Privacy Policy
1. Introduction
Welcome to BIM Guard (accessible at https://bim-guard.xyz). BIM Guard is an OpenBIM compliance verification and coordination platform that performs automated building code checks and ISO 19650 Common Data Environment (CDE) workflow tracking for architectural, structural, and MEP models.
We are committed to protecting your privacy and being transparent about how we collect, use, store, and safeguard your personal information and project data. This Privacy Policy explains our practices regarding data collected when you visit our website, create an account, authenticate via Google Sign-In, or use our services.
2. Information We Collect
We collect information in the following categories:
- Google OAuth Account Information: When you sign in to BIM Guard using Google OAuth 2.0, we receive your basic profile information as permitted by Google's consent screen. This includes your email address, full name, and avatar image URL. We do not receive or store your Google account password.
- User-Provided Account Details: If you sign up via standard email and password, we collect your email address and store a cryptographically hashed representation of your password managed by Supabase Auth.
- BIM Project & Engineering Data: When you use our platform, you or your team members may upload Industry Foundation Classes (IFC) models, BIM Collaboration Format (BCF) coordination topics, architectural rulesets, technical documentation, and project metadata (e.g., project codes, originator tags, suitability classifications, and revision codes).
- Audit & System Logs: We log system interactions for compliance audit trails, security, and debugging, including timestamps, ISO 19650 workflow state transitions (WIP → SHARED → PUBLISHED → ARCHIVED), rule evaluation results, and API access logs.
3. How We Use Your Information
We use the collected information strictly for the following purposes:
- To authenticate your identity, maintain your secure session, and protect your account from unauthorized access.
- To display your name, email, and avatar in collaborative project contexts (such as BCF topic assignment, comment authorship, and ISO 19650 approval logs).
- To execute architectural compliance audits and clearance checks on the IFC models you submit.
- To provide real-time Server-Sent Events (SSE) updates on background pipeline progress.
- To diagnose technical errors, improve system performance, and maintain platform security.
BIM Guard's use and transfer to any other app of information received from Google APIs adheres to the Google API Services User Data Policy , including the Limited Use requirements. We never use Google user data for advertising, marketing, or to train artificial intelligence or machine learning models without explicit consent.
4. Data Sharing & Third-Party Services
We do not sell, rent, monetize, or trade your personal information or Google account data to third parties.
We only share data with trusted infrastructure providers required to operate BIM Guard:
- Supabase: Provides managed PostgreSQL database services, Row-Level Security (RLS), and secure authentication.
- Cloudflare: Provides DNS routing, SSL/TLS certificate termination, DDoS mitigation, and edge delivery.
- Google Identity Services: Facilitates secure single sign-on authentication via OAuth 2.0.
5. Data Security & Storage
We implement rigorous technical and organizational measures to safeguard your personal data and proprietary BIM files:
- Encryption in Transit: All web traffic and API communications are encrypted using Transport Layer Security (TLS 1.3 / HTTPS).
- Database Row-Level Security (RLS): Multi-tenant isolation is enforced at the database kernel layer via Supabase RLS policies, ensuring users only access projects within their authorized organization.
- Access Control: Administrative access to underlying infrastructure is restricted, monitored, and protected by multi-factor authentication (MFA).
6. Data Retention & User Rights
You retain control over your data. Under applicable privacy laws (including GDPR and CCPA), you have the right to:
- Access the personal information we hold about you.
- Request correction of inaccurate or incomplete information.
- Request permanent deletion of your account, personal data, and associated BIM files.
- Export your project deliverables, BCF coordination packages, and compliance reports.
To exercise any of these rights, or to request account deletion, please email us at [email protected]. We process verified requests within 30 days.
7. Cookies and Local Storage
BIM Guard uses strictly necessary browser cookies and LocalStorage items exclusively for session authentication tokens (JWTs) and user interface preferences (such as dark theme preference and active project selection). We do not deploy third-party advertising trackers or behavioral analytics pixels.
8. Changes to this Privacy Policy
We may update this Privacy Policy from time to time to reflect modifications in our services, technological enhancements, or regulatory requirements. Any updates will be posted on this page with an updated "Last Updated" date.
9. Contact Us
If you have questions, concerns, or inquiries regarding this Privacy Policy or our data handling practices, please contact us at:
- Email: [email protected]
- Website: https://bim-guard.xyz
- Support: [email protected]