share.
We do not intentionally collect special-category data (health, biometrics, precise geolocation, government identifiers). Please do not place such data in workspace content or prompts.
03.How We Use Your Information & Legal Bases
For users in the EEA, UK, and Switzerland, the legal basis for each purpose is noted in brackets.
- Provide, provision, and sync your workspace, documents, and collaborative editing sessions. [Contract]
- Execute the AI features and agent runs you initiate, including retrieval, research, and sandboxed code execution. [Contract]
- Process payments, manage subscriptions and renewals, and issue receipts. [Contract; Legal obligation for tax and accounting records]
- Authenticate users, enforce workspace access controls, detect abuse and fraud, and maintain platform integrity. [Legitimate interests; Legal obligation]
- Monitor reliability, diagnose faults, and improve performance and product quality using aggregated or de-identified usage data. [Legitimate interests]
- Send service, security, and transactional messages. [Contract; Legitimate interests]
- Send product and marketing emails where you have opted in, with an unsubscribe link in every message. [Consent]
- Comply with law and respond to lawful requests. [Legal obligation]
Where we rely on legitimate interests, we have assessed that our interest in operating a secure, functioning platform is not overridden by your rights. You may object — see section 11.
04.AI Processing & Model Providers
Blueprint Nexus routes AI requests to third-party model providers to generate blueprints, run agents, and perform research. When you invoke an AI feature, the prompt and the workspace context attached to it are transmitted to the applicable provider over encrypted channels.
No training on your content
Our agreements with our AI model providers prohibit the use of your prompts, workspace content, and outputs to train their models. We do not use your workspace content to train our own models. Providers may retain request data for a limited period for abuse monitoring under their own terms; we contract for zero- or limited-retention handling where the provider offers it.
Research and retrieval features work the same way: when you or an agent runs a search or fetches a page, the query and the target URL are sent to our search and crawling providers, and the request reaches the public sources being read — for example web pages, academic indices, and public code repositories.
We route each request to whichever supported provider is configured for the model you select, so a given prompt may be handled by any of the AI providers listed in section 5.
If you supply your own provider API keys, requests made with those keys are governed by your agreement with that provider, and their retention and training terms apply instead of ours.
AI output is probabilistic and may be inaccurate. We do not use AI to make decisions that produce legal or similarly significant effects about you without human involvement.
05.Sub-processors & Data Sharing
We do not sell, rent, or trade your personal information. We share it only with the service providers below, each bound by contract to process it solely on our instructions:
We may also disclose information to comply with law or valid legal process, to enforce our Terms, to protect the rights and safety of users or the public, or in connection with a merger, acquisition, or asset sale — in which case we will notify you before your information becomes subject to a different privacy policy.
06.Connected Accounts & Integrations
Integrations are optional and off by default. When you connect a third-party account, you authorize us to access the data covered by the scopes shown at the time of connection, and we store an access token so agents and sync features can act on your behalf.
- You can disconnect any integration from your workspace settings at any time.
- Disconnecting stops future access and deletes the stored token; data already synced into your workspace remains until you delete it.
- Data you send toa third-party service through an integration is governed by that service's own privacy policy.
08.Data Retention
- Account and workspace content: retained while your account is active.
- After deletion: you can delete your account from Settings → Danger Zone. Your personal data and workspace content are removed from production systems immediately, and your login is destroyed in the same operation. Encrypted backups are purged on their normal rotation, which may take up to a further 90 days.
- Sandbox VMs: destroyed when the session ends or the environment is reclaimed; execution logs are kept for up to 30 days for debugging and abuse detection.
- Security and audit logs: up to 12 months.
- Billing and tax records: retained as long as required by law, typically 7 years.
We may retain information longer where necessary to resolve disputes, enforce agreements, or comply with a legal hold. Content you shared into a workspace you do not own may remain visible to that workspace after you leave it.
09.Security
We maintain administrative, technical, and physical safeguards, including:
- Encryption of data in transit (TLS) and at rest (AES-256) across our infrastructure.
- Row-Level Security policies that isolate workspace data between accounts and organizations.
- Least-privilege access controls and audit logging for internal administrative access.
- Isolated, ephemeral sandbox environments for agent code execution.
No method of transmission or storage is completely secure, and we cannot guarantee absolute security. If we become aware of a breach affecting your personal information, we will notify you and any applicable regulator as required by law. Report a suspected vulnerability to security@blueprintsociety.com.
10.International Data Transfers
We operate in the United States, and our sub-processors may process data in the United States and other countries. Where we transfer personal data out of the EEA, UK, or Switzerland, we rely on the European Commission's Standard Contractual Clauses (and the UK Addendum where applicable), together with supplementary technical measures such as encryption in transit and at rest. You may request a copy of the relevant transfer mechanism at privacy@blueprintsociety.com.
Some AI inference and retrieval providers listed in section 5 operate outside the United States and the EEA, including in countries that are not the subject of an adequacy decision. Where a request is routed to such a provider, the prompt and attached workspace context are transferred to that country under the safeguards described above.
11.Your Rights (EEA, UK & Switzerland)
Subject to the conditions in applicable law, you have the right to:
- Access the personal data we hold about you and receive a copy.
- Rectify inaccurate or incomplete data from your account settings or by request.
- Erase your data ("right to be forgotten").
- Restrict processing in certain circumstances.
- Object to processing based on legitimate interests, and to direct marketing at any time.
- Receive your data in a portable, machine-readable format — export your full account as JSON from Settings → Data & Export.
- Withdraw consent at any time, without affecting processing already carried out.
- Lodge a complaint with your local supervisory authority (or the UK Information Commissioner's Office).
Email privacy@blueprintsociety.com to exercise a right. We verify requests against your account and respond within 30 days, extendable by a further 60 days for complex requests with notice to you.
12.U.S. State Privacy Rights (CCPA/CPRA & Others)
In the past 12 months we collected the following categories of personal information, from you and from the identity providers and integrations you connect, for the business purposes described in section 3: identifiers (name, email, account and device IDs); commercial information (subscription and transaction records); internet or network activity (usage and log data); professional information (employer or role, if you provide it); and the contents of your workspace and communications.
We do not sell or share your personal information
We have not sold personal information, and have not shared it for cross-context behavioral advertising, in the preceding 12 months — including personal information of consumers under 16. We do not use or disclose sensitive personal information for purposes that require an opt-out under the CPRA.
If you are a resident of California, Colorado, Connecticut, Virginia, Texas, or another state with comparable law, you may request to know, access, correct, delete, or obtain a portable copy of your personal information, and may appeal a denied request by replying to our decision. We will not discriminate against you for exercising these rights. An authorized agent may submit a request on your behalf with proof of authorization.
Submit requests to privacy@blueprintsociety.com. We respond within 45 days, extendable once by 45 days with notice.
13.Children's Privacy
The Service is not directed to children. We do not knowingly collect personal information from anyone under 16 (or under 13 in the United States). If you believe a child has provided us personal information, contact privacy@blueprintsociety.com and we will delete it.
14.Changes to This Policy
We may update this policy as the Service evolves. We will revise the "Last Revised" date above and, for material changes, notify registered users by email or in-app notice at least 14 days before the change takes effect. Continued use after the effective date constitutes acceptance.
15.Contact Us
For questions about this policy, to exercise your rights, or to reach our privacy team:
Blueprint Nexus Inc. — Privacy Team
Privacy: privacy@blueprintsociety.com
Security: security@blueprintsociety.com
General: hello@nexus.dev
2710 Carnegie Dr, Boulder, CO 80305, United States