What we store, who processes it, how long we keep it, and how to have it deleted. Last updated 27 August 2026.
HVAC Builder is an engineering tool. Most of what it holds is equipment data you typed — coil geometries, weather years, system graphs. This page is about the rest.
| Data | Why we have it |
|---|---|
| Account identifier — the subject id issued by our sign-in provider, plus your plan, token balance and usage counters | To attach your work to your account and meter what your plan includes |
| Your designs — saved systems, buildings, simulation runs, weather datasets you import | They are the product; they are yours |
| Supplier profile and listings, if you register as a supplier — company, contact email, territory reps, published components and systems, product links and images | Published listings are public by design; that is what a directory is |
| Quote requests (RFQ) — name, email, company and message of whoever asks a supplier for a quote, plus the design referenced | To pass the enquiry to the supplier it was addressed to |
| Credentials — SHA-256 hashes of API keys and OAuth tokens (never the values), registered OAuth clients, and your own AI provider key if you store one | To authenticate programmatic access you asked for |
| Billing identifiers — the customer and subscription ids issued by our payment processor | To reconcile a subscription with an account. We never see or store card details. |
We do not run advertising or analytics trackers. There is no third-party analytics script on any page of this site, and no advertising cookies. The only cookies in play are the ones our sign-in provider sets to keep you signed in. We do count page views on the public site — one number per day, page path and language, kept for 400 days — and nothing about the visitor: no cookie, no IP address, no referrer, no record of the request. The browser's user-agent string is read only to leave search-engine and advertising crawlers out of the count, and is not kept. We count what the app does the same way — solves, simulations, saved designs, quote requests, connector calls, assistant messages, first sign-ins, and whether each solve worked or which kind of error stopped it — one number per day, kind and plan, with nothing about who did it. When a visit arrives on one of our own advertising links, we count it under that campaign's name — the name we wrote into the link — and read nothing else from the address.
Rate limits. To stop the catalog being harvested in bulk, the server counts how many data pages have come from a network in the last five minutes. What it holds while it counts is the network the request came from — the first two or three numbers of the address, never the address itself — and a count, in memory only, forgotten within minutes and never written to disk or to the page-view figures. Signed-out quote requests are limited the same way, by address and email, for an hour. None of it is linked to an account, a session or a page you read.
To run the product you asked for: solving and simulating your designs, storing them under your account, metering your plan, billing your subscription, publishing the listings you choose to publish, and delivering quote requests to the supplier they name. Nothing else. We do not sell personal data, and we do not use your designs to train AI models.
These are the only third parties our servers talk to on your behalf:
| Processor | What reaches them |
|---|---|
| Clerk — authentication | Your sign-in identity. They hold your email and password/social identity; we hold only the identifier they issue. |
| Stripe — payments | Your payment details, which go to Stripe directly and never through our servers. |
| Resend — email delivery | The contents of a quote request, emailed to the supplier it was sent to; the contents of a bug report or feedback you file in the app, emailed to us. |
| Anthropic — the AI assistant and the MCP connector | Only when you use them: the messages you send and the parts of the design the assistant reads. If you store your own AI provider key, the traffic is billed to your account instead of ours. |
| Hetzner — hosting (Germany) | Everything above, at rest. The application and its database run on servers in the EU. |
Outbound weather data comes from PVGIS (European Commission, JRC). No personal data is sent to obtain it.
Product notes are opt-in: nothing is mailed to an account that has not ticked the box. Ticking it stores your address and an unsubscribe token; every note carries a one-click unsubscribe link that deletes both, and the box on your account does the same. Notes are written and sent by hand when there is news — there is no schedule, no open or click tracking, and the sender sees a count of subscribers, not the list.
Saved systems, buildings and supplier listings are kept until you delete them or close your account. Simulation runs are pruned automatically to your plan's limit, oldest first. A building run you share by link is readable by anyone holding that link — the results, never the design — until you stop sharing it or the run is deleted; the link is a random token, not the run's id. Quote requests are kept per supplier up to a fixed retention cap (currently 500), after which the oldest are deleted. Bug reports and feedback filed in the app — including the design snapshot the form attaches when you leave that box ticked — are kept up to a fixed cap (currently 500 across all users), oldest deleted first. OAuth access tokens expire after 8 hours and refresh tokens after 90 days; revoking a connection deletes them immediately. An API key exists until you revoke it. Deleting an item in the app deletes the record, not a flag on it.
In the app you can delete any saved system, building or run, revoke any API key, and disconnect any connected app — each takes effect immediately. To close your account and have everything associated with it deleted, or to request a copy of it, email privacy@hvacbuilder.app and we will action it. If you are in the EU or UK, the GDPR rights of access, rectification, erasure, restriction, portability and objection apply, and you may complain to your local supervisory authority.
Everything is served over HTTPS. API keys and OAuth tokens are stored only as SHA-256 hashes — a database copy would not yield a usable credential. Administrative actions require an interactive signed-in session, never a long-lived key. Access to another account's data is refused by owner scoping, not by hiding links.
HVAC Builder is a professional engineering tool. It is not directed at children and we do not knowingly collect data from them.
If this policy changes materially we will update the date above and, for changes that affect how your data is used, tell account holders by email. Questions: privacy@hvacbuilder.app.