Privacy Policy for CivilTakeoff.ai
Effective Date: 06/22/2026
This Privacy Policy explains how CivilTakeoff.ai, operated by Vertigraph ("we", "us", or "our"), collects, uses, shares, and protects your information across our websites, applications, and services — including the CivilTakeoff.ai / Vertigraph web application at app.vertigraph.com, our companion email add-ins (the Vertigraph Pursuit CRM add-in for Microsoft Outlook and our Gmail add-on), and our spreadsheet add-ins for Google Sheets and Microsoft Excel (collectively, the "Service"). This policy applies to the Service as a whole, not merely to our website. By using the Service, you agree to the collection and use of information as described in this policy.
1. Applicability & International Compliance
This policy applies to all users of CivilTakeoff.ai, regardless of location. We comply with applicable privacy laws, including the EU General Data Protection Regulation (GDPR) and the California Consumer Privacy Act (CCPA).
2. Information We Collect
- Account Information: Name, email, phone, company, address, password, and other registration details.
- Uploaded Content: Civil plans, drawings, documents, and other files you upload.
- Usage Data: Analytics on features accessed, frequency, duration, and interaction with the Service.
- Device & Log Data: IP address, browser type, device identifiers, timestamps, and diagnostic logs.
- Performance & Technical Data: To optimize your experience and improve our service, we automatically collect technical performance metrics during your use of the Service, including:
- Device capabilities (CPU core count, approximate device memory)
- Performance metrics (frames per second, page load times, session duration)
- Screen and viewport dimensions
- Browser and device identifiers
- Performance events (e.g., low frame rate occurrences, high latency events)
- Project association (which project you were working on during the session)
- Payment Data: Processed securely by Stripe; we do not store full payment details.
- Location Data: IP-based location, timezone, city, region, and country (inferred from your IP address) for service delivery, security, and fraud prevention.
- Communications: Content of messages, support requests, and feedback you send us.
- Google Account & Gmail Data (when you connect Gmail): If you connect your Google account via OAuth, we access and store: (a) your Google account email address, (b) OAuth access and refresh tokens (encrypted at rest), and (c) the contents of email messages and threads you explicitly track within a CivilTakeoff.ai project, including subject, body (text and HTML), sender, recipients, attachments, message and thread identifiers, and timestamps. We do not import messages from threads you have not explicitly tracked.
- Google Sheets & Drive Data (Live Spreadsheet Sync): If you connect your Google account to keep spreadsheet cells synced with your takeoff quantities, we access and store: (a) your Google account email and basic profile, used to match the connection to your CivilTakeoff.ai account; (b) OAuth access and refresh tokens (encrypted at rest); and (c) the locations of the specific spreadsheet cells you choose to link, together with the project and takeoff category each cell is bound to. We write computed takeoff quantities into those linked cells and read them back only to verify the current value. We do not access, scan, or store any other content in your spreadsheets or Google Drive.
- Microsoft Outlook & Microsoft 365 Data (Vertigraph Pursuit CRM add-in): When you use the Vertigraph Pursuit CRM add-in in Outlook, we access your Outlook account email address and, for each email you explicitly choose to save or track, that message's subject, body (text and HTML), sender and recipient addresses, send/receive timestamps, conversation and message identifiers, and any attachments you include. If you connect your Microsoft account ("Sign in with Microsoft" or "Track Thread"), we also use your Microsoft OAuth access and refresh tokens (encrypted at rest) to retrieve the messages in the conversations you choose to track via the Microsoft Graph API. We do not read or import messages you have not explicitly saved or tracked.
- Email Engagement Data: When we send emails on your behalf or to you (such as project correspondence or RFQ emails), we may use tracking pixels (small transparent images) to determine whether and when an email was opened, along with the IP address and user agent of the device used to open it.
- Push Notification Data: If you opt in to browser push notifications, we collect and store your push subscription endpoint and encryption keys to deliver notifications to your device.
- Business Verification & Due-Diligence Data: When you use our customer/vendor verification ("Intelligence Report") feature, we collect and process information about the businesses you choose to check — including company registration and status, VAT-registration status, named directors and officers, financial-distress, insolvency, judgment, litigation, safety, accreditation, and reputation records — gathered from public registries (such as Companies House and HM Revenue & Customs), official authorities, and publicly available web content. Some of this may be personal data about sole traders or named individuals. See Section 7.
- Information from Third Parties: Data from service providers, analytics, or integrations to supplement your profile or usage.
3. How We Use Your Information
- Provide, operate, and improve our Service
- Process your files and deliver takeoff results
- Communicate with you about your account, updates, or support
- Analyze usage and improve platform performance
- Monitor and optimize platform performance and user experience
- Identify and resolve technical performance issues
- Process your uploaded documents using third-party AI services (such as Google Gemini) to provide features like scale detection, scope extraction, and construction notes analysis
- Compile customer and vendor due-diligence ("Intelligence") reports to help you assess the legitimacy, financial standing, and risk of businesses you work with (see Section 7)
- If you enable AI-powered CRM features, we may process the content of Gmail messages and threads that you have explicitly synced to a CivilTakeoff.ai project using Google's paid Gemini API, solely to provide user-facing features such as email summarization, follow-up drafting assistance, and reply suggestions. Under Google's paid Gemini API terms, your inputs and outputs are not used to train Google's generalized models. We do not retain Gmail content for AI training, do not use it to train any of our own AI/ML models, and do not allow human review of Gmail content except (a) with your explicit consent, (b) where necessary for security or abuse investigation, or (c) where required by law.
- Comply with legal obligations and enforce our rights
- Send marketing or promotional communications (with your consent)
- Detect, prevent, and address security or technical issues
Use of Google user data
Information received from Google APIs, including Gmail messages, metadata, attachments, and account information, is used exclusively to provide and improve user-facing features of the Service. We do not use Google user data for advertising, marketing, training AI/ML models, or any purpose unrelated to providing the Service's features to you.
Use of non-Google uploaded content
By using our platform, you grant us the right to use content you upload directly to CivilTakeoff.ai (such as construction plans and documents) to improve and enhance our Service, including training internal AI models in a de-identified and aggregated manner. This grant applies only to content uploaded directly to CivilTakeoff.ai and does not extend to any data obtained from Google APIs or from Microsoft / Outlook (including email content accessed through the Vertigraph Pursuit CRM add-in or the Microsoft Graph API).
4. How We Share Your Information
- With trusted service providers who assist us in operating the Service, including: Stripe (payment processing), Supabase (database and authentication), Google (Gemini AI for document analysis, Analytics for usage insights, Maps for location features), Brevo (email marketing and newsletters), Netlify (hosting and form processing), and ip-api.com (IP-based geolocation for security and timezone inference)
- When you run a customer or vendor Intelligence Report, we send that business's name and location to public registries and search services — including Companies House, HM Revenue & Customs (HMRC), and Google Gemini (with Google Search) — solely to compile the report you requested (see Section 7)
- With legal authorities when required by law or to protect our rights
- With affiliates, contractors, or consultants as needed to provide the Service
- In connection with a business transfer (e.g., merger, acquisition, sale of assets)
- With your consent, for specific purposes
- We do not sell your personal data
5. AI Services & Google API: Limited Use of Google User Data
CivilTakeoff.ai uses the Google Gemini API as its AI service provider. Gemini powers features such as construction document analysis (scale detection, scope extraction, notes identification) and, for users who opt in, email summarization and reply suggestions. No other third-party AI service processes user data.
CivilTakeoff.ai's use and transfer to any other app of information received from Google APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Scopes we request and why
When you connect your Google account, we request the following Gmail scopes only to power features you have explicitly opted into:
- gmail.readonly: to read messages on email threads you have explicitly tracked, so they can be synced into the CRM of the CivilTakeoff.ai project you've attached them to.
- gmail.send and gmail.compose: to send RFI, RFQ, and project correspondence emails from your own Gmail address when you initiate them inside CivilTakeoff.ai.
- gmail.modify: to label or organize messages associated with your CivilTakeoff.ai projects when you ask us to.
How we use Google user data
We access, store, and process Google user data only to provide and improve user-facing features of CivilTakeoff.ai. Specifically: syncing tracked email threads into your project CRM, sending email correspondence on your behalf, attaching messages to user and contact profiles, detecting RFI/RFQ replies, and (for users who enable them) AI-powered features such as email summarization and reply suggestions.
Third-party AI processing of Gmail content
CivilTakeoff.ai uses Google Gemini (via Google's paid Gemini API, Tier 1) as its sole third-party AI provider. If you enable AI-powered CRM features such as email summarization or reply suggestions, the content of Gmail threads you have synced to your project may be sent to Google Gemini solely to generate the requested user-facing output. Under Google's paid Gemini API terms, your inputs and outputs are not used to train Google's generalized AI/ML models. We do not send Google user data to any other AI provider, and we do not use Gmail content to train, fine-tune, or improve any AI/ML model that we develop.
Google Sheets & Drive scopes (Live Spreadsheet Sync)
Separately from the Gmail add-on, CivilTakeoff.ai offers a Live Spreadsheet Sync feature — available through our web application, our Google Sheets add-on, and our Microsoft Excel add-in — that keeps a cell in your own spreadsheet automatically updated with a takeoff quantity from your CivilTakeoff.ai project, including while the spreadsheet is closed. When you connect your Google account for this feature, we request only the following scopes:
- openid, userinfo.email, and userinfo.profile: at connection time only, to identify the Google account you are linking and match it to your CivilTakeoff.ai account.
- spreadsheets: to write the current takeoff quantity into the specific cells you choose to link in your Google Sheets workbooks, to re-write those cells automatically when the underlying measurements change (including from our servers while the spreadsheet is closed), and to read back those same linked cells only to verify the current value and avoid unnecessary writes. We do not read, scan, or write any cell you have not explicitly linked. We request the full Sheets scope because the feature updates cells in spreadsheets you already created, on your behalf, while the file is closed and you are offline — which the narrower per-file and editor-only scopes cannot support.
- drive.file: to access only the specific spreadsheets you open or create through CivilTakeoff.ai, scoped to those files rather than your entire Google Drive.
This sync is strictly one-way (from CivilTakeoff.ai into your spreadsheet), and the data exchanged is limited to numeric takeoff quantities and the cell locations you designate. Spreadsheet content accessed through these scopes is never sent to any AI service, including Google Gemini, and is never used to train, fine-tune, or improve any AI/ML model. We store only your encrypted OAuth tokens and your cell-binding definitions (project, takeoff category, and target cell); the quantity values themselves are computed on demand from your own takeoff data.
What we will never do with Google user data
In compliance with Google's Limited Use requirements, CivilTakeoff.ai will not:
- Use Google user data to serve advertisements of any kind, including retargeted, personalized, or interest-based advertising.
- Sell, rent, or transfer Google user data to data brokers, advertising platforms, or any third party for independent use.
- Use Google user data to develop, train, improve, or fine-tune generalized or non-personalized AI/ML models, whether our own or anyone else's.
- Allow humans to read Google user data, except (a) with your explicit, affirmative consent for specific messages, (b) where necessary for security purposes such as investigating abuse, (c) to comply with applicable law, or (d) where the data has been aggregated and anonymized for internal operations such as billing reconciliation or capacity planning.
Revoking access and deleting Google data
You can disconnect your Google account at any time from your CivilTakeoff.ai dashboard, which immediately revokes our access tokens and stops all further Gmail syncing. If you connected Google for Live Spreadsheet Sync, you can disconnect it under Settings → Spreadsheet sync, which revokes that token and stops all further cell updates. You may also revoke CivilTakeoff.ai's access directly from your Google Account permissions page. To request deletion of Gmail content or spreadsheet-binding data already stored in your CivilTakeoff.ai projects, contact us at support@vertigraph.com.
6. Microsoft 365 & Outlook Data (Vertigraph Pursuit CRM Add-in)
Vertigraph Pursuit CRM is our add-in for Microsoft Outlook. It lets you attach emails to your CivilTakeoff.ai construction projects, detect RFI and RFQ replies, view project context, and manage follow-up reminders — directly from your Outlook inbox. This section describes how the Vertigraph Pursuit CRM add-in handles your personal information; it supplements, and is governed by, the rest of this Privacy Policy.
Microsoft data the add-in accesses
- Your Outlook account email address, used to identify your account and pre-fill sign-in.
- The content of emails you explicitly choose to save or track — subject, body (text and HTML), sender and recipient addresses, timestamps, conversation and message identifiers, and any attachments you include. The add-in reads the currently open message only when you act on it; it does not scan your mailbox in the background.
- Microsoft account connection (optional): If you choose "Sign in with Microsoft" or use "Track Thread," we use your Microsoft OAuth access and refresh tokens (encrypted at rest) to retrieve the messages in the specific conversations you choose to track through the Microsoft Graph API. We request only the access needed to read those messages and identify your account.
How we use Microsoft data
We access, store, and process Microsoft and Outlook data only to provide and improve the user-facing features of the Vertigraph Pursuit CRM add-in and your CivilTakeoff.ai projects: saving the emails you select to a project, detecting RFI/RFQ replies, attaching messages to customer and vendor records, showing project context, and managing follow-up reminders. Messages and attachments you save are stored in your CivilTakeoff.ai account so you and your team can view them alongside the related project.
AI processing of Outlook content
If you enable AI-powered CRM features such as email summarization or reply suggestions, the content of Outlook messages you have saved to a project may be sent to Google Gemini (via Google's paid Gemini API, Tier 1) solely to generate the output you requested. Google Gemini is our sole third-party AI provider, and under Google's paid API terms your inputs and outputs are not used to train Google's generalized AI/ML models. We do not send your Outlook data to any other AI provider, and we do not use it to train, fine-tune, or improve any AI/ML model we develop.
What we will never do with your Microsoft data
- Use it to serve advertising of any kind.
- Sell, rent, or transfer it to data brokers or any third party for their independent use.
- Use it to develop, train, or improve generalized or non-personalized AI/ML models, whether our own or anyone else's.
- Allow humans to read it, except (a) with your explicit consent, (b) where necessary for security or abuse investigation, or (c) where required by applicable law.
Revoking access and deleting Microsoft data
You can remove the Vertigraph Pursuit CRM add-in from Outlook at any time, and you can disconnect your Microsoft account from your CivilTakeoff.ai dashboard, which revokes our stored Microsoft tokens and stops further access to your Outlook mail. You may also revoke access directly from your Microsoft account permissions page. To request deletion of Outlook content already stored in your CivilTakeoff.ai projects, contact us at support@vertigraph.com.
7. Business Verification, Customer & Vendor Due Diligence
CivilTakeoff.ai offers an optional Intelligence Report feature within our Pursuit CRM that helps you assess the legitimacy, financial standing, and risk of companies you add as customers or vendors. When you or your organization runs a report on a business, we compile information about that business from public registries, official government sources, and the open web, and present it to you as a risk summary. This section describes how that feature handles information; it supplements, and is governed by, the rest of this Privacy Policy.
Information we process about the businesses you check
For each business you choose to verify, we may collect and process: the business's name, trading address, and website; company registration number, type, status, and incorporation date; nature-of-business (SIC) codes; VAT-registration status and number; filed-accounts status and registered charges; the names and roles of company officers and directors; director disqualification and conduct records; insolvency and bankruptcy events; county court judgments (CCJs), liens, and payment defaults; litigation and regulatory records; health-and-safety enforcement records; trade accreditations; and online reviews and reputation signals. Where the business is a sole trader or partnership, or where company officers are named, some of this is personal data about individuals. We do not collect company officers' full dates of birth.
Sources we use
Depending on the country of the business being checked, these sources may include:
- United Kingdom: Companies House, HM Revenue & Customs (HMRC) "Check a UK VAT Number" service, the Health and Safety Executive (HSE), The Gazette, court and judgment records, and construction prequalification/accreditation schemes.
- Ireland and other European countries: the relevant national company register, the national occupational-health-and-safety authority, and insolvency and court records.
- United States and elsewhere: state and federal business and contractor-licensing registries, OSHA, and equivalent public records.
- All countries: publicly available web content, retrieved and summarized using our AI provider, Google Gemini (with Google Search).
Lawful basis (UK & EU GDPR)
Where this feature processes personal data about individuals (such as sole traders or named directors), we rely on the legitimate interests of you and of CivilTakeoff.ai — namely conducting commercial due diligence, counterparty and credit-risk assessment, and the prevention of fraud — as the lawful basis under Article 6(1)(f) of the UK GDPR and the EU GDPR. We have weighed these interests against the rights and freedoms of the individuals concerned: the information used is limited to data already published in official public registers or otherwise made publicly available, and is used only for legitimate business-vetting purposes. You are responsible for ensuring that your own use of any report complies with applicable law.
Purpose limitation
Information obtained through this feature — including any data from HMRC and Companies House — is made available to you solely so that you can carry out due diligence on the business concerned, consistent with the stated purpose of those services. You agree to use it only for that purpose. We do not use this information to serve advertising, we do not sell or rent it, and we do not use the contents of these due-diligence reports — or any data obtained from HMRC, Companies House, or other official registries — to train, fine-tune, or improve any generalized or non-personalized AI/ML model.
Source acknowledgements and no affiliation
This feature uses public-sector information. Companies House data is Crown copyright and is used under the terms that permit reuse of public register information. UK VAT-registration data is provided by HMRC for the sole purpose of due diligence on VAT-registered businesses. CivilTakeoff.ai and Vertigraph are independent and are not affiliated with, endorsed by, or approved, accredited, or recognised by HMRC, Companies House, or any other government body. Where a report states that a detail was "verified with HMRC" or "verified on Companies House," this means only that the specific record (such as a VAT number or company number) was confirmed against that source; it is not a statement that our software is government-approved.
Accuracy and limitations
Intelligence Reports are generated automatically, in part using AI, from third-party and public sources that may be incomplete, out of date, or inaccurate, and some records may not be accessible to us. Reports are provided for your information only and do not constitute legal, financial, credit, or other professional advice, and are not a guarantee of any business's legitimacy, solvency, or future performance. You should independently verify any material finding before relying on it, and you remain solely responsible for your own business decisions.
Security, retention, and the rights of the businesses you check
We protect the credentials used to access these registries and transmit and store report data using encryption in transit and at rest. We retain an Intelligence Report for as long as its related customer or vendor record exists in your account, so the report remains available to you and can be refreshed; reports are deleted when you delete the underlying record or your account, and can be re-run to obtain current information. If an individual who is the subject of a report (for example, a named director or a sole trader) wishes to exercise their data-protection rights — including access, correction, objection, or erasure — they, or you on their behalf, may contact us at support@vertigraph.com, and we will respond in accordance with applicable law. Because much of this information originates from official public registers, the most authoritative corrections are those made at the source registry.
8. International Data Transfers
Your information may be transferred to, processed, and stored in the United States or other countries where we or our service providers operate. We take steps to ensure appropriate safeguards for international transfers as required by law.
9. Cookies & Tracking Technologies
We use cookies, browser APIs, and similar technologies to personalize content, provide social media features, analyze traffic, improve your experience, and monitor performance. Some technologies are necessary for the operation of the Service; others require your consent. You can control cookies through your browser settings or cookie banners. Note that performance monitoring uses standard browser APIs (such as navigator.hardwareConcurrency and navigator.deviceMemory) and cannot be disabled without impacting service functionality. We also use tracking pixels (tiny transparent images) in certain emails to measure email engagement, as described in Section 2 above.
10. Data Retention
We retain your information as long as necessary to provide the Service, fulfill the purposes described in this policy, resolve disputes, enforce agreements, and comply with legal obligations.
11. Data Security
We use industry-standard security measures, including encryption in transit and at rest, to protect your data. However, no system is 100% secure. We encourage you to use strong passwords and protect your account credentials.
12. Children's Data
The Service is not directed to children under 18. We do not knowingly collect personal information from children under 18. If you believe a child has provided us with personal data, please contact us and we will promptly delete it.
13. Your Rights & Choices
- Access or update your personal data
- Request deletion of your account and associated files
- Request a copy of your stored data (data portability)
- Opt out of marketing communications
- Withdraw consent for processing (where applicable)
- Object to or restrict certain processing activities
To exercise your rights, please contact us at support@vertigraph.com. We will respond in accordance with applicable law.
14. Third-Party Sites & Services
Our Service may contain links to third-party websites or services. We are not responsible for the privacy practices or content of those sites. Please review their privacy policies before providing information.
15. Changes to This Policy
We may update this Privacy Policy from time to time. Material changes will be communicated via email or through our platform. The revised policy is effective immediately when posted unless otherwise stated.
16. Contact
For privacy-related questions or requests, email us at:
📧 support@vertigraph.com
By using CivilTakeoff.ai, you acknowledge that you have read, understood, and agree to this Privacy Policy.