Legal
Privacy Policy
Effective
CostLogic is a browser-based construction takeoff, estimating, and invoicing service operated by Prodigy Labs LLC ("CostLogic", "we", "us", or "our"). This Privacy Policy explains what information we collect when you use costlogic.co and our related services (the "Service"), how we use and share it, and the choices you have. We do not sell your personal information, and we never use the plans, estimates, or customer records you put into CostLogic for anything other than delivering the Service to you. We do advertise CostLogic, and our public marketing pages carry the measurement tags that come with that - section 1 sets out exactly what they see, and section 7 explains how to refuse them.
1. Information We Collect
We collect information you provide directly and information generated as you use the Service.
Information you provide
- Account details such as your name, email address, and password if you set one.
- Company details such as your company name, address, logo, and the teammates you invite.
- Project content you upload or create, including plan and blueprint PDFs, measurements, takeoffs, estimates, invoices, presets, and notes.
- Customer records you enter about the people and businesses you work for, such as their name, email address, phone number, and mailing address. Section 5 explains how we handle that information.
- Messages you send to the Onyx AI assistant.
- Communications with us, such as support requests, contact-form messages, and feedback.
Information collected automatically
- Usage data: which features are used, actions taken, and timestamps.
- Device and log data: IP address, browser type, operating system, referring page, approximate country-level location derived from the IP address, and error reports.
- Cookies and similar local storage used to keep you signed in, remember the browsers you have already verified, and store your interface preferences.
- Campaign information, when you arrive at one of our public marketing pages from an ad, a search result, an emailed link, or a QR code: the campaign parameters in the address, the site that referred you, the page you landed on, and any advertising click identifier the address carries. This is described under "Advertising and campaign measurement" below.
Product analytics and abuse prevention
We use third-party analytics and security tooling, currently provided by vendors operating on United States infrastructure, to understand which features are used and how quickly pages load, and to keep automated abuse off the Service. The product analytics we use today is aggregate and cookieless: it reports patterns such as page views, referrers, and performance timings, and is not used to build a profile of you or to follow you across other websites. The advertising measurement described below is separate, and works differently.
We also use bot-detection and challenge tooling on sign-up, sign-in, and the links you send to customers. That tooling inspects request signals such as IP address and browser characteristics to tell a person apart from an automated script. Section 8 names the providers we use for both purposes today.
Advertising and campaign measurement
We advertise CostLogic. On our public marketing pages - the home page, the pricing page, the booking page, and campaign landing pages - we load measurement tags belonging to the advertising platforms we buy from, currently Meta, LinkedIn, and Google Ads. Each tag loads only while we are running campaigns on that platform. These tags set their own cookies and let the platform recognise that a visit came from one of its ads and measure whether that visit led anywhere. California law calls this sharing for cross-context behavioral advertising, and section 13 addresses it directly.
These tags run on the public marketing pages only. They are never loaded inside the signed-in application, so your projects, plans, takeoffs, estimates, invoices, customer records, and the pages you move through while working are never exposed to an advertising platform.
We also keep a record in your own browser, for 90 days, of how you first reached us and how you most recently reached us: the campaign parameters in the address, the referring site, the page you landed on, and any advertising click identifier you arrived with. If you later join the waitlist or create an account, a copy is stored with that record so we can tell which campaign produced a customer.
When you do something we count as a conversion - joining the waitlist, booking a call, or finishing signup - we also report it to those platforms directly from our servers, because tags in the browser are widely blocked. That report contains a one-way SHA-256 hash of your email address rather than the address itself, your IP address, your browser user-agent, the advertising click identifier you arrived with if there was one, and the platform's own cookie values. The hash lets a platform match the conversion against an account it already holds; it does not let anyone recover an address they do not already have.
We do not use session-replay tooling, and we do not load any advertising tag on the pages where you do your work. Section 7 explains how to refuse the ones on the marketing pages.
Payment information
Subscription payments are handled by Stripe. When you subscribe, you enter your card and payment details directly on Stripe's hosted checkout and billing portal. We do not receive or store your full card number. We receive limited billing information from Stripe, such as your subscription status, plan, and the last four digits of your card, so we can manage your account.
2. How We Use Your Information
We use the information we collect to operate, maintain, secure, and improve the Service. Specifically, we use information to:
- Provide takeoff, estimating, invoicing, and project management features.
- Provide AI-assisted features, including Auto Room detection, AI page naming, AI scale detection, and the Onyx AI assistant.
- Authenticate users, verify new devices, secure accounts, enforce usage limits, and prevent fraud and abuse.
- Process subscription payments, meter AI credits and storage, and manage billing.
- Send transactional and customer-facing emails, such as sign-in codes, team invitations, estimates, and invoices.
- Send you product updates, tips, and occasional offers about CostLogic by email. Creating an account subscribes you to these; every such email includes an unsubscribe link, and opting out never affects your account or the transactional emails the Service depends on.
- Respond to support requests and communicate about service and product changes.
- Measure aggregate feature usage and performance so we can fix what is slow or confusing.
- Measure which campaigns and landing pages bring people to CostLogic, and report conversions back to the advertising platforms we buy from, as described in section 1.
- Comply with legal obligations and enforce our agreements.
We do not sell your personal information. We do not use your project content - your plans, takeoffs, estimates, invoices, or customer records - for advertising, and we do not use it to train AI models of our own. The advertising measurement in section 1 is confined to how you reached our public marketing pages and whether you converted.
3. Legal Bases for Processing
If you are in the European Economic Area, the United Kingdom, or another region with similar laws, we process personal information on the following legal bases:
- Performance of a contract: providing the Service you signed up for, including hosting your content, running the features you invoke, and processing your subscription.
- Legitimate interests: securing accounts, preventing fraud and abuse, measuring aggregate usage and performance, and communicating about the Service - including occasional marketing emails to account holders about CostLogic, which you can opt out of at any time - balanced against your rights and expectations.
- Legal obligation: retaining billing records and responding to lawful requests.
- Consent: where we ask for it, such as optional communications. You can withdraw consent at any time without affecting processing already carried out.
4. AI Features and Third-Party AI Processing
CostLogic includes optional AI-assisted features. They are usage-gated, meaning they run only when you choose to use them, and they transmit only the content needed to deliver the feature you requested. When an AI feature runs, the relevant content is sent to a third-party AI provider that performs the processing and returns a result. AI features never run in the background and never process your content on their own.
Auto Room (Tectly)
When you run Auto Room, an image of the drawing or plan page you are working on is sent to Tectly, which detects rooms and areas and returns them so we can build takeoff layers for you. Only that page image is sent; your estimates, invoices, and customer records are not.
AI page naming, AI scale detection, and Onyx assistant (Fireworks AI)
AI page naming and AI scale detection send the text from a plan page to Fireworks AI so it can suggest a page name or read the drawing scale. The Onyx AI assistant sends the chat messages you write plus the project, takeoff, estimate, and invoice data relevant to your request, read through your own account permissions. If you ask Onyx about your notes pad, that text is sent too; the "Read your notes pad" tool can be switched off in Settings, and the pad is never read unless you ask.
Fireworks AI is a United States company and processes this content on US-based infrastructure. It serves an open-weight model whose parameters were published by DeepSeek, an AI lab based in China; the model is run by Fireworks AI, and your content is not sent to DeepSeek. Our Security page describes this in more detail.
Your content is not used to train AI models. We do not train models on it, and Fireworks AI's terms of service commit that customer content is not used to train or improve its models. Fireworks AI also operates under a zero-data-retention policy for the inference requests we make: your content is processed to generate the response and is not stored on its systems afterward, apart from narrow exceptions in its terms such as automated safety screening and retention required by law. Your Onyx conversations are stored in your CostLogic account, not by the AI provider.
Each AI provider processes the content it receives under its own terms and privacy policy, which govern how it retains or uses that content. We share only what is needed to provide the feature you requested, and we do not control how these providers operate their own systems. If you would rather not have particular content processed by a third-party AI provider, do not run the AI features on that content.
AI output can be incomplete or inaccurate. Review any AI-generated measurement, name, scale, or figure before you rely on it.
5. Your Customers' Information
CostLogic is a tool you use to do business with your own customers, so some of the information in your account is about other people: the customer records you enter, the recipients you email estimates and invoices to, and any personal details that appear in your notes or documents.
For that information you are the controller and we are the processor. In plain terms: you decide what to collect and why, and we handle it on your instructions in order to run the Service for you. We do not use it for our own purposes, we do not sell it, and we do not market to your customers. You are responsible for having a lawful basis to collect and share it, and for honoring the privacy rights of the people it describes. If someone contacts us directly about information held in your account, we will refer them to you and support you in responding.
If your organization requires a data processing agreement covering this relationship, contact us at hello@costlogic.co.
8. Service Providers and Sub-Processors
These are the providers that process data on our behalf so we can deliver the Service. Each is bound by contract to use the information only to provide its service to us.
- Supabase (Supabase Inc.) - database, authentication, and file storage, including the plan and blueprint PDFs you upload. Authentication emails such as sign-in and confirmation codes are delivered through the email provider configured in our Supabase project.
- Vercel Inc. - application hosting and content delivery; processes requests in transit. Also provides the aggregate, cookieless product analytics and page-performance measurement described in section 1, and the bot-detection tooling used on sign-up and sign-in.
- Cloudflare, Inc. - the human-verification challenge shown on shared document links, which inspects request signals such as IP address and browser characteristics to block automated scanning of those links.
- Stripe, Inc. - payment processing for CostLogic subscriptions. Stripe collects card and payment details directly on its own hosted checkout and billing portal.
- Tectly - powers the Auto Room feature. When you run Auto Room, the drawing or plan page image is sent to Tectly to detect rooms and areas.
- Fireworks AI, Inc. - the AI provider that powers AI page naming, AI scale detection, and the Onyx AI assistant, as described in section 4.
- Resend (Plus Five Five, Inc.) - sends transactional and customer-facing emails, such as team invitations, estimates, and invoices, including PDF attachments.
- Google LLC - provides "Sign in with Google" OAuth authentication when you choose to sign in with your Google account.
- Meta Platforms, Inc., LinkedIn Corporation, and Google LLC (Google Ads) - advertising measurement on our public marketing pages, as described in section 1. Each receives visit events from its own measurement tag while we are running campaigns on that platform, and a server-side conversion report containing a hashed email address, IP address, and user-agent when you join the waitlist, book a call, or complete signup. None receives your project content or your customer records, and none of their tags load inside the application.
- Calendly LLC - powers the scheduling page at costlogic.co/book. If you book a call, the name, email address, and any answers you give on the booking form go to Calendly to create the booking, together with the campaign parameters you arrived with. Calendly handles that information under its own privacy policy as well as ours.
This list changes as our infrastructure does. We will update this page and revise the effective date before a new provider begins processing personal information, and we will describe material changes in-app or by email. If you would like advance notice of sub-processor changes for a contractual reason, contact us at hello@costlogic.co.
9. Data Retention
We keep information for as long as it is needed to provide the Service, and then delete it. In practice:
- Account, company, and project content is retained while your account is active.
- Deleted projects, takeoffs, estimates, invoices, and customers go to Recently deleted and are permanently removed 30 days later, along with their stored files. You can restore or permanently delete them yourself during that window.
- A verified-device record lasts about six months, after which that browser is asked for a sign-in code again.
- Onyx conversations are kept until you clear them; clearing a chat deletes its messages and any notes-pad text that was read into it.
- Documents you send to customers keep a snapshot so the link you sent keeps working. You can revoke a share link at any time.
- The record in your browser of which campaign brought you to the site expires after 90 days. The copy stored on a waitlist entry or an account is kept for as long as that record is.
- Billing records are retained as long as required by tax and accounting law, typically several years, even after an account closes.
- Backup copies may persist for a limited period after deletion before they are overwritten in the ordinary course.
When you delete your account, we remove your account and its content from active systems within 30 days, except where we are required to keep something longer by law or to resolve a dispute or enforce our agreements.
10. Security
We use administrative and technical safeguards to help protect your information, including encryption of data in transit. Data is stored with our cloud infrastructure providers, such as Supabase, which apply encryption at rest and access controls to the data they hold. Row-level security policies scope every database read and write to the company that owns the record, and uploaded plans live in a private storage bucket that is never publicly readable. Our Security page describes this in more detail.
Sign-in uses one-time codes sent to your email, a password you set, or "Sign in with Google". Signing in with a password from a browser we have not seen before also requires a one-time code, so a stolen password alone cannot open a session. Keep your email and Google accounts secure and never share a sign-in code. If you believe your account has been compromised, contact us at hello@costlogic.co.
No system is perfectly secure. If a breach affects your personal information, we will notify you and any applicable regulator without undue delay and consistent with applicable law.
11. Your Rights and Choices
Depending on where you live, you may have the right to access, correct, export, delete, or restrict the personal information we hold about you, to object to certain processing, and to lodge a complaint with your local data protection authority. You can update your profile and company details in Settings, export your estimates and invoices from the app, and delete your account at any time.
You can opt out of marketing emails at any time using the unsubscribe link included in every marketing email, or by contacting us at hello@costlogic.co. Transactional emails - such as sign-in codes, billing receipts, and the estimates and invoices you send - are part of operating the Service and are not affected by a marketing opt-out.
To exercise any other right, contact us at hello@costlogic.co. We will respond consistent with applicable law, normally within 30 days, and may need to verify your identity before acting on a request. We will not deny you service, charge you a different price, or provide a lower quality of service because you exercised a privacy right.
If your request concerns information a CostLogic user entered about you, such as a customer record, that user is the controller of it and we will refer you to them. See section 5.
12. California Privacy Rights
If you are a California resident, the California Consumer Privacy Act as amended by the CPRA gives you specific rights. In the twelve months before the effective date of this Policy, we collected the categories of personal information described in section 1: identifiers, commercial information, internet or network activity, approximate geolocation derived from IP address, and the content you choose to store in the Service. We collected it from you and from your use of the Service, for the business purposes in section 2, and disclosed it to the service providers in section 8. We shared identifiers and internet or network activity with the advertising platforms in section 8 for cross-context behavioral advertising.
You have the right to know what we collect and why, to request a copy of it, to correct inaccuracies, to request deletion, to opt out of sharing for cross-context behavioral advertising, to limit the use of sensitive personal information, and not to be discriminated against for exercising these rights. We do not sell personal information. We do share personal information for cross-context behavioral advertising, as described in section 1 - to opt out, email hello@costlogic.co, or use the browser and platform controls in section 7. We do not knowingly sell or share the personal information of anyone under 16. We do not use or disclose sensitive personal information for purposes beyond those permitted without a right to limit.
Submit a request at hello@costlogic.co, or have an authorized agent do so on your behalf with written permission we can verify.
13. Selling and Sharing Your Information
We do not sell your personal information, and we never have. No one pays us for anything about you.
We do share limited information with advertising platforms so they can measure their own campaigns, which California law calls sharing for cross-context behavioral advertising. Section 1 sets out exactly what that covers. It is confined to our public marketing pages and to the fact that a conversion happened: your project content, your customer records, and everything you do inside the application are never part of it, and no advertising tag loads on those pages at all.
To opt out, email hello@costlogic.co and we will stop it for you. You can also block it yourself at any time with the browser and platform controls in section 7, which take effect immediately and need nothing from us.
14. Children's Privacy
The Service is a business tool that is not directed to children under 16, and we do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it.
15. International Data Transfers
CostLogic is operated from the United States, and our service providers process data primarily on United States infrastructure. If you access the Service from outside the United States, your information will be transferred to and processed in the United States and other countries where we and our service providers operate. These locations may have data protection laws that differ from those in your country.
Where required for transfers out of the European Economic Area, the United Kingdom, or Switzerland, we rely on appropriate safeguards such as the European Commission's Standard Contractual Clauses, or on our providers' own certifications under an applicable data privacy framework.
16. Governing Law
This Privacy Policy and any dispute arising from it are governed by the laws of the State of Texas, USA, without regard to its conflict of laws principles. Nothing here limits any non-waivable right you have under the privacy law of your own jurisdiction.
17. Changes to This Policy
We may update this Privacy Policy from time to time. When we do, we will revise the effective date at the top of this page. If the changes are material, such as a new category of processing or a new provider handling your content, we will tell you in-app or by email before they take effect where practicable.
18. Contact Us
Questions about this Privacy Policy or your information? Prodigy Labs LLC operates CostLogic, and you can reach us at:
Email us:hello@costlogic.co