EnginAIer is built local-first. Your drawings and models never leave your computer. Your conversations do. This policy explains exactly where that line falls, who else processes your data, and what you can require us to do with it.
Digital Thread AI is the data controller for the personal data described in this policy. EnginAIer is the software and service Digital Thread AI provides; the company, not the product, is the controller and the party accountable to you and to supervisory authorities.
This policy covers the EnginAIer desktop application, the local connector, the CAD and BIM plugins, the website, and the EnginAIer cloud service.
[PLACEHOLDER 1 — registered legal name and company number.] Insert Digital Thread AI's full registered legal name including its legal form (the correct form — "Ltd", "LLC", "Inc.", "Pty Ltd" or otherwise — is not yet confirmed and must not be guessed) and its company registration number.
[PLACEHOLDER 2 — registered address.] Insert Digital Thread AI's registered postal address. GDPR requires the controller to be identifiable and contactable, so this cannot be left out at publication.
[PLACEHOLDER 5 — EU and UK representatives.] If Digital Thread AI is established outside the EU/EEA but offers the Service to people in it, an Article 27 EU representative must be appointed and named here, and a UK representative for UK users. Whether this applies depends on where the company turns out to be established — see Placeholder 1.
This is the most important section of this policy. EnginAIer runs a connector on your own Windows machine. It talks to your CAD software over Windows named pipes — a local, machine-only channel. Every tool the assistant calls executes there.
Read this before assuming your project is private. Keeping a drawing on your machine does not keep its contents private if you describe them in a message. Whatever you type, and whatever a tool reports back that the assistant needs in order to answer, is transmitted to our servers and on to our AI provider. Do not enter information you are not permitted to disclose to a third-party AI provider.
We do not retain the content of your conversations on our servers. The cloud service relays each turn to the AI provider and returns the answer; what it records afterwards is the metering data — how many tokens, which model, what it cost — and not what was said. Your readable chat history is the copy kept on your own machine.
| Category | Data | Source |
|---|---|---|
| Account | Email address, username, hashed password (bcrypt — we never store the password itself), account creation date, the version of the Terms you accepted and when | You, at registration |
| Organization | Organization name, your role in it, membership | You or your organization's administrator |
| Billing | Plan, billing interval, credit balance, monthly allowance, reset date, Stripe customer and subscription identifiers | You and Stripe |
| Usage metering | Per request: agent used, AI model, input and output token counts, provider cost, platform fee, charged amount, timestamp | Generated by the service |
| Conversation content | Message text, in transit only, for the purpose of generating a reply | You, through the app |
| Integration tokens | Autodesk access and refresh tokens, their scope, expiry and the app that issued them; APS client credentials if you or your organization supply your own | Autodesk, when you connect |
| Preferences | Selected AI model | You |
| Technical | Server logs generated when handling requests, including IP address and timestamps | Automatic |
We do not use advertising cookies or third-party analytics trackers on the website. We do not sell personal data, and we do not share it for behavioural advertising.
We do not currently verify that you own the email address you register with.
The connector writes several things to a data folder on the machine it runs on. For a desktop
customer, that machine is your own PC, and we have no access to it:
You control this data directly. Deleting it is a matter of removing those files or uninstalling the app; you do not need to ask us, and we cannot do it for you. Autodesk access tokens borrowed by the connector are held in memory only and are never written to disk there.
Because this data sits on your own hardware, its security is your responsibility — disk encryption, machine access control and backups are yours to manage.
| Purpose | Legal basis (GDPR Art. 6) |
|---|---|
| Creating and running your account, authenticating you | Performance of a contract |
| Relaying conversations to the AI provider and returning answers | Performance of a contract |
| Metering usage, charging credit, taking payment, invoicing | Performance of a contract; legal obligation for tax and accounting records |
| Recording which version of the Terms you accepted, and when | Legal obligation; legitimate interest in proving agreement |
| Connecting to Autodesk Construction Cloud on your behalf | Performance of a contract, at your request |
| Keeping the service secure, preventing abuse and fraud | Legitimate interests |
| Service and security notices about your account | Performance of a contract; legitimate interests |
We do not use your data for automated decision-making producing legal or similarly significant effects. We do not use your content to train our own models, and we do not profile you for marketing.
These are the third parties that process data on our behalf. Each is bound by a data processing agreement.
| Subprocessor | What it does | What it receives |
|---|---|---|
| Anthropic | Provides the AI models behind every conversation. We call it with our own API key on your behalf. | The full text of each conversation turn — your messages, prior context, and tool results |
| Render | Hosts the EnginAIer cloud service, in its Frankfurt region. | All data handled by the cloud service, including data in transit |
| MongoDB Atlas | Managed database for accounts, organizations, billing state and usage records. | Account, organization, billing and metering data; Autodesk tokens |
| Stripe | Payment processing for subscriptions and top-ups. Stripe is a controller in its own right for payment data. | Your email, the amounts charged, and the card details you give it directly — we never see or store card numbers |
| Autodesk | Only if you choose to connect an Autodesk account for ACC access. Not a subprocessor of ours in the ordinary sense — you are authorising us against your own Autodesk account. | The OAuth authorisation you grant, and requests the connector makes with your token |
Anthropic is worth singling out. Everything you type in a chat is sent to Anthropic for processing, along with enough surrounding context for the model to answer. Anthropic's handling of that content is governed by our commercial agreement with them and their published policies. If your work is covered by a client confidentiality obligation, an NDA, or export control rules, check that disclosure to an AI provider is permitted before using the Service on it.
We will update this list before adding a new subprocessor that processes personal data.
The EnginAIer cloud service and its database are hosted in the European Union, in the Frankfurt region. For users in the EU and EEA, account, billing and metering data therefore stays in the EU at rest.
Conversation content is transmitted to Anthropic for processing, which may involve a transfer to the United States. Stripe likewise operates internationally. Where personal data is transferred outside the EEA or UK, it is done under an appropriate safeguard — Standard Contractual Clauses, the EU–US Data Privacy Framework where the recipient is certified, or the UK International Data Transfer Addendum.
[PLACEHOLDER 8 — international transfer mechanisms.] Confirm and name the specific transfer mechanism relied on for each subprocessor, and record the transfer impact assessment. Do not publish this section as final until the executed DPAs with Anthropic, Render, MongoDB and Stripe have been checked against it.
| Data | Kept for |
|---|---|
| Account record | As long as your account is open |
| Conversation content on our servers | Not retained — relayed to the AI provider and discarded once the reply is returned |
| Usage metering records | While the account is open, and afterwards where needed for tax, accounting and dispute resolution |
| Billing and payment records | As required by tax and accounting law, typically several years, independently of account closure |
| Autodesk tokens | Until you disconnect, or the account is deleted — disconnecting removes them immediately |
| Terms acceptance record | Retained after closure as evidence of the agreement you entered into |
| Server logs | A short operational period, then discarded or aggregated |
| Local chat history, uploads and CAD files | On your machine, under your control, until you delete them |
Deleting your account. Email us and we will delete your account record and personal data, except where we must keep something to meet a legal obligation — principally financial records, and the record that you accepted the Terms. Where data must be kept, we keep the minimum and stop using it for anything else. Deletion on our side has no effect on the files on your own machine, which remain yours.
[PLACEHOLDER 9 — concrete retention periods.] State the concrete retention periods actually operated — how long server logs are kept, and the exact statutory retention period for financial records in the governing jurisdiction. "A short operational period" is not a sufficient answer under GDPR Article 13(2)(a).
If you are in the EU, EEA or UK, the GDPR (and the UK GDPR) give you the following rights. We extend the same handling to all users regardless of location.
To exercise any of these, contact Digital Thread AI at the address in section 14. We respond within one month, extendable by two further months for complex requests, and we will tell you if we need the extension. We may ask you to confirm your identity first. There is no charge unless a request is manifestly unfounded or excessive.
Note that much of what you may want to reach — your conversations, your uploads, your drawings — is on your own machine, not ours. You can access and delete it directly without making a request to us.
No system is perfectly secure. If we become aware of a personal data breach likely to result in a risk to your rights, we will notify the relevant supervisory authority within 72 hours and, where the risk is high, notify you directly.
If you use EnginAIer through an organization account, its owners and administrators can see usage attributed to you — which agent and model you used, token counts, cost and time — because they pay for the shared credit pool. They cannot see the content of your conversations, which we do not retain.
Where an employer provides the account, that employer may itself be a controller for your use of it, and its own privacy notice will apply alongside this one.
The Service is a professional engineering tool and is not directed at children. It is not for anyone under 18. We do not knowingly collect data from children; if you believe a child has given us personal data, contact us and we will delete it.
We may update this policy. Each version carries a version number and effective date, shown at the top of this page. This policy is incorporated into the Terms of Use, so a material change is published as a new Terms version and you will be asked to accept it before continuing to use the Service. Your acceptance is recorded against your account with its version and timestamp.
The controller is Digital Thread AI. Privacy questions, data subject requests and account deletion should be sent to the address below.
[PLACEHOLDER 6 — privacy and data protection contact email.] Insert the email address that receives privacy questions, data subject access requests, erasure requests and breach reports. GDPR requires the controller to be contactable, and this is the address relied on for that. No address has been assumed here, because publishing one that nobody monitors would leave statutory requests unanswered.
[PLACEHOLDER 7 — DPO and lead supervisory authority.] Confirm whether a Data Protection Officer is required; if one is appointed, name them and give their contact details. Also name the lead supervisory authority for EU users, which follows from where the company is established.
Questions about the agreement itself, billing and refunds go to the contact given in the Terms of Use.