Skip to main content

Privacy Policy

Last updated: March 17, 2026

Summary

Minimal data collection. No tracking cookies. No ads. No data selling. Microphone audio stays on your device. Payments handled by Paddle. Plausible analytics is cookieless.

1. Who We Are

AcousPlan (acousplan.com) is a cloud-based acoustic design platform. This Privacy Policy explains how we collect, use, store, and protect your data. Contact: [email protected].

2. Data We Collect

Account Data: email, hashed password, display name, subscription tier. Project Data: room dimensions, materials, simulation results. AI Data: inputs processed in real-time, not retained beyond session. Microphone: audio processed client-side only, never transmitted. Payments: handled exclusively by Paddle — we never see card details. Analytics: Plausible (cookieless, no PII). Logs: masked IPs, 90-day retention.

3. How We Use Your Data

We use data to: operate the Service, process simulations, send transactional emails, monitor performance, and improve the Service. We do NOT use data for advertising, sell data, or share with data brokers.

4. AI Data Processing

AI inputs are sent to Anthropic's Claude API, which does not use API inputs for model training. Floor plan images are processed and discarded after response. Chat conversations are session-scoped.

5. Third-Party Processors

We use: Paddle (payments), Anthropic (AI), Cloudflare (CDN), Resend (email), Plausible (analytics), Contabo (hosting, Singapore). Each operates under its own privacy policy.

6. International Data Transfers

Primary servers in Singapore. Cloudflare distributes via global CDN. We rely on Standard Contractual Clauses where applicable for transfers outside your country.

7. Data Security

We implement HTTPS encryption, bcrypt password hashing, encrypted database storage, Docker network isolation, and no public database port exposure.

8. Data Retention

Account/project data: until deletion + 30-day export window. Logs: 90-day rolling deletion. Analytics: aggregated indefinitely (no PII). Payment records: per Paddle's policies.

9. Your Rights (GDPR)

EEA/UK users have rights to: access, rectification, erasure, portability, restrict processing, object to processing, withdraw consent. Email [email protected]. Response within 30 days.

10. Your Rights (CCPA/CPRA)

California residents: right to know, delete, opt-out of sale (we don't sell data), non-discrimination. Email [email protected] with subject "CCPA Request".

11. Cookies and Tracking

No tracking cookies, no ad pixels. We store in localStorage: auth token, locale, theme, calculator state. localStorage stays on your device and is never transmitted to third parties.

12. Children's Privacy

Not directed at children under 16. We do not knowingly collect data from children. Contact [email protected] to report.

13. Changes to This Policy

Material changes notified 30 days in advance. Continued use constitutes acceptance.

14. Contact

For privacy enquiries: [email protected].