SiteLog AI — Privacy Policy

Effective date: August 1, 2026

SiteLog AI ("SiteLog," "we," "us") is a field documentation app for construction professionals. This policy describes what information we collect, how it is used, and the choices you have. It applies to the SiteLog AI iOS app, the sitelog-ai.com website (including team account signup and the team dashboard), and related services.

Operated by: Block Management Services LLC (Florida, USA)

Contact: support@sitelog-ai.com

Published at: https://sitelog-ai.com/privacy

What we collect

Account information. Your name, email address, and optional company name, provided when you create your account or complete setup.

Team accounts (website). If you start a team on our website, we collect your company name, your name and email, the email addresses of team members you invite, and the job names and addresses you enter. As you type a job address on the signup page, the text in that field is sent to an OpenStreetMap-based geocoding service (Photon, operated by komoot) to offer address suggestions; we store only the address you save.

Payments (team subscriptions). Team subscriptions are processed by Stripe. Your card details go directly to Stripe and never touch our servers; we receive only subscription status and billing metadata (such as the last four digits of the card and invoice history). Stripe's privacy policy applies to its processing.

Project information. Project names, project addresses, and the email addresses you choose as report recipients. These are entered by you. SiteLog does not collect your device's location — the only addresses in the app are ones you type in.

Field logs (your content). The notes you record, type, or photograph: text transcripts of voice notes, typed notes, jobsite photos, log categories, and the dates and times logs were created.

Voice recordings. When you record a voice note, audio is transcribed two ways: using Apple's speech recognition for the live words shown while you speak (Apple may process this audio under Apple's privacy terms), and by OpenAI to improve the saved transcript. OpenAI's current API data controls state that audio transcription requests have no abuse-monitoring or application-state retention. SiteLog does not keep a permanent library of your raw audio in the cloud — the transcript becomes the log.

AI processing of your logs. SiteLog sends log text to OpenAI to clean up a transcript and, when you ask a Vault question, sends relevant excerpts of your own saved logs to generate an answer. OpenAI's current API data controls allow other API requests to appear in abuse-monitoring logs for up to 30 days. OpenAI does not use API data to train its models unless the API customer opts in; SiteLog does not opt in. Vault answers are grounded only in your own data.

Diagnostics. If the app crashes or hits an error, technical diagnostic data (device model, OS version, stack trace) is collected via Sentry to help us fix it. This diagnostic data is not tied to your name or email.

Usage limits. We keep simple daily counters (for example, minutes of audio transcribed) to prevent abuse of the service. These are quantities only, not content.

What we do NOT collect

•  Device location (GPS)

•  Contacts, calendars, or browsing history

•  Advertising identifiers — SiteLog has no ads and no trackers

•  Payment card numbers — team subscription cards are handled entirely by Stripe; we never see or store them

How your information is used

•  To provide the service: transcribing notes, storing logs, generating and emailing your daily reports to the recipients you chose, and answering your Vault questions

•  To secure the service and enforce usage limits

•  To fix crashes and improve reliability

•  To send account emails (sign-in codes) and your project reports

We do not sell your data. We do not share it for advertising. We do not use your content to train AI models. We do not track you across other apps or websites.

Service providers

We use a small number of processors to run SiteLog, each only for the purpose described:

ProviderPurpose
SupabaseDatabase, file storage, and sign-in (hosted in the United States)
OpenAIVoice transcription and AI answers over your own logs (API data not used for training)
AppleOn-device / Apple-server speech recognition for live transcription
SentryCrash and error diagnostics
ResendSending sign-in codes and your report emails
StripePayment processing and billing for team subscriptions
Photon (komoot)Address suggestions while typing a job address on the website

Cookies and tracking

This website does not use advertising trackers, analytics cookies, session-recording tools, or advertising pixels, and we do not sell or share personal information for advertising. The only cookies or similar storage used are strictly necessary ones: keeping you signed in to the team dashboard after you authenticate, and the technical storage our payment processor (Stripe) and infrastructure provider (Supabase) require to deliver the service you request. Because we set no non-essential cookies, this site does not show a cookie consent banner.

Report emails

When you choose to send a report, it is emailed to the recipient address you configured for that project, with the report attached as a PDF. You control when a report is sent and who that recipient is.

Retention and deletion

Individual accounts. Your logs, photos, projects, and account information are retained until you delete them or delete your account. You can delete your account inside the app (Projects screen → Delete Account); this permanently removes your account and its associated data from our systems.

Company team accounts. A team member can delete their personal SiteLog login and profile inside the app (Projects screen → Delete My Work Account). This immediately removes their access and deletes personal data that is not part of a company record. Company-managed projects, job logs, reports, photos, and PDFs are business records owned and controlled by the company, so they remain with the company account and are reassigned to the team administrator. A historical author name and email may remain with a company job record to identify who created it. The team administrator can delete the entire company account and all company records from the team dashboard.

You can also request deletion or a copy of your personal data by emailing us at the contact address above. Company record retention is also subject to the company account owner's policies and applicable legal obligations.

Security

Data is encrypted in transit (HTTPS/TLS). Access to your data is restricted to your authenticated account; logs are also stored on your device so the app works offline.

Children

SiteLog is a professional tool and is not directed at children under 13 (or the applicable age in your region). We do not knowingly collect information from children.

Your rights

Depending on where you live (for example, California or the EU/UK), you may have rights to access, correct, export, or delete your personal information. Use the in-app deletion or contact us at the address above; we will respond as required by law.

Changes

If we make material changes to this policy, we will update the effective date above and note the change in the app or by email.