Who we are: Hacky Apps LLC, the company behind Bilt Base, a construction management application for the web and for iPhone and Android.
Contact: privacy@biltbase.com
This policy explains what Bilt Base collects, why, who else sees it, and what you can ask us to do about it. It is written to be read, not to be survived.
Bilt Base is sold to construction companies. That means there are two relationships here, and they work differently.
If your company subscribes to Bilt Base, that company decides what goes into it. We hold and process those records on its instructions, under the Subscription Agreement. In data-protection terms your company is the controller and we are its processor. If you want records corrected or removed, ask your company first — they can do most of it themselves, and we will help them.
If you visit our website or ask us about the product, we are acting for ourselves, and this policy covers what we do with your enquiry.
Everything a construction company puts in: clients and their contact details, properties and addresses, jobs, estimates, proposals, invoices, payments, photographs from site, daily logs, time entries, documents, and messages sent through the software.
Most of it is business information. Some of it is personal: a homeowner's name, address, phone number and email; an employee's name and hours; a signature on a proposal; the network address a client signed from.
We hold it because a construction company cannot run a job without it. We do not decide what goes in — the company using the software does.
Account details. Name, work email, company name, role, and a password we store only as a salted hash. We never see the password itself.
Sign-in records. When you signed in, from what address, and on what device, kept so we can show you your own sessions and detect an account being attacked.
Mobile number, if you give one. A number you verify on your account page is used for one thing: sending the six-digit code that is asked for after your password, at sign-in and when you reset your password. We record that a code was sent to it and whether it arrived, never the code. You can remove the number at any time from your account page.
Usage and diagnostics. Which screens are opened, how long requests take, and what fails. Our error records deliberately exclude the contents of requests: a fault report says what broke and where, not the value of a contract or somebody's home address.
Signature evidence. When someone signs a proposal, change order or purchase order through a client link, we record their name, their title, the time, the network address, the browser and operating system, the sentence they agreed to, and a fingerprint of the document. This is what makes an electronic signature hold up, and it is kept for as long as the signed document is kept.
Payments. If a company turns on online payment, card and bank details are collected by Stripe on its own pages and never reach us. We see the amount, the date, and a reference.
the one that keeps you signed in.
Running the software means other companies process some data on our behalf. Each is bound by contract to use it only to provide their service.
| What they do | Who | What they see |
| Hosting and database | A cloud hosting provider | Everything, at rest |
| Photographs and documents | Cloudflare R2 | Files you upload |
| Outbound email | A transactional email provider | Messages sent through the software, and their recipients |
| Push notifications | Expo | A device token and the notification text |
| Sign-in codes by text, only if you verify a number | Twilio | Your mobile number and the code sent to it |
| AI features, only when used | Anthropic | The text or image submitted at that moment |
| Online payment, only when enabled | Stripe | The payer's bank or card details, which we never see |
We may change providers. If a change materially reduces the protection of a customer's data, we tell that customer at least thirty days beforehand.
AI features are off unless switched on. When somebody uses one, only the text or image submitted at that moment is sent to the model provider.
Data is held in the United States. If you are outside the United States and your company sends data to us, it is transferred there and processed under this policy and the Subscription Agreement.
Encryption in transit. Passwords stored only as salted hashes. Secrets such as email and payment keys encrypted at rest. Access controls so that each company's records are separated from every other company's, enforced in the software and tested on every build. Nightly backups kept off site, with a restore procedure that is exercised, not assumed.
Our people look at a customer's records only to run the service, to help when asked, or to investigate a fault.
No system is perfectly secure. If there is a breach affecting a customer's data, we tell that customer without undue delay after confirming it, and share what we know about what happened, what was affected, and what we are doing.
While a company is a customer, for as long as they keep the records. After a subscription ends, they may request an export for thirty days, and we may permanently delete their data after ninety days. Deletion requested in writing is carried out within thirty days, except for copies inside routine backups, which are overwritten on their normal cycle.
Sign-in records and diagnostics are kept for a limited period and then discarded. Records we must keep by law — invoices, for instance — are kept for as long as the law requires.
Depending on where you live, you may have the right to know what we hold, to get a copy, to have it corrected, to have it deleted, to restrict or object to how it is used, and to take it elsewhere in a machine-readable form. California residents have these rights under the CCPA, including the right not to be discriminated against for exercising them; there is nothing to opt out of on sale or sharing, because we do neither.
If your company subscribes to Bilt Base, ask them first — they control the records and can act immediately. If you cannot reach them, or the request is about data we hold for ourselves, write to privacy@biltbase.com and we will respond within thirty days.
Bilt Base is a tool for businesses. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe we have, tell us and we will delete it.
The Bilt Base app for iPhone and Android collects nothing beyond what is described above. Specifically:
a job. Photographs go to your company's account, nowhere else.
daily log with where it was taken. Location is never collected in the background.
token with Expo so we can deliver them.
The app contains no third-party analytics, no advertising, and no trackers. We do not track you across other apps or websites.
If we change this policy materially, we will tell customers at least thirty days beforehand by email or in the software. The version and date below always say which policy is in force.
Version 2026-09-11. Questions: privacy@biltbase.com
bee4dbcebe9581c5b6c741a48fb52b28b03d4cf3116713d465e2b761c185db0d