Privacy policy
Effective Details to follow
Plainbuilt collects what you type into a form (name, email, a phone number where the form needs one, your message), analytics only after you allow it where the law says we must ask, anonymized conversations with the site's question-and-answer bot, and, on the demo platform, the account and saved-work data listed below. We never store your API keys.
Who is responsible for your data?
Plainbuilt (Plainbuilt (registered entity name to follow)), 2737 N. Cullen Ave, Sector 2, Evansville, IN 47715, United States, is responsible for the personal data described here. For anything in this policy, write to Details to follow or to that address.
What do we collect when you send a form?
Every form on this site (the contact form, the call-me form on the call page and the home page, the guide download, the demo waitlist, a booking) sends the same kind of record to our database: the fields you filled in (your name, email, phone, your budget range and your message on the contact form; your name, phone and email on the call-me form; your email and the guide you asked for on a guide download), the page you sent it from, the name of the form, the campaign the link you arrived by carried (the UTM parameters, ad click ids, the referring site and the page you landed on, from the pb-attr cookie described in the cookie policy), and the time. We use that record to reply. The contact form and the call-me form ask you to check a box that says we may call you, text you and email you back about what you sent; we record the time you checked it, and without it the form does not send. Sending it triggers an automatic acknowledgement by email, and by SMS if you gave a mobile number (a booking gets Cal.com's own confirmation, and our note only once Cal.com confirms the booking to us); an internal notification to our team on Slack and by email; and a copy to our CRM (Details to follow), so a person follows up. On the call-me form, once our voice agent's phone line is switched on, we first text a one-time code to the number you typed and the agent calls only after you enter it, so a number is never called on someone else's say-so; the time the code matched is stored with the lead. The agent says at the start of the call that it is an AI and that the call is recorded. That call is transcribed, and the transcript, its length, its telephony call id and an estimate of its cost are stored against your lead; how long we keep them is in the retention section below.
To limit abuse, each submission is counted against a hash of your IP address for 10 minutes; we do not store the address itself. Our own code does not write your full email address, your phone number, or the body of what you sent to its logs. A hidden field catches automated submissions, which are dropped.
What happens when you book, call, or text?
Booking a working session happens on this site through Cal.com's calendar; what you enter there is covered by Cal.com's privacy policy and lands in our calendar, and Cal.com tells us the booking was made so we can store it as a lead with the campaign that brought you; a reschedule updates that lead rather than adding one. Calls and texts to our numbers are carried by Twilio, and your phone number is visible to us as with any call. The demo line is answered by an AI voice agent. Timeline set in the working session
What does the question-and-answer bot store?
The bot is the chat assistant in the corner of every page. It answers from this site's own content and refuses questions outside it. Your chat with the assistant is stored anonymized so we can improve the FAQ content; it is not tied to your name or account. In voice mode, the clip you record is sent to the speech provider for transcription and the answer text is sent to the speech provider for audio; the audio is not stored, and the transcript is stored like a typed message. The bot never asks for or collects an API key, and it is rate-limited per IP address and session. Do not type or say personal details into it.
What does the demo platform store?
Scripted demos need no sign-in and send nothing to a model; no demo data is stored, and analytics events may be recorded when you have allowed analytics cookies. An account on the demo platform holds your email and the counts used to enforce the daily caps. It also stores the simulation runs you save (the script, the branch you picked, and the outcome), the builds you save (the fields you typed into the agent builder), and a downloads log (the asset and the time). Live mode is open on an account once phone verification is switched on; the live page says so when it is not. A live call stores your phone verification (a keyed hash of the verified number, a one-way code computed with a server secret, and when it was verified), the session (mode, industry, start and end time, outcome), and the call itself (the transcript, the actions the agent would have taken in your CRM, the duration, a keyed hash of the number called when the call went to your phone, and a cost estimate). The SMS and email demo agents store the text of each message you send and the reply on the session row. The typed chat with a demo agent on your own key stores nothing: the messages exist in your browser while the page is open and travel to your provider through our server for each reply; only the count of turns is kept for the hourly cap. No table stores user API keys. Your key is held in memory for the session only, never logged, never persisted, and redacted from error reports. Every live call opens with a recording consent line. Signing up also tags your contact in Brevo, our email list tool. The demo terms say more.
What do we collect with analytics, and when do we ask first?
Google Tag Manager loads Google Analytics, which measures page views and which calls to action are clicked (booking, phone, text, form, demo, and guide events). If your connection shows you are in the European Union, the European Economic Area, the United Kingdom, or Switzerland, analytics stays off until you choose Allow in the banner; Decline keeps it off. Elsewhere analytics runs by default and no banner is shown. On the live deployment, Vercel's analytics and speed measurement scripts also run. The cookie policy lists every cookie and how long it lasts. Tracked short links on this site (the /go/ links) count clicks per link; the count is all the redirect stores.
Who processes it for us?
Supabase (the database and the demo platform accounts), Vercel (hosting and analytics), Brevo (transactional email: the acknowledgements, the notifications to our team and the demo agents' replies; and our email lists), Resend (transactional email when it is configured instead), Twilio (calls, texts, and verification codes), Slack (internal notifications), Google (Tag Manager, Analytics, and the embedded map on the Evansville page), YouTube (embedded video in privacy-enhanced mode), Cal.com (booking), Anthropic (the bot's answers, the SMS and email demo agents, and, with your own key, the typed chat with a demo agent), OpenAI (the bot's voice mode and, with your own key on your own account, live calls and the typed chat with a demo agent), Deepgram and ElevenLabs (the bot's voice mode, when they are configured instead of OpenAI), Sentry (error reports, with keys and secrets redacted), and Details to follow. Each processes data on our instructions under its own terms.
How long do we keep it?
Details to followIs your data moved across borders?
Plainbuilt's headquarters is in Evansville, Indiana, and its engineering center is in India; people in both places may handle your data to reply to you or to deliver an engagement. The site and database are hosted in Details to follow. Where the law requires safeguards for a transfer, we rely on Details to follow.
What are your rights under the GDPR?
If you are in the European Union, the European Economic Area, the United Kingdom, or Switzerland, you can ask what we hold about you, ask us to correct or delete it, ask us to restrict or stop processing it, ask for a copy in a portable form, and withdraw consent at any time (declining or deleting the consent cookie withdraws analytics consent). Our grounds for processing are your consent (analytics cookies where we ask), the steps you asked for (replying to a form, running a demo you signed up for), and our legitimate interest in keeping the site secure and improving its content. You can complain to your data protection authority. Write to Details to follow to exercise any of these.
What are your rights under the CCPA?
If you are a California resident, you can ask what personal information we collect, use, and disclose; ask for a copy; ask us to delete or correct it; and you will not be treated differently for asking. Details to follow Write to Details to follow to make a request; we verify a request before acting on it.
How do we change this policy?
We post the new version here with a new effective date.
How do you reach us?
Plainbuilt, 2737 N. Cullen Ave, Sector 2, Evansville, IN 47715, United States, or Details to follow.