The short version. We keep your account, your company and the project files you upload, because that is the product. We measure which screens get used, and only while you are signed in. We do not set cookies, we do not run any third-party tracker, we do not store your IP address in our own database, and we never sell or rent anything to anybody.
This summary is here so you can stop reading if that answered your question. It is not the agreement — the sections below are.
01Who we are
VDClens is made by VDC lens LLC, a Florida limited liability company. In this policy, «we», «us» and «VDClens» mean that company, and «you» means whoever is using the product or writing to us.
You can reach us about anything on this page at hello@vdclens.com. A person reads that address.
02What this covers
This policy covers the vdclens.com website and the VDClens application — every screen of it, including the ones you use on a phone at a jobsite. It does not cover anybody else's website, even if we linked to it.
A note on roles, because it matters for who you should ask. When your company subscribes and uploads a project, your company decides what goes in and who sees it — we hold and process it on their instructions. If you work for a VDClens customer and you want your name or your entries removed from a project, start with your company; we will help them, but the decision is theirs, not ours.
03What we collect
Your account
Your email address and a password, which is stored only as a cryptographic hash — we cannot read it and neither can anyone else. Optionally a display name, a first and last name, and the company and role you tell us. If somebody invited you, we also keep who invited you and to which organization.
What you put into a project
Everything the product exists to hold: models and drawings you upload, measurements and takeoff items, budgets and unit prices, schedules, RFIs, submittals, punch items, daily reports, photographs taken in the field, inspections, change orders and the comments attached to any of them. We call this your content, and it stays yours.
Much of it carries a name and a timestamp, because that is the point: a quantity that cannot say who measured it and when is not traceable. Your content is stored in private buckets — it is not published, indexed or reachable by a public address.
Usage measurement
So we know which screens are actually used, we record an event when you open a screen, a heartbeat every two minutes only while the tab is visible and you have actually touched something, and the occasional named action such as generating a budget. Each event carries exactly this and nothing more:
- the name of the screen, such as
budgetor3d-viewer - a random session identifier that lasts until you close the tab
- your user id and the email on your account
- the project id, if you had a project open
- your browser's time zone and language setting
- the date and time
None of this is collected unless you are signed in. If you are not, none of it is sent — no user id, no email, no project. What we do measure on the public pages, anonymously and without cookies, is described right below. The time zone is what the browser hands over for free; we do not ask for location and we do not store your IP address in this record.
The public pages, before you have an account
On the home page and these legal pages we count visits, so a launch is not run blind. It is our own measurement, written to our own database — there is no Google Analytics, no advertising pixel and no third-party tracker of any kind. We record:
- which page you opened, and the date and time
- a random identifier that lives in your tab and is destroyed when you close it — not a cookie, and useless for recognising you tomorrow
- the site you arrived from, as a domain only —
linkedin.com, never the exact link somebody shared - the campaign tags in the address, if the link you followed carried any (
utm_sourceand the like) - a two-letter country derived from your browser's time zone, your language setting, and whether the screen is phone-, tablet- or desktop-sized
- whether you stayed — that is, whether you touched the screen or had it in front of you for fifteen seconds. A yes or a no, with no duration and no idea what you touched. It exists so that search-engine crawlers, which do neither, are not counted as people
- whether you opened the access form and whether the email was actually saved
No cookies, no IP address, no name and no email are involved — the email only exists if you type it into the form yourself, and that is the next section. The country comes from the time zone the browser gives away for free; we never ask for your location. Nobody outside VDClens receives any of it.
If you ask for access before you have an account
The form on the home page stores your email address, optionally your company name, and which plan you were looking at when you asked. That last one is the only reason the form is worth having: it tells us which price somebody was reading when they decided. Nothing else is captured, and nobody can read that list through the website — it accepts entries and returns none.
Devices and offline work
Because the field screens have to work in a basement with no signal, your browser keeps a local copy of the app and of the work you have not yet sent. That copy lives on your device. We also keep a random device identifier, a label you can edit, and when it was last seen — so you can tell your phone from your tablet and sign one of them out.
If you send feedback
The rating, whatever you wrote, which screen you were on, and your email so we can answer.
Server logs
Our hosting provider keeps ordinary web server logs of requests to the site, and those do include IP addresses — that is how any web server on the internet works, and we are telling you rather than pretending otherwise. We do not use them to build a profile of anybody; they exist for security and for finding out why something broke, and the provider rotates them out on its own schedule.
04What we never do
Not now, and not later without telling you first
- No cookies. The site sets none — not for analytics, not for advertising, not for anything. There is no cookie banner because there is nothing to consent to.
- No third-party trackers. No Google Analytics, no Meta pixel, no session recorder, no heatmap, no advertising network. Our own measurement is the one described above.
- We do not sell or rent your data. Not to advertisers, not to data brokers, not to anyone, for money or for anything else.
- We do not train AI models on your content, and neither does the AI provider we use — its terms for the interface we call forbid it.
- We do not look at your projects unless you ask us to, or unless we have to in order to fix something you reported.
- We do not ask for your location, and no screen requests it from your browser.
If any of this ever changes, it changes here first and we email everyone with an account before it takes effect. A quiet edit to a privacy page is how trust gets spent.
05How we use it
- To run the product. Sign you in, show you your projects, keep your work, sync what you did offline, send the notifications you asked for.
- To bill you, once billing is on, and to know how many seats your organization is using.
- To decide what to build next. This is what the usage measurement is for, and it is not a euphemism: before it existed, only a handful of screens reported anything, so the dashboard said the 3D viewer was the most used part of the product when all that was true is that it was one of the few raising its hand.
- To answer you when you write, and to fix what you report.
- To keep the thing secure — spot abuse, investigate an incident, meet a legal obligation.
- To write to you about VDClens itself if you joined the list or have an account: that we opened, that something changed, that a price is moving. You can stop those in one click and it never affects the ones you need — a password reset is not marketing.
06The AI features
Some screens have an optional helper — drafting an RFI, suggesting budget lines, reading a specification, explaining a clash. When you run one, the text and figures of that document or view are sent through our server to Anthropic, which returns the answer. Nothing is sent unless you press the button, and no helper runs on your projects in the background.
What is sent is scoped to what the helper needs — not your whole project, not your other projects, and not your account details. Anthropic does not use it to train its models. If you would rather nothing of yours ever left for this purpose, simply do not use the helpers: every screen works without them, and none of them is required to get an answer out of the product.
07Who else touches it
Four companies, and this is the whole list. Each one is bound by a contract to handle it only for us, and none of them may use it for their own purposes.
| Who | What it does for us | What it touches |
|---|---|---|
| Supabase | Database, sign-in and file storage | Your account, your organization, your content and the usage records |
| Vercel | Hosting for the site and the server the AI helpers pass through | Web request logs, which include IP addresses |
| Anthropic | The AI helpers inside the product | Only what you send by pressing an AI button. Not used for training. |
| Stripe | Subscription payments, once billing is on | Billing name and email. Card numbers go straight to Stripe and never reach our servers. |
Beyond those four: we will hand something over if a valid legal process requires it, and we will tell you when we are allowed to. If the company is ever sold or merged, your data goes with the product and this policy travels with it until you are told otherwise.
08How it is protected
- Everything travels over an encrypted connection, and the database is encrypted where it sits.
- Every table is closed by default. Access is decided row by row inside the database itself, by rules that ask whether you belong to that project and what you are allowed to do there. It is not a check the screen makes and could forget — a request that should not return your neighbour's project returns nothing, whoever makes it.
- Uploaded files sit in private storage. They are reached through short-lived links issued to someone who already has permission, never through a public address.
- Passwords are stored as hashes. Nobody at VDClens can read yours, and we will never ask you for it.
No system is beyond reach, and anyone who tells you theirs is should worry you. If a breach ever affects your data, we will write to you without delay, say what happened, what was reached and what we did — and we will notify whatever authority the law requires.
09How long we keep it
| What | How long |
|---|---|
| Account and organization | While the account is open, and 30 days after it closes so it can be recovered by mistake-correction rather than by luck. |
| Your content | While your subscription is active. After it ends you have 30 days to export it, and then we delete it. Ask sooner and we delete it sooner. |
| Usage records | 24 months, then deleted. |
| Access list | Until we launch or until you ask us to remove you, whichever comes first. |
| Invoices and tax records | As long as tax law requires us to, which is longer than we would otherwise keep them. |
10Your rights
Wherever you live, you can ask us to show you what we hold about you, correct it, export it in a format you can use elsewhere, or delete it. You can also tell us to stop writing to you. Write to hello@vdclens.com and we answer within 30 days — usually the same week.
Exercising any of these costs nothing and we will not treat you differently for it. Two honest limits: if the data belongs to a project your employer owns, we point you at them first, as explained above; and we cannot delete what tax law obliges us to keep.
If you are in California: we do not sell or share personal information as those words are defined there, and we have no advertising to opt out of. The rights in the paragraph above are the ones you have, and asking is how you use them.
11Europe and the UK
Our servers and every company in the list above are in the United States, so if you write to us from the EEA, the UK or Switzerland, your data is transferred there. We rely on the European Commission's standard contractual clauses with our providers for that transfer.
Our legal bases are the plain ones: performing the contract when we run the product for you, legitimate interest when we measure use and keep the service secure, consent when you join the access list, and legal obligation for tax and accounting. You can withdraw consent at any time, and you can complain to your national supervisory authority — though we would rather you wrote to us first, because we can actually fix things.
12Children
VDClens is a tool for construction professionals. It is not meant for anyone under 18 and we do not knowingly collect anything from them. If you believe a minor gave us data, write to us and we will delete it.
13Changes
When this policy changes, the date at the top changes with it. If the change is a real one — new data collected, a new company on that list, a new purpose — we email everyone with an account at least 30 days before it takes effect, so that saying no is still an option.
This page is written in English and Spanish. We work hard to keep them saying the same thing; if they ever do not, the English version is the one that governs.
14Contact
VDC lens LLC — Florida, United States.
Privacy questions, requests and complaints: hello@vdclens.com
The Terms of Service are the other half of this. They cover what you can expect from the product and what we expect from you.