SpecUp, LLC ("SpecUp," "we") builds construction compliance and field software. This policy explains what we collect, why, and what we do and do not do with it. It covers buildspecup.com and the SpecUp application.
Who we deal with. SpecUp is business software. Most information in it belongs to a construction company that is our customer. That company decides what goes in and who sees it. If you use SpecUp because your employer or a general contractor gave you access, contact them first about your information; we will help them respond.
Account information — name, work email, phone (optional), company, job title, role, and password or single sign-on identifier.
Project content you or your company enter — projects, activities, schedules, submittals, specifications and drawings you upload, quality checklists and inspections, punch and deficiency items, deliveries, daily reports, and signatures on those reports.
Photos and media — jobsite photographs and markup you add. Photos are re-encoded on capture, so embedded camera metadata (including GPS location) is not retained in the stored image.
Voice — if you use the voice log, your browser's built-in speech service converts audio to text (on Android this service is typically operated by Google as part of the browser; SpecUp does not receive or store the audio unless you choose to keep it). We store the resulting text.
Usage and technical data — pages and features used, timestamps, device and browser type, app version, IP address, and error diagnostics.
Support communications — what you send us when you report a problem.
We do not collect Social Security numbers, financial account numbers, health records, or biometric identifiers, and our terms prohibit uploading them.
To run the service and store your records; to generate the reports, packages, and documents you ask for; to authenticate users and enforce who can see what; to send service notifications; to provide support and fix defects; to secure the service and investigate misuse; to improve the product; and to meet legal obligations.
Some features use AI to suggest, draft, summarize, and answer questions from your project documents. To do that, the relevant portions of your content are sent to our AI provider over an encrypted connection and processed to return a result.
We will update this section and notify customers before adding or changing an AI provider.
We do not sell personal information and we do not share it for cross-context behavioral advertising. We share only with:
| Service provider | What it does | What it can see |
|---|---|---|
| Render | Application hosting and database (United States) | All stored application data |
| Anthropic | AI features (Russell) | Content sent for a specific AI request |
| Resend | Transactional email | Recipient name, email, notification content |
| Netlify | Marketing website hosting | Website visits and form submissions |
| Google Workspace | Our email and business files | Anything you email us |
| Sentry (planned) | Error monitoring | Technical error data, scrubbed of content |
| Microsoft 365 / SharePoint (only if your company connects it) | File publishing to your own tenant | Files your company chooses to publish, inside your own tenant |
We also share when required by law, to protect rights and safety, and in connection with a merger, acquisition, or sale of assets — in which case this policy continues to apply until replaced with notice.
Data is stored in the United States. We keep project data for as long as your company's account is active. After termination, your company can export for 30 days, and we delete within 60 days unless a longer retention is agreed in writing or the law requires us to keep it. Backups are overwritten on a rolling cycle. Support emails and business records are kept as long as needed for legal and accounting purposes.
Encrypted connections (HTTPS/TLS) for all traffic. Access to production limited to personnel who need it. Role-based access enforced on the server, so a subcontractor account cannot reach another company's records. Vendor accounts protected by multi-factor authentication. Data stored with a reputable U.S. hosting provider.
We are candid about our stage: SpecUp is an early-stage product and is not SOC 2 audited, FedRAMP-authorized, or CMMC-certified. Do not put classified information, CUI, FOUO-marked drawings, or export-controlled technical data into SpecUp. No system is perfectly secure.
If we become aware of a breach affecting your data, we will notify the affected customer's administrator without undue delay and within 72 hours of confirming it, with what we know and what we are doing.
You can access and correct most of your information in the app, or ask your company's administrator. Depending on where you live, you may have rights to access, correct, delete, or receive a copy of personal information, and to appeal a decision. Where we hold information on behalf of a customer company, we will refer your request to them and assist. To make a request, email privacy@buildspecup.com. We do not discriminate against anyone who exercises these rights.
You can turn off non-essential email notifications in your settings. Service and security messages cannot be turned off while your account is active.
Jobsite photos may include workers. Our customers are responsible for any notice or consent their sites require. If you appear in a photo and want it addressed, contact the company that runs the project, or email us and we will route it.
SpecUp is for business use by adults. We do not knowingly collect information from anyone under 18.
The website and app use cookies and local storage strictly to keep you signed in, remember preferences, and let the app work offline. We do not use advertising cookies or third-party ad trackers.
We will post changes here with a new effective date, and will notify customer administrators by email before material changes take effect.
SpecUp, LLC · privacy@buildspecup.com · Mailing address available on request (entity of record: SpecUp, LLC, Arizona Corporation Commission).
← Back to SPECUP