Privacy Policy
Last updated: July 10, 2026
This policy explains what data AI Internal Tool Builder collects, why we collect it, who we share it with, and the choices you have.
Overview
AI Internal Tool Builder (“we”, “us”, or the “Service”) helps teams generate internal tools from natural-language prompts. This policy applies to our website, application, and APIs. By using the Service you agree to the practices described here.
Information we collect
- Account data. Your email address and organization details, provided when you sign up or are invited to a workspace. We use passwordless magic-link authentication, so we do not store passwords.
- Workspace content. The tool specifications, prompts, connected data sources, and uploaded files you create or import in order to generate and run tools.
- Usage and telemetry. Product events, AI-generation metadata (model, token counts, credits consumed), audit-log entries, and basic device/browser information used to operate and secure the Service.
- Billing data. Subscription tier and payment status. Card details are handled directly by Stripe; we never receive or store full card numbers.
How we use your information
- Provide, maintain, and improve the Service and generate the tools you request.
- Authenticate users, enforce plan limits, and meter AI-credit usage.
- Detect, prevent, and investigate abuse, security incidents, and fraud.
- Communicate with you about your account, billing, and material changes to the Service.
Subprocessors
We rely on a small set of trusted infrastructure providers to run the Service. Each processes data only as needed to provide their service to us:
- Supabase — managed Postgres database and authentication hosting for workspace content and account data.
- Stripe — subscription billing and payment processing.
- Anthropic — the Claude models that power tool generation. Prompts and the minimum context required for a generation are sent to Anthropic to produce your tool.
- Vercel — application hosting and content delivery.
Data retention
We retain workspace content for as long as your account is active. When you delete content or close your account, we remove or anonymize the associated data within 30 days, except where a longer period is required for legal, tax, security, or backup purposes. Audit-log and billing records may be retained as required to meet our compliance obligations.
Security
Data is encrypted in transit (TLS) and at rest. Every tenant table is isolated with row-level security keyed to your organization. For more detail, see our Security page.
Your rights
Depending on your jurisdiction, you may have the right to access, correct, export, or delete your personal data, and to object to or restrict certain processing. To exercise these rights, contact us using the details below. Business-tier customers may request a Data Processing Addendum (DPA).
International transfers
Our subprocessors may process data in the United States and other countries. Where required, we rely on appropriate safeguards such as Standard Contractual Clauses for cross-border transfers.
Changes to this policy
We may update this policy from time to time. Material changes will be reflected by updating the “Last updated” date above and, where appropriate, by notifying you directly.
Contact
Questions about privacy? Email us at privacy@aitoolbuilder.app.