ContractorOS ContractorOS

Privacy Policy

Effective Date: July 19, 2026

ContractorOS helps contractors and project teams organize workspaces, customers, projects, schedules, estimates, messages, files, photos, and related field information. This policy describes the information ContractorOS processes and includes specific disclosures for the optional room-measurement feature.

Information We Process

Depending on the features you use, ContractorOS may process:

  • Account and profile information, such as your email address, name, avatar, and authentication records.
  • Business and workspace information, including workspace membership, roles, customers, projects, estimates, schedules, messages, photos, files, and other content you or your team submit.
  • App-usage and diagnostic information, including workspace and session identifiers, screen names, platform, app version, timestamps, limited event metadata, and error logs used to operate, secure, and improve the service.
  • Information you submit through feedback, support, onboarding, or custom trade-suggestion features.
  • Subscription status. Apple processes App Store payment details; ContractorOS receives the information needed to determine subscription entitlement.

Room Scans and Interior Geometry

Camera and LiDAR processing

Room scanning is optional and is available only on supported LiDAR-equipped Apple devices. ContractorOS requests camera permission when you start a scan. The live camera and LiDAR feed is handled on the device by Apple's RoomPlan framework to construct a room model. The current ContractorOS room-scan flow does not record or upload the live camera stream and does not save still photographs from that stream.

After RoomPlan finishes processing, ContractorOS serializes the resulting CapturedRoom model. This model may describe sensitive interior information such as wall and floor geometry, dimensions, doors, windows, openings, room sections, object classifications, and confidence information. ContractorOS derives estimating values such as floor area, perimeter, wall area, ceiling area, baseboard length, and opening counts from that model.

The project-measurement flow stores a raw CapturedRoom JSON artifact and does not generate or upload a USDZ model. A separate local-only flow can export a mesh USDZ model without creating project measurements or requiring Room Measurement Manager access. ContractorOS places that model in protected, backup-excluded temporary staging, presents the system Files picker, does not attach or upload the model, and removes the staging copy when the capture screen closes. A Files provider selected by the user may synchronize the saved copy under that provider's settings. Android does not perform RoomPlan capture; it supports manual field measurements and display of authorized accepted values.

Why room data is used

ContractorOS uses room data to let an authorized project team member review and correct captured values, preserve measurement provenance, calculate estimate quantities, and synchronize accepted measurements with the project. RoomPlan output is an estimate, not a certified survey or safety measurement. Critical dimensions must be independently field-verified before bidding, ordering materials, fabrication, or construction.

Only scan a property when you are authorized to do so. Because a room model can reveal a customer's interior layout, obtain any permission required from the property owner or occupant before scanning.

Storage and access

  • Before upload, the raw JSON artifact is stored in the iOS app's Application Support directory with complete file protection, a user/workspace/project/scan-scoped path, size and SHA-256 integrity checks, and exclusion from device backup.
  • Cloud artifacts are stored in a non-public room-scans bucket. The database stores scan metadata, a compact geometry summary, normalized measurements, verification state, and estimate provenance. Raw artifact bytes are kept separate from the ordinary synchronization payload.
  • Raw scans, full measurement records, and raw JSON artifacts are available in the app only to the workspace owner, workspace administrators, and internal members assigned the manager job role.
  • Other authorized internal workspace members may receive only accepted or field-checked measurement values through a redacted server projection. That projection removes the scan identifier, original captured value, quality and assumption flags, classification confidence, and verifier identity and timestamp.
  • Linked vendors and customers are not permitted to retrieve raw room scans or the room-measurement projection.
  • ContractorOS's cloud infrastructure provider processes stored data as needed to host and deliver the service.

Retention and deletion

Live room-scan records and their referenced cloud artifacts do not currently have a time-based expiration. They remain available while their live database references are retained. An authorized workspace owner, administrator, or manager can delete an individual scan in the app. After the server authorizes that request, ContractorOS soft-deletes the scan and its linked measurement records and immediately queues the exact current cloud-object generation for asynchronous deletion. Existing estimate items are not silently deleted; they retain their snapshotted quantities and frozen measurement provenance. A weekly orphan sweep separately finds other unreferenced cloud objects that are at least seven days old. Immediately before any physical deletion, the cleanup worker revalidates the exact object generation and confirms that it still has no live database reference. Cleanup is not immediate, and a failed cleanup remains pending for a later retry instead of being recorded as successful.

A successfully saved local JSON artifact is not deleted merely because its cloud upload succeeds. It remains in the app's protected local storage until you sign out, the server reports that your room-measurement access was revoked, an explicit cleanup removes it, or the app's local data is removed. The scan-specific control can remove only the protected copy on the current device after that device has confirmed upload; this does not remove the shared scan or cloud copy. Full scan deletion removes the initiating device's local copy only after the online server deletion is accepted, so an offline tombstone cannot silently destroy the only recoverable raw model.

Another device that previously stored the protected copy retains it while that device is offline or while authoritative synchronization fails. After its next successful authorized synchronization, ContractorOS detects that the formerly live scan disappeared and atomically records the exact workspace/project/scan as durable pending local cleanup before attempting deletion. It then removes that scan's protected local artifact and upload checkpoints across its local user scopes, including when capture attribution has been removed or pseudonymized. Already-absent files are treated idempotently. Filesystem, checkpoint, or cleanup-state failures remain visible and are retried from durable pending state after a later successful synchronization; ContractorOS does not infer deletion from an offline cache tombstone. If durable pending state cannot be saved after the server already accepted deletion on the initiating device, the app reports that partial outcome and makes one explicit emergency cleanup attempt without claiming that a retry was stored. If saving the measurement records fails before the scan is accepted, the app attempts to delete the local artifact and logs any cleanup failure. Local cleanup failures are reported and logged rather than treated as success.

RoomPlan diagnostic logs contain operational event names, lifecycle states, error codes, artifact byte counts, and scoped identifiers or object paths. The RoomPlan flow does not intentionally place raw CapturedRoom JSON, derived geometry payloads, still images, or live camera frames into diagnostic log messages.

Self-service account deletion is available. If you own a workspace with other members, you must first transfer ownership or remove those members. Data belonging to a retained shared workspace may remain as workspace content after an individual member leaves or deletes their account. For retained accepted room scans, measurements, and related estimate provenance, ContractorOS removes the account linkage used to identify who captured the scan and replaces current verifier references with one random pseudonymous identifier shared across those provenance records. That identifier has no authentication or profile account record and cannot be resolved through those account tables to identify the departing user. The verification timestamps remain with the retained workspace records for auditability. Contact us if you need assistance with a room-data deletion request.

How We Use Information

We use information to provide authentication, collaboration, synchronization, estimating, storage, support, subscription access, security, diagnostics, and product-improvement functions. ContractorOS does not sell personal information or room-scan data, and it does not use interior geometry or other account content for behavioral advertising.

Location Services

If you enable location access, ContractorOS may use device location for location-specific notifications and to assist with project entry. You can change location permission in your device settings.

Data Security

ContractorOS uses authentication, database row-level authorization, private object storage, scoped object paths, integrity checks, and protected local storage to reduce unauthorized access. No storage or transmission system can guarantee absolute security.

Subscriptions

ContractorOS offers auto-renewable subscriptions (Small Business, Contractor, and Enterprise). Payment is charged to your Apple ID account at confirmation of purchase. Subscriptions automatically renew unless canceled at least 24 hours before the end of the current period. Your account will be charged for renewal within 24 hours before the end of the current period. You can manage and cancel subscriptions in Settings > Apple ID > Subscriptions on your device.

Contact

For privacy questions or deletion assistance, contact craftsmannsoftware@gmail.com.