Skip to main content

Privacy Policy

Last Updated – 14 July 2026

This Privacy Policy explains how BuildingPP OÜ (“Bilt”, “we”, “us” or “our”) collects, uses, shares and protects personal data when you use our websites at https://bilt.me and https://app.bilt.me (the “Site”) and the services we provide through them (the “Services”). It should be read together with our Terms of Service and Acceptable Use Policy. Capitalised terms not defined here have the meaning given in the Terms of Service.

1. Who we are (data controller)

BuildingPP OÜ is the controller of the personal data described in this Policy. Our details are:

We have not appointed a Data Protection Officer, as we are not required to do so. For any question about this Policy or your personal data, contact us at [email protected].

2. Who and what this Policy covers

This Policy applies to personal data we process about:

  • users and account holders of the Services (“users” or “customers”);

  • visitors to our Site;

  • newsletter subscribers, prospects and other people we communicate with about the Services.

Personal data of our job applicants and staff is handled under a separate privacy notice and is not covered here.

3. What personal data we collect, why, and our legal basis

The table below summarises how we use personal data in connection with the Services and the legal basis under the EU General Data Protection Regulation (“GDPR”) for each use.

PurposePersonal dataLegal basis (GDPR)
Creating and operating your account; authenticating you; delivering the core product featuresName, email, hashed password or single sign-on identifier, phone/address where provided, profile data, in-app actions, device/app identifiersArt. 6(1)(b) – performance of our contract with you
Service (transactional) emails: receipts, password resets, security alerts, product notices needed to use the ServicesName, email, account/order identifiers, message contentArt. 6(1)(b) – contract
Taking payment; managing subscriptions, refunds and chargebacksName, billing address, email, order/subscription details, payment status. Full card/bank details are collected directly by our payment providers – we do not see or store themArt. 6(1)(b) – contract; Art. 6(1)(c) – accounting and tax obligations
Marketing, newsletters, online advertising and lead generationName, email, country, marketing preferences, campaign engagement, source/referrer, IP and device data via cookies, consent records; hashed email for custom audiences; public profile data for outreachArt. 6(1)(a) – consent (newsletter sign-up, marketing cookies, advertising); Art. 6(1)(f) – legitimate interest (soft opt-in to existing customers and limited B2B outreach)
Product analytics and usage measurement to improve and debug the ServicesPseudonymous user/device identifiers, in-app events, screen/feature usage, country/region, IP, app version, device and OS typeArt. 6(1)(f) – legitimate interest in operating and improving the Services; Art. 6(1)(a) – consent where non-essential cookies/device identifiers are used
Providing in-product AI features (see Section 9)Customer Content - Your prompts and inputs (which may contain anything you type or upload), session/user identifier, model output, usage telemetryArt. 6(1)(b) – contract; Art. 6(1)(a) – consent where an AI feature is optional/opt-in
Handling feedback, feature requests, user research and beta programmesName, email, role, feedback content, votes, and – only with your consent – recorded research conversationsArt. 6(1)(a) – consent (research and recordings); Art. 6(1)(f) – legitimate interest in improving the Services
Customer support and ticketingName, email, account identifier, contents of the conversation, screenshots, device/app infoArt. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interest in handling general enquiries
Verifying identity for account-recovery and rights requestsMinimum verification data (account email, last login, recent activity)Art. 6(1)(c) – legal obligation to verify rights requests; Art. 6(1)(b) – contract
Hosting, infrastructure, backups and disaster recoveryProduction account data, technical telemetry (IP, request metadata), admin audit logs, encrypted backupsArt. 6(1)(b) – contract; Art. 6(1)(f) – legitimate interest in operating the Services
Security, access logging, monitoring and incident/breach responseUser/admin identifier, IP, action, timestamp; logs of AI calls; incident and affected-account detailsArt. 6(1)(c) – security and breach-notification obligations (Art. 32–34); Art. 6(1)(f) – legitimate interest in security
Legal, compliance, contracts, disputes and handling your data-protection rightsContract and correspondence data; identification data only where strictly neededArt. 6(1)(b) – contract; Art. 6(1)(c) – legal obligations; Art. 6(1)(f) – legal claims

We do not aim to collect special categories of personal data (such as health data). Please do not include such data, or other people’s personal data you are not entitled to share, in your prompts or other content you submit. Where we rely on consent, you can withdraw it at any time (see Section 8); withdrawal does not affect processing carried out before withdrawal.

4. Cookies and similar technologies

We use cookies and similar technologies when you use the Site and Services. Non-essential cookies (analytics and marketing) are set only after you consent through our cookie banner, which blocks analytics and advertising trackers until you accept them. You can change your choices at any time via the user settings or your browser settings.

CategoryPurposeExamples / providersLegal basis
Strictly necessarySign-in, session, security, load balancing and remembering your cookie choicesAuthentication (Supabase Auth, Clerk); Cloudflare securityArt. 6(1)(f) – essential, no consent required
Analytics / performanceUnderstand how the Site and Services are used so we can improve themGoogle Analytics; PostHog (EU); Cloudflare Web AnalyticsArt. 6(1)(a) – consent
Marketing / advertisingMeasure campaigns and show relevant ads across platformsMeta Pixel; Google Ads; X; Dub.coArt. 6(1)(a) – consent

5. Marketing communications

If you subscribe or otherwise consent, we send newsletters and product marketing by email. Where permitted, we may also send information about similar products to existing customers on a soft opt-in basis. Every marketing email contains an unsubscribe link, and you can opt out at any time by using it or by emailing [email protected]. Opting out of marketing does not stop essential service (transactional) messages about your account.

6. Who we share personal data with

We share personal data with service providers who process it on our behalf (our processors / sub-processors) and, where required, with authorities and professional advisers. We do not sell your personal data. The main recipients are:

RecipientRole / serviceLocation & transfer safeguard
Hetzner Online GmbHPrimary hosting (servers, storage)Germany / Finland (EU)
Cloudflare, Inc.CDN, WAF, edge and web analyticsEU regions; US parent – SCCs + EU–U.S. DPF
Supabase Inc.Authentication and databaseEU region; US parent – SCCs Module 2
Neon Inc.Serverless Postgres databaseEU region; US parent – SCCs + DPF
Clerk Inc.AuthenticationUnited States – SCCs + DPF
Brevo (Sendinblue SAS)Newsletter, CRM and transactional emailFrance (EU)
Proton AGSupport mailbox (support@ / info@)Switzerland (EU adequacy)
Stripe Payments Europe, Ltd.Card, SEPA and subscription paymentsIreland (EU); onward to Stripe, Inc. (US) – SCCs + DPF
PayPal (Europe) S.à r.l. et Cie, S.C.A.Alternative payment methodLuxembourg (EU); onward US processing – SCCs + DPF
Google (Ireland Ltd / LLC)Analytics and advertisingEU contracting entity; onward US – SCCs + DPF
PostHog Inc.Product analyticsEU cloud; US parent – SCCs + DPF
Anthropic Ireland LtdAI model provider (see Section 9)Ireland (EU); onward to Anthropic, PBC (US) – SCCs
OpenAI Ireland LtdAI model providerIreland (EU); any onward transfer to the US is made by the provider under its own safeguards
Luma Labs, IncEvent hosting and registrationUnited States – SCCs
Amazon Web Services (AWS EMEA SARL)AI model hosting (Bedrock)Sweden (EU); onward US – SCCs + DPF
Meta Platforms Ireland LtdAdvertising / custom audiencesIreland (EU); onward US
X Corp.AdvertisingUnited States – SCCs
HeyReach; RankUpLead generation / SEOEstonia (EU)
Dub Technologies, Inc.Link trackingUnited States – SCCs
CORDNET OÜ (Featurebase)Feedback, ticketing and feature boardEstonia (EU)
Cal.com GmbHScheduling / research callsGermany (EU)
Authorities & advisersTax and Customs Board, data protection authority, courts, banks, accountant, legal counselEU / EEA, as required by law

We keep our sub-processor list up to date and will provide the current version on request at [email protected]. Where a Bilt-managed component processes personal data on your behalf under a Data Processing Agreement, it acts as our sub-processor under that agreement (see the Terms of Service).

7. Where your data is stored and international transfers

Your personal data is stored in the European Union. Some of our providers are based in, or have parent companies or support operations in, countries outside the EEA — mainly the United States, and for one provider Switzerland. Where personal data is transferred outside the EEA — whether by us, or by a provider acting on our behalf as part of its own operations — it is protected by an appropriate safeguard recognised under the GDPR: an EU adequacy decision (for example, Switzerland), the EU Standard Contractual Clauses, or certification under the EU–U.S. Data Privacy Framework, as indicated in the table above. You can request a copy of the relevant safeguards at [email protected].

8. Your rights

Subject to the conditions in the GDPR, you have the right to:

  • access the personal data we hold about you and receive a copy;

  • have inaccurate or incomplete data corrected;

  • have your data erased (“right to be forgotten”);

  • restrict or object to certain processing, including direct marketing;

  • receive your data in a portable format and have it transferred where technically feasible;

  • withdraw consent at any time where we rely on consent.

To exercise any of these rights, contact [email protected]. We may need to verify your identity first. You also have the right to lodge a complaint with a supervisory authority. Our lead authority is the Estonian Data Protection Inspectorate (Andmekaitse Inspektsioon), Tatari 39, 10134 Tallinn, [email protected], www.aki.ee. You may also complain to the authority in your country of residence.

9. AI features and your inputs

When you use our AI features, the prompts and content you submit (Customer Content) are sent to third-party AI model providers — currently Anthropic, OpenAI and Amazon Web Services (Bedrock) — to generate the output you request. These providers are engaged as our sub-processors under contract, and none of them uses your prompts or the resulting outputs to train their models.

AI calls are logged for quality, troubleshooting and abuse detection. We also use aggregated, non-identifying metrics about AI usage (such as error rates, latency and feature usage) to improve the Services. We do not use the content of your prompts to train our own models; if that ever changes, we will update this Policy and the Terms of Service before it does.

Because output is generated from what you submit, please do not enter sensitive personal data, other people’s personal data you are not entitled to share, or confidential information into prompts. We do not seek or knowingly use such information, and we apply measures intended to avoid reproducing it, but we cannot guarantee that information you include in an input will not appear in the output. This section should be read together with the Terms of Service and Acceptable Use Policy.

10. Automated decision-making

We do not make decisions that produce legal effects concerning you, or similarly significantly affect you, based solely on automated processing within the meaning of Article 22 GDPR. Our AI features generate content at your request but do not make such decisions about you.

11. How long we keep your data

We keep personal data only for as long as necessary for the purposes described in this Policy, or longer where the law requires (for example, accounting and tax records). Indicative retention periods:

Data categoryRetention period
Account dataFor the life of your account, then deleted or anonymised 30 days after closure
Billing, order and invoice records7 years from the end of the financial year of the record (Estonian accounting and tax law)
Transactional email logsUp to 2 years
Support communications and tickets1 year after the ticket is closed
Marketing consent recordsFor as long as the consent is in force, plus 3 years
Product analytics / event data13 months
AI inputs and outputs (stored by us)For the life of the associated project or account, then deleted 30 days after it is removed
Cookie dataConsent is re-requested at least every 13 months; analytics data is kept for 13 months (see Section 4)
Security and audit logs30 days
BackupsUp to 14 days, Deleted data is removed from backups as they rotate, within one full backup cycle
Security-incident records3 years after the incident is closed

12. How we protect your data

We apply technical and organisational measures appropriate to the risk, including encryption in transit and at rest, multi-factor authentication for staff access, role-based and least-privilege access controls, audit logging, environment separation, regular access reviews, encrypted backups with restore testing, and a documented incident-response process with 72-hour breach notification to the supervisory authority where required.

13. Children

The Services are not directed to children. You must be at least 18, or have the consent of your legal guardian, to use the Services, as set out in the Terms of Service. We do not knowingly collect personal data from children.

14. Information for United States residents

If you are a resident of a U.S. state with a comprehensive privacy law (such as California under the CCPA/CPRA), the following applies in addition to the rest of this Policy. We collect the categories of personal information described in Section 3 (identifiers, account and commercial information, internet/usage activity, and inputs you provide). We use it for the business purposes described above.

We do not “sell” personal information for money. We may “share” personal information for cross-context behavioural advertising through advertising cookies (e.g. Meta, Google, X); you can opt out at any time through our user cookie settings. Subject to your state’s law, you may have the right to know, access, correct and delete your personal information, to opt out of sale/sharing and certain profiling, and to be free from discrimination for exercising these rights. To exercise them, contact [email protected]. You may use an authorised agent; where you do, we may require written proof of the agent's authority and may verify your identity with you directly before acting on the request.

15. Changes to this Policy

We may update this Policy from time to time. We will post the updated version on the Site and update the “Last updated” date above, and where changes are material we will notify you by email or in-app. If we ever intend to change how we use your data for training our own systems, we will update this Policy and the Terms of Service before doing so.

16. How to contact us

  • Company: BuildingPP OÜ (registry code 17224732)

  • Address: Laulupeo tn 3-2, Tallinn, 10121, Estonia

  • Privacy enquiries and rights requests: [email protected]

  • General support: [email protected]