Privacy Policy
Last updated July 2026
Biilda is local-first: everything you build and your operational data stay on your own machine. This policy explains exactly what information we do hold to run accounts, AI access, and billing, what we never see, who processes data on our behalf, and your rights.
What stays on your machine — and never reaches us
Your workflows, AI employees, features, skills, tasks, connector configurations, run history, chat history, local files, and all connector credentials and secrets remain on your device. Secrets are encrypted with your operating system’s secure storage (Keychain on macOS, Windows credential protection). We do not upload, back up, or have any ability to access this data. Backups and encrypted exports are created and stored locally by you.
What we hold server-side
Account: your email address and a hashed password (managed by our sign-in provider). Profile: the details you choose to give us during signup — name, country/region/city, business name, and your onboarding answers (role, team size, goals, how you found us). Billing: your credit balance, transaction history, and usage metering — which quality tier was used, credits consumed, and timestamps. We do not receive card numbers; payments are handled entirely by our payment provider.
Your prompts pass through us but are not kept
When Biilda calls an AI model, your request is routed through our cloud relay to the model provider and the response streams back to your machine. We do not store the content of your prompts or the model’s responses server-side; our metering records only tier, token quantities, cost, and time. Operational logs are retained for a maximum of 14 days for debugging and abuse prevention and never include more content than necessary.
Who processes data on our behalf
We use a small set of processors: Amazon Web Services (United States region) for accounts, billing records, and infrastructure; AI model providers (currently Anthropic) which receive the content of the AI requests you make in order to generate responses, under their commercial API terms — your requests are not used to train their models; and our merchant-of-record payment provider (currently Stripe, whose Link service appears as the seller on receipts) which handles checkout, payment, tax collection, and receipts. If you opt in to product analytics (below) or a crash report is sent, the relevant analytics/error-monitoring provider processes that data. We do not sell your personal information, and we do not share it with anyone else except as legally required.
Analytics is opt-in
Product analytics are off by default. We collect usage analytics only if you explicitly opt in, and you can turn it off at any time in the app’s settings. Marketing email is likewise opt-in; when you opt in we record the time of your consent, and every message includes an unsubscribe.
Cookies
The website uses only the cookies and local storage needed to keep you signed in and to remember basic preferences. We do not use advertising cookies or cross-site trackers.
How long we keep account data
Account, profile, and billing records are kept while your account is active and as required afterward for tax, accounting, and fraud-prevention obligations. Operational logs are deleted within 14 days.
Your rights — export and deletion
You can request a copy or the deletion of the account data we hold at any time by emailing support@biilda.com from your account address; we honor these requests regardless of where you live, including rights under GDPR (EU/UK), PIPEDA (Canada), and the CCPA (California). Deletion removes your profile and account; billing records we are legally required to retain are kept only as long as the law requires. Because your created work lives locally, deleting it is as simple as removing it from your machine — we could not delete it for you even if asked, because we never had it.
Where data lives and international transfers
Our servers are in the United States (AWS us-east-1). If you use Biilda from elsewhere, your account data is processed in the United States, and AI requests are processed by the model provider in the regions they operate. We rely on recognized safeguards (such as standard contractual clauses) where transfer rules apply.
Children
Biilda is not directed at children and may not be used by anyone under 16 (or the age of digital consent in your jurisdiction). We do not knowingly collect children’s data.
Changes and contact
If we materially change this policy we will notify you in the app or by email before the change takes effect. Privacy questions and requests: support@biilda.com.