Blueprint Privacy Policy

Home

Last updated: August 4, 2026

What we collect

Your account email and authentication data (via Supabase Auth and optional Google sign-in); real estate project data you create in the app (project names, tasks, contacts, notes); and, only for the specific Google and Microsoft features you use: Google Calendar events (read-only, to show upcoming events in your workspace), Google Drive files that Blueprint creates on your behalf or that you open via the file picker, Gmail send access (used only to send messages you compose inside the app), and Microsoft OneDrive/Excel files you connect.

How we use Google and Microsoft access

These connections are per-user and opt-in. Specifically: Calendar access is read-only — we never create, edit, or delete your calendar events. Drive access is limited to files Blueprint creates for you or that you explicitly select — we cannot see or access the rest of your Drive. Gmail access is send-only — we cannot read your inbox, and every email is one you wrote and chose to send from inside a Blueprint project. You can disconnect any of these at any time in Settings, which revokes our access immediately.

Requested Google scopes

Blueprint requests the following Google OAuth scopes — nothing more. This list matches the scopes configured on the OAuth consent screen for Google Cloud project keystone-502520 (project number 794437982756), and this Privacy Policy applies to that OAuth client. Each connection is opt-in and can be revoked at any time in Settings.

  • openidIdentifies your Google account so you can sign in to Blueprint without a separate password.
  • https://www.googleapis.com/auth/userinfo.emailReads only your email address, which is the identifier for your Blueprint workspace account.
  • https://www.googleapis.com/auth/userinfo.profileReads your basic profile (name and avatar) to display who is signed in.
  • https://www.googleapis.com/auth/calendar.readonlyDisplays your upcoming events beside your deals; Blueprint never creates, edits, or deletes calendar entries.
  • https://www.googleapis.com/auth/drive.fileCreates underwriting models and write-ups in your Drive and opens only the individual files you pick in Google's own file picker — Blueprint cannot see the rest of your Drive.
  • https://www.googleapis.com/auth/gmail.sendSends only the deal emails you compose inside a Blueprint project; Blueprint cannot read, list, or modify your mailbox.

Blueprint does not request any restricted scopes such as drive.readonly or gmail.readonly, and cannot read your Drive contents or your inbox.

How we use AI features

Voice commands and chat requests are processed by Anthropic's Claude to interpret your instructions and generate underwriting models, acquisition models, and write-ups. We do not use your data to train third-party AI models.

Data protection

All data in transit between your device, Blueprint, and our service providers (Supabase, Google, Microsoft, Anthropic) is encrypted using TLS/HTTPS. Your account and project data are stored at rest in Supabase's encrypted PostgreSQL infrastructure. OAuth access and refresh tokens for connected Google and Microsoft accounts are encrypted before storage and are never visible to Blueprint staff or stored in plain text. Access to production data is restricted to the systems that need it to run the app — we do not grant broad manual access to user data, and every connected service is bound by its own security and privacy terms.

Data sharing

We do not sell your data. We share data only with the service providers necessary to run the app (Supabase, Google, Microsoft, Anthropic), each bound by their own privacy and security terms.

Data retention & deletion

We retain your account and project data for as long as your account is active. If you disconnect a Google or Microsoft account in Settings, the associated access tokens are deleted from our systems immediately. If you request full account deletion by contacting us, we delete your account, project data, and any stored tokens within 30 days.

Limited Use compliance

Blueprint's use of information received from Google APIs adheres to the Google API Services User Data Policy, including the Limited Use requirements. Data accessed through Google Calendar, Drive, and Gmail is used only to provide and improve the user-facing features described above, is never used to train Claude or any other AI/ML model beyond generating your requested output, and is never sold or shared with advertisers or data brokers.

Your rights

You can request deletion of your account and associated data at any time by contacting jaysonvanjani@gmail.com.

Contact

jaysonvanjani@gmail.com