Support · Policies
Terms, Privacy, DPA & Security.
neuroBLDR is operated by PlazaTech LLC (Texas). Last updated September 1, 2026.
Terms of Service
1. Agreement. These Terms are an agreement between you and PlazaTech LLC, a Texas limited liability company (“PlazaTech,” “we,” “us”), which operates neuroBLDR (the “Service”). By creating an account or using the Service, you agree to these Terms on behalf of yourself and any organization you represent, and you confirm you have authority to accept them for that organization. If you don't agree, don't use the Service.
2. The Service. neuroBLDR is construction project-management software with AI features. It helps you draft, organize, and assemble documents. It is a tool — not a licensed architect, engineer, attorney, accountant, or insurer — and does not provide professional advice. neuroBLDR is record-keeping and document-preparation software: it does not hold, move, transmit, disburse, or process funds, and it is not a bank, money transmitter, or payment processor. Any “paid,” payment, or accounts-payable status you record is a bookkeeping entry — you remain responsible for actually paying vendors and subcontractors through your own bank or accounting system. Documents the Service generates — including pay applications, lien waivers, change orders, proposals, and financial reports — are drafts and templates for your review, not legal, accounting, or tax advice; you are responsible for their accuracy and for having them reviewed by your own attorney or accountant before you rely on, send, or submit them.
3. Accounts & acceptable use. You're responsible for your account, your users, and your content, and for keeping credentials secure. Don't misuse the Service: no unlawful use, no reverse-engineering, no attempts to breach security or other tenants' data, no uploading content you don't have the right to upload.
4. AI outputs. AI features generate drafts. They can be wrong or incomplete. You are responsible for reviewing every AI output before you rely on it, send it, or submit it. AI in your workspace drafts; it does not send. There is no autonomous outbound path to an owner, architect, or sub — a person on your team presses send on any AI-drafted communication that leaves your workspace. Scheduled reports you switch on yourself in settings (for example a daily brief) are a separate, data-only feature: they carry no AI-composed content and go only to the recipients you enable, each of whom can unsubscribe. We make no warranty that AI outputs are accurate, complete, or fit for any purpose, and AI output is not professional advice of any kind.
5. Your content & IP. You own the data and documents you put into the Service. You grant us a limited license to host and process that content solely to provide the Service. We own the Service software, and feedback you give us may be used to improve it.
6. Billing. Paid plans are priced per office seat — Pro at $149 per seat / month, and Ultra at $409 per seat / month; annual prepay bills 10 months for 12. Field-crew, client, and subcontractor access carries no charge on every plan, and design-partner rates are available on request. Trials. There is no self-serve trial and no plan converts from one. We may grant an invited trial, which runs for 30 days on the Pro feature set, requires no payment method, and does not convert: when it ends the workspace moves to the Starter plan — a $0, capped, no-AI state we do not sell — and your data is kept. AI usage during an invited trial is capped workspace-wide. Paid plans renew automatically until cancelled. Fees are non-refundable except where required by law. Add-on refill AI-action packs don't expire while your subscription is active — they roll over until used. Beta. Beta access we grant at no charge runs for one month from the start of beta access; after that, the workspace moves to the Starter plan and your data is kept. Everything else in this section applies to a discounted beta subscription exactly as it applies to a standard one — including that fees are non-refundable. You can cancel anytime; access continues through the end of the paid period (see the Privacy Policy for what happens to your data after). Digital products. We also sell one-time downloadable tools at neurobldr.com/tools, priced at $39 each. They are delivered immediately after payment (download plus email), so digital-product purchases are non-refundable except where required by law. Each purchase is licensed for use within the purchasing organization; resale or redistribution is not permitted. Taxes. Prices for subscriptions and digital products exclude applicable sales tax, which is calculated and added at checkout where required.
7. Availability, change & support. The Service is under active development. Features may be added, changed, or removed; screens and workflows may move; and a capability available today may not be available later. We do not commit to an uptime service level, and the Service may be unavailable for maintenance, for a provider outage, or for an incident outside our control. Support is by email at contact@plazatech.llc on every plan, with a priority queue on Ultra; any response time we publish in the Help Center is a target we work to, not a contractual service level. Your records stay yours throughout: export is available to you at any time (see the Privacy Policy), and ongoing development never changes that.
8. Suspension & termination. You can stop using the Service at any time and cancel as described in section 6. We may suspend or limit access if payment fails after the grace period, if an account is used in a way section 3 prohibits, or where we reasonably must to protect the Service, other customers, or ourselves — and we will tell you why. When a paid subscription ends for any reason, the workspace moves to the Starter plan (a $0, capped, no-AI state) rather than being deleted: your data is kept and stays exportable. We do not delete a workspace because a subscription lapsed; deletion happens when you ask for it, as described in the Privacy Policy.
9. Disclaimers & limitation of liability. The Service is provided “as is” and “as available,” without warranties of any kind — express, implied, or statutory — to the fullest extent permitted by law, including any implied warranty of merchantability, fitness for a particular purpose, title, and non-infringement, and any warranty that the Service will be uninterrupted, error-free, or that its output will be accurate. To the maximum extent permitted by law, PlazaTech LLC will not be liable for indirect, incidental, special, consequential, or punitive damages, or for lost profits, lost business, delay or disruption claims, or lost or inaccurate data, and our total aggregate liability is limited to the amounts you paid for the Service in the 12 months before the claim. These disclaimers and this limit apply in full during beta and to free, invited-trial, and discounted access.
10. Governing law & disputes. These Terms are governed by the laws of the State of Texas, without regard to its conflict-of-laws rules. Any dispute will be resolved by binding arbitration administered under the American Arbitration Association's Commercial Rules, seated in Montgomery County, Texas. You and PlazaTech LLC waive any right to a jury trial and to participate in a class action — disputes are brought only in an individual capacity. Either party may still bring an individual claim in small-claims court. For any claim that is not subject to arbitration, the state and federal courts located in Montgomery County, Texas have exclusive jurisdiction, and both parties consent to venue there. You may opt out of arbitration by emailing us within 30 days of first accepting these Terms.
11. Changes. We may update these Terms; material changes will be posted here with a new “last updated” date. Continued use after changes means you accept them. Each version is dated, and the version in effect when you created your account is recorded with your account.
Privacy Policy
What we collect. Account details (name, work email, company, role), the content you upload to run your projects, and usage/diagnostic data needed to operate the Service.
How we use it. To provide and improve the Service, process payments, send transactional email, and provide support. We do not sell your personal information or use your project data to train neuroBLDR models. When an AI feature runs — because you asked for it, or because one of the automatic drafting and classification agents ran on a record you created — we send the context needed for that request through configured model providers under their applicable data terms.
Analytics & diagnostics — what that actually means. Product analytics are a small set of server-side events (an account was created, a project was created, a drawing set was indexed, an AI action ran), keyed to an internal account or workspace identifier — or, for public marketing forms, to a hashed identifier — never to your raw email address, and dollar figures are stripped from event properties before they leave our servers. Error monitoring captures crash and error reports with the vendor's personal-data collection switched off plus an additional scrubbing pass, and reports are not tied to a named user. We do not use either to build advertising profiles.
Google user data (connected Gmail mailboxes). If you connect a Google mailbox, neuroBLDR requests two Gmail scopes and uses each for exactly one feature: gmail.modifyto read recent inbox threads so you can file them against your construction projects and to update those messages' labels/read state in your own mailbox when you do; and gmail.sendto send project correspondence (for example an RFI to your architect) from your own address — every send is user-initiated in the UI, and the product has no automated sending. neuroBLDR's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. We do not use Gmail data for advertising, do not sell it, do not use it to train models, and do not allow humans to read it except with your explicit permission, for security, or to comply with law. OAuth tokens are encrypted at rest (AES-256-GCM); disconnect at any time from Settings → Mailboxes, which stops all access.
Sub-processors. We rely on a short list of vendors to run the Service under their applicable terms and our agreements:
- Vercel — hosting, serverless compute, file/blob storage, and the AI Gateway.
- Neon — managed Postgres database.
- Anthropic, Google & OpenAI — model inference, routed through the Vercel AI Gateway when an AI feature is requested.
- Google Cloud — the Blueprint PDF engine (Cloud Run) and Google sign-in.
- Upstash — Redis for sign-in codes and rate limiting.
- Stripe — subscription billing and payments.
- Cloudflare — R2 object storage for the second-provider backup copy of files and database snapshots.
- Resend — transactional and newsletter email.
- Sentry — error monitoring.
- PostHog — product and usage analytics.
- Intuit QuickBooks and Microsoft / Google (Gmail, Outlook) — only when you connect them, for accounting sync and email integration.
We give notice before adding a new sub-processor.
Data retention. We retain workspace data while needed to provide the Service and meet legal or security obligations; a lapsed subscription moves the workspace to a $0 state, it does not delete it. Two operational logs are pruned on a schedule rather than kept forever: email delivery records are removed after 180 days, and stored billing-webhook payloads are blanked after 90 days (the event id is kept so a payment cannot be processed twice). You can export project documents and core registers, request a full account export, or request workspace deletion at contact@plazatech.llc. Verified deletion requests are handled from active systems, with residual backup copies expiring under provider backup schedules. The Service does not yet provide an automated 90-day post-cancellation purge, so contact us when you want the workspace deleted.
Your rights. You can access, export, correct, or delete your data at any time. We honor applicable privacy rights, including under the CCPA (California) and the GDPR (EU/UK) — including access, portability, and deletion requests. To exercise any right, email contact@plazatech.llc.
Cookies. We use only the cookies needed to run the site and keep you signed in, plus a first-party analytics cookie for privacy-friendly product analytics. We don't run third-party advertising trackers.
Data Processing Addendum
This DPA applies where we process personal data on your behalf and supplements the Terms. A countersigned copy is available on request at contact@plazatech.llc.
Roles. For data you upload, you are the data controller and PlazaTech LLC is the data processor. We process personal data only on your documented instructions and to provide the Service.
Security & sub-processors. We maintain the technical and organizational measures described in the Security section and use the sub-processors listed in the Privacy Policy under their applicable terms and our agreements. We'll give notice of material new sub-processors.
Data-subject requests & breach. We'll assist you in responding to data-subject requests, and we'll notify you without undue delay after becoming aware of a personal-data breach affecting your data.
Return & deletion. On termination, use the available project and account exports or contact us for assistance. We handle verified written deletion requests from active systems, with residual backup copies expiring under provider schedules. International transfers rely on appropriate safeguards where required.
Security
How we protect your data today:
- Workspace isolation — authenticated requests derive workspace and project access from the signed-in user, and child record IDs are revalidated at request boundaries.
- Database-layer tenant isolation — Postgres row-level security policies are enforced in production, and tenant-scoped requests run under a non-superuser role those policies bind, so a tenant query that loses its context returns nothing rather than another customer's rows. A small set of scheduled system jobs (backups, retention pruning, cross-workspace sweeps) runs under a separately audited service role. The per-request access guards above remain a second, independent layer.
- Encryption — HTTPS in transit, provider-managed encryption at rest, and AES-256-GCM for connected-service OAuth tokens before database storage.
- Time-bounded magic links — scoped per project, expiring on a schedule, revocable anytime.
- Drafts never auto-send — financial and contractual AI outputs require a human to review and send.
- Audit log — security-sensitive and core business mutations record workspace, actor, action, and target information.
- AI boundaries — neuroBLDR does not train its own models on your project data; requested AI features send only the context needed for inference.
Our controls are built to be SOC 2-aligned and we run on SOC 2-certified infrastructure providers, but neuroBLDR is not itself SOC 2 certified — a Type II audit is on the roadmap, and we will not describe it as anything else until it is done. We are not a HIPAA covered entity or business associate, hold no protected health information, and do not sign BAAs. For vendor due diligence, a DPA, or a security questionnaire, email contact@plazatech.llc.
Live status and recovery posture. Our public status page runs its checks when you load it and publishes what we would lose and how long recovery takes — with a sentence rather than a number wherever no machinery produces one. We also keep a runnable proof of the database-layer tenant isolation described above, including what it does not prove; ask and we will walk your reviewer through it.