Effective 2026-07-17 · Last updated 2026-07-17
Privacy Policy
This Privacy Policy explains how Ollie.Cloud LLC ("Ollie", "we", "us", or "our") collects, uses, discloses, and protects information when you use the Ollie construction-takeoff platform at ollie.cloud and app.ollie.cloud, together with our related websites, applications, and services (collectively, the "Service").
Ollie is a business-to-business tool that construction contractors and estimators use to turn architectural PDF plans into material and quantity estimates. Most of the personal information we handle is provided by our business customers about their own personnel and projects. When a customer uploads its own project files and end-user data, that customer acts as the data controller and Ollie acts as a data processor; our Data Processing Agreement governs that relationship.
1. Who we are and how to contact us
Ollie.Cloud LLC is a New Jersey limited liability company. We are the controller of the account and website information described in this Policy. For customer project content, the customer is the controller, and you should contact that customer directly to exercise your rights. You can reach us here:
2. Information we collect
2.1 Information you provide
- Account and identity data. Sign-in and identity are handled by our authentication provider, Clerk. Ollie does not create, receive, or store your password — Clerk manages your credentials, and our systems receive only a verified sign-in token plus your profile fields: your name, email address, user ID, the organization(s) you belong to, your role (admin, estimator with edit access, or viewer with read-only access), and your avatar. We read most of these live from Clerk as needed; we store a user ID and role, and you may save an optional editable profile (name and email display overrides) in your settings.
- Organization data. The name, slug, and identifier of the organization you create or join, and that organization's membership roster (retrieved from Clerk).
- Project content. The files you upload — principally architectural and specification PDFs — together with rendered page images, takeoff measurements and items, drawing sets and folders, project and general-contractor names, project tags, due dates, status, notes, and the templates you create.
- Chat and AI interactions. When you use in-app chat or AI features, we store your chat threads — the questions and messages you send, the AI's responses, thread titles, and which plan pages the assistant viewed — associated with your account and project.
- Preferences and settings. Your unit, theme, density, and color preferences, any name or email display overrides, and your personal or organization template libraries.
- Billing information. Our payment processor, Stripe, collects your payment method and billing details through Stripe-hosted checkout and billing pages. This happens when you subscribe to a paid plan, and also when you add a card to activate a free Solo workspace — in the second case a card is stored and verified but not charged. Ollie never sees or stores your card number; we store only a Stripe customer and subscription reference, your plan, billing cycle, subscription status, seat count, and current-period and trial-end dates. Invoices and receipts are provided to you as links to Stripe-hosted pages. For billing questions, contact billing@ollie.cloud.
- Support and bug reports. If you contact support or submit a bug report from within the Service, we process the information in your report — your email address, your user and organization identifiers, the project and page you were on, recent actions, a browser and platform string, your message or support-chat transcript, and (for bug reports) an optional screenshot you choose to attach. These are transmitted to our support team by email through Resend and received in our Google Workspace inboxes.
- Other communications. If you request a demo on our website or email us, we collect the information you submit, such as your name, email, company, and message. If you schedule a demo through Calendly, we also receive the name, email, and company you provide there.
2.2 Information collected automatically
- Product analytics. We use PostHog to understand how the Service is used — for example, which pages are viewed, which features are used, and events such as creating a project or running an AI action. You are identified in PostHog by your user ID together with your email, name, and role, and grouped by your organization. PostHog sets cookies, captures interaction events, and records masked session replays (in which text and form inputs are masked) to help us diagnose usability issues. This data is processed in the United States (us.i.posthog.com).
- Error and performance monitoring. We use Sentry to capture crash reports, error traces, and performance samples, including on-error session replay, so we can diagnose and fix problems. This may include your user ID or email and diagnostic context about the error. This data is processed in the United States.
- Website analytics. On our marketing website, ollie.cloud, we use Plausible, a cookieless analytics tool that collects only aggregate pageview, referrer, and country data. It sets no cookies and collects no personal data or cross-site identifiers. Plausible processes this data in the European Union.
- Approximate location. Our infrastructure and analytics providers may infer a coarse location — such as your city or region — from your IP address. We do not collect precise geolocation.
- Activity log. To provide collaboration history and security, the Service records an activity log of actions taken in an organization — the acting user, the action, the related project, and a timestamp.
- Presence and render progress. To show teammates who is currently viewing a project, we briefly store presence information (your user and organization identifiers and the project you are viewing), which expires within about a minute. While plans are being processed, we temporarily store render-progress state, which expires within about 24 hours.
- Logs and connection data. Our application sends operational logs — timestamps, organization and session identifiers, request paths, and error detail — to our logging provider, Better Stack, and these logs may include your IP address at the infrastructure level. Our infrastructure providers (Cloudflare, Fly.io, and Vercel) process connection metadata such as IP address at the network edge to deliver content and protect against abuse. Rate and usage limits are enforced by account and organization.
2.3 Information from third parties
We receive account and authentication signals from Clerk and subscription and payment status from Stripe. We do not buy personal information from data brokers. Our AI subprocessor's role in processing the plans you choose to submit is described in Section 4.
3. How we use information
We use the information above to:
- Provide, operate, maintain, and secure the Service, including authenticating you and enforcing organization and role boundaries;
- Process, render, analyze, and store your uploaded plans and generate takeoff estimates and AI-assisted outputs;
- Process payments, manage subscriptions, and send billing and transactional communications;
- Provide customer support and respond to your requests;
- Monitor, debug, and improve the performance, reliability, and features of the Service, including through analytics and error monitoring;
- Detect, prevent, and address fraud, abuse, security incidents, and violations of our terms;
- Comply with legal obligations and enforce our agreements; and
- With your consent where required, send product updates or marketing, which you can opt out of at any time.
We may create and use aggregated or de-identified data — which cannot reasonably be used to identify you — to operate, analyze, and improve the Service. We do not use your Customer Content to train our own or any third party's AI models.
4. AI processing of your plans
Ollie's AI features — automatic sheet naming, callout and reference detection, scale detection, chat, and assembly analysis — use Anthropic (Claude) as our AI subprocessor. To keep processing efficient and private, several steps run first on our own servers with no external call: PDF rendering, optical character recognition (Tesseract), and shape detection (OpenCV). Only the items those local steps cannot resolve are sent to Anthropic.
Depending on the feature, the content sent to Anthropic includes full-page or cropped images of your drawings, text extracted from your PDFs and uploaded specifications, and — for chat — your messages together with the project name and general-contractor name. Anthropic processes this content solely to return the AI output to you. Under our commercial terms with Anthropic, your content is not used to train Anthropic's models.
Automatic sheet-naming runs on upload by default and can be turned off in your organization settings; other AI features run only for the pages and actions you or your organization initiate. We may cache AI results (keyed to the contents of the processed image or text, not to your identity) to avoid re-processing the same page. We do not use your Customer Content to train our own or any third party's AI models.
5. Legal bases for processing (EEA, UK, and Switzerland)
If you are in the European Economic Area, the United Kingdom, or Switzerland, we rely on the following legal bases under the GDPR and UK GDPR:
| Purpose | Legal basis |
|---|
| Providing the Service and your account | Performance of a contract |
| AI processing of plans you submit | Performance of a contract; our and our customers' legitimate interests |
| Billing and fraud prevention | Contract; legal obligation; legitimate interests |
| Product analytics, error monitoring, and product improvement | Legitimate interests |
| Marketing communications | Consent (or legitimate interests, where permitted) |
| Security and abuse prevention | Legitimate interests; legal obligation |
Where we rely on legitimate interests, we have balanced those interests against your rights and freedoms. You may object to such processing, and you can opt out of analytics as described in Sections 9 and 11.
6. How we share information
We do not sell your personal information, and we do not share it for cross-context behavioral advertising. We disclose it only as follows:
- With subprocessors and service providers. We share information with vetted third parties that host and help operate the Service — hosting, storage, authentication, payments, email, AI, analytics, and monitoring. The complete, current list, with each provider's purpose, the data processed, and its location, is at /subprocessors.
- Within your organization. Project content and activity are visible to other members of your organization according to their role and the sharing settings you choose.
- For legal reasons. We may disclose information if required by law, subpoena, or legal process, or to protect the rights, property, or safety of Ollie, our users, or the public.
- Business transfers. If we are involved in a merger, acquisition, financing, or sale of assets, information may be transferred as part of that transaction, subject to this Policy.
- With your direction or consent. When you ask us to share information or otherwise consent to it.
7. International data transfers
Ollie is operated from the United States, and most of our subprocessors host and process data in the United States. If you access the Service from outside the United States, your information will be transferred to, stored, and processed in the United States, where data-protection laws may differ from those in your country.
For transfers of personal data from the EEA, UK, or Switzerland to the United States, we rely on appropriate safeguards, including the European Commission's Standard Contractual Clauses (and the UK Addendum) with our subprocessors, together with supplementary measures such as encryption in transit and at rest. You can request a copy of the relevant safeguards by emailing support@ollie.cloud.
8. Data retention and deletion
We keep personal information for as long as needed to provide the Service and for the legitimate and legal purposes described in this Policy. In particular:
- Project trash. When you delete a project it is moved to trash and permanently purged about 30 days later.
- Organization closure. When an organization is closed, we apply a recovery window of about 30 days, after which we permanently purge its settings, folders, activity logs, chat threads, stored files, and related assets. If the organization is deleted directly through our identity provider (Clerk), the purge happens immediately, without the recovery window.
- Presence data expires automatically within about a minute.
- Render-progress state expires automatically within about 24 hours.
- Signed image links to rendered plan images expire automatically within about 24 hours and are regenerated on access.
- Billing records are retained by us and by Stripe as required for tax and accounting purposes.
- Application logs are retained by our logging provider for a limited period before being overwritten in the ordinary course.
9. Your privacy rights
Subject to conditions and exceptions in applicable law, you can access, correct, delete, port, or object to the processing of your personal data. We honor these requests through a manual, best-effort process: email support@ollie.cloud, and we will verify your identity and respond within the timeframe required by applicable law. You may use an authorized agent where the law permits.
On an active plan, you can export any individual takeoff to Excel or PDF. We do not offer a bulk, self-service export of all account data or a self-service account-deletion tool; for a broader copy of your information, contact us at support@ollie.cloud.
Deletion is organization-scoped. Closing an organization begins a recovery window of about 30 days, after which its data is permanently purged; if the organization is deleted directly through our identity provider (Clerk), the purge happens immediately. We can also delete or de-identify individual account information on request, subject to legal and contractual retention obligations.
If you are in the EEA, the UK, or Switzerland, you may also withdraw consent where we rely on it and lodge a complaint with your local supervisory authority. If your personal data was uploaded to Ollie by a business customer as part of its project content, that customer is the controller — please direct your request to them, and we will assist as their processor.
10. California and other U.S. state privacy disclosures
If you are a California resident, the CCPA/CPRA gives you the right to know and access the personal information we collect, to correct or delete it, and to not be discriminated against for exercising these rights. Residents of other U.S. states with comprehensive privacy laws — such as Virginia, Colorado, and Connecticut — have similar rights.
We do not sell personal information, and we do not use it for cross-context behavioral advertising or targeted advertising. Under California's Shine the Light law (Civil Code section 1798.83), we do not disclose personal information to third parties for their own direct-marketing purposes.
To exercise any of these rights, email support@ollie.cloud.
11. Cookies and similar technologies
We use a small number of cookies and similar technologies. We use no advertising cookies and engage in no cross-context behavioral advertising. For full detail, see our Cookie policy.
- Marketing site (ollie.cloud). Our only analytics here is Plausible, which is cookieless and sets no cookies at all.
- Application (app.ollie.cloud). Clerk sets strictly necessary authentication and session cookies; PostHog sets product-analytics cookies and runs masked session replay; and Sentry performs error monitoring with on-error session replay.
You can opt out of analytics by emailing support@ollie.cloud, by using your browser's cookie controls, and through the analytics providers' own opt-out mechanisms. Strictly necessary cookies cannot be switched off, because the Service cannot function without them.
12. Security
We use technical and organizational measures designed to protect your information, including:
- encryption in transit (TLS) and at rest, with at-rest encryption provided by our infrastructure providers (Neon, Cloudflare R2, and Upstash) under their certifications;
- organization-scoped access controls enforced at the application layer, with database row-level security as an additional defense-in-depth measure;
- authentication that fails closed, managed by Clerk, so Ollie never stores your password;
- signed, time-limited file links and signed, idempotent webhooks; and
- internal security reviews.
The Service is provided on an "as is" and "as available" basis. We aim for high availability but do not guarantee uninterrupted or error-free operation. No method of transmission or storage is completely secure, so we cannot guarantee absolute security. If we become aware of a personal-data breach, we will notify affected customers and users without undue delay after becoming aware, as required by applicable law. Report suspected vulnerabilities or account compromise to support@ollie.cloud.
13. Children's privacy
The Service is intended for users who are at least 18 years old. It is not directed to children, and we do not knowingly collect personal information from anyone under 18 (or under 16 in the EEA/UK). If you believe someone under these ages has provided us information, contact support@ollie.cloud and we will delete it.
14. Changes to this Policy
We may update this Policy from time to time. If we make material changes, we will notify you by email or through the Service and update the effective date above. Your continued use of the Service after the change takes effect constitutes acceptance of the updated Policy. This Policy works alongside our Terms of Service, Data Processing Agreement, Cookie policy, Subprocessors list, and Acceptable Use Policy.
15. Contact us
Questions about this Policy or our data practices? Contact our privacy team at support@ollie.cloud or write to us at Ollie.Cloud LLC, 28 Spring St #5161, Princeton, NJ 08542.
For legal notices and DPA execution, email support@ollie.cloud. For general enquiries and demo requests, email hello@ollie.cloud.