OPEN TAKEOFF / LEGAL
Privacy Policy
Effective September 19, 2026 · Initial publication
Your drawings stay on your device in the default local workspace. Connecting a cloud drive, an AI provider, or a contribution endpoint changes where the data you choose to share goes.
Who this policy covers
OpenTakeoff is maintained by Michael Edlin / Kentucky AI. This policy covers our hosted site at opentakeoff.kentucky-ai.com and the OpenTakeoff software we distribute. Independent deployments, AI assistants, bounty platforms, and cloud providers have their own policies. Contact michael@kentucky-ai.com with privacy questions.
Plans and local work
In the default browser workspace, PDFs, images, extracted drawing text, measurements, annotations, materials, and project settings are processed on your device and stored in browser storage such as IndexedDB and localStorage. Opening a local plan does not by itself upload that plan to us. Exported files go to the destination you select. If you link a local folder, the app reads and writes that folder with your browser permission.
The local MCP server reads plans and writes exports on the machine where you run it. Your MCP client or AI assistant receives the tool results it requests, which can include drawing text, images, quantities, and project information. Its operator may process and retain those results under its own policy. Running a tool locally does not mean the connected assistant is local.
Optional connections
- Cloud storage: configured Google Drive or Microsoft 365 integrations use your sign-in and permissions to read and synchronize project files. Account identifiers, authorization tokens, and project content are processed as needed for those connections. Files and collaboration information can be visible to others with access to the selected drive or folder.
- AI features: when you use a configured AI endpoint, prompts and the context or tool results needed for that task are sent to that provider. Where the optional scanned-schedule service is enabled, a selected schedule image is sent through the hosting function to Google's Gemini service, and Google sign-in information is used to authorize the request. Provider terms, retention, and training settings apply to data they receive.
- Voice: built-in push-to-talk transcription processes microphone audio on your device. The resulting text may become part of a task you send to an AI provider.
- Dataset contributions: contributing is optional. The contribution feature sends derived geometry, quantities, finish tags, settings, selected provenance and evidence fields, and any contributor name you supply to the configured endpoint for dataset and model development. The standard payload excludes source PDFs and plan images, but derived labels or evidence can still contain identifying information. Review what you contribute and only share material you have permission to contribute. Public or distributed datasets may be copied by others; deletion from those copies or already trained models may not be possible.
Website requests and service providers
Our site uses Netlify hosting, Cloudflare Web Analytics, and Google Fonts. Serving pages, assets, and fonts involves technical request information such as IP address, browser information, requested URLs, and request time. Cloudflare Web Analytics measures page visits and performance without analytics cookies or individual visitor fingerprinting. These website requests are separate from uploading a construction plan.
See Netlify's privacy policy, Cloudflare's analytics description, and Google's privacy policy. Optional sign-in providers may use their own cookies or storage. OpenTakeoff also uses browser storage to save your workspace and preferences.
Support, purposes, and sharing
If you email us or open a support issue, we receive the information you provide, including contact details, messages, and attachments. GitHub issues are public: do not post confidential plans, credentials, or client information there. We use information we receive to respond to requests, maintain and secure the service, diagnose problems, and meet legal obligations. We do not sell personal information or use it for targeted advertising.
Information may be processed by providers delivering these services, disclosed when legally required, or shared as necessary to address fraud, security incidents, or protect legal rights. Using the default workspace does not authorize us to collect your private plans for model training.
Retention and your choices
Local project data remains until you remove it, clear site storage, or your browser removes it. Export a backup first: we cannot recover data stored only on your device. Disconnecting an integration does not delete files already stored with that provider; remove those files and revoke access through the provider as appropriate.
We retain support correspondence and information we receive for as long as reasonably needed to handle the request, maintain security and records, or meet legal obligations. Hosting and other providers apply their own retention rules. Contact us to request access, correction, or deletion of personal information we hold. We may need to verify your request, and legal requirements may limit deletion. Depending on your location, you may also have rights to object, restrict processing, obtain a portable copy, withdraw consent, or complain to a privacy authority.
Security, location, and children
No storage or transmission method is risk-free. Protect your device, backups, credentials, and access to shared folders. Providers may process information in the United States or other countries. The service is intended for construction professionals and developers, not children under 13. Contact us if you believe a child has supplied personal information.
Changes
We will update this page and its effective date when the policy changes. Material changes will be identified on this page; where required, we will provide notice or request consent before applying a new use of personal information.