Privacy Policy
What BrickNote processes, where, and your rights
1. Data controller
The data controller for the bricknote.ai website and for the exchanges you start with us (contact, licence) is:
- APITHINGS — SARL, Lyon trade register
- SIREN: 890 251 184 — SIRET: 890 251 184 00010
- Registered office: 4 rue de la République, 69001 Lyon, France
- Email: contact@bricknote.ai
For the data of your projects, the data controller is your firm. BrickNote is an application installed on your computer: APITHINGS hosts, receives and sees none of that data (section 2). APITHINGS has not appointed a data protection officer — the law does not require one given its activity and size; your requests reach the gérant directly, at the address above.
2. What BrickNote processes, and where
2.1 On your computer
The BrickNote desktop app (macOS, Windows) works on the project folder as it exists on your computer: meeting reports, drawings, schedules, contracts, minutes, emails, photos, scans, the action register. It builds an index and a state from it — worksheets, register, reports, journal — kept in a local database on that same computer. There is no BrickNote server: none of this content is transmitted to APITHINGS.
These documents contain personal data of third parties — the names, professional email addresses and statements of contractors, the client and the design team. They remain under your control and your responsibility, as they were before BrickNote.
2.2 The AI model you configure
Worksheets, the reading of scanned pages, the extraction of commitments and the transcription of meetings are performed by the model provider you choose and configure in Settings: Azure OpenAI, OpenAI, Anthropic, Mistral, OpenRouter, or a local model (Ollama) that never leaves the computer. OpenRouter, Inc. is an American company that does not run the model itself: it passes each request to a provider it picks from those it lists, so the place of processing is not guaranteed within the European Union and BrickNote cannot establish it. BrickNote asks on every call that the provider chosen neither keeps the data nor uses it to train its models; that is a request repeated on each request, not a contract. BrickNote sends that provider the excerpts of documents needed for the question asked and, if you use transcription, the audio recording.
That processing is governed by your contract with the provider and by its own privacy policy; APITHINGS is not a party to it and has no access to those exchanges. Your key is kept in your operating system’s keychain (section 8). The “Models on this machine only” setting refuses any model call off the machine — it checks the endpoint’s host, not the provider’s name, so only an address on this computer is accepted.
2.3 Your Microsoft 365 mailbox (optional)
You may connect your firm’s Microsoft 365 account. Sign-in happens in your browser, at Microsoft, with your own credentials: BrickNote never sees your password. The app asks for permission to read mail, send mail and read your profile, plus offline access to renew the session.
Messages from the Outlook folder linked to a project — and, if you choose so, inbox messages from that project’s known senders — are copied into the project folder, on your computer. Reminders and meeting reports leave from your mailbox, on your action only; Microsoft keeps the record in your sent items. Session tokens are stored encrypted on your computer; you can disconnect the account at any time in Settings, and revoke “BrickNote Desktop” from your Microsoft account.
2.4 Meeting recordings
Recording a site meeting requires informing the people recorded and obtaining their agreement (article 226-1 of the French Penal Code). Before every recording, BrickNote shows the announcement to read to the participants and asks you to confirm that they accepted it; the confirmation is noted in the project folder, with its date — it is your record, and it is not sent to us. The audio file is written into the project folder; the transcript lives in the application’s local database while the report is being written — a backup of the project folder alone therefore does not contain it. Both stay on your computer and are sent only to the model provider described in 2.2, if you ask for a transcription.
That confirmation records the steps you took; it does not replace informing the participants, which is your responsibility and for which the notice supplied with the application gives the wording. Anyone who declines must be able to take part without being recorded.
2.5 The mobile companion
The mobile companion is not distributed at this date: its shape is still being decided, and this policy will be completed before it is made available. What is planned, and what will not change: capturing in the field — photos, dictated notes, a meeting recording — with captures stored on the device, reaching the project folder through the file synchronisation you already use, with no account and no BrickNote server.
2.6 Application updates
The installed app checks for an update at launch and every six hours, against our distribution server (Microsoft Azure, European Union), and automatically downloads any it finds; you choose when to install, and failing that a downloaded update installs when the application is closed. That check transmits what any download transmits — your computer’s IP address, the app and system versions — with no account identifier and no project content. It happens even when “Models on this machine only” is on: that setting governs models and telemetry, not security updates. The updater also creates a durable random identifier in the application’s data and sends it with every check. It exists for staged rollouts — shipping a version to a fraction of installs first — and for nothing else: it carries no name, no firm and no content, and it is independent of section 2.8’s two switches, which do not govern it.
2.7 The bricknote.ai website
The website is a presentation site. The contact form opens your mail client: the message goes from your mailbox to contact@bricknote.ai without passing through a BrickNote server. Our host keeps technical logs (IP address, pages requested) for the security and operation of the service.
The invitation to talk, after a download or a first meeting report. Once an installer has been clicked, the download page offers to let us write to you once, the following week, about your trial — including if you did not manage to install the application or to connect a model. The desktop app makes the same offer, once only, after your first issued meeting report from this computer: a card in the report’s drawer, with “No thanks” beside it. In both cases the purpose, the address and the retention period are the same — neither the page nor the app collects anything: your mail client opens, addressed to feedback@bricknote.ai, and only the message you choose to send gives us your address. It serves that one contact only, never a newsletter nor the security alerts, and it is deleted, with the exchange, within 90 days or as soon as you ask.
Audience measurement only happens with your consent. You are asked on your first visit, with two answers of equal weight; until you have answered, no measurement tool is loaded. If you accept, it relies on PostHog, hosted in the European Union, in cookieless mode: no cookie is set and nothing is kept on your device — with one exception we would rather write down: on load, PostHog’s library checks whether local storage works by writing a value it reads back and deletes at once; nothing of it remains and nothing in it identifies you. It is PostHog that then computes, on its own servers, a hash of your connection’s technical headers with a salt renewed every day, so that nobody is recognised from one day to the next. Your IP address is not stored. If you refuse, nothing is measured: no script is loaded and no data is sent. You can change your answer at any time through the “Audience measurement” link at the bottom of every page.
On the show site, your visit is recorded — under the same consent. The “Show site” page runs the real BrickNote desk on a fictitious construction site, in your browser. If you have accepted audience measurement, we also record the visit there: the screens and the clicks on that demonstration desk, to see where it is hard to read on first contact. Everything on it is invented — the site, the companies, the documents — and whatever you type into a field is masked before it leaves your browser. The visit gets a random identifier, held in memory and forgotten when the tab closes: no cookie, nothing written to your device. These recordings are hosted by PostHog, in the European Union; we watch them ourselves, one by one, and PostHog deletes them after thirty days (section 6). If you refuse audience measurement, nothing is recorded. An answer given before 15 September 2026 does not cover this recording: you are asked again.
2.8 Usage measurement and error reports: optional
The desktop app can send us two things, and two only, each behind its own switch: usage measurement and error reports. Both are off by default; you are asked at first launch, with a real choice, and you can change your mind at any time in Settings › Privacy.
Usage measurement, if you turn it on, sends counted facts, never content:
- the app was active on a given day;
- a real project folder was opened;
- the model set-up screen was shown, with or without a model already configured, and it was left without a connection being attempted — which is how we learn where the first step gets stuck;
- the connection to a model provider was attempted, succeeded or failed, with the kind of provider (Azure, OpenAI, Anthropic, Mistral, OpenRouter, Ollama) and, on failure, a fixed code — not the model calls that follow, which we do not count;
- a meeting report was exported, handed to your mail client, or accepted by Microsoft 365 — and, when a distinct report is issued, that is, when its PDF has been written into the project folder and the message has either left your mailbox or been handed to your mail client, whether it is the first, the second or a later one from this computer;
- an update failed, or the installed version changed;
- you sent us feedback from the application, with its nature — a defect or an idea — and nothing of its content.
Error reports, if you turn them on, send the class of the error, a fixed error code and the positions in BrickNote’s own code — the call lines inside the application, and those only. Three facts about the application’s health go with them, with no content at all: one of its processes stopped abnormally (which one, why, with what exit code), the window stopped responding, or the application closed without going through its shutdown. Never the message text, never a file name, an address, a key, a prompt or a document.
Both are keyed to a random installation identifier, generated only after you agree and shown in Settings › Privacy; it is retired as soon as both switches are off, and a new agreement creates a new one. Nothing is sent while “Models on this machine only” is on. The error log itself stays on your computer as before, and you decide whether to send us an excerpt when you ask for help.
One point about location. Your IP address is not kept, but our processor PostHog derives from it, before discarding it, an approximate location — country, continent, time zone and coordinates at the scale of a region (a radius of some 200 km) — which it stores with these measures and keys to the installation identifier. It is neither your address nor a project’s: it is the country the software was used from. It is only derived if you have turned on one of the two switches, and it goes with the rest when you ask for erasure.
3. Purposes and legal bases
For the processing APITHINGS is responsible for:
- Answering your contact request and preparing a licence: pre-contractual measures, then performance of the contract.
- Operating and securing the website and the app’s distribution: legitimate interest.
- Measuring the website’s audience: your consent, collected on your first visit and revocable at any time.
- Contacting you once about your trial: your consent, given by the message you send us from the download page or from the app after your first issued meeting report, and withdrawn with a word in reply.
- Measuring the app’s usage and receiving its error reports: your consent, given switch by switch in Settings › Privacy.
For the data of your projects, the purposes and legal bases are your firm’s: BrickNote is the tool, not the controller.
4. Recipients and processors
We do not sell personal data. The providers that process data on behalf of APITHINGS are:
- Vercel: hosting of the bricknote.ai website (technical logs).
- Microsoft Azure: distribution of the app’s updates (European Union).
- PostHog: audience measurement of the website, with your consent, and — if you turn them on — usage measurement and error reports from the desktop app. Hosted in the European Union; a processor within the meaning of article 28 GDPR, acting on our instructions alone.
Model providers and Microsoft 365 are not our processors: you choose them and contract with them directly (sections 2.2 and 2.3).
If the BrickNote business is transferred, the contact and contract-management data needed for its continuity may be passed on to the successor, on the basis of our legitimate interest in organising that continuity, after an assessment of the rights of the persons concerned. You will be informed of the successor’s identity, of the processing that continues and of how to exercise your rights. The files kept solely on your own computers are not transferred by APITHINGS.
5. Transfers outside the European Union
The site’s server-side processing is pinned to the Vercel region “fra1”, in Frankfurt, Germany; the pages themselves being static, they reach you from the nearest point of presence on the host’s global network, wherever that is. Vercel’s own platform operations — support, security — may also involve processing in the United States, covered by the European Commission’s standard contractual clauses. Your project data is transferred nowhere by APITHINGS. Where your model provider processes depends on your choice: Azure OpenAI in the France Central region and Mistral process within the European Union; OpenAI and Anthropic apply their own transfer terms; with OpenRouter the processing may take place outside the European Union, at a provider it picks for each request, and we cannot establish it; a local model never leaves the computer.
6. Retention periods
- Your project data: on your computer, for as long as you keep it. It is for your firm to set retention periods justified by its purposes and its need for evidence — the app imposes none. Removing a project from BrickNote erases its state and its index from the local database; the folder’s files stay where they are: you are the one who deletes them. An erased database is not an overwritten one: its freed pages disappear as writes reuse them, and any backup or migration copy outlives you until you delete it.
- Trial feedback (after a download or a first meeting report): 90 days from your message, or as soon as you ask; beyond that, only lessons with nothing that identifies you.
- Contact requests and licence exchanges: the duration of the relationship, then three years.
- Website technical logs: kept by the host under its own security policy.
- App usage measurement and error reports: with our processor PostHog, for as long as our subscription lasts — PostHog keeps events for up to seven years and offers no shorter period; recordings of a visit to the show site, for their part, are deleted after thirty days. These measurements are erased, together with the installation identifier, as soon as you ask (section 7).
- Website audience measurement: same processor, same period. With no cookie or identifier on your device, these measurements are tied to no one we could find again; they therefore cannot be erased individually.
7. Your rights
Under the GDPR, you have the following rights:
- Right of access: obtain a copy of your data
- Right to rectification: correct your data
- Right to erasure: delete your data
- Right to portability: receive your data in a structured format
- Right to object: object to certain processing
- Right to restriction: limit the processing of your data
No decision producing a legal effect is taken automatically: the app proposes, a person validates, and nothing is sent without a click (article 22 GDPR).
To exercise them with APITHINGS, write to: contact@bricknote.ai. For the app’s usage measurement and error reports, quote the installation identifier shown in Settings › Privacy: it is the only key that can find those sends, and an erasure request to that same address deletes them. For the data of a project, contact the firm coordinating it: the data is on their computer, not with us.
8. Security
On your computer, the model key and the Microsoft tokens are guarded by the operating system’s secure store — and where the system offers none, the app refuses to save the key rather than write it in the clear; the app opens, reads and sends only files that sit inside a project folder or that you handed to it; the links it opens are limited to the web and your mail client. Every issued meeting report carries the SHA-256 fingerprint of its frozen content. The website is served over HTTPS.
BrickNote’s local database is not encrypted by the application (only secrets are): it is protected the way the rest of your computer is. Disk encryption, an individual user session and a locked screen are what actually protects a project folder. We recommend them; in a public beta nobody comes to check them for you — the application downloads and installs itself, and it is for your firm to make sure.
Backing up your project folders remains your responsibility, as for any file on your computer.
9. Cookies
The bricknote.ai website uses a single, strictly necessary cookie: the one that remembers the language you are reading it in. It keeps one other thing on your device: your answer to the audience-measurement question — a record that is strictly necessary too, without which the question would come back on every page. That record is removed as soon as it expires. If you accept audience measurement, PostHog runs with no cookie and keeps nothing on your device, except the availability check described in section 2.7, written and deleted in the same breath. No advertising cookies, no third-party trackers. The desktop app uses no cookies.
10. Minors
BrickNote is intended for construction professionals. It is not designed for use by minors under 16.
11. Changes
We may change this policy. The date at the bottom of the page states the version in force; a substantial change is announced in the app’s release notes.
12. Complaints
If you believe your rights are not respected, you may file a complaint with the CNIL (www.cnil.fr).
13. Contact
For any question about this privacy policy:
- Email: contact@bricknote.ai
- Form: Contact page
Last updated: September 2026