BuildKnack Privacy Policy

Last updated: 29 July 2026

This Privacy Policy explains how Tecknack ("we", "us", "our"), the provider of the BuildKnack app ("App"), collects, uses, stores and shares personal data. It is written to comply with the UK General Data Protection Regulation (UK GDPR) and the Data Protection Act 2018.

We are the data controller for the personal data described in this Policy, except where stated otherwise (see Section 9, "Your Customers' Data").

1. Who We Are

Tecknack / BuildKnack
Tecknack Limited
Company Number: 15701534
support@tecknack.co.uk

If you have any questions about this Policy or how we handle your data, contact us at privacy@tecknack.co.uk

2. Personal Data We Collect

2.1 Account and identity data

  • Firebase user ID
  • Email address
  • Display name
  • Sign-in provider (Google or Apple) and provider identifier
  • Email verification status
  • Authentication and session security timestamps
  • Where you sign in with Apple, Apple may provide a private relay email address instead of your real address if you choose that option

2.2 Business profile

If you complete your business profile, we store:

  • Trading/business name
  • Contact name
  • Telephone number
  • Email address
  • Business address, city and postcode
  • Company number
  • VAT number
  • Date last updated

This is stored on your device and synchronised to our servers (Google Firestore) so it is available across your sessions.

2.3 Labour-rate profile

  • Town/location name you enter
  • Approximate coordinates (latitude/longitude) derived from that location
  • Labour categories, hourly rates and any custom rate categories you create
  • Date last updated

2.4 Job, customer and site information you enter

When you create a job in the App, you may enter:

  • Job title, type of work and description
  • Customer name, phone number and email address
  • Site address, city/town and postcode
  • Dimensions (length, width, height, calculated floor area)
  • Photographs of the job site
  • Creation, modification and archive status

Important: much of this information relates to your customers, not you. Section 9 explains your responsibilities regarding this data.

Job records, photos, estimates, quotes and contracts are stored locally on your device. Business profile, labour-rate profile and quote-template preference are also synchronised to our servers. Full job, customer, estimate, quote and contract records are not currently synchronised to our servers — they exist locally, on your device, only.

2.5 Photographs

Photos you attach to a job are copied into the App's private storage on your device, compressed, and linked to that job. Depending on the applicable allowance, up to five compressed photographs may be submitted for job analysis (see Section 4). We do not upload photos to any general cloud storage bucket. Photos are deleted from your device when you permanently delete the associated job.

2.6 Estimates, quotes and contracts

Draft estimates, finalised quotes and finalised contracts (including customer, job and business details embedded in them, and your company logo where added) are generated and stored locally on your device. PDF documents are created on your device when you preview or share them.

2.7 Purchase data

  • Firebase user ID (used as your identifier with our payment processor, RevenueCat)
  • Product identifiers
  • Purchase and entitlement status
  • Store transaction identifiers and environment (e.g. sandbox/production)

We do not receive or store your full card details. These are processed directly by Apple or Google as the store operator.

2.8 Usage and allowance data

To manage free job allowances and paid "Job Pack" credits, our servers store:

  • Remaining credits
  • Whether your free job has been used
  • The source of your allowance (free, purchased pack, or app-review testing)
  • Photo and analysis limits associated with a job
  • Number of successful analyses performed and whether one is in progress
  • Associated timestamps

2.9 Technical and diagnostic data

Where the App crashes or encounters certain errors, we may collect (via Firebase Crashlytics, in release builds only):

  • Crash reports and stack traces
  • Exception/error messages
  • App version and build number
  • Device model and operating system version
  • Other diagnostic identifiers

We do not deliberately attach your user ID to crash reports. However, certain manually logged sign-in error messages could incidentally include diagnostic text related to the authentication attempt.

2.10 Location information

We do not access your device's GPS or precise location. If you type a town or postcode during onboarding, that text is sent to a third-party postcode look-up service (postcodes.io), which returns an approximate location name and coordinates. This is a one-off, manually entered reference point used to determine your local labour rates — we do not track your ongoing location.

3. How We Use Your Data and Our Legal Basis

PurposeData usedLegal basis (UK GDPR Art. 6)
Creating and managing your accountAccount/identity dataPerformance of a contract
Storing your business and rate profilesBusiness profile, labour-rate profilePerformance of a contract
Letting you create jobs, estimates, quotes and contractsJob, estimate, quote, contract dataPerformance of a contract
Generating AI-assisted estimatesSelected job details and photos (Section 4)Performance of a contract; your explicit action in requesting an estimate
Processing Job Pack purchasesPurchase dataPerformance of a contract
Preventing abuse of the lifetime free-job allowance and repeat claimsHashed provider identifiersLegitimate interests (fraud/abuse prevention)
Restoring purchased credits after account recreationHashed provider identifiers, credit balanceLegitimate interests; performance of a contract
Diagnosing crashes and technical issuesCrash/diagnostic dataLegitimate interests (keeping the App working)
Complying with legal, accounting or tax obligationsPurchase and transaction recordsLegal obligation

We do not use your data for third-party advertising, and we do not sell personal data.

4. AI-Assisted Estimate Generation

If you request an AI-generated estimate, the App sends the following to our backend (hosted in Google Cloud's London, UK region) and then to our AI provider, OpenAI:

  • Job title, type of work, description
  • Site city/town (not the full address or postcode)
  • Dimensions
  • Labour categories and hourly rates
  • Depending on the applicable allowance, up to five compressed photographs (if you provide them), sent at low image detail
  • If you are updating an existing estimate, the previous estimate and a description of what changed

We do not deliberately send your customer's name, phone number, email, full site address, postcode, your business profile, or your company logo as part of this request.

Our contract with OpenAI is configured so that submitted content is not used to train OpenAI's models and is not retained by OpenAI for that purpose (store: false). OpenAI may still retain data for 30 days, for abuse-monitoring and safety purposes under its own API terms, consistent with its standard data-processing arrangements.

The estimate that is generated is returned to your device and stored locally. We do not deliberately store the resulting estimate text on our servers.

Automated processing: the AI-generated estimate is a draft suggestion only. You review, edit and approve all figures before creating a quote or contract, and no automated decision with legal or similarly significant effect is made about you or your customers without your review.

5. Who We Share Your Data With

We use the following service providers and platform operators. Some process data on our behalf, while others, including app-store and sign-in providers, may act as independent controllers under their own privacy terms:

RecipientWhat they receiveWhy
Google Firebase / Google CloudAuthentication data, synced profile data, allowance/analysis records, crash reportsHosting our authentication, database, backend functions and diagnostics
Google (Sign-In / Play)Sign-in credentials; purchase data if buying via Google PlayEnabling Google sign-in and Play purchases
Apple (Sign-In / App Store)Sign-in credentials; purchase data if buying via the App StoreEnabling Apple sign-in and App Store purchases
RevenueCatFirebase user ID, product IDs, purchase/entitlement and transaction dataProcessing and reconciling in-app purchases
OpenAISelected job details and optional photos (Section 4)Generating AI-assisted estimates
postcodes.ioTown/postcode text you enterConverting it to coordinates for labour-rate lookup
Your chosen email/messaging/file-sharing appA quote or contract PDF, only when you choose to share itLetting you send documents to your customer or elsewhere

We do not sell personal data or disclose it to third parties for their independent advertising purposes. Platform operators may process information for the purposes described in their own privacy notices.

Where you use the "share" or "email" function, the PDF leaves our control entirely once handed to your device's operating system and the app you choose (e.g. Mail, Gmail, WhatsApp, cloud storage). That recipient processes it under its own privacy terms, not ours.

6. International Data Transfers

Some of our service providers and platform operators—including Google (Firebase, Google Cloud, Google Sign-In and Google Play), OpenAI, RevenueCat, Apple, and Ideal Postcodes/Postcodes.io—may process personal data outside the UK, including in the European Economic Area and the United States. Where personal data is transferred to a country that is not covered by UK adequacy regulations, we use an applicable lawful transfer mechanism. This may include the UK International Data Transfer Agreement, the UK Addendum to the European Commission’s Standard Contractual Clauses, or another safeguard permitted under UK data protection law.

  • Google — Firebase Authentication, Firestore, Cloud Functions, Remote Config, Crashlytics, Google Sign-In and Google Play.
  • OpenAI — job analysis, including any submitted descriptions and optional photos.
  • RevenueCat — purchase validation and Job Pack entitlement management.
  • Apple — Sign in with Apple, App Store distribution and purchases.
  • Ideal Postcodes / Postcodes.io — postcode and town lookup. Postcodes.io states that it is maintained by Ideal Postcodes.

7. How Long We Keep Your Data

DataRetention
Account, business profile, labour-rate profile, quote preferenceUntil you delete your account
Local job, photo, estimate, quote and contract dataUntil you permanently delete the individual job, delete your account from that device, or otherwise remove the App's local data. Information included in a device backup may remain until that backup is separately deleted or expires under the backup provider's retention policy.
Billing/allowance records (Firestore)Active account allowance records — until account deletion, except for the retained records described in section 7
Hashed anti-abuse claim recordRetained for six months after account deletion to prevent repeated claims of the lifetime free-job allowance
Hashed purchase-credit restoration recordRetained for six months after account deletion so credits can be restored if you sign back in with the same account within that period, then automatically deleted
BuildKnack’s pseudonymised RevenueCat webhook event recordsThree years from the event date for accounting, fraud prevention and purchase reconciliation.
Crash/diagnostic logs (Crashlytics)Crash and diagnostic data is generally retained by Firebase Crashlytics for 90 days.
Cloud Function / server logsApplication and Cloud Function logs are generally retained for 30 days. Certain Google Cloud audit logs may be retained for longer under Google Cloud’s applicable default retention periods.

8. Deleting Your Account and Your Rights

8.1 What happens when you delete your account

When you delete your BuildKnack account, we:

  • Delete your Firestore data record (business profile, labour-rate profile, preferences, allowance and analysis records)
  • Delete your Firebase Authentication account
  • Erase BuildKnack content stored locally on the device from which you delete the account. Content stored on another device, in a device backup, or previously exported or shared must be deleted separately.
  • Local data may be included in device backups controlled by Google or Apple.
  • Retain, in hashed (non-reversible) form only, a record used to prevent repeated free-trial claims, for the period described in Section 7
  • Automatically delete the retained purchase-credit record after its defined retention period expires, per Section 7

Some information is not removed immediately by account deletion. This includes BuildKnack's pseudonymised purchase-event records and technical logs retained for the periods in Section 7. RevenueCat, Apple and Google may also retain their own purchase or platform records under their respective privacy policies.

8.2 Your rights under UK GDPR

You have the right to:

  • Access the personal data we hold about you
  • Rectify inaccurate or incomplete data
  • Erase your data ("right to be forgotten"), subject to Section 8.1 above
  • Restrict or object to our processing in certain circumstances
  • Data portability for data you provided to us and that we process by automated means under contract
  • Withdraw consent at any time, where processing is based on consent
  • Complain to the Information Commissioner's Office (ICO) at ico.org.uk or 0303 123 1113, if you believe we have not handled your data properly

Information stored only on your device is not normally accessible to Tecknack and may therefore need to be accessed, corrected, exported or deleted directly through the App or on that device.

To exercise these rights, contact us at privacy@tecknack.co.uk. We will respond within one month, as required by law.

9. Your Customers' Data

BuildKnack lets you, the builder or tradesperson using the App, enter personal information belonging to your own customers — including names, phone numbers, email addresses, site addresses and photographs of their property.

In relation to this information:

  • You, not Tecknack, are the data controller for your customers' personal data that you input into the App. You are responsible for having a lawful basis (typically your contract with your customer, or your legitimate interest in providing a quote) to collect and process it.
  • For customer information stored only on your device, Tecknack does not ordinarily receive or have access to that information. Tecknack processes selected customer-related job information on your behalf when you request job analysis or use another server-based feature.
  • Where customer-related information is transmitted to our backend for job analysis, Tecknack processes that information on your behalf as a data processor. OpenAI and relevant cloud providers act as our subprocessors for that processing.
  • You should let your customers know, in an appropriate way, that their information may be used to generate quotes and estimates, including through an AI-assisted process where photos or job descriptions may be involved.
  • We recommend avoiding the inclusion of people's faces, vehicle number plates, documents, or unrelated personal belongings in photographs submitted for AI analysis, and cropping or selecting photos accordingly.
  • You should only collect the customer information reasonably necessary to provide your quote or service, and should handle it securely (e.g. not sharing your device or exported PDFs insecurely).

10. Children

BuildKnack is a business tool intended for use by tradespeople and is not directed at, or intended for use by, children. We do not knowingly collect personal data from children.

11. Security

We use industry-standard measures to protect your data, including encrypted connections (TLS) between the App and our servers, access-controlled cloud infrastructure, and Firestore security rules that restrict your synced records to your own authenticated account. No system can be guaranteed completely secure, and you are responsible for keeping your device and sign-in credentials secure.

12. Analytics

BuildKnack does not currently use Firebase Analytics or any equivalent analytics or advertising SDK. If this changes in future, we will update this Policy before doing so, and will ensure that:

  • No customer names, job details, addresses or other user-entered content are placed into analytics event data
  • You are informed of what is collected and, where required, given the ability to opt out
  • Any advertising-related signals (e.g. Google Signals) are disabled unless we specifically state and obtain consent otherwise

13. Changes to This Policy

We may update this Privacy Policy from time to time, for example to reflect new features (such as analytics) or changes to our service providers. We will post the updated version in the App and update the "Last updated" date above. Material changes will be brought to your attention.

14. Contact Us

If you have questions, concerns, or wish to exercise your data protection rights, contact us at:

privacy@tecknack.co.uk

You also have the right to lodge a complaint with the UK Information Commissioner's Office (ICO) at any time: ico.org.uk.