Privacy Policy

Effective July 29, 2026

Who we are

Punchlist Live (punchlist.live) helps construction teams turn site walkthrough videos into punch lists. If you have any questions about this policy or your data, contact us at support@punchlist.live.

What we collect

  • Account information: your name, email address, and password (stored as a bcrypt hash).
  • Content you upload: walkthrough videos, extracted photos and frames, transcripts, tasks, and comments.
  • Product usage: pages viewed, features used, projects created, walkthrough-processing outcomes, task-review actions, exports, and invitations.
  • Acquisition data: referring page, landing page, campaign tags (such as UTM parameters), and ad-platform campaign and click identifiers. Analytics events record only whether a click identifier was present rather than copying the raw identifier into PostHog event properties.
  • Public-site interactions: clicks, form submissions, scrolling, mouse movement, navigation, and session-replay snapshots collected through PostHog. Form and input values are masked in replay.
  • Technical data: IP address, approximate location derived from IP, browser, device, operating system, timestamps, performance information, and error or diagnostic data.
  • Cookies and similar storage used to keep you signed in, remember analytics context, connect activity across a session, and measure campaign performance.

We do not use session replay in the signed-in project workspace. Uploaded videos, transcripts, project names, task text, comments, and other customer project content are not intentionally included in replay. We still record limited product events there so we can measure whether the service is working and which features are used.

How we use it

We use your data to provide the service. That includes AI processing of your uploads: audio is transcribed and tasks are drafted using third-party AI providers (OpenAI; OpenRouter). AI output is a draft for human review. We also use data to operate and secure the service, troubleshoot errors, improve the product, understand the signup and activation funnel, attribute signups to campaigns, measure advertising effectiveness, optimize advertising spend, provide support, and comply with legal obligations.

Analytics, session replay, and advertising

We use PostHog for product analytics, web analytics, performance measurement, and session replay on the public website and signup journey. Replay can show the page structure and how a visitor navigates it, but input values are masked. We use campaign tags and conversion events to compare traffic sources and understand whether visitors sign up and reach useful product milestones.

We do not currently load Meta or LinkedIn advertising tags. If we enable them, those providers may receive page URLs, referrers, IP address, browser/device data, cookie or similar identifiers, and conversion events such as signup. We will use required consent and opt-out controls before enabling those tags where applicable. Server-side advertising integrations are not used to bypass browser, platform, or legal privacy choices.

Cookies and similar technologies

Essential cookies support authentication and security. PostHog uses cookies, local storage, and similar technologies for analytics, attribution, and session continuity. Blocking or deleting them may reduce measurement accuracy and can affect sign-in or other service features when the technology is essential. Advertising cookies will be described and controlled separately if advertising tags are enabled.

Where it lives

Files you upload are stored on DigitalOcean Spaces in US data centers. Our application database is hosted with our infrastructure provider.

Service providers (subprocessors)

  • DigitalOcean — hosting and storage
  • OpenAI — transcription and AI processing
  • OpenRouter — AI processing
  • PostHog — product analytics, web analytics, performance measurement, and public-site session replay
  • Sentry — error monitoring
  • Postmark — transactional email
  • Meta and LinkedIn — advertising measurement and optimization, only if their advertising tools are enabled

Sharing

Project content is visible to the members of that project. We disclose data to service providers that process it for the purposes above and when required by law, to protect rights and safety, or as part of a business transaction. We do not sell personal data for money. We do not currently share personal data for cross-context behavioral advertising. If that changes, we will provide any notice and opt-out mechanism required by applicable law before the processing begins.

Retention and deletion

We keep your data while your account is active. Deleting your account (Settings → Delete account) permanently removes your account and everything you own; uploaded files are removed from storage within 30 days. Analytics, diagnostic, and campaign data are kept according to our configured provider retention periods and only as long as reasonably necessary for measurement, security, dispute resolution, and legal obligations. Aggregated or de-identified information may be retained longer when it can no longer reasonably identify you.

Your choices

You can access and update your information in the app, and delete your account in Settings. You can also control cookies through your browser, although blocking essential cookies may prevent parts of the service from working. Depending on where you live, you may have rights to request access, correction, deletion, portability, or restriction of certain processing, or to opt out of certain sale, sharing, targeted advertising, or profiling. Where applicable, we will honor valid browser-based opt-out preference signals for processing to which they apply. To make a request, email support@punchlist.live. We may need to verify your identity before completing it.

Children

Punchlist Live is not directed at children under 13.

Changes

We will update this page and the effective date above when this policy changes.