BlueTape AI Privacy Policy

Version 2026-09-17.1 · Effective September 17, 2026

In plain language

  • We collect what is needed to make and store inspection reports: your account details, the photographs you take, and the property and client details you type in.
  • Photographs and the comments on them are sent to Anthropic to draft findings. Nothing is sold, and nothing is used for advertising.
  • You can delete your account from inside the app. That removes your details, your photographs and your inspections; a short record of security events and payments is kept, and this policy says exactly which.

This summary is for convenience. The full policy below is what applies.

1. Who this policy is from

This policy explains what BlueTape AI ("we", "us") does with personal information in the BlueTape AI application, website and related services (the "Service").

It covers two different groups of people, and the difference matters. The first is you: the inspector or the company that holds the account. The second is everybody whose home you photograph and whose name appears on a report. We hold that second kind of information on your behalf, because you decided to collect it — you remain responsible to those people for it, and this policy sets out what we do with it while we hold it.

2. What we collect

We collect the following, and nothing else:

  • Account details: your company's name, your username, your full name, your inspector licence number, your telephone number if you give one, and your email address — required of an administrator, optional for an inspector.
  • Your password, stored only as a scrypt hash. We never hold the password itself and cannot recover it for you.
  • Two-step sign-in details, if you switch it on: a shared secret and a set of one-time recovery codes, both encrypted.
  • Password-reset codes: when you ask to set a new password, a hash of the six-digit code and when it expires. The code itself is not kept, and the record is deleted as soon as it is used, expires, or is guessed at five times.
  • Inspection content: the photographs you take, the arrows and comments on them, the property address, the client's surname, the inspection date, the estate agent's name if you enter one, and the styles, materials and section descriptions you record.
  • Your corrections: when you rewrite a comment the AI drafted, we keep both versions so later drafts for your company read more like you.
  • Technical records: your IP address, your browser or device description, when you signed in, which sessions are open, and a log of security-relevant actions such as password changes, invitations and deletions.
  • Billing records: which plan the company is on, which reports have been opened, and what has been charged.

Your email address is used for password-reset codes and nothing else. We do not collect location data, contacts, advertising identifiers, health data, or anything about you from other companies. We do not use cookies for tracking; the only cookie the Service sets is the one that keeps you signed in.

Card numbers never reach our servers. When payment is switched on, the card is entered on Stripe's own pages and we receive only a reference, the result, and the last four digits.

3. Why we hold it, and what we do with it

Account details identify you, let your company's administrator manage who has access, and print your name and licence number on the reports you produce, which is what makes them yours.

Inspection content exists to produce the report. Photographs are analysed to draft a finding and place an arrow; the comments, materials and section text you record are assembled into the finished document.

Technical records exist to keep the account secure: to show you where you are signed in, to lock out password guessing, to rate-limit abuse, and to let an administrator see what happened after something goes wrong.

Billing records exist to charge the right amount and to prove what was charged.

We do not sell personal information, we do not share it for advertising, and we do not profile anyone.

4. What is sent to the AI

BlueTape drafts findings by sending your photographs, and the text you have recorded against them, to Anthropic's API. This is the part of the Service that cannot work without sending data to somebody else, so it is set out plainly:

  • The photograph itself, when you take it as a finding or ask for it to be filed automatically.
  • The report item it belongs to, the comments already recorded in that section, and the styles and materials you have entered, when a section description is written.
  • Your company's reference library — the standard wording you have supplied — so drafts come out in your house style.

Anthropic processes this to return the draft and does not use it to train its models. We do not send the client's name, the property address or your licence number with these requests.

Corrections you make are kept and used only to improve drafts for your own company. They are never shown to, or used for, another company.

Every draft is a draft. The licensed inspector reviews and confirms it before it reaches a client, as set out in the User Agreement.

5. Who else sees it

Five companies, each doing one job:

  • Anthropic, for drafting findings and descriptions, as described above.
  • Fly.io, which hosts the Service. Our servers and stored data are in Ashburn, Virginia, in the United States.
  • Stripe, for payments, when payment is switched on. Stripe holds the card details; we do not.
  • Have I Been Pwned, when you choose a password. Only the first five characters of a hash of it are sent, which is not enough to identify the password; the password itself never leaves our server.
  • Resend, to deliver one kind of message and no other: the code that lets you set a new password when you have forgotten it. Your address is sent to them only at the moment such a code is sent. There is no newsletter and no marketing mail.

We will also disclose information where the law requires it, and we will tell you when we are allowed to.

Within your own company, administrators can see the inspections and photographs of everyone on the account. That is deliberate — it is the company's work — and it is worth knowing before you use a company account for anything personal.

6. How it is protected

The measures actually in place:

  • Everything travels over HTTPS.
  • Your name, licence number, telephone number and two-step secret are encrypted in the database with AES-256-GCM, so a copy of the database file is useless without the key.
  • Passwords are hashed with scrypt and checked against known-breached password lists when chosen.
  • Administrator accounts must use two-step sign-in before they can manage people or billing.
  • Repeated wrong passwords lock the account, and every request is rate-limited.
  • You can see every open session and end any of them, and changing your password ends all of them.
  • Photographs and inspection records are stored on an encrypted disk.

No system is perfectly secure. If a breach affects your personal information, we will tell you and the relevant authorities as the law requires.

7. How long we keep it

Inspections and photographs are kept for as long as the account exists, because a report you may be asked about years later is only useful if it is still there. Photographs also stay on the device that took them until you remove them.

Technical and security records are kept while they are useful for spotting and investigating misuse.

You can delete an individual inspection at any time from inside the app. Doing so removes it from your device and from the backup on your account.

8. Deleting your account

You can delete your account from inside the app, on the same screen you sign out from. It asks for your password, and it is not reversible.

Deleting removes your user record, your encrypted name, licence number and telephone number, every open session, and every inspection and photograph backed up to the account. If you are the last administrator, you can also delete the company, which removes everybody in it and cancels any subscription.

Three things are kept, and you are told so before you confirm:

  • The security log — which account did what, and when — because a record that can be erased by the person it describes is not a record.
  • The fact that you accepted the User Agreement, and which version.
  • The record of reports paid for, which we are required to keep for tax and accounting.

None of the three contains your photographs or your clients' details.

9. Your rights

You can ask us for a copy of the personal information we hold about you, ask us to correct it, or ask us to delete it. Deletion you can do yourself, immediately, from inside the app.

Your licence number and full name cannot be edited once the account is made, because they are printed on reports that have already gone to clients. If either is wrong, write to us and we will fix it.

Depending on where you live you may have further rights, including the right to complain to a data protection authority. We will not treat you differently for exercising any of them.

10. Children

The Service is a professional tool for licensed inspectors. It is not intended for anyone under 18, and we do not knowingly collect information from children. If you believe a child has given us information, write to us and we will remove it.

11. Changes to this policy

If this policy changes in a way that matters, we will raise the version at the top of this page and, where the change is significant, tell you in the app before it takes effect. The version you are reading now is the one that applies.

12. How to reach us

Questions about this policy, requests for a copy of your information, and corrections can all be sent to bluetapehelp@gmail.com. We answer within 30 days.

User Agreement · Sign in