Guest use
A guest can design without providing identifying information. Drafts are stored on the device unless the user explicitly signs in and asks for cloud features.
Privacy policy
AtriBuild, 7 Whittier Pl Ste 108 Boston, MA 02114, operating under Massachusetts, USA provides this policy for AtriBuild. AtriBuild minimizes project-data collection and never puts a project in the public gallery automatically.
A guest can design without providing identifying information. Drafts are stored on the device unless the user explicitly signs in and asks for cloud features.
This policy is effective August 9, 2026. Material changes should be dated and presented before a user is asked to make a new public submission or accept a materially changed data use.
AtriBuild, 7 Whittier Pl Ste 108 Boston, MA 02114, operating under Massachusetts, USA is responsible for this policy. Privacy requests may be sent to privacy@atribuild.com.
Project geometry, measurements, object names, notes, ZIP code, hidden layers, share tokens, and floorplan images are excluded from advertising and routine analytics payloads. Cloud projects remain private unless their owner separately creates a share link or completes the public-gallery opt-in flow.
Gallery publication is per project and off by default. Before submission, the owner sees a generated public preview and must affirm both privacy review and authority to publish. If moderation approves it, the public page may show the supplied title, description, optional creator display name, category, tags, visible floor and object counts, broad dimensions, and a metadata-stripped cover generated from visible geometry. Project and account IDs, email, notes, entity and floor names, hidden floors, utilities, estimates, prices, share links, and billing data are excluded from the public projection.
AtriBuild records publication, moderation, unpublish, remix, and abuse-report events needed to operate the gallery safely. Anonymous reports use a keyed one-way network fingerprint to limit duplicate abuse; the raw address is not stored in the report record. Moderators may review submitted public text, the scrubbed projection and cover, reports, and audit history.
Configured providers process authentication and payments under their own terms. Secret keys and payment details never belong in browser storage or application logs.
Signed-in users can download a bounded, privacy-minimized account archive and owners can unpublish a gallery project at any time. Unpublishing removes its AtriBuild public page, but search caches, lawful copies, and editable remixes that were separately permitted and created before unpublishing may remain. Retention schedule: projects and exports are kept while the account is active and purged within 30 days of account or project deletion; gallery moderation and abuse-report records are kept for 12 months; security and audit logs for 12 months; billing and tax records for 7 years as required by law.
Depending on enabled features, AtriBuild may use Vercel for hosting, Supabase for authentication/database/storage, Stripe for payments, Resend for transactional email, Cloudflare Turnstile for abuse prevention, Upstash for distributed rate limits, Sentry for content-minimized error monitoring, and Google AdSense only after the separate advertising consent and release gates are enabled. Their roles and enabled status must match the production configuration.