Privacy Notice
This Privacy Notice describes how BuildingLogiX, Inc. (“BuildingLogiX”) handles personal information and operational building data in connection with the bdx-mcp service. It does not describe how any third-party AI client you connect to the Service handles that data — for that, consult the AI client provider's own privacy notice.
1. What we collect
- Account identity. The email address you sign in with, the Supabase user identifier issued at sign-in, and the tenant your administrator linked you to.
- Authorization records. The MCP client registrations and API keys issued to your tenant, the redirect URIs registered for each client, and timestamps of when each was created or revoked.
- Policy acceptance. The fact that you accepted the current Terms / AUP / Privacy bundle, the version you accepted, the timestamp, and your browser's IP and user-agent at the moment of acceptance. This is the record we rely on if a question is later raised about whether a user consented.
- Audit log. One row per tool invocation: tenant id, MCP client id, tool name, redacted input parameters, success / error code, duration, and correlation id. Inputs are scrubbed of any field whose name suggests a secret (password, token, key, credential).
- Operational telemetry. Standard server logs (request paths, response codes, timing) needed to operate and secure the Service.
2. What we don't collect
- We do not store the bodies of MCP tool responses (the building data returned to the AI client). Tool responses flow through the Service in memory and are not persisted on our side.
- We do not log AI-client conversation content. The Service has no visibility into the prompts you send to your AI client or the messages it returns to you, except as those messages translate into tool calls against bdx-mcp.
- We do not sell personal information.
3. BDX site credentials
The credentials BuildingLogiX uses to connect to your BDX site are stored encrypted, are used only to service a tool call while it is in flight, and are never written to logs.
4. AI client data flow
When you authorize an AI client, building data returned by the Service is transmitted directly from bdx-mcp to that client over the MCP transport. The client's provider may retain, log, train on, or otherwise process that data under its own terms. BuildingLogiX has no visibility into and exercises no control over the client's downstream handling of that data. See the Acceptable Use Policy for guidance on choosing an AI client whose data practices match your needs.
5. Retention
Audit-log rows are retained for as long as the tenant is active, and then for a reasonable period after termination for operational, security, and legal purposes. Account identity and policy-acceptance rows are retained while the user has an active tenant_users row and for as long as needed afterwards to evidence the acceptance.
6. Your rights
Depending on your location, you may have rights to access, correct, or delete personal information we hold about you, or to object to certain processing. Send those requests to privacy@buildinglogix.net. We will route them to the appropriate tenant administrator where the request concerns operational data the tenant controls.
7. Changes
We update this Privacy Notice when the Service's data handling changes substantively. When we do, we bump the policy version and require each active user to accept the updated documents on next sign-in.
Effective May 22, 2026.