Privacy Policy

Effective August 3, 2026 · Version 2026-08-03

In short

We collect your email, your subscription status, the documents you upload, and records of what the system did with them. We use that to run and bill the Service. Your documents are sent to the AI and infrastructure providers listed below so they can be processed. Nobody, including us, trains AI models on them, and we do not sell your data.

This summary is for orientation only. The numbered sections below are the agreement.

1. Scope

This policy explains what Grey Software, LLC ("Grey", "we") collects when you use Pinpoint and the Grey website, why, who we share it with, and what you can ask us to do about it. It forms part of our Terms of Service.

Grey is the controller of the personal data described here. Where you upload documents containing other people's personal data, you are the controller of that data and we process it on your behalf.

2. What we collect

Account and identity

  • Your email address. We do not use passwords — sign-in is by one-time link — so we do not hold password data of any kind.
  • Your plan, subscription status, billing period dates, and any trade or division selections you save.

Billing

  • A Stripe customer and subscription identifier, the status of your subscription, and your billing dates.
  • We do not receive or store your card number, CVC, or expiry. Those go directly to Stripe. We can see the type and last four digits of the method on file so we can show it to you.

Your project content

  • The drawings, specifications and other documents you upload.
  • Data derived from them: recognized text, page and sheet indexes, numerical representations used for search, extracted scope items, spec references, locations, packages, and generated scope text.
  • Questions you ask about your documents and the answers given.
  • Notes, edits, exclusions and review state you create.
  • Project names, numbers, and anything else you type into a project.

Operational records

  • Usage events: which processing step ran, when, on which project, how many tokens it used and what it cost us to run. This is how your allowance is metered.
  • Run history and pipeline events, used to show progress and to diagnose failures.
  • Server logs, including IP address, request paths, timestamps and errors.
  • The record of your acceptance of these documents — which version, when, from which IP address and browser.

Voice features, where you use them, send a recording of what you say to a speech-to-text provider and send generated text to a speech provider. Audio is processed to produce the transcript and is not retained by us.

We do not use advertising cookies, analytics trackers or third-party marketing pixels. The only cookies we set are the ones that keep you signed in.

3. Why we use it

  • To run the Service: process your documents, produce and display results, answer your questions, and keep your projects available to you.
  • To meter your plan allowance and bill you accurately.
  • To send you transactional email — sign-in links, notifications that a run has finished if you asked for them, plan and cancellation confirmations, and price-change notices.
  • To provide support, which may involve looking at a project you have asked us about.
  • To keep the Service secure, prevent abuse, and enforce our Terms.
  • To understand and improve how the Service performs, using aggregated and de-identified data.
  • To comply with legal, tax and accounting obligations.

Where the law requires a legal basis, ours is: performance of our contract with you (running and billing the Service); our legitimate interests (security, abuse prevention, improving the Service); and legal obligation (tax and accounting records). We do not rely on consent except for optional notification emails, which you can turn off.

4. What we do not do

  • We do not sell your personal data, and we never have.
  • We do not use your documents or project data to train AI models, and our AI providers do not train on data submitted through their business APIs.
  • We do not share your projects with other customers.
  • We do not use your data for advertising or share it with advertisers.

5. Who we share it with

We rely on a small number of specialist providers to run the Service. Each is bound by contract, receives only what it needs to perform its function, and may not use your data for its own purposes. They fall into these categories:

  • AI model providers — receive the contents of your drawings and specifications in order to read them, extract scope, answer your questions and draft scope text. This is the category that sees your project documents. None of them train models on data submitted through the business APIs we use.
  • Cloud hosting, database and file storage — hold your account, your uploaded documents and everything derived from them, and run the application itself.
  • Background job processing — runs the long document-processing pipeline.
  • Payment processing — handles card details, invoices and subscriptions. We never receive your card number.
  • Transactional email delivery — sends sign-in links and notifications.
  • Rate limiting and caching — sees identifiers and request patterns, not document content.
  • Speech-to-text and text-to-speech — only if you use the voice features.

We will tell you exactly who these providers are on request — email support@grey.software and we will send you the current list. We keep the list rather than publishing it because the providers change as the product does, and a published list that has gone stale is worse than one that is accurate on the day you ask for it.

We may also disclose data where legally required, to protect our rights or someone's safety, or as part of a merger, acquisition or sale of assets — in which case we will notify you and this policy continues to apply until it is replaced.

If we add a provider in a new category — in particular one that would receive the contents of your documents — that is a material change and will be published under "Changes to this policy".

6. Where data is processed

We operate from the United States and our providers process data primarily in the United States. If you are outside the US, using the Service involves transferring your data there. Where required, transfers rely on standard contractual clauses or an equivalent mechanism through our providers.

7. How long we keep it

  • Project documents and derived data: for as long as your account is active. If your subscription ends, they are retained for 90 days so you can resubscribe and pick up where you left off, then deleted. We email you 14 days before that deadline, to the address on your account, so it never happens without warning.
  • Anything you delete yourself — a project, a file — is removed from active systems promptly and from backups within 30 days.
  • Account records: for the life of the account, then deleted on request or within 90 days of closure.
  • Billing, tax and invoice records: seven years, because we are required to keep them.
  • Usage and metering records: retained in aggregated form for capacity planning after the underlying projects are deleted.
  • Acceptance records for these legal documents: retained for as long as we may need to evidence the agreement, which outlasts the account.
  • Server logs: 90 days.

8. Security

Data is encrypted in transit and at rest. Access to production data is limited to people who need it, protected by multi-factor authentication, and separated by customer account at the database level. Sign-in is by one-time email link, so there is no password to be reused or leaked.

No system is perfectly secure. If a breach affects your data we will tell you and any required regulator without undue delay, and within any legally mandated period.

Because sign-in is by email link, the security of your email account is the security of your Pinpoint account. Protect it accordingly.

9. Your rights

Whatever your location, you can ask us to:

  • give you a copy of the personal data we hold about you;
  • correct anything inaccurate;
  • delete your account and its data;
  • export your projects;
  • restrict or object to a particular use;
  • tell you what an automated decision was based on.

Most of these you can do yourself in the application. For the rest, email support@grey.software and we will respond within 30 days. We will not treat you differently for exercising a right.

If you are in the EEA or the UK you also have the right to complain to your data protection authority. If you are in California, we confirm we do not sell or share personal information as those terms are defined by the CCPA, and we have not in the preceding twelve months.

10. Children

The Service is for business use by adults. It is not directed at anyone under 18 and we do not knowingly collect their data. If we learn that we have, we will delete it.

11. Changes to this policy

We will post any update here with a new effective date. If a change is material — a new category of data, a new purpose, or a new provider receiving your documents — we will email you and ask you to accept it the next time you sign in.

12. Contact

Grey Software, LLC

Privacy questions and requests: support@grey.software