Privacy Policy
Last updated 1 October 2026
This document is in English, and the English text is the one that applies.
This policy describes how AEC-flow actually handles data during the beta. No selling your information, no advertising trackers. The operating legal entity and governing law will be finalised before general release, and everyone using AEC-flow will be told before anything material changes.
Who we are
AEC-flow is made by CADflow (“we”, “us”). This policy covers aec-flow.com and beta.aec-flow.com. CADflow’s other products publish their own policies on cad-flow.com. If anything here is unclear, email hello@cad-flow.com and a person will answer.
Two kinds of data
Your account. Your name, email and how you use AEC-flow. We decide how this is handled, and this policy explains it.
What your practice puts in. Clients, contacts, contractors, projects, drawings, letters, contracts and invoices often contain other people’s personal details. Your practice decides what is collected and why; we store and process it on your practice’s behalf and for no other purpose. If you are one of those people and want to see or change what a practice holds about you, contact that practice first — we will help it answer you.
What we collect
- Account details — name, email, role, your practice’s name, and your password, stored only as a one-way hash we cannot read back.
- Sign-up record — when you sign up for the beta: the time, the access code you used, your IP address, the country it resolves to, and your browser’s description of itself, so we can tell where beta users come from and spot abuse.
- Agreement record — when you accepted these terms and this policy, and which versions.
- Security records — to limit password guessing and code guessing, we count recent attempts per IP address and per email address; these counters are removed after about a day. A password-reset or email-confirmation link records the IP address that asked for it and the one that used it.
- Your practice’s work — everything you enter or upload, including drawings and letters, and the activity record the app keeps of changes.
- Email you send from AEC-flow — when you email a document from the app, we keep a record for your practice of who it went to, the subject and the message, so you can see what was sent. Attachments are not kept.
- Feedback — when you use the Feedback button: your message, the page you were on, your browser’s description, and the screenshot if you attach one.
What we don't do
- We don’t sell or rent personal information to anyone.
- We don’t run advertising, analytics or tracking scripts in AEC-flow.
- We don’t use your practice’s data to train AI models, or let our AI provider do so.
- We don’t look at your practice’s data except to support you or fix a problem.
Who processes data for us
We use a small number of providers, each only for the job described:
- Supabase — the database and private file storage where all AEC-flow data lives, in the United States (US West). Files are never public; each download uses a link that expires within minutes.
- Vercel — hosts and runs the AEC-flow application.
- Resend — delivers email: invitations, password resets, email confirmation, and documents you choose to email.
- Anthropic — the AI model behind the AI features, used only when one of them runs (see below). Anthropic does not train its models on this data.
- Nucleus — our own licensing service. Where licence checking is switched on, for a workspace that signed up with a personal beta code, the app checks the licence at most once an hour, sending the code, the app version and the IP address of the person using it.
When you choose to email something through Gmail or Outlook on the web, your browser opens that service with the message filled in; what happens there is between you and that provider.
AI features and what they send
Nothing is sent to the AI provider unless one of these runs:
- Write with AI (General Documents) — the summary you type and the details of the letter: your practice, the client, the project, the recipient, subject, reference and date.
- Construction Contract Generator — your contract template PDF and the contract particulars: the parties’ names, addresses and contact details, the project, the sum, dates and payment stages.
- Permit process summary — the permit’s history: authority, site, applicant, dates, meeting decisions, letter summaries and open actions.
- Drawing sheet detection — when an uploaded drawing’s type can’t be read reliably from its title block, up to 1,200 characters of that title block text, which can include project and client names.
- Estimates wiki — the topic you ask about.
How we protect it
- Each practice’s workspace is isolated from every other in the application itself.
- The database is closed to direct public access; only the application can reach it.
- Passwords are hashed; sign-in and reset attempts are rate-limited; changing a password signs out every other session.
- All traffic is encrypted in transit.
How long we keep it
We keep your account and your practice’s data for as long as the account or workspace is active. Attempt counters are cleared after about a day. If you ask us to close an account or a workspace, we delete the personal data in it within 30 days, except where we must keep limited records by law; copies in our provider’s backups expire on their own schedule after that.
Your choices and rights
You can change your name and password yourself under Account. To see the personal data we hold about you, correct it, have it deleted, or get a copy, email hello@cad-flow.com from the address on your account. If you are in a country with data-protection law, such as the EU or UK, you may also complain to your data-protection authority; we would rather you came to us first.
Where your data is
AEC-flow’s data is stored in the United States. If you use AEC-flow from elsewhere, your data is transferred there, and our providers process it under their own data-protection commitments.
Children
AEC-flow is a tool for professional practices and is not meant for anyone under 16.
Payments
The beta is free, so we take no payment details. Before paid plans launch, this policy will be updated to name the payment provider; we won’t store full card numbers ourselves.
Changes to this policy
If we change how we handle data, we will update this page and, for anything material, tell you before it takes effect. The date at the top always shows the current version. See also the Terms of Service.
Contact
Questions about your data, or want it removed? Email hello@cad-flow.com. It reaches the same small team that builds AEC-flow.