BitBuilder

Privacy

What we do with your data.

A short policy for a small site: what we collect, who helps us handle it, how long we keep it and what you can ask us to do with it.

Last updated 13 September 2026

Who we are

BitBuilder is a software studio based in Romania. We decide how the personal data described here is handled, which under the GDPR makes us the data controller. For anything on this page, including any of the requests below, write to rosu.ovi@gmail.com.

What we collect

Only what the site needs to do its job:

  • Account details. Your email address, the name you give us, and a password held as a hash by our authentication provider. We never see the password itself.
  • What you create in the app. Projects you add, the prompts you send to the AI tools, and the results those tools return.
  • Messages you send us. If you email us, we keep the message so we can reply and remember the conversation.
  • Technical records. Our host keeps short-lived server logs, which include IP addresses, so the service can be operated and abuse investigated.

We do not run advertising, analytics or profiling on this site, and we do not buy or sell personal data.

Why we are allowed to use it

  • To give you the account you asked for — creating it, signing you in, storing your projects and running the AI features. This is performance of our contract with you.
  • To keep the service working and secure — logs, rate limiting and abuse prevention. This is our legitimate interest in running a service that stays up and is not misused.
  • To reply to you when you get in touch, which is either our contract with you or our legitimate interest in answering enquiries.

Who else handles it

We use a small number of providers to run the service. They process data on our instructions and for no purpose of their own:

  • Supabase — the database, sign-in and file storage behind your account.
  • Railway — hosting for the application itself.
  • Resend — sending transactional email, such as confirmation and password reset messages.
  • Anthropic and OpenAI — running the AI models, when you use an AI feature.

These providers operate outside the European Economic Area, so using them means your data may be processed elsewhere. We rely on the data-processing terms each of them publishes, which include the safeguards required for international transfers. We will tell you who the current providers are on request.

The AI features in particular

When you use an AI feature, the text you submit is sent to the model provider named above so it can generate a response. The prompt and the result are stored against your account so you can see your own history.

We do not use your prompts or results to train models, and we do not read them except where we have to in order to investigate a fault or abuse. Do not put information in a prompt that you would not be comfortable sending to a third-party provider.

How long we keep it

Account data, projects and AI history stay for as long as your account exists. Ask us to delete the account and we remove them, allowing a short period for the deletion to pass through our providers' backups. Email correspondence is kept while it is useful for the conversation it belongs to. Server logs are short-lived and held by our host.

Your rights

Under the GDPR you can ask us to give you a copy of your data, correct it, delete it, export it, restrict what we do with it, or object to processing we base on legitimate interests. Write to rosu.ovi@gmail.com and we will reply within one month.

If you think we have handled your data badly, please tell us first so we can fix it. You also have the right to complain to a supervisory authority — in Romania that is the National Supervisory Authority for Personal Data Processing (ANSPDCP).

Cookies and browser storage

The public pages set no cookies at all. Signing in sets a session cookie, and the site remembers your appearance choice in your browser. Everything stored, and how to clear it, is listed on the cookies page.

How we protect it

Traffic is served over HTTPS only. Database access is row-level restricted so one account cannot read another's data, API keys are held on the server and never sent to your browser, and the AI endpoints are rate limited. No service is perfectly secure, and we will tell you and the supervisory authority if a breach affects you and the law requires it.

Changes to this policy

If we change how we handle personal data we will update this page and the date at the top. Where a change materially affects you and you have an account, we will email you.