Privacy Policy
Urban Structure OS · Effective September 27, 2026
1. About this policy
Urban Structure OS is a construction project management and monitoring application, used by project managers, clients, warehouse personnel, site engineers and site architects to run building projects together: progress tracking, procurement, materials, labor, expenses, daily reports and client updates. This policy explains what information the app collects, why, who can see it, and what happens to it when you delete your account.
The app is operated by Urban Structure and Development Corp. You can reach us at urbanstructure@urbanfitai.com.
2. Information the app collects
A. Account information
| What | Why we use it |
|---|---|
| Account information. Your name, your email address, a unique account/user identifier, whether your email is verified, your account status (for example, waiting for approval or active), and when you last signed in. Your password is handled by Google's Firebase Authentication; we do not see or store it. | To create your account, sign you in, show your name to your teammates, and control what you can access. |
| Project membership. The projects you belong to, your role in each (project manager, client, warehouse, site engineer or architect), your membership status and the dates you were invited and joined. A copy of your name and email is kept with each membership. | To give you access to the right projects and show your teammates who is on the project. |
| Invitations. The email address and name of the person invited, the project and role offered, the invitation status and dates, and who sent it. Invitations exist inside the app; the app does not send invitation emails itself. | To let a project manager invite a person to a project and to let that person accept. |
| Project and business information. Project details; materials and inventory; bills of quantities and estimates (BOM); procurement requests, quotations and purchase orders; suppliers and their contact details; expenses and budgets; labor contracts, payments and allocations; progress and work-breakdown-structure records; daily reports; client updates; and other information entered by authorized project members. Records show the name of the person who created or last changed them. | To run the project. This is the core function of the app. |
| Progress photos. Photos you choose from your library or take with your camera and attach to progress updates, daily reports or project images. Photos are reduced in size before they are uploaded. The app only accesses photos you select or take. Progress photos are project records: they may be accessible to other authorized project members according to their role, their project membership, and, for a client, the photo's approval status. | To document site progress for the project team. |
| Diagnostic information. In release builds, crash reports and reports of errors the app recovered from, sent to Firebase Crashlytics, to improve application reliability. See section 5. | To find and fix bugs and keep the app stable. |
| Data stored on your device. The app keeps a working copy of project data in its own storage on your device so that it can be used and displayed quickly. | To make the app work. It is removed if you clear the app's data or uninstall the app. |
3. Information the app does not collect
Based on how the app is built today, it does not access your location, your contacts, your text messages, or your device's advertising identifier, and it does not include advertising or third-party analytics software. It does not use your camera or photo library except when you choose to take or select a photo.
4. Who can see your information
- People on your projects. Other members of a project can see the project's records and the names (and, on the members list, email addresses) of the people on it, according to their roles. Business records you create are shared with the project team, not private to you.
- System administrators. Administrators of Urban Structure OS can view user accounts, project details and project memberships as needed to run and support the service. Sensitive records such as expenses and labor payments are limited to project managers of that project.
- Our service providers. The app is built on Google's Firebase and Google Cloud services, listed in section 6. The app does not send personal information to any other third-party service.
5. Crash and diagnostic reporting
Release builds of the app send crash and error reports to Firebase Crashlytics, a Google service, to help us find bugs and keep the app reliable. A report can include the technical error details (such as the error type and where in the code it occurred), the app version, the device model and operating system version, and technical identifiers that Crashlytics uses to tell installations apart. We also attach a small amount of context to help us understand a problem: your account identifier, your role name, the identifier of the project you had open, and the name of the operation that failed. We do not attach your email address, your name, passwords, or the content of your records or photos.
Crash reports are kept by Google according to Google's own retention policies, and we cannot delete individual reports. When you delete your account the app stops attaching your identifier to new reports, but reports already sent may remain until Google's retention period ends. Crash reporting is not active in development builds.
6. Where information is processed and stored, and who we share it with
Information is stored and processed by Google under the Firebase and Google Cloud services the app uses. These are our service providers, and they do not receive any personal information beyond what is needed to operate the app on our behalf:
- Firebase Authentication – sign-in accounts
- Cloud Firestore – profiles, memberships, invitations and project records
- Cloud Storage for Firebase – progress photos and other uploaded images
- Cloud Functions – server-side actions such as invitations and account deletion (the account-deletion function runs in Google's asia-southeast1 region)
- Firebase Crashlytics – diagnostic reports
- Firebase Hosting – this website, which, like any web host, may process technical request information such as IP addresses in its logs
Database location (verified): Cloud Firestore runs in Google's asia-southeast1 region. Cloud Storage location: to be specified when production Cloud Storage is provisioned. Google's own terms and privacy documentation govern how it handles data on these services.
We use reasonable technical safeguards to protect your information, including encrypted network connections between the app and Google's services and Firebase's own security rules limiting who can read or write which records. No method of transmission or storage is completely secure, and we cannot guarantee absolute security.
7. How long we keep information
We keep account information while your account exists. Project and business records are kept for as long as the project's records are needed. Information that we remove when you delete your account is described in the next section. Copies held by our cloud provider, for example in backups or logs, follow the provider's own retention policies. We have not set a fixed retention period for project records.
8. Deleting your account
You can request deletion of your Urban Structure OS account at any time, in either of two ways:
- In the app: Settings → Delete Account.
- On the web: the account deletion page, for example if you have uninstalled the app. Sign in with your email and password, confirm your password again, and type DELETE.
In both cases you must confirm your password again and type DELETE, and deletion is permanent. Accounts that are administrator accounts cannot be deleted this way; please contact your administrator.
Account deletion removes your personal account information and authentication data, as described below. Some shared project and business records may remain because they belong to the project or business, not exclusively to you – see “What is kept”.
What is deleted
- Your sign-in account, so you can no longer sign in.
- Your user profile.
- Your access to every project.
- Invitations that were still waiting to be accepted and that you sent, and pending invitations addressed to your verified email address.
What is anonymized
- Your membership entry on each project stays as part of the project's history but no longer shows your name or email; it is shown as “Deleted user”. This anonymization preserves the project's historical record while removing your personal identity from it. The role and the dates are kept.
- Accepted invitations addressed to you are kept as history with your name and email removed.
What is kept, and why
- Projects are never deleted when a member deletes their account. Projects belong to everyone who works on them. If you were a project's only manager, the project remains and another authorized person will need to be assigned.
- Shared project and business records are kept, including records you created: expenses, procurement, labor, progress records, daily reports, client updates, suppliers, financial records, and the progress photos attached to project history. These remain because they are project history shared with your teammates, not personal records belonging only to you – deleting your account does not delete records that belong to other project participants.
- Historical attribution may remain. Where a record shows the name you used when you created or changed it, that name may stay so the project history stays accurate. Records may also refer to you by an internal identifier that no longer belongs to any account.
- Some information may be kept where needed for legitimate business, legal, accounting, contractual or security purposes. We have not verified any specific legal retention period and do not claim one.
- A minimal deletion record, containing no name or email, is kept so that the deleted account cannot be silently re-created.
- Diagnostic reports already sent to Crashlytics, as described in section 5.
- Data on your own device stays there until you clear the app's data or uninstall the app.
9. Your choices and requests
You can correct your display name in the app. To ask a question about your information, to request a correction, or to raise a privacy concern, contact us using the details in section 1. If you cannot use the app or the web page to delete your account, contact us and we will help.
10. Children's privacy
Urban Structure OS is intended for users 18 years of age and older and is not directed to children. We do not knowingly collect information from children.
11. Security
Access to project data is limited by account and role, and those limits are enforced on the server. Data is sent between the app and Google's services over encrypted connections. No system is perfectly secure, and we do not claim the app is 100% secure or that data is completely safe from every possible risk.
12. Changes to this policy
If the app's handling of information changes, we will update this page and its effective date.