01Overview
SlabSignal Tech, INC ("SlabSignal", "we", "us", "our") provides an AI construction risk command center at slabsignal.co. This Privacy Policy explains what information we collect, how we use it, who we share it with, and the choices you have. It applies to our marketing site, the SlabSignal web application, and related communications.
We treat construction project data — schedules, budgets, captures, change orders, supplier updates, and field reports — as confidential operational data of the customer organization that owns the workspace. We do not sell personal data, and we do not use customer project data to train third-party foundation models.
02Account data
When you create or use an account, we collect:
- Name, work email address, and password credentials.
- Job title, role, and the organization or workspace you belong to.
- Profile preferences such as time zone, locale, and notification settings.
- Authentication metadata such as session tokens, sign-in timestamps, and IP address used for security and fraud prevention.
03Organization and workspace data
SlabSignal is organized around customer workspaces. Workspace administrators control members, roles, projects, and access permissions. We collect workspace settings, member rosters, role assignments, invitations, and audit events created by user actions inside the workspace.
If you join a workspace through an invitation, your administrator can see account, profile, and activity information associated with your membership.
04Project and field data you upload or connect
The core purpose of SlabSignal is to analyze construction project data that you choose to upload or connect. Depending on how your workspace is configured, this may include:
- Project schedules, milestones, baselines, and look-ahead plans.
- Budgets, cost reports, commitments, and change-order records.
- Site progress photos, drone captures, and 360-degree walks.
- Plans, specifications, RFIs, submittals, and other project documents.
- Supplier and subcontractor updates, lead times, and delivery confirmations.
- Field notes, daily logs, and observations entered by your team.
- Safety incident notes and field-evidence flags raised by your team.
This information is treated as customer content. The customer organization that owns the workspace controls how it is used, shared inside the workspace, retained, and deleted.
05AI feature inputs and outputs
When you use AI features, SlabSignal sends relevant project inputs to an AI provider to generate risk summaries, schedule and cost observations, change-order analyses, supplier risk notes, safety signal flags, and recovery-plan suggestions. The output is written back into your workspace.
SlabSignal uses your project data — schedules, budgets, captures, change orders, supplier updates, and field reports — to generate risk intelligence inside your workspace only. Your data is never used to train third-party foundation models, and analysis providers process content under zero-retention agreements.
AI output is decision-support, not a decision. Risk summaries, recovery plans, and any other AI-generated content must be reviewed by qualified construction professionals before being used to act on the project. AI output may be incomplete, out of date, or wrong.
06Product usage and analytics data
We collect product usage data to operate, secure, and improve SlabSignal:
- Pages and features used, navigation paths, and feature adoption events.
- Performance, latency, and error diagnostics.
- Device, browser, and operating system metadata.
- Approximate geolocation derived from IP for security and routing.
Where required by law, analytics that are not strictly necessary are controlled by your cookie preferences.
07Billing and payment data
Paid plans are not currently active for all customers. If billing is enabled for your workspace, payments are processed by a third-party payment processor. SlabSignal receives limited billing metadata such as plan, seats, invoice amounts, billing contact, and payment status. We do not store full payment card numbers on our infrastructure.
08Contact and support communications
When you contact hello@slabsignal.co or use in-product support, we collect the contents of your message, attachments you choose to share, and any context needed to respond. We retain support communications to provide continuity across follow-ups and to improve the product.
10Email preferences and marketing consent
SlabSignal sends two categories of email:
- Transactional email — account, security, billing, and workspace activity, sent from notifications@slabsignal.co. These are required for the service and cannot be disabled while you have an active account.
- Product and editorial email — Field Notes articles, product updates, and marketing communications sent only with consent or where permitted by law. You can unsubscribe at any time using the link in any such message or by visiting your email preferences.
11Third-party service providers
We rely on a small set of vetted infrastructure providers to deliver SlabSignal. They process data on our behalf under written agreements and only for the purposes described here.
- Database, authentication, file storage, and serverless functions. Customer content, account records, and authentication data are stored on managed infrastructure operated through Lovable Cloud, which is built on Supabase. Access is restricted by row-level security policies and service-role credentials held only by SlabSignal.
- AI processing. AI features are routed through the Lovable AI Gateway to selected model providers. Inputs are sent only to fulfill the requested operation. AI providers are contracted under zero-retention terms and do not train models on customer content. API keys for AI providers are stored as server-side secrets and are never exposed to the browser.
- Email delivery. Transactional and editorial email is delivered through Resend. Resend processes recipient address, subject, body, and delivery metadata to send messages and report delivery status.
- Web hosting and CDN. The marketing site and application are served through Lovable's edge hosting infrastructure.
A current list of subprocessors and any material changes can be requested at privacy@slabsignal.co.
12Data retention
Project records, schedules, budgets, captures, and risk analyses are retained for the life of your account and for 90 days after account closure, after which they are permanently deleted unless a longer period is required by law or an active legal hold.
Backups are retained on a rolling schedule and overwritten in the normal course of operations. Deleted records may persist in encrypted backups for a limited period before being overwritten.
13Security
We protect data through, among other measures:
- Encryption in transit (TLS) and encryption at rest on managed infrastructure.
- Row-level security and per-workspace authorization for customer data.
- Secret management for API keys, with no secrets in client-side code.
- Principle-of-least-privilege access controls for SlabSignal personnel.
- Logging and monitoring of authentication and administrative actions.
No system is perfectly secure. We do not claim certifications, audits, or regulatory approvals that we have not actually completed. To report a suspected vulnerability, contact security@slabsignal.co.
14Your rights and choices
Depending on your location and applicable law, you may have rights to access, correct, export, restrict, object to, or delete personal data we hold about you, and to withdraw consent where processing is based on consent.
For personal data inside a customer workspace, the customer organization is the controller. We will refer requests to the relevant administrator and assist with fulfillment as a processor.
To exercise rights, contact privacy@slabsignal.co.
15Children's privacy
SlabSignal is built for construction professionals and is not directed to children. We do not knowingly collect personal data from children under 16. If you believe a child has provided personal data, contact privacy@slabsignal.co so we can remove it.
16International data transfers
SlabSignal is operated from the United States. If you access the service from another country, you understand that information is processed in the United States and other jurisdictions where our infrastructure providers operate. Where required, we rely on appropriate safeguards such as standard contractual clauses for cross-border transfers.
17Changes to this policy
We will update this policy as the product evolves. Material changes will be communicated through the application or by email to workspace administrators. The "Last updated" date at the top of this page reflects the most recent revision.
18Contact us
Privacy questions: privacy@slabsignal.co
General contact: hello@slabsignal.co
Security: security@slabsignal.co
SlabSignal Tech, INC
201 N Union St Ste 110, Alexandria, VA 22314, United States
This policy is governed by the laws of Commonwealth of Virginia, United States. See also our Terms of service.