OVICON BETA PRIVACY POLICY
Version: beta-1.3 Effective: on publication, and remains in effect until superseded by an updated version
Changes in beta-1.3 (September 7, 2026) — four corrections carried in this version: (1) the training-control sentence in §4 now states the schema and role separation between Customer Content and the reference data model-improvement work draws on, and the method by which that separation is verified, with no internal control identifier or verification date in the public text; (2) the provenance claim for trade rosters and reference libraries in §4 is narrowed to entries admitted since the control took effect; (3) the personnel-access sentence in §6 states that both the authorized-request branch and the service-restoration or security-incident branch are logged; (4) backup verification in §6 is stated as a recorded schedule rather than a per-backup guarantee. Items (2) and (4) apply to this document only; items (1) and (3) are carried identically in the Beta Pilot Terms.
1 · Scope
Ovicon LLC ("Ovicon") operates a preconstruction platform for commercial construction companies at app.ovicon.io, currently in an invite-only beta pilot, and a website at ovicon.io. Ovicon is a business-to-business service, not directed to consumers or anyone under 18. For documents and project data a pilot company uploads, Ovicon processes on that company's behalf as its service provider under the Beta Pilot Terms (which contain the corresponding service-provider commitments); the company controls what is uploaded. Documents provided for a pre-pilot demonstration are governed by the Demo Evaluation Terms, including their deletion rules. If you use Ovicon through your employer, contact your employer about how it uses the Service.
2 · What we collect
Account data: name, business email, organization (authentication by our identity provider — we never store passwords). Customer Content: construction documents and project data your company uploads, which may contain third parties' business contact details. Usage and diagnostics: feature events, device/browser type, IP, timestamps; error reports through our monitoring provider, configured so console output, request bodies, and local variables are not transmitted and free-text fields are truncated (see §6). Review actions: when a user accepts, edits, or reclassifies generated material, we record the action, user, and timestamp (see §4 for what we keep). Payments (paid pilots): processed by Stripe; we never receive full card numbers. Cookies and trackers: strictly necessary session, authentication, and security cookies only — no advertising cookies, no ad networks, no data brokers, and no third-party analytics, on any Ovicon property. Our standing rule: no analytics or advertising technology is added to any Ovicon property until this policy is first updated to describe it — the policy changes before the pixel does, never after.
3 · How we use it
To operate, secure, and support the Service; process your documents and generate scope output for your company; authenticate users; send transactional email; bill paid pilots; prevent fraud and abuse; improve accuracy within the limits of §4; and comply with law. We do not sell personal information and do not share it for advertising.
4 · AI and training — the commitments
- We use AI to process your documents. Customer Content is transmitted to our AI providers to extract and analyze scope. Their agreements with us prohibit training their models on it.
- We do not train models on Customer Content — not drawings, specifications, plansets, project documents, or extracted text. Stated precisely: no automated training pipeline exists in our systems today; model-improvement work is manual and reads only the categorical review data described below. Within our database, Customer Content and the reference data that model-improvement work draws on are held in separate schemas under separate role permissions, and we verify that separation by reading the live permission set on a recorded schedule.
- What we learn from: when a user corrects output, we keep the categorical classification change in our own vocabulary — never the text of the correction, never project names, party names, addresses, or dollar values.
- Changing this would require your company's separate, affirmative, revocable opt-in — never a quiet policy update — and no use occurs before our counsel-approved data-use terms take effect, whatever consent state is recorded.
- Our trade rosters and reference libraries are built from publicly issued procurement records and Ovicon-authored material, not from Customer Content — an origin our provenance controls record for every entry admitted since the control took effect.
5 · Who we share with
Only service providers under contract, processing on our instructions: Vercel (hosting; private document storage), Railway (database/processing), Clerk (identity), Anthropic (AI analysis), Upstash (queueing), Sentry (error monitoring, scrubbed per §2), Resend (transactional email), Stripe (payments), Google Workspace (business email). We update this list before any new provider processes Customer Content, and notify account administrators of the change. Within your company's workspace, teammates see shared project data. We disclose if law requires — where legally permitted, we notify your company first and produce only the minimum. In a merger or asset sale, any acquirer remains bound by this policy as it applies to information collected under it. We do not sell your information.
6 · Security
Tenant isolation enforced at the database level · uploaded documents in private object storage that returns an authorization error to any unauthenticated request · TLS in transit, encryption at rest · secrets in a dedicated manager with every commit scanned · audit logging of security-relevant actions · layered backups (point-in-time recovery, daily snapshots, and frequent automated backups, verified by test restore on a recorded schedule), with the full restore procedure exercised on a recorded cadence of at least quarterly. Our personnel do not access Customer Content except on a request authorized by your company, or as strictly necessary to restore service or investigate a security incident. Both cases are logged. The error-monitoring scrubbing described in §2 is guarded by automated testing. No system is perfectly secure; we notify affected companies without undue delay after confirming an incident.
7 · Retention
- Account data: while the account is active; deleted within 90 days after account closure, except records tax or accounting law requires.
- Customer Content and Output: until your company deletes them or the pilot ends — then a 30-day export window, deletion from active systems, and backup copies expiring on schedule (longest tier 56 days). A written litigation hold on identified projects suspends deletion until released.
- Error diagnostics: up to 90 days. Usage events: up to 24 months, then deleted or de-identified. Review actions: kept in the categorical form described in §4.
- Demo materials: per the Demo Evaluation Terms — deleted on request, otherwise 30 days after the demonstration (unless converted to a pilot).
- Billing records: as tax and accounting law require.
8 · Your rights and choices
Depending on your state, you may have the right to: know and access the personal information we hold about you; correct inaccurate information; delete it; obtain a portable copy; opt out of sale, sharing, or targeted advertising (we do none of these); and appeal a refusal, where your state provides one. We honor these rights without discrimination.
- Pilot workspace users: direct requests to your company's administrator, who controls the data; we assist them.
- Anyone else:
privacy@ovicon.io— we verify identity and respond within the period your state's law requires. - Marketing email: unsubscribe from any message; transactional and security messages continue while an account is active.
U.S.-operated; not offered outside the U.S. during the pilot.
9 · Changes
Updates change the version and date above; material changes are emailed to account administrators and presented in the Service for acknowledgment. The transition to the full Privacy Policy will be presented to every user in the application — and per §4, no change to training practices can arrive by policy update.
10 · Contact
Ovicon LLC 1870 10th Ave, Newport, MN 55055 Privacy: privacy@ovicon.io · Support: support@ovicon.io · Security & general: info@ovicon.io · Legal: legal@ovicon.io
Beta Privacy Policy beta-1.3