Legal
Foreman AI Privacy Policy
Effective date: May 13, 2026
This Privacy Policy explains how Foreman AI collects, uses, and protects information when you interact with the Blueprints application, dashboard, marketing site, and APIs (the "Services"). Capitalized terms not defined here have the meanings given in the Terms of Service. To the maximum extent permitted by law, this Privacy Policy is incorporated into and forms part of the Terms of Service; the Terms of Service govern in the event of any conflict, except where mandatory privacy law requires otherwise.
Business-to-business notice. The Services are offered to businesses and licensed construction professionals for commercial use. Where applicable, Foreman AI treats data you submit on behalf of your business as Customer Data of that business, not as your individual personal information. Under the California Consumer Privacy Act (CCPA/CPRA), business contact information and information collected in a business-to-business context is processed under the available B2B framework to the extent permitted.
2. How We Use Information
- Deliver, operate, secure, and improve the Services, including AI-powered plan analysis.
- Train, fine-tune, and evaluate our AI models, algorithms, and product features.
- Build de-identified, anonymized, and aggregated datasets — including industry pricing, cost, and productivity benchmarks — used to develop new features, publish market insights, and improve future products.
- Provide customer support, training, and product announcements.
- Monitor abuse, enforce policies, prevent fraud, and secure the platform.
- Comply with legal obligations and respond to lawful requests.
We do not sell, rent, or trade your identifiable personal information or Customer Data to third-party advertisers, data brokers, or marketing networks. We may publish, license, sell, distribute, and otherwise commercialize aggregated and de-identified data (data that does not identify you, your company, your customers, or any specific project) — including pricing benchmarks, cost indices, productivity metrics, market reports, and other data products — for any lawful purpose. We commit not to attempt to re-identify de-identified data, and we contractually require recipients of de-identified data to make the same commitment.
Automated decision-making and AI outputs. The Services use artificial intelligence, machine learning, large language models, and other automated systems to generate plan analyses, takeoffs, estimates, schedules, RFIs, and other outputs. AI outputs are decision-support tools, not decisions. They do not produce legal, financial, employment, credit, housing, insurance, education, or healthcare effects on individuals, and they are not intended to be used for any purpose that would constitute "profiling" or "solely automated decision-making" with legal or similarly significant effects under GDPR Article 22, the Colorado Privacy Act, the California Automated Decision-making Technology rules, or comparable laws. You are solely responsible for any human review, verification, and final decision based on AI outputs. See the Terms of Service for the full no-warranty and decision-support disclaimers.
Legal bases (GDPR). Where GDPR or UK GDPR applies, Foreman AI processes personal data on one or more of the following bases: (a) performance of a contract with you; (b) our legitimate interests in operating, securing, improving, and commercializing the Services; (c) compliance with legal obligations; and (d) your consent, where required.
For details on your contractual rights regarding training and aggregation — including enterprise opt-out from AI model training — see Section 3 of the Terms of Service.
2a. Third-Party Email Integrations (Gmail & Outlook)
Foreman AI offers optional email integrations so you can search, read, and send email directly from within the application. These integrations are entirely opt-in — no email data is accessed until you explicitly connect your account.
Google Gmail Integration
When you connect your Gmail account, Foreman AI requests the following permissions (scopes):
- gmail.readonly — Read email messages and metadata so you can search and view emails within Foreman AI.
- gmail.send — Send emails on your behalf when you compose and send a message through Foreman AI.
How we use your Gmail data:
- Display email search results and message content inside the Foreman AI interface when you request it.
- Send emails you compose through the Foreman AI interface.
- Provide AI-assisted email drafting and responses when you use the Foreman Autopilot feature.
What we do NOT do with your Gmail data:
- We do not store, cache, or retain copies of your email messages on our servers. Email content is fetched in real time and displayed only during your active session.
- We do not use your email data for advertising, marketing, or any purpose unrelated to the Services.
- We do not sell, share, or transfer your email data to third parties, except as required to provide the Services or comply with law.
- We do not use your email data to train machine-learning or AI models.
Foreman AI's use and transfer of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements.
Microsoft Outlook Integration
When you connect your Microsoft account, similar permissions are requested via Microsoft Graph to search, read, and send email. The same data-handling principles described above apply.
Disconnecting Email Integrations
You may disconnect your Gmail or Outlook account at any time from the Integrations panel in your Foreman AI session. Upon disconnection, all stored OAuth tokens are immediately deleted from our systems and no further access to your email occurs.
3. How We Share Information
- With service providers that support hosting, storage, email, AI infrastructure, and analytics under confidentiality obligations.
- With your authorized teammates or workspace admins, per your settings.
- When required by law, subpoena, or to protect Foreman AI and its users.
- As aggregated or de-identified data, which Foreman AI may publish, license, sell, or otherwise commercialize without restriction.
- In connection with, or in preparation for, a merger, acquisition, financing, reorganization, joint venture, sale of all or substantially all of our assets or equity, change of control, or bankruptcy. In any such transaction, Customer Data, aggregated data, AI models, and the rights granted under the Terms of Service may be transferred to the acquiring, surviving, or successor entity.
4. Security & Retention
- We employ encryption in transit, role-based access, monitoring, and secure infrastructure designed in accordance with industry-recognized practices. No method of electronic transmission or storage is one hundred percent (100%) secure. Foreman AI cannot and does not warrant or guarantee absolute security of information transmitted to or stored on its systems, and to the maximum extent permitted by law disclaims any such warranty.
- Customer Data is retained for the duration of your subscription and deleted within 90 days of termination unless otherwise agreed. Aggregated and de-identified data, AI model weights and embeddings derived from your data, and business records required for legal, tax, audit, fraud-prevention, security, or accounting purposes are retained indefinitely and survive termination.
- Backups, audit logs, security telemetry, and dispute-defense records may be stored longer to meet regulatory, contractual, safety, or litigation-hold requirements.
- Security incident notification. In the event of a personal-data breach affecting your information, Foreman AI will notify you and applicable regulators only to the extent and within the timeframes required by applicable law. Notification is not, and shall not be construed as, an admission of fault or liability by Foreman AI or its affiliates, agents, or service providers.
5. Your Choices & Rights
Depending on where you live, you may have specific rights under privacy laws including the CCPA/CPRA (California), CPA (Colorado), CDPA (Virginia), CTDPA (Connecticut), UCPA (Utah), TDPSA (Texas), OCPA (Oregon), as well as GDPR / UK GDPR. These may include the right to know, access, correct, delete, port, restrict, or object to certain processing, and to opt out of "sales," "sharing," or targeted advertising. Foreman AI does not engage in cross-context behavioral advertising and does not "sell" or "share" personal information for advertising purposes within the meaning of those statutes.
- Update profile details in-app or by contacting privacy@foremanai.co.
- Request export or deletion of Customer Data, subject to contractual and legal limits, by emailing privacy@foremanai.co.
- Manage marketing communications via unsubscribe links or email preferences.
- Connect or disconnect third-party email accounts (Gmail, Outlook) at any time from the Integrations panel. You can also revoke Foreman AI's access directly from your Google Account permissions or Microsoft account permissions pages.
- Appeal a denied privacy request by replying to our decision email; we will respond within the timeframe required by applicable law (typically 45–60 days).
Identity verification. Before fulfilling a rights request, Foreman AI will take commercially reasonable steps to verify your identity. This may include matching information you provide against information we already maintain, requesting government-issued identification (which we will destroy after verification), or requiring you to authenticate through your account. We will not fulfill a request we cannot verify. Requests submitted through authorized agents must include written, signed authorization and proof of identity.
Limits. Foreman AI may deny or limit a request to the extent (a) verification fails, (b) the request is manifestly unfounded, repetitive, or excessive, (c) compliance would conflict with a legal obligation, contract, security or fraud-prevention need, defense of legal claims, free expression, or another permitted exception, or (d) the data has been aggregated or de-identified in a manner that cannot reasonably be linked back to you.
No discrimination. Foreman AI will not deny services, charge different prices, or provide a different level of service because you exercised a privacy right, except as permitted by law.
6. International Transfers
- We store data in the United States and rely on contractual safeguards for cross-border transfers.
- EU/UK users may enter into standard contractual clauses for additional assurances.
7. Children
The Services are not directed to individuals under 18. We do not knowingly collect personal information from children. If you believe a minor has provided data, contact us to remove it.
8. Changes to This Policy
We may update this Privacy Policy to reflect operational, legal, or regulatory changes. We will post the revised version with a new effective date and notify you when material updates occur. Your continued use of the Services after the effective date of an updated Privacy Policy constitutes acceptance of the updated terms.
9. State-Specific Disclosures
California (CCPA/CPRA). In the preceding twelve (12) months, Foreman AI has collected the categories of personal information described in Section 1 for the business and commercial purposes described in Section 2 and disclosed them to the categories of recipients described in Section 3. Foreman AI does not sell or share personal information for cross-context behavioral advertising and does not knowingly sell or share the personal information of consumers under sixteen (16) years of age. To exercise California rights, email privacy@foremanai.co.
Colorado (CPA), Connecticut (CTDPA), Virginia (CDPA), Utah (UCPA), Texas (TDPSA), Oregon (OCPA), and other state laws. Residents of these states have rights described in Section 5 and may submit requests to privacy@foremanai.co. Foreman AI does not engage in targeted advertising, sale of personal data, or profiling in furtherance of decisions producing legal or similarly significant effects, as those terms are defined under applicable state laws.
EU / UK / EEA / Switzerland. Where required, Foreman AI relies on Standard Contractual Clauses and other approved transfer mechanisms for cross-border transfers. The controller for personal data processed under this Privacy Policy is Foreman AI (United States). EU/UK data subjects may contact a supervisory authority. A Data Processing Addendum (DPA) is available to enterprise customers on request.
10. Privacy Disputes; No Private Right of Action; Governing Law
To the maximum extent permitted by applicable law, any dispute, claim, or controversy arising out of or relating to this Privacy Policy, the collection, use, retention, disclosure, or commercialization of information described herein, or any alleged privacy harm is subject to the arbitration agreement, class-action waiver, jury-trial waiver, limitation of liability, prevailing-party fees, one-year limitations period, El Paso County (Colorado) venue, Colorado governing law, and all other defensive and procedural provisions of the Terms of Service, which are incorporated herein by reference.
Except where a statute expressly grants a non-waivable private right of action, this Privacy Policy does not create, and shall not be construed to create, any private right of action, third-party-beneficiary right, or independent cause of action. Statutory rights expressly conferred by applicable privacy laws are preserved only to the extent and in the manner required by such laws.
If any portion of this Privacy Policy is held unenforceable, the remainder shall remain in full force and effect, and the unenforceable portion shall be reformed to the minimum extent necessary to make it enforceable while preserving the parties' original intent (blue-pencil reform).