Privacy Policy
Last updated: March 17, 2026
Summary
Minimal data collection. No tracking cookies. No ads. No data selling. Microphone audio stays on your device. Payments handled by Paddle. Plausible analytics is cookieless.
1. Who We Are
AcousPlan (acousplan.com) is a cloud-based acoustic design platform. This Privacy Policy explains how we collect, use, store, and protect your data. Contact: [email protected].
2. Data We Collect
Account Data: email, hashed password, display name, subscription tier. Project Data: room dimensions, materials, simulation results. AI Data: inputs processed in real-time, not retained beyond session. Microphone: audio processed client-side only, never transmitted. Payments: handled exclusively by Paddle — we never see card details. Analytics: Plausible (cookieless, no PII). Logs: masked IPs, 90-day retention.
3. How We Use Your Data
We use data to: operate the Service, process simulations, send transactional emails, monitor performance, and improve the Service. We do NOT use data for advertising, sell data, or share with data brokers.
4. AI Data Processing
AI inputs are sent to Anthropic's Claude API, which does not use API inputs for model training. Floor plan images are processed and discarded after response. Chat conversations are session-scoped.
5. Third-Party Processors
We use: Paddle (payments), Anthropic (AI), Cloudflare (CDN), Resend (email), Plausible (analytics), Contabo (hosting, Singapore). Each operates under its own privacy policy.
6. International Data Transfers
Primary servers in Singapore. Cloudflare distributes via global CDN. We rely on Standard Contractual Clauses where applicable for transfers outside your country.
7. Data Security
We implement HTTPS encryption, bcrypt password hashing, encrypted database storage, Docker network isolation, and no public database port exposure.
8. Data Retention
Account/project data: until deletion + 30-day export window. Logs: 90-day rolling deletion. Analytics: aggregated indefinitely (no PII). Payment records: per Paddle's policies.
9. Your Rights (GDPR)
EEA/UK users have rights to: access, rectification, erasure, portability, restrict processing, object to processing, withdraw consent. Email [email protected]. Response within 30 days.
10. Your Rights (CCPA/CPRA)
California residents: right to know, delete, opt-out of sale (we don't sell data), non-discrimination. Email [email protected] with subject "CCPA Request".
11. Cookies and Tracking
No tracking cookies, no ad pixels. We store in localStorage: auth token, locale, theme, calculator state. localStorage stays on your device and is never transmitted to third parties.
12. Children's Privacy
Not directed at children under 16. We do not knowingly collect data from children. Contact [email protected] to report.
13. Changes to This Policy
Material changes notified 30 days in advance. Continued use constitutes acceptance.
14. Contact
For privacy enquiries: [email protected].