Skip to content
Blueprint Ledger

Legal

Privacy Policy

Last updated: August 15, 2026

This Privacy Policy explains what information Blueprint Ledger (the “Service”) collects, why, how we use it, and the choices you have. We try to collect the minimum we need to run the Service, and we don't sell your data.

1. Information we collect

We collect information in three ways:

  • Information you give us.When you create an account we collect your email address and, depending on the sign‑in method, your name and avatar from your identity provider (Google, for example). When you fill in your profile or company details we store the information you enter (first/last name, company name, address, phone, website, license number, and optional logo).
  • Information you upload or create.Jobs, buckets, line items, transactions, proposals, change orders, client payments, schedule events, file imports, and related metadata. This is “Your Content” as described in our Terms of Service.
  • Information collected automatically.Basic server and request logs (IP address, user‑agent, URL, and timestamp), authentication session identifiers, and minimal preferences stored in your browser's local storage (for example, view toggles and theme). We don't use third‑party advertising cookies.
  • Marketing attribution.If you arrive from a link carrying campaign parameters — for example from an advertisement or a newsletter — we store those parameters in a first‑party cookie on your device for up to 30 days, and attach them to your account if you go on to sign up. This is how we tell which channels bring us customers. The cookie is ours alone: it is not readable by any advertiser, it is never sent to a third party, and it cannot follow you to another website. We record only the campaign parameters themselves, the page you landed on, and the hostof the referring site — never the full referring address, which can contain another site's search terms.
  • Performance measurement.We measure how fast the Service runs, so we can find and fix slow pages. This is first‑party only — the measurements go to our own servers, never to an analytics company. Two kinds: server timings (which page was rendered, how long it took, and how many database queries it needed), and page‑speed measurementsreported by your browser (standard web‑performance metrics such as how long the largest element took to appear). The browser measurements deliberately contain no account identifier, no IP address, and no device fingerprint— only the metric, the page pattern (for example /jobs/[id], never the specific job), and whether the device was mobile or desktop. They set no cookie and cannot be linked back to you or across visits.

2. How we use information

We use the information we collect to:

  • provide, operate, maintain, and improve the Service;
  • authenticate you, keep your session active, and protect accounts;
  • send transactional email (magic‑link sign‑in, team invites, security notices). We don't send marketing email without your consent;
  • respond to support requests;
  • detect, prevent, and address fraud, abuse, and technical issues;
  • comply with legal obligations.

3. How we share information

We share information only as described here. We do not sell personal information.

  • With your team.Other members of a team you're part of can see the team's data according to their role (owner, admin, member). Your name and email are visible to them.
  • With service providers.We use trusted sub‑processors to run the Service. They handle data only on our behalf, under contract. Current providers include:
    • Vercel - application hosting and edge network.
    • Neon - managed PostgreSQL database.
    • Resend- transactional email (sign‑in links, team invites).
    • Google- optional OAuth sign‑in. If you use it, Google shares your profile basics (name, email, avatar) with us.
    • Stripe - subscription payments. Card details go directly to Stripe; we never see or store them.
    • Cloudflare R2 - file storage for receipts and screenshots you upload.
    • SimpleFIN Bridge- optional bank‑feed connection. Only if you choose to connect an account, and only to import transactions into the Service.
    • Ably- real‑time messaging for live support sessions. Only if you grant support access and then accept a live session. It carries cursor position, scrolling, which page you are on, and anything support draws on screen - never your financial data. Nothing about your screen is captured or recorded; both sides simply load the same pages independently.
  • For legal reasons. If required by law, legal process, or to protect our rights, property, or the safety of our users or others.
  • In a business transfer.If Blueprint Ledger is acquired, merged, or reorganized, your information may be transferred as part of that transaction. We'll notify you and the acquirer will be bound by this Policy or an equivalent one.

4. Data retention

We keep your information as long as your account is active and for a reasonable period afterward to comply with legal obligations, resolve disputes, and enforce agreements. When you delete your account we delete or anonymize personal information within a reasonable timeframe, except where we're required to retain it. Backup copies are purged on a rolling schedule.

Performance measurements are diagnostics rather than account data and are kept on a much shorter clock: server timings for 30 daysand browser page‑speed measurements for 90 days, after which they're deleted automatically.

5. Security

We use reasonable administrative, technical, and physical safeguards to protect the information we hold: encryption in transit, encryption at rest for the database, access controls, and least‑privilege operational practices. No system is perfectly secure. Please use a strong, unique sign‑in method (Google or a protected email inbox) and tell us at privacy@blueprintledger.work if you suspect a compromise.

6. Your choices and rights

Depending on where you live, you may have rights to access, correct, export, or delete your personal information, or to object to or restrict certain processing. You can exercise most of these directly in the Service (edit your profile, leave teams, delete data). For anything else, email privacy@blueprintledger.work and we'll respond within a reasonable timeframe.

You can stop receiving transactional email by deleting your account (these messages are required for the Service to work: sign‑in links, for example, so we can't suppress them while keeping the account live).

7. Cookies and local storage

We set a small number of first‑party cookies: some are strictly necessary to run the Service (primarily to keep you signed in), and—if you arrived from a campaign link—one that remembers where you came from, described in section 1. We use browser local storage to remember UI preferences (theme, view toggles) on your device. We don't use advertising or cross‑site tracking cookies.

Our page‑speed measurements (section 1) set no cookie and no identifier of any kind. There is nothing stored on your device that could recognize you on a later visit, and nothing in the measurement that could be tied to your account.

8. International transfers

Blueprint Ledger is operated from the United States. If you use the Service from outside the US, you understand that your information will be transferred to and processed in the US and in the locations our sub‑processors operate. Data‑protection laws in those locations may differ from yours.

9. Changes

We may update this Policy from time to time. If we make material changes we'll give you reasonable notice - by email or an in‑app banner - before they take effect. The “Last updated” date at the top always reflects the current version.

10. Contact

Questions, concerns, or requests? Email privacy@blueprintledger.work.