Legal

Privacy policy

How AutoIFC collects, uses, stores and protects your information, what happens to the scans you upload, and the rights you have over your data.

Last updated: 13 September 2026

AutoIFC ("we", "us" or "our") is a scan-to-BIM service operated by Lidarvisor LLC, a New Mexico limited liability company, at autoifc.com and app.autoifc.com (the "Service"). This policy explains what information we collect when you use the Service, why, where it is kept, who else touches it, and what you can ask us to do with it.

We comply with the privacy laws that apply to us in the United States, including the California Consumer Privacy Act (CCPA), and with the General Data Protection Regulation (GDPR) for our users in the European Economic Area, the United Kingdom and Switzerland. The Service is hosted in the European Union.

1. Information we collect

1.1 Account information

When you create an account we collect your first and last name, your email address, your password (stored as a salted hash, never in clear), your country, and, when you tell us, your industry. When you buy credits, Stripe collects your card and billing details; we receive the outcome of the payment, the amount, and a receipt reference, never your card number.

1.2 Scans and models

To model a facade you upload a terrestrial point cloud (E57, LAS, LAZ or PLY). From it the Service derives and stores: the facade measurement made at upload, images derived from the facade (each tile), the proposed and reviewed IFC models, the PDF report, and the review actions you take on each element. A scan may contain the coordinates of the building and, in colourised clouds, images of its surroundings; you are responsible for having the right to upload and process it.

We do not train models on your scans. Your scans, the images derived from them and your models are used to run your own projects and for nothing else.

1.3 Usage and technical data

  • IP address, browser and operating system, and the approximate location they imply
  • The pages and app screens you open, the actions you take (upload, launch, review, download, purchase) and when
  • Processing records: scan size, facade area, run duration, model calls and their cost
  • The credit ledger of your account: every credit granted, bought or charged, with the run it belongs to
  • Server and access logs, kept for security and troubleshooting

1.4 Cookies and similar technologies

  • Essential cookies: the session cookie that keeps you signed in to the app, and the security cookies WordPress sets on the website when you sign in there. The Service does not work without them.
  • Preferences: your viewer and interface settings, stored in your browser.
  • Analytics cookies: Google Analytics 4, loaded through Google Tag Manager on both the website and the app, to understand how the Service is used: pages viewed, sign-ups, uploads, runs launched, downloads and purchases. Analytics data is pseudonymous; we do not send your name or email to Google.

2. How we use your information

  • Provide the Service: store your scans, run the modelling pipeline, show the result in the viewer, produce the IFC and the report, keep your credit ledger
  • Manage your account: sign you in, send the activation and password emails, process payments and receipts
  • Support you: answer your questions and investigate a failed run, which may mean an engineer opening that run's files
  • Improve the Service: measure which steps work and which fail, fix bugs, and evaluate the modelling engine against the results of real runs, in aggregate
  • Protect the Service: detect abuse, fraud and security incidents
  • Meet our legal obligations: tax, accounting and lawful requests

Because you are a customer, we may also email you product news about AutoIFC; every such email carries an unsubscribe link, and one click stops them. Transactional emails (activation, password, run ready, receipt) are part of the Service and continue while your account exists.

  • Performance of a contract: everything needed to provide the Service you signed up for, including sending images derived from your facade to our model provider
  • Legitimate interests: security, fraud prevention, product analytics, product news to existing customers, and the improvement of the modelling engine
  • Consent: analytics cookies where the law of your country requires consent for them
  • Legal obligation: keeping billing records, answering lawful requests

4. Where your data is stored, and for how long

4.1 Where

The Service runs on Google Cloud in the Netherlands (region europe-west4): database, processing and the storage buckets that hold your scans, the images derived from them and your models all live there. Download links are signed and expire within hours; nothing is served from a public bucket.

4.2 For how long

  • Scans, derived images, models and reports: kept while the project exists. Deleting a project from the app removes its files from storage; the sweep runs in the background and finishes within minutes for a large scan.
  • Account data and the credit ledger: kept while your account is active. When you ask us to erase your account we anonymise the account row and delete every project it owned, including storage.
  • Usage and access logs: up to 12 months.
  • Processing records and model call costs: kept per run for as long as the run exists, and in aggregate afterwards.
  • Billing records: 7 years, as tax law requires. Stripe keeps its own records under its own policy.

5. Who we share your data with

We do not sell your personal data, and we do not share your scans or models with anyone except the processors below, in the course of running your own projects.

  • Google Cloud (hosting, storage, logging) in the European Union.
  • Anthropic (model provider): during the drawing step of a run, the Service sends images derived from your facade, the measurements that go with them, and its instructions to Anthropic's API, which returns the proposed openings. No account information travels with them. Anthropic processes these requests under its commercial API terms, which exclude the use of customer data for training its models.
  • Stripe (payments): card details, billing address and receipts. Stripe is an independent controller for the payment itself.
  • Twilio SendGrid (email): your email address and the content of the transactional and, if opted in, marketing emails we send you.
  • Google Analytics and Google Tag Manager (analytics): pseudonymous usage events, as described in section 1.4.
  • People you share with: when you create a share link, whoever holds the link (and the password, if you set one) can view that project's model in the viewer until the link expires or you revoke it. Recipients cannot download your files.

We may also disclose information when the law requires it, to establish or defend legal claims, or, with prior notice to you, in a merger, acquisition or sale of the business. Every processor above is bound by a data processing agreement or equivalent terms.

6. Your rights

Wherever you live, you can ask us what personal data we hold about you, correct it, receive a copy, or have it deleted. Under the GDPR you also have the right to restrict or object to processing based on our legitimate interests, to data portability, and to withdraw a consent at any time without affecting what was done before. Under the CCPA you have the right to know, to delete, to correct, and to not be discriminated against for exercising those rights; we do not sell or share personal information in the CCPA sense.

To exercise a right, write to contact@lidarvisor.com from the address of your account. We answer within 30 days. Scans, models and reports you can delete yourself at any time by deleting the project; the account itself is erased on request, and the erasure cannot be undone. You also have the right to lodge a complaint with your data protection authority.

Your browser lets you block or delete cookies for autoifc.com and app.autoifc.com, and browser extensions can block the analytics scripts entirely; the Service keeps working without analytics. Blocking the essential session cookie signs you out of the app.

8. Security

  • TLS on every connection to the website, the app and the API
  • Encryption at rest on the database and on every storage bucket
  • Uploads and downloads through short-lived signed URLs, never a public bucket
  • Passwords stored as salted hashes; sign-in rate limited
  • Access to production restricted to the people who operate it, with an audit log of administrative actions
  • Database backups kept in the same region

No system is perfectly secure. Use a strong, unique password, keep your API keys secret, and tell us at once at contact@lidarvisor.com if you believe your account has been accessed by someone else.

9. Children

The Service is a professional tool and is not intended for anyone under 16. We do not knowingly collect personal data from children; if you believe we have, contact us and we will delete it.

10. International transfers

Your data is stored in the European Union. Some of our processors (Anthropic, Stripe, SendGrid, Google for analytics) process data in the United States. Those transfers rely on the EU-US Data Privacy Framework where the processor is certified, and otherwise on the European Commission's Standard Contractual Clauses.

11. Changes to this policy

We will update this page when our practices change and move the date at the top. For a change that matters to you, such as a new processor that receives your scans, we will tell you by email or with a notice in the app before it takes effect.

12. Contact

Lidarvisor LLC, operator of AutoIFC. Email contact@lidarvisor.com, or use the contact page. We aim to answer within two working days.