Legal

Privacy Policy

Last updated September 26, 2026

This policy explains what BimCode collects, what stays on your machine, where your data goes — including to the AI model providers behind the assistant — and the choices you have. We try to keep it in plain language, without leaving anything out.

What this policy covers

This policy covers the BimCode website, the BimCode add-in for Autodesk Revit, the plugins you build and install through it, and the emails you exchange with us. It explains what we collect, what we deliberately do not collect, where your data goes — including to the AI model providers behind the assistant — how long we keep it, and the choices you have.

If you use BimCode through your organization, read “Organizations and teams” below as well: your organization decides how its workspace is run.

What we collect

We keep collection to what is needed to run BimCode, bill it accurately, and keep it secure:

  • Account details — your name and email address, handled through our identity provider when you sign in. If you sign in through your organization's directory, we also receive the role and status your directory assigns you.
  • Usage and billing — for every AI request, how many tokens it used, which model handled it and what it cost, plus your plan and payment status. Payments are processed by our payment provider; we never see or store your card number.
  • Free trials — when you start a free trial we keep Stripe's identifier for your card, its brand and last four digits, and the network address and browser you used, to make sure each card is used for one free trial. We keep this after you close your account.
  • Computer name — when the add-in signs in, it sends the name of your computer. We store it with that sign-in session and show it to whoever is signed out when another machine takes over a seat, so the sign-out names the machine instead of looking like a fault.
  • Plugin installs — when you install a community plugin, we record the install together with a hashed identifier of the browser you installed from (we never store the raw value) and your IP address. We use these to apply monthly install limits and to spot abuse.
  • Plugin runs — each time you open a BimCode plugin or a community plugin, we record which plugin it was and when, with your account, so we can see which plugins people use. Plugins you build yourself and plugins only your organization uses are not counted.
  • Publisher profile — if you publish plugins to the community, the publisher handle you choose is shown publicly on your listings.
  • Support correspondence — anything you send us by email when you ask for help.
  • Crash and error reports — when the add-in or our servers hit an error, a report is sent to our error-reporting provider: a description of the failure, the add-in and Revit versions and, for our servers, your account's internal id. The add-in removes your Windows user name from file paths, and our servers filter prompt and conversation content out of a report before it is sent. Reports never include your Revit model.
  • Server logs — our servers keep operational logs of each request: which endpoint was called, the outcome, how long it took, and your account's internal id.
  • Where you came from — when you create an account, we keep the campaign tags in the link that brought you, the website you came from, any advertising click identifier in that link, and the page you landed on, so we know which of our marketing works. We keep this with your account and never add to it later.
  • Partner code — when you create an account after following a partner's link, we keep that partner's code with your account so we can pay the partner for introducing you. The partner sees only counts and amounts, never your name or email.

What we don't collect

Your Revit models stay on your machine. BimCode only ever sees the specific elements, parameters or views you point it at, and only while it is working on them — there is no full-model upload, and we don't store your project files.

Your conversations with the assistant are stored on your own computer, in your Windows user profile, not on our servers. We keep no copy of them; they are yours to keep or delete.

A plugin you have made runs inside Revit on your own machine, and contacts us each time it opens so we can confirm your subscription. That check carries your account, never your model.

We do not use advertising trackers on the website, and nothing on it follows you from one website to another.

How the AI features use your data

When you use BimCode's AI features, the content of your request leaves our systems. Your prompts and the conversation, the element data and view images the assistant reads from your model, and the code it writes are sent to third-party AI model providers to generate a response. Today these providers are Anthropic, OpenAI, Google, xAI, DeepSeek, Moonshot and Z.ai; which one handles a request depends on the model you, or your organization, select. Usage is measured in tokens, and those tokens are processed by the provider under the provider's own terms and privacy policy, not ours. BimCode does not control what a provider does with data once it has left our systems beyond the contractual terms that provider offers. If your organization connects its own provider account or endpoint, that provider's terms govern those requests. Do not include personal data, or information you are not permitted to share with those providers, in your requests.

The assistant reads only what a request needs. When it needs to see a view to do what you asked — or when you ask it to look — the add-in exports an image of that view and sends it with the request; the image is also kept with the chat on your computer.

BimCode itself does not use your prompts, your model data or the code it generates to train AI models. Whether a provider does is governed by that provider's terms — one more reason to keep personal data out of your requests.

Why we use your data

We use your data:

  • To provide the service you asked for — signing you in, generating and installing plugins, syncing them to your devices, and confirming your subscription when a plugin opens.
  • To bill you — metering tokens, taking payment, issuing invoices and keeping the records that accounting rules require.
  • For our legitimate interest in keeping the service secure and working — rate limits, abuse prevention, crash reports and logs, and enforcing plan limits.
  • To respond when you contact us.
  • With your consent, where the law requires it. You can withdraw consent at any time.

Service providers

We rely on a small set of providers to run BimCode. Each receives only what its job needs:

  • WorkOS — sign-in, single sign-on and directory sync: your name, email and organization membership.
  • Stripe — payments and invoices: your billing details and card data. Card numbers are held by Stripe, never by us.
  • Microsoft Azure — hosting for our servers, database and encrypted plugin storage, in the United States.
  • AI model providers — Anthropic, OpenAI, Google, xAI, DeepSeek, Moonshot and Z.ai: the content of your requests, as described above.
  • Sentry — crash and error reports.
  • Langfuse — measurement of AI usage: token counts, model, timing, and your account and chat-session ids. Prompt and response content is not sent from the live service. Hosted in the United States.
  • Grafana Cloud — server logs.
  • PostHog — website visit statistics: which pages are viewed, what is clicked, where a visit came from, and the browser, device and time zone of the visit. Collected without cookies and never linked to your name, email or account. Hosted in the United States.
  • Google Fonts — the typefaces on this website. Your browser fetches them from Google, which sees your IP address.

Where your data goes

Our servers run on Microsoft Azure in the United States, and the providers above process data there or wherever they operate. If you use BimCode from outside the United States, your data is transferred to it. If you live in the EEA, the United Kingdom or another place with data-transfer rules, we rely on the data-protection terms our providers offer for those transfers.

If your organization connects its own AI provider account or endpoint, that provider is chosen and contracted by your organization, not by us, and your organization decides where those requests go.

How long we keep it

  • Account data — until your account is closed. When it is closed, billing stops and it can no longer sign in; we keep the account record and its usage and payment history for as long as accounting and tax rules require.
  • Server and platform logs — up to 30 days, then deleted.
  • Crash reports — for a limited period in our error-reporting provider.
  • Conversations — on your machine, for as long as you keep them.
  • Backups — our database is backed up on a schedule and older backups are deleted on a schedule, so a copy of deleted data can remain in a backup until it ages out.

How we protect it

Data moves over encrypted connections, secrets are kept in a managed store, plugin packages are encrypted and signed, and access to secrets and the database is logged. The full picture is on our Security page.

Your rights and choices

Depending on where you live, you may have the right to access, correct, export or delete your personal data, to object to or restrict how we use it, and to withdraw consent. To exercise any of these, email us at info@bimcode.ai. We will check that the request came from you and answer within the time the law allows.

To close your account, email us at the same address; we will stop billing it and end its access. If your organization manages your account, ask your organization's admin.

If you believe we have not handled your data properly, you can complain to the data-protection authority where you live.

Children

BimCode is a professional tool and is not directed at anyone under 18. We do not knowingly collect personal data from children; if you believe a child has given us data, email us and we will delete it.

Organizations and teams

When your organization manages your account, the organization is responsible for that workspace and decides how it is run. Its admins can see the workspace's usage, including each member's usage, add and remove members, connect the organization's own AI provider, and choose which plugins are available. If the organization uses directory sync, its directory can create your account and, when you leave, deactivate it. The organization keeps its usage history after a member leaves.

We process that workspace's data on the organization's instructions and under this policy.

Cookies and website storage

Our website does not set cookies of its own. It stores a few values in your browser's local storage: your sign-in tokens, a random device identifier used for plugin-install limits, and a flag remembering that you dismissed a payment notice. While you sign in from the add-in, it briefly keeps the sign-in hand-off in session storage. While you browse, the tab remembers those campaign tags in session storage so they survive until you sign up; they are cleared when the tab closes. If you arrived through a partner's link, the tab remembers that partner's code in session storage until you sign up; it is cleared when the tab closes.

On checkout and billing pages, Stripe's payment form runs in your browser and may set Stripe's own cookies for fraud prevention. The website's typefaces load from Google Fonts.

Changes to this policy

We may update this policy as BimCode changes. The date at the top shows when it was last updated. For changes that matter to you — new kinds of data, new providers, new purposes — we will tell you in the product or by email before they take effect, where we reasonably can.

Contact

The data controller for BimCode is BIMME, Dubai, United Arab Emirates. Questions about this policy or your data? Email info@bimcode.ai.