Privacy Policy
Last Updated – 14 July 2026
This Privacy Policy explains how BuildingPP OÜ (“Bilt”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use our websites at https://bilt.me and https://app.bilt.me (the “Site”) and the services we provide through them (the “Services”). It should be read together with our Terms of Service and Acceptable Use Policy. Capitalised terms not defined here have the meaning given in the Terms of Service.
1. Who we are (data controller)
BuildingPP OÜ is the controller of the personal data described in this Policy. Our details are:
-
Company: BuildingPP OÜ (registry code 17224732)
-
Address: Laulupeo tn 3-2, Tallinn, 10121, Estonia
-
General contact: [email protected]
-
Privacy contact: [email protected]
We have not appointed a Data Protection Officer, as we are not required to do so. For any question about this Policy or your personal data, contact us at [email protected].
2. Who and what this Policy covers
This Policy applies to personal data we process about:
-
users and account holders of the Services (“users” or “customers”);
-
visitors to our Site;
-
newsletter subscribers, prospects and other people we communicate with about the Services.
Personal data of our job applicants and staff is handled under a separate privacy notice and is not covered here.
3. What personal data we collect, why, and our legal basis
The table below summarises how we use personal data in connection with the Services and the legal basis under the EU General Data Protection Regulation (“GDPR”) for each use.
| Purpose | Personal data | Legal basis (GDPR) |
|---|---|---|
| Creating and operating your account; authenticating you; delivering the core product features | Name, email, hashed password or single sign-on identifier, phone/address where provided, profile data, in-app actions, device/app identifiers | Art. 6(1)(b) – performance of our contract with you |
| Service (transactional) emails: receipts, password resets, security alerts, product notices needed to use the Services | Name, email, account/order identifiers, message content | Art. 6(1)(b) – contract |
| Taking payment; managing subscriptions, refunds and chargebacks | Name, billing address, email, order/subscription details, payment status. Full card/bank details are collected directly by our payment providers – we do not see or store them | Art. 6(1)(b) – contract; Art. 6(1)(c) – accounting and tax obligations |
| Marketing, newsletters, online advertising and lead generation | Name, email, country, marketing preferences, campaign engagement, source/referrer, IP and device data via cookies, consent records; hashed email for custom audiences; public profile data for outreach | Art. 6(1)(a) – consent (newsletter sign-up, marketing cookies, advertising); Art. 6(1)(f) – legitimate interest (soft opt-in to existing customers and limited B2B outreach) |
| Product analytics and usage measurement to improve and debug the Services | Pseudonymous user/device identifiers, in-app events, screen/feature usage, country/region, IP, app version, device and OS type | Art. 6(1)(f) – legitimate interest in operating and improving the Services; Art. 6(1)(a) – consent where non-essential cookies/device identifiers are used |
| Providing in-product AI features (see Section 9) | Customer Content - Your prompts and inputs (which may contain anything you type or upload), session/user identifier, model output, usage telemetry | Art. 6(1)(b) – contract; Art. 6(1)(a) – consent where an AI feature is optional/opt-in |
| Handling feedback, feature requests, user research and beta programmes | Name, email, role, feedback content, votes, and – only with your consent – recorded research conversations | Art. 6(1)(a) – consent (research and recordings); Art. 6(1)(f) – legitimate interest in improving the Services |
| Customer support and ticketing | Name, email, account identifier, contents of the conversation, screenshots, device/app info | Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interest in handling general enquiries |
| Verifying identity for account-recovery and rights requests | Minimum verification data (account email, last login, recent activity) | Art. 6(1)(c) – legal obligation to verify rights requests; Art. 6(1)(b) – contract |
| Hosting, infrastructure, backups and disaster recovery | Production account data, technical telemetry (IP, request metadata), admin audit logs, encrypted backups | Art. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interest in operating the Services |
| Security, access logging, monitoring and incident/breach response | User/admin identifier, IP, action, timestamp; logs of AI calls; incident and affected-account details | Art. 6(1)(c) – security and breach-notification obligations (Art. 32–34); Art. 6(1)(f) – legitimate interest in security |
| Legal, compliance, contracts, disputes and handling your data-protection rights | Contract and correspondence data; identification data only where strictly needed | Art. 6(1)(b) – contract; Art. 6(1)(c) – legal obligations; Art. 6(1)(f) – legal claims |
We do not aim to collect special categories of personal data (such as health data). Please do not include such data, or other people’s personal data you are not entitled to share, in your prompts or other content you submit. Where we rely on consent, you can withdraw it at any time (see Section 8); withdrawal does not affect processing carried out before withdrawal.
4. Cookies and similar technologies
We use cookies and similar technologies when you use the Site and Services. Non-essential cookies (analytics and marketing) are set only after you consent through our cookie banner, which blocks analytics and advertising trackers until you accept them. You can change your choices at any time via the user settings or your browser settings.
| Category | Purpose | Examples / providers | Legal basis |
|---|---|---|---|
| Strictly necessary | Sign-in, session, security, load balancing and remembering your cookie choices | Authentication (Supabase Auth, Clerk); Cloudflare security | Art. 6(1)(f) – essential, no consent required |
| Analytics / performance | Understand how the Site and Services are used so we can improve them | Google Analytics; PostHog (EU); Cloudflare Web Analytics | Art. 6(1)(a) – consent |
| Marketing / advertising | Measure campaigns and show relevant ads across platforms | Meta Pixel; Google Ads; X; Dub.co | Art. 6(1)(a) – consent |
5. Marketing communications
If you subscribe or otherwise consent, we send newsletters and product marketing by email. Where permitted, we may also send information about similar products to existing customers on a soft opt-in basis. Every marketing email contains an unsubscribe link, and you can opt out at any time by using it or by emailing [email protected]. Opting out of marketing does not stop essential service (transactional) messages about your account.
6. Who we share personal data with
We share personal data with service providers who process it on our behalf (our processors / sub-processors) and, where required, with authorities and professional advisers. We do not sell your personal data. The main recipients are:
| Recipient | Role / service | Location & transfer safeguard |
|---|---|---|
| Hetzner Online GmbH | Primary hosting (servers, storage) | Germany / Finland (EU) |
| Cloudflare, Inc. | CDN, WAF, edge and web analytics | EU regions; US parent – SCCs + EU–U.S. DPF |
| Supabase Inc. | Authentication and database | EU region; US parent – SCCs Module 2 |
| Neon Inc. | Serverless Postgres database | EU region; US parent – SCCs + DPF |
| Clerk Inc. | Authentication | United States – SCCs + DPF |
| Brevo (Sendinblue SAS) | Newsletter, CRM and transactional email | France (EU) |
| Proton AG | Support mailbox (support@ / info@) | Switzerland (EU adequacy) |
| Stripe Payments Europe, Ltd. | Card, SEPA and subscription payments | Ireland (EU); onward to Stripe, Inc. (US) – SCCs + DPF |
| PayPal (Europe) S.à r.l. et Cie, S.C.A. | Alternative payment method | Luxembourg (EU); onward US processing – SCCs + DPF |
| Google (Ireland Ltd / LLC) | Analytics and advertising | EU contracting entity; onward US – SCCs + DPF |
| PostHog Inc. | Product analytics | EU cloud; US parent – SCCs + DPF |
| Anthropic Ireland Ltd | AI model provider (see Section 9) | Ireland (EU); onward to Anthropic, PBC (US) – SCCs |
| OpenAI Ireland Ltd | AI model provider | Ireland (EU); any onward transfer to the US is made by the provider under its own safeguards |
| Luma Labs, Inc | Event hosting and registration | United States – SCCs |
| Amazon Web Services (AWS EMEA SARL) | AI model hosting (Bedrock) | Sweden (EU); onward US – SCCs + DPF |
| Meta Platforms Ireland Ltd | Advertising / custom audiences | Ireland (EU); onward US |
| X Corp. | Advertising | United States – SCCs |
| HeyReach; RankUp | Lead generation / SEO | Estonia (EU) |
| Dub Technologies, Inc. | Link tracking | United States – SCCs |
| CORDNET OÜ (Featurebase) | Feedback, ticketing and feature board | Estonia (EU) |
| Cal.com GmbH | Scheduling / research calls | Germany (EU) |
| Authorities & advisers | Tax and Customs Board, data protection authority, courts, banks, accountant, legal counsel | EU / EEA, as required by law |
We keep our sub-processor list up to date and will provide the current version on request at [email protected]. Where a Bilt-managed component processes personal data on your behalf under a Data Processing Agreement, it acts as our sub-processor under that agreement (see the Terms of Service).
7. Where your data is stored and international transfers
Your personal data is stored in the European Union. Some of our providers are based in, or have parent companies or support operations in, countries outside the EEA — mainly the United States, and for one provider Switzerland. Where personal data is transferred outside the EEA — whether by us, or by a provider acting on our behalf as part of its own operations — it is protected by an appropriate safeguard recognised under the GDPR: an EU adequacy decision (for example, Switzerland), the EU Standard Contractual Clauses, or certification under the EU–U.S. Data Privacy Framework, as indicated in the table above. You can request a copy of the relevant safeguards at [email protected].
8. Your rights
Subject to the conditions in the GDPR, you have the right to:
-
access the personal data we hold about you and receive a copy;
-
have inaccurate or incomplete data corrected;
-
have your data erased (“right to be forgotten”);
-
restrict or object to certain processing, including direct marketing;
-
receive your data in a portable format and have it transferred where technically feasible;
-
withdraw consent at any time where we rely on consent.
To exercise any of these rights, contact [email protected]. We may need to verify your identity first. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, [email protected], www.aki.ee. You may also complain to the authority in your country of residence.
9. AI features and your inputs
When you use our AI features, the prompts and content you submit (Customer Content) are sent to third-party AI model providers — currently Anthropic, OpenAI and Amazon Web Services (Bedrock) — to generate the output you request. These providers are engaged as our sub-processors under contract, and none of them uses your prompts or the resulting outputs to train their models.
AI calls are logged for quality, troubleshooting and abuse detection. We also use aggregated, non-identifying metrics about AI usage (such as error rates, latency and feature usage) to improve the Services. We do not use the content of your prompts to train our own models; if that ever changes, we will update this Policy and the Terms of Service before it does.
Because output is generated from what you submit, please do not enter sensitive personal data, other people’s personal data you are not entitled to share, or confidential information into prompts. We do not seek or knowingly use such information, and we apply measures intended to avoid reproducing it, but we cannot guarantee that information you include in an input will not appear in the output. This section should be read together with the Terms of Service and Acceptable Use Policy.
10. Automated decision-making
We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing within the meaning of Article 22 GDPR. Our AI features generate content at your request but do not make such decisions about you.
11. How long we keep your data
We keep personal data only for as long as necessary for the purposes described in this Policy, or longer where the law requires (for example, accounting and tax records). Indicative retention periods:
| Data category | Retention period |
|---|---|
| Account data | For the life of your account, then deleted or anonymised 30 days after closure |
| Billing, order and invoice records | 7 years from the end of the financial year of the record (Estonian accounting and tax law) |
| Transactional email logs | Up to 2 years |
| Support communications and tickets | 1 year after the ticket is closed |
| Marketing consent records | For as long as the consent is in force, plus 3 years |
| Product analytics / event data | 13 months |
| AI inputs and outputs (stored by us) | For the life of the associated project or account, then deleted 30 days after it is removed |
| Cookie data | Consent is re-requested at least every 13 months; analytics data is kept for 13 months (see Section 4) |
| Security and audit logs | 30 days |
| Backups | Up to 14 days, Deleted data is removed from backups as they rotate, within one full backup cycle |
| Security-incident records | 3 years after the incident is closed |
12. How we protect your data
We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, multi-factor authentication for staff access, role-based and least-privilege access controls, audit logging, environment separation, regular access reviews, encrypted backups with restore testing, and a documented incident-response process with 72-hour breach notification to the supervisory authority where required.
13. Children
The Services are not directed to children. You must be at least 18, or have the consent of your legal guardian, to use the Services, as set out in the Terms of Service. We do not knowingly collect personal data from children.
14. Information for United States residents
If you are a resident of a U.S. state with a comprehensive privacy law (such as California under the CCPA/CPRA), the following applies in addition to the rest of this Policy. We collect the categories of personal information described in Section 3 (identifiers, account and commercial information, internet/usage activity, and inputs you provide). We use it for the business purposes described above.
We do not “sell” personal information for money. We may “share” personal information for cross-context behavioural advertising through advertising cookies (e.g. Meta, Google, X); you can opt out at any time through our user cookie settings. Subject to your state’s law, you may have the right to know, access, correct and delete your personal information, to opt out of sale/sharing and certain profiling, and to be free from discrimination for exercising these rights. To exercise them, contact [email protected]. You may use an authorised agent; where you do, we may require written proof of the agent's authority and may verify your identity with you directly before acting on the request.
15. Changes to this Policy
We may update this Policy from time to time. We will post the updated version on the Site and update the “Last updated” date above, and where changes are material we will notify you by email or in-app. If we ever intend to change how we use your data for training our own systems, we will update this Policy and the Terms of Service before doing so.
16. How to contact us
-
Company: BuildingPP OÜ (registry code 17224732)
-
Address: Laulupeo tn 3-2, Tallinn, 10121, Estonia
-
Privacy enquiries and rights requests: [email protected]
-
General support: [email protected]