Supasite privacy policy
Updated: 3 Sep 2026
1. Purpose and scope of this policy
BuildPass Pty Ltd (ACN 652 324 635), referred to in this policy as "we", "us" or "our", provides Supasite, a tool for capturing and organising phone calls, meetings, voice notes, photos and supa snap walkthroughs. Supasite can also give you a business phone number (a supa number) with voicemail, and can process audio and photos to create transcripts, notes, tasks and other requested outputs. This privacy policy explains what personal information we collect through Supasite, how we use and handle it, and the rights individuals have regarding their information.
This privacy policy explains our information-handling practices. Where applicable law requires consent for a particular collection, use, disclosure or transfer, we will request that consent separately. Using Supasite does not constitute consent where valid consent must be specific and affirmative.
2. Who this policy applies to
Users: This policy applies to all users of the Supasite platform, whether you create an account or use our services in any capacity. It covers personal information we handle in our own capacity and information we process on behalf of our users through Supasite.
Personal information: In this policy, "personal information" (or "personal data") means any information about an identifiable individual, as defined under the Australian Privacy Act and GDPR. This policy does not cover information about companies or organisations, but it does cover information about individuals within those entities.
Minors: Supasite is intended for users 18 years and older. We do not knowingly collect personal information from children under 18 without parental consent. If we become aware of such data collection, we will promptly delete the information. By providing us personal information about someone else, you must have their consent to do so.
Capture participants: A capture participant is anyone whose voice, image, statements or personal information is captured through a phone call, meeting, voice note, photo or supa snap capture. When a Supasite account holder captures other people, BuildPass may process their personal information on behalf of that account holder. The account holder is responsible for providing any required notice and obtaining any consent required by applicable privacy, recording, surveillance and workplace laws. Section 3A explains what Supasite does and does not do to tell other people that a call or meeting is being captured.
Contacts and callers: If you appear in a Supasite user's phone contacts, call a supa number, or leave a voicemail, Supasite may hold your name, phone number and what you said, on behalf of that user. Section 3C explains this.
3. Information we collect
We only collect information that is reasonably necessary to operate Supasite and provide our services. This may include:
Identity information: Your name and, if you choose to tell us, your trade.
Contact information: Mobile phone number (required for account verification and service delivery). Email address (optional, collected only if you link your Supasite account to a BuildPass account or provide it to us for support).
Account credentials: Your account is authenticated via your verified mobile phone number. We do not collect passwords.
Profile and usage data: Information you provide when setting up your profile or using Supasite, including your timezone, language and country as derived from your device. We also collect usage data like feature use, clicks and interactions to understand how our service is used.
Contacts on your device: If you allow Supasite to access your phone contacts, the app reads contact names, phone numbers and contact photos on your device so you can call people by name. When you start a call from a contact, or receive a call from someone in your contacts, that contact's name and phone number are sent to our servers and to our telecommunications provider to place or label the call, label your call history and include the name in call notes. We do not upload your whole address book.
Audio capture data: When you use phone-call notes, meeting notes, voice notes or supa snap, Supasite processes audio and creates temporary transcript text to produce notes, tasks and other requested outputs. Audio may include the voices and personal information of people other than the account holder.
Saved transcripts: Depending on your transcript settings when a capture begins, Supasite may retain the completed transcript as part of the capture. Saved transcripts may contain transcript text, timestamps, speaker or channel labels where available, the capture type, and technical metadata about the transcription process.
Generated notes and tasks: Supasite stores the notes, tasks, titles, reminders and other outputs generated from a capture. These outputs are separate from the saved transcript.
Call metadata: For phone calls, we may retain the date, time, duration, call status, participating Supasite account, and the other party's number or contact name where available.
Supa number and voicemail data: If you activate a supa number, we hold that number, the calls and voicemails it receives, the caller's number, the voicemail transcript and the notes generated from it. See Section 3C.
Meeting and capture metadata: For meetings, voice notes and supa snap captures, we may retain the capture title, date, duration, associated project, calendar or meeting identifiers, photos, agendas, locations, links and other context supplied by you or an authorised integration.
Transcript preferences and audit data: We retain your transcript-storage preferences, when they were selected, the policy version that applied, and the preference applying when each capture began.
Photos: Supasite stores the photos you take or upload, including supa snap walkthrough photos and photos attached to notes and tasks, together with any caption, project or task you attach to them. Photos may show people, places, vehicles or documents. Each photo is described once by a model provider so that it can be searched and summarised. See Section 7.
Team data: If you create or join a team, we hold the team name, its members' names and phone numbers, invitations sent by phone number, and the captures, notes, tasks and projects placed in that team. See Section 3D.
Calendar data (optional): If you choose to connect Google Calendar or Microsoft calendar, Supasite accesses events that you own using read-only access. The information accessed may include event titles, dates and times, locations, descriptions, agendas, attendee details and links. Supasite does not create, modify or delete events in your calendar. Section 7.3 sets out the Google-specific terms.
Analytics and diagnostic data: We use analytics and error-monitoring tooling to collect technical information when you use Supasite. This can include your device type, operating system, app version, IP address, referring URLs, timestamps of actions, crash reports and, for a small sample of sessions and for sessions where an error occurs, a replay of what was shown on screen. Analytics profiles are linked to your account and include your name, phone numbers, email (if provided) and trade. See Section 6.
Advertising identifiers: If you allow tracking when iOS asks, the app shares your device's advertising identifier and app-install events with Meta so we can measure which advertising led to an install. See Section 6.
Cookies and similar technologies: Supasite uses cookies and similar tracking technologies to operate the website and gather analytics. See Section 6.
Communications: If you contact us (for example, via support email or feedback forms), we will collect the information you provide in those communications.
Supasite does not ask you to provide sensitive personal information unless it is required for a feature you choose to use. However, recordings, transcripts, photos and generated notes may incidentally contain sensitive information, including health information, racial or ethnic origin, political opinions, religious beliefs, trade-union membership, sexual orientation or criminal-history information. Do not capture sensitive information unless you and every affected participant are authorised to provide it and the collection is permitted by applicable law.
3A. Audio, transcripts, notes, tasks and photos
Supasite processes audio from phone calls, meetings, voice notes and supa snap captures to create transcripts, notes, tasks and other requested outputs. It also processes the photos you take or upload.
Audio is not retained by Supasite: Supasite streams audio to its contracted transcription provider while a capture is taking place. Supasite does not retain the audio as a durable record in your account or application database. Our contracted transcription and telecommunications providers process audio only as needed to transmit, transcribe, secure and operate the service, under contractual data-protection terms. See Sections 7 and 8. Voicemail is the one exception and is described in Section 3C.
Transcripts
While a capture is running, Supasite streams audio to its contracted transcription provider and receives transcript text back. That text is used to produce your notes and tasks whether or not the transcript is saved.
For meetings, voice notes and supa snap captures, saving the completed transcript is on by default. You can turn it off in the app under You, App, Notes and transcripts. The setting that applies is the one in force when the capture begins, so changing it affects future captures rather than ones already taken. When saving is on, you can open the transcript from the capture it belongs to, and you can permanently delete it on its own without losing the notes and tasks. Turning saving off does not remove transcripts that were already saved.
For phone calls, the transcript is always saved and there is no setting. It is held as an internal record. It is not shown in the app, not included in shares, and not sent to BuildPass. We use it to produce your call notes and tasks, and so that Supa can answer a later question you ask about that call. Supa may draw on the transcript when answering you, but the app does not offer playback or a word-for-word view. You can request a copy of the transcript for a call on your account by contacting us, and we will verify who you are before we release it. You cannot delete a call transcript on its own; it is deleted when you delete the call.
Saved transcripts are not included in ordinary public shares unless you choose to include them.
Photos
Photos you take or upload are stored in your account until you delete them. When a photo is uploaded, it is sent once to our model provider to generate a short description so that Supasite can search it and mention it in notes. The description is stored with the photo. Photos placed in a team, added to a share link or synced to BuildPass are visible to the people who can see that team, link or BuildPass project.
Telling other people that Supasite is taking notes
Supasite does not automatically tell the other people on a phone call, in a meeting or in a walkthrough that audio is being processed. Whether they are told, and how, is up to you, and you are responsible for complying with the recording, surveillance and workplace laws that apply to you. See the Terms of service, Section 4A.
To help you, the app shows you a reminder to let other people know when a meeting or voice note starts and during phone calls. For phone calls, the app also offers an optional spoken announcement (You, Phone calls, Play disclosure on calls) that is played to the other party before the call connects. This announcement is off by default. Supasite may enable or disable the announcement feature on the service side, and it is not a substitute for you meeting your own legal obligations. Voicemail callers always hear an announcement that their message will be transcribed.
3B. US SMS and text messaging
This subsection applies to service and transactional text messages we send to Supasite users in the United States, and explains how we handle mobile and SMS data for that purpose.
What we use: We use your mobile phone number, your SMS opt-in record and your consent status to send transactional and service text messages. These include one-time passcodes, login verification, account notices and service notices, including warnings that an account or supa number is about to be closed for inactivity. We do not send marketing or promotional texts through this program.
Non-sale and non-sharing: We do not sell or rent your mobile information, and we do not share your mobile information or SMS opt-in or consent data with third parties or affiliates for their marketing or promotional purposes.
Service providers: We share mobile information only with service providers that help us deliver these messages, being carriers, telecommunications and messaging infrastructure providers, and our hosting and support vendors, solely to operate SMS delivery on our behalf and under contractual data-protection terms.
3C. Supa number, calls and voicemail
Your supa number: A supa number is a business phone number we provision for you through our telecommunications provider. It is licensed to you for use with Supasite and remains registered to BuildPass. If a supa number goes 30 days without an inbound or outbound call, we send you a text message warning and release the number seven days later if it is still unused. A released number cannot be recovered. The Terms of service set out the conditions of use.
Calls: When you make or receive a call through Supasite, our telecommunications provider carries the call and, when notes are enabled, streams the audio to our live audio bridge and transcription provider. Supasite does not ask the telecommunications provider to record calls. We retain the call metadata described in Section 3.
Inbound callers: When someone calls your supa number, we hold their phone number and, where your contacts or BuildPass provide it, their name, so we can label the call and the notes.
Voicemail: Voicemail is on by default for a supa number. Callers hear an announcement that the message will be transcribed. The message is recorded briefly by our telecommunications provider, transcribed by that provider's transcription service, summarised by our model provider, and the recording is then deleted from the provider. Section 8 describes how long the provider may take to remove recording media and metadata. Supasite keeps the voicemail transcript and notes as part of the call record.
3D. Teams and sharing
Teams: Supasite lets you create a team and invite other people by phone number. Captures, notes, tasks, photos and projects placed in a team are visible to every member of that team, and each member can see the names and phone numbers of the other members. Team members can also connect their own BuildPass account to the team. If you leave a team or delete your account, content you placed in the team stays with the team, and if you were the team's admin another member becomes the admin. Personal captures that you did not place in a shared team are yours alone.
Share links: You can create a link to a note, task, voice note or photo page. Anyone who has the link can open it without signing in. The page shows the shared content, including any photos, together with your name and profile photo. Links expire after seven days unless you choose 30, 60 or 90 days, and you can revoke any link at any time under You, Sharing links. Saved transcripts and hidden call transcripts are never included in a share link. Once someone has opened a link, we cannot recall a copy they made.
4. How we collect information
We collect personal information in several ways:
Directly from you: Most data is provided directly by you. For example, you enter information when signing up for Supasite, completing your user profile, or contacting us for support.
Through your use of Supasite: As you interact with our platform or app, we automatically collect technical data via cookies, log files and analytics scripts.
Audio capture: When you start a phone call with notes enabled, meeting, voice note or supa snap capture, audio is captured by your device or telecommunications provider and transmitted to our transcription provider. The resulting transcript is processed by our model providers to create the requested notes, tasks and other outputs. See Section 3A.
Photos: Photos are captured by your device camera or chosen from your photo library and uploaded to Supasite, where they are described by our model provider. See Section 3A.
From your device: With your permission, Supasite reads contacts from your phone as described in Section 3, and receives your device's push notification token so we can send you notifications.
Collection from other participants: Where a capture includes another person, we ordinarily receive their personal information through the Supasite account holder rather than directly from that participant. The account holder is responsible for providing any required collection notice. Participants can contact us using Section 12.
From callers: When someone calls your supa number or leaves a voicemail, we receive their number and what they said directly from our telecommunications provider.
From your team and from BuildPass: Team members may place content that mentions you into a shared team. If your team is connected to BuildPass, contacts and projects from BuildPass are synced into Supasite. See Section 5.
AI processing of user content: If you use our AI features, the content you provide will be transmitted to our AI model providers for processing. See Section 7 for more details on how AI inputs and outputs are handled.
Third-party services: Some information may be collected or transmitted through third-party service providers integrated with Supasite. For example, when you sign up or log in, our identity and SMS verification provider processes your phone number on our behalf to authenticate you. If you connect a calendar, the calendar provider tells us your account name and email address for that calendar. These third parties collect and share information with us as needed to provide the Supasite service.
We will always endeavour to let you know when personal information is being collected and the purpose (for instance, by providing just-in-time notices or through this privacy policy). You may choose not to provide certain information; however, this may limit your ability to use some Supasite features. For example, if you do not allow contacts access, you can still call by typing a number, but Supasite cannot show the caller's name.
5. How we use personal information
We use the collected information for purposes necessary to provide and improve Supasite. The primary purposes include:
Providing services: We use your information to create and manage your Supasite account, authenticate you upon login, provision and operate your supa number, and deliver the features of the service.
Captures, transcripts, notes and photos: We process audio, temporary transcript text and photos to provide phone-call notes, meeting notes, voice notes, supa snap walkthroughs, photo descriptions, tasks and other requested outputs. Where transcript storage was enabled when the capture began, we retain the completed transcript so the account holder can review and manage it.
Answering your questions: When you ask Supa a question, we use your notes, tasks, saved transcripts and hidden call transcripts to answer it.
Notifications: We use your device's push token and the content of your calls, notes and tasks to send you notifications, such as a call summary being ready, a voicemail arriving or a task falling due. Notification content may include the other party's name and number. You can turn each category of notification off under You, Notifications.
Improving and developing Supasite: Usage data and analytics help us understand how our product is performing. We analyse this data to fix bugs, optimise user experience and inform new features.
Communications: We may use your contact information to send service-related communications. This includes confirmations, technical alerts, inactivity warnings and customer support responses, as well as material change notices to the Terms of service or to this privacy policy.
Analytics and product research: We use third-party analytics (PostHog) and error monitoring (Sentry) to understand how Supasite is used and where it fails. Analytics profiles are linked to your account and include your name, phone numbers, email (if provided) and trade so that we can follow up on problems you report. See Section 6.
Advertising measurement: We use install-measurement data from Meta to understand which advertising led people to install Supasite. We do not show advertising inside Supasite and do not use your captures, notes or transcripts for advertising.
BuildPass integration: If you or your team connect Supasite to a BuildPass account, we send call notes, meeting notes, tasks, photos and project links from Supasite to that BuildPass account, and we receive contacts and projects from BuildPass so that calls and notes can be matched to the right people and jobs. Photos are uploaded directly to BuildPass file storage. You choose whether the BuildPass account is in the Australian or United States region. Hidden call transcripts are never sent to BuildPass. We may also use your information to offer relevant BuildPass services based on your Supasite activity, pursuant to our legitimate business interests in providing a cohesive suite of services.
AI model training and improvement: We may use anonymised data from AI interactions that does not originate from Google Workspace APIs to evaluate and improve Supasite, subject to this policy and applicable law. Google Workspace API data, including raw, aggregated, anonymised or derived data, is expressly excluded from these activities. Neither Supasite nor its service providers use or transfer Google Workspace API data to create, train or improve generalised or foundational machine learning or artificial intelligence models.
Security and fraud prevention: We may process personal information to monitor for suspicious or malicious activity, verify user identities where necessary, and otherwise protect against unauthorised access, fraud or abuse of our services.
Legal compliance: Where required, we will use and disclose personal information to comply with legal obligations, resolve disputes, enforce our Terms of service, or respond to lawful requests by public authorities.
We do not use the contents of recordings, transcripts, photos, notes or tasks to train our own or our providers' general-purpose models without explicit consent.
We will only use your personal information for the purposes outlined above or for purposes that are compatible with those original purposes. If we need to use your information for an unrelated purpose, we will notify you and obtain your consent or ensure we have a lawful basis as required by applicable law.
5A. Lawful bases
We identify and document a lawful basis for each purpose for which we process personal information. Depending on the processing activity and our relationship with you, this may include performance of a contract, compliance with a legal obligation, legitimate interests or consent.
Where we rely on legitimate interests, the relevant interests include providing, securing and improving the Supasite service, subject to an assessment that those interests are not overridden by the affected person's rights and interests. Where we rely on consent, you may withdraw that consent at any time, without affecting processing that occurred before withdrawal.
5B. Retention of captures, transcripts, notes, tasks and photos
Transcripts
A saved capture transcript is kept for as long as you keep the capture it belongs to, or until you delete the transcript on its own. Where transcript saving is off, the temporary transcript text is removed from Supasite's active systems once finalisation or failure handling is complete.
A phone call transcript, including a voicemail transcript, is kept for as long as you keep the call.
We also keep a versioned record of the transcript storage setting that applied to each capture, where that is reasonably necessary to show what the setting was at the time.
Photos
A photo and its description are kept for as long as you keep the note, task or walkthrough it belongs to.
Deleting a capture or a call
Deleting a capture or a call in the app moves it to Graveyard, a recoverable shelf where it stays for 30 days. During that time you can restore it, or delete it permanently yourself. At the end of the 30 days Supasite deletes it automatically. Permanent deletion removes the whole record: its transcript, its notes and tasks, any stored photos, and its share links and related activity records. Content you placed in a shared team is removed for the whole team.
Closing your account, and inactive accounts
Supasite keeps your captures, transcripts, notes, tasks and photos for as long as your account is open. You can delete your account at any time from the app, and doing so removes your data from Supasite's systems straight away, releases your supa number, and disconnects any BuildPass and calendar accounts. Content you placed in a shared team stays with that team. If an account is not used for a year, we send you a text message notice and delete the account about 30 days later. Our inactivity checks run monthly, so the exact timing can vary by up to a month.
Limits on deletion
Deletion from Supasite's active systems is not deletion everywhere. Routine backups of our application database are kept for seven days, and copies held by our providers for their own operations may persist for up to 30 days. Section 8 explains what our transcription and telecommunications providers separately retain, and what we can and cannot remove there. Content you have already shared, synced to BuildPass, or that another team member holds is outside our control once it has left Supasite.
6. Cookies, analytics and advertising measurement
Supasite uses cookies and similar technologies on its website, and analytics software in the app, to ensure the platform functions correctly and to analyse usage.
What are cookies: Cookies are small text files stored on your device that allow us to remember certain information between pages or visits.
Essential cookies: Some cookies are necessary for the website to operate.
Analytics: We use PostHog to understand how people interact with Supasite, on the website and in the app. In the app, analytics events are linked to your account. We do not record your screen in PostHog. Where applicable law requires a choice before non-essential analytics technologies are used, we will present that choice first.
Error monitoring: We use Sentry to record crashes and errors in the app and on our servers. For a small sample of sessions, and for sessions where an error occurs, Sentry records a replay of what was shown on screen so that we can reproduce the problem. A replay can include the content that was on screen at the time, such as a note, a contact name or a photo. Replays are available to a small number of authorised BuildPass staff and are deleted after 90 days.
Advertising measurement: The app includes Meta's software so that we can measure how many installs come from our advertising. On iOS, Meta only receives your advertising identifier if you allow tracking when the system asks. Whether or not you allow tracking, Meta receives basic app events such as the app being opened. You can change your choice at any time under iOS Settings, Privacy and security, Tracking. We do not show advertising inside Supasite.
Your choices: Upon your first visit, and from time to time, we may present a cookie notice or preferences tool where required by law. You can manage or disable cookies in your browser settings.
Do not track: Supasite does not currently respond to "Do Not Track" signals.
You can manage cookies through any preferences tool we provide and through your browser settings. Disabling some technologies may affect non-essential analytics or website functionality.
7. AI and automated processing
Supasite is an AI-powered platform. We leverage third-party artificial intelligence services to provide certain features, including voice transcription, photo description, and the creation of notes, tasks and other requested outputs from phone calls, meetings, voice notes, supa snap captures and photos. It is important for you to understand how your data is handled in these processes.
7.1 AI providers and processing
Supasite integrates with third-party AI model providers to power our intelligent features, including contracted voice-transcription providers and large language model providers used to create notes, tasks, photo descriptions and other requested outputs.
These providers act as processors of data on our behalf when you use our AI-powered features. They receive the input data we provide on your behalf (such as capture audio for transcription, transcripts used to create requested outputs, or a photo to describe) and return an output (such as transcript text, notes, tasks, reminders or a description).
At the date of this policy:
- ElevenLabs provides live and batch voice transcription for phone calls, meetings, voice notes and supa snap captures.
- Twilio, our telecommunications provider, transcribes voicemail messages left on a supa number.
- Anthropic (Claude models) and Google (Gemini models) provide the language and vision models that create call notes, voicemail notes, meeting notes, tasks, photo descriptions, and Supa's answers to your questions. Both are accessed through Vercel AI Gateway. Which model is used depends on the feature.
These providers process information on our behalf under contractual data-protection terms. We may change which provider performs a given task, or add a provider in the same category, without changing this policy, provided the new provider is bound by equivalent data-protection terms. The current list is always available in this section.
7.2 Data handling in AI features
Audio capture data: When you use phone-call notes, meeting notes, voice notes or supa snap, audio is transmitted to our voice transcription provider over an encrypted connection. The provider returns transcript text, which is then transmitted to our model providers to create notes, tasks and other requested outputs.
Photos: When you upload a photo, it is transmitted once to our model provider to create a description. The provider is given temporary access to the photo for that request only.
Questions to Supa: When you ask Supa a question, the question and the relevant notes, tasks and transcripts from your account are transmitted to our model provider to produce the answer.
Calendar context: When you start a meeting note from a calendar event, the event's title, agenda and other details are transmitted to our model provider as context. See Section 7.3.
Input data transmission: When you use any AI feature, the necessary data is sent securely to the corresponding AI provider's API. We send only the information required for the task.
Provider-specific retention: ElevenLabs uses standard non-Enterprise retention and retains speech-to-text audio and transcript output in its request history. Twilio retains voicemail transcriptions with the call record for the periods described in Section 8. Anthropic and Google models are accessed through Vercel AI Gateway with team-wide zero data retention enabled, so prompts and outputs are not retained by the gateway or used for training by the model providers.
No secondary use by Supasite: We do not use the contents of recordings, transcripts, photos, notes or tasks to train our own AI models without your explicit consent. We may review AI interactions in an aggregated or anonymised way to evaluate performance. For clarity, Google Workspace API data is never included in model training, generalised model improvement or routine human review, even where the data has been aggregated, anonymised or derived from other Google Workspace data.
Quality monitoring: Prompts sent to model providers and the outputs they return, which can include transcript text, are recorded in our analytics provider (PostHog) and our error-monitoring provider (Sentry) so that we can measure quality and diagnose failures. Prompt and output content is retained in PostHog for 30 days. Authorised team members might review specific interactions if needed to investigate a problem or misuse, always under strict privacy controls. This general quality-review provision does not apply to Google Workspace API data. Human access to Google Workspace API data is limited to the circumstances described in Section 7.3.
7.3 Calendar data, Google Workspace API data and Limited Use
If you choose to connect Google Calendar, Supasite requests read-only access to events that you own on your primary Google Calendar. If you choose to connect a Microsoft calendar, Supasite requests read-only access to your calendar events through Microsoft Graph. The paragraphs below apply to both providers, and the Limited Use commitments apply to Google Workspace API data specifically.
How we use calendar data: Supasite uses event details to show upcoming meetings and reminders, prefill meeting notes, and provide relevant event titles and agendas as context when you choose to start Supasite's AI note-taking feature. Supasite does not create, modify or delete calendar events.
AI processing and sharing: When you request an AI note-taking feature associated with a calendar event, relevant event details may be transmitted to our contracted AI service providers solely to provide that user-facing feature. Those providers process the information on our behalf under contractual data-protection and Limited Use restrictions. They are not permitted to use Google Workspace API data for their own purposes or to create, train or improve generalised or foundational AI or machine-learning models.
Storage and retention: Supasite securely stores the OAuth credentials and connected-account metadata (including the account name and email address for the calendar) needed to maintain the integration. Calendar events are retrieved to provide the features described above. If you create a Supasite meeting note from a calendar event, selected event details, such as its title, time, agenda, location, links and calendar event identifier, may be stored as part of that Supasite note. These details are retained and deleted according to the applicable retention and deletion provisions in this policy.
Disconnecting and deleting data: You can disconnect a calendar through Supasite's calendar integration settings. Disconnecting removes Supasite's stored connection credentials and prevents further access to your calendar. Event details already included in saved Supasite notes remain subject to Supasite's normal retention and deletion processes. You may request deletion of those notes or your account as described in Sections 5B, 11 and 12. You may also revoke Supasite's access through your Google Account or Microsoft account settings.
Human access: Supasite personnel do not access Google Workspace API data except with your explicit consent for support, when necessary to investigate security or abuse, or when required to comply with applicable law.
Limited Use compliance: The use of raw or derived user data received from Google Workspace APIs will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
Supasite does not sell Google Workspace API data, use it for advertising, or use, transfer or share it to create, train or improve generalised or foundational machine-learning or artificial-intelligence models.
7.4 No fully automated decisions with legal effects
Supasite's AI features are tools to assist users in capturing and organising information from phone calls, meetings, voice notes, photos and supa snap captures. They do not independently make binding decisions about individuals. All AI outputs should be reviewed by a human user. We do not subject anyone to purely automated decisions that have legal or significant effects on them, as defined under GDPR Article 22.
7.5 Accuracy and limitations
While we strive to use high-quality AI models, AI predictions or generated outputs can sometimes be incorrect or misleading. We do not guarantee the accuracy or completeness of any AI-generated content. Users should not rely on Supasite's AI features as professional advice or the sole basis for decisions.
7.6 User control
If you do not want information processed through an AI-powered feature, do not start or request that feature. When you request an AI-powered feature, we process the information needed to provide it under the lawful basis described in Section 5A. Where applicable law requires consent for a particular processing activity or transfer, we will request that consent separately.
8. Disclosure of personal information to third parties
We treat your personal information with care and confidentiality. We do not sell your personal data to unrelated third parties for their own marketing or any other purposes. However, we do share information with certain trusted third parties in order to run Supasite effectively, as outlined below:
Service providers: We use third-party companies to support our operations and services. These providers only receive the information necessary for them to perform their function, and they are contractually obligated to protect it and use it only for our purposes. At the date of this policy our service providers are:
Convex: Hosts our application database and file storage, including photos, in Virginia, United States. Backups run daily at 1:00 am and expire after seven days.
Fly.io: Hosts our live audio bridge in Sydney, Australia. All live audio, transcript text and note-generation requests pass through the bridge while a capture is running. The bridge does not intentionally persist raw audio.
Vercel: Hosts and serves the Supasite web application and provides Vercel AI Gateway, through which we reach our model providers. Vercel AI Gateway has team-wide zero data retention enabled. Prompts and outputs are not retained, prompt training is prohibited, and requests are restricted to qualifying zero-retention providers.
Anthropic: Provides Claude language and vision models, accessed through Vercel AI Gateway, used to create call notes, voicemail notes, photo descriptions and Supa's answers. It acts as a processor on our behalf under contractual data-protection terms. Its processing location is not region-restricted.
Google: Provides Gemini language models, accessed through Vercel AI Gateway, used to create meeting, voice note and supa snap notes and tasks. It acts as a processor on our behalf under contractual data-protection terms. Its processing location is not region-restricted.
ElevenLabs: Processes live audio and transcript output in the United States under its standard non-Enterprise retention arrangements. Zero retention mode is not available to Supasite. ElevenLabs retains speech-to-text audio and transcript output in its request history. Supasite does not currently delete that provider data when an in-app transcript is deleted. ElevenLabs' "Improve the models for everyone" setting is disabled, so new Supasite data is not used for model training. If provider data is separately deleted, primary database content is removed, backups may retain it for up to 30 days, and debugging or moderation information may remain under ElevenLabs' standard policies.
Twilio: Carries phone calls and text messages, provisions supa numbers, verifies your phone number at sign-in, and processes Supasite calls in its US1 region. Twilio receives the phone numbers of both parties to a call and, where you call from a contact, that contact's name. Voice Trace is disabled on the Supasite Twilio account. Ordinary calls use Media Streams and Twilio does not store call audio because Supasite does not invoke Twilio recording for those calls. Voicemail is the exception. Voicemail audio is temporarily recorded, transcribed by Twilio, and then deleted. Recording media may take up to 30 days to be completely removed from Twilio systems, while recording metadata remains for 40 days after deletion. Twilio call and conference logs, including voicemail transcriptions, are available through the Console and API for 13 months. This is an availability period, not a guaranteed deletion deadline.
PostHog: Provides analytics services from the United States. Analytics profiles include your name, phone numbers, email (if provided) and trade. Prompt and generated-output content is retained for 30 days. Model, provider, token, cost, latency and trace metadata remains available after content expiry.
Sentry: Provides error monitoring from the United States on its Team plan. Errors are retained for 90 days; logs, profiles and ordinary spans or transactions for 30 days; sampled transaction data for up to 13 months; and attachments, replays and uptime data for 90 days. Sentry receives your account identifier, phone number and email (if provided) with each error, sampled screen replays as described in Section 6, and model inputs and outputs for failed requests.
Expo: Provides the services we use to build and update the mobile app, and relays push notifications from our servers to Apple's notification service. Notification content, which can include a contact's name, phone number and the text of a task, passes through Expo in transit.
Apple: Delivers push notifications to your device and distributes the app through the App Store.
Meta: Receives your device's advertising identifier (only if you allow tracking) and app-install and app-open events so we can measure advertising. Meta processes this information under its own data policy as well as our contractual terms.
BuildPass: BuildPass is our own construction platform, operated by BuildPass Pty Ltd and BuildPass Inc. If you connect a BuildPass account, the information described in Section 5 flows between Supasite and BuildPass in the region you select (Australia or United States). BuildPass stores photos in Amazon Web Services storage in that region.
Calendar providers: Google and Microsoft provide calendar data to us at your request, as described in Section 7.3.
Provider changes: We may replace a provider or add another provider in a category already described in this policy where reasonably necessary to operate Supasite, provided the new provider is bound by equivalent contractual data-protection terms. We will update the list in this section when we do. If a change materially alters how personal information is handled, we will present any notice or choice required by law before the change applies to the affected user.
9. International data transfers
Supasite is a global service. The personal information we collect may be accessed or processed in countries other than the country you reside in. In particular, many of our third-party providers are based in (or may store data in) the United States and other jurisdictions outside of Australia or the European Economic Area (EEA).
Business transactions: If BuildPass is involved in a merger, acquisition, sale of assets or reorganisation, your information may be transferred as part of that transaction. We will provide notice before personal data is transferred or becomes subject to a different privacy policy.
Our location: BuildPass Pty Ltd is based in Australia, but Supasite application data is stored with Convex in Virginia, United States. Live audio passes through our bridge in Sydney, Australia, and audio, transcript, photo and note data may also be processed by the providers described in Sections 7 and 8.
Risks: Different countries have different data protection laws. When your data is transferred from your home country to another country, it may become subject to those foreign laws.
Our safeguards: We take reasonable steps to ensure that international data transfers comply with applicable laws. For transfers from Australia, we abide by Australian Privacy Principle 8. For transfers from the EEA, UK or other regions with data transfer restrictions, we utilise appropriate safeguards such as Standard Contractual Clauses (SCCs) approved by the European Commission, or we rely on an adequacy decision where applicable.
Your consent in some cases: In certain situations, we may ask for your consent to transfer data overseas. If you agree to such a transfer, we will inform you of any relevant risks and handle the data in accordance with that consent and this policy.
Despite the global transfer of data, your information remains protected by the measures described in this policy. We maintain high standards of data protection regardless of where data is processed and continue to be responsible for it. If you have questions about our international data transfer practices, please contact us (see Section 12).
10. Data security and storage
We implement a variety of administrative, technical and physical security measures to protect your data from unauthorised access, alteration, disclosure or destruction. These include:
Encryption: Data exchanged with Supasite is encrypted in transit using TLS. Data in our databases and file storage is encrypted at rest.
Access controls: Personal information is accessible only to those personnel and service providers who need it to perform their duties or services.
Security testing and maintenance: We regularly update our software and systems to address security vulnerabilities.
Analytics and testing environments: Our analytics and error-monitoring tools can identify you, as described in Section 6, so that we can follow up on problems. We do not use production captures, transcripts or photos as test data.
Physical security: Our data is stored on secure servers operated by reputable cloud providers.
Despite our efforts, no method of transmission over the internet or electronic storage is 100% secure. We cannot guarantee absolute security of your information.
If we become aware of a data breach that compromises your personal information, we will notify affected individuals and relevant authorities as required by law.
11. Your rights and choices
You have certain rights regarding your personal information held by us:
Access: You have the right to request a copy of the personal information we hold about you.
Correction: If you believe any personal data we have is incorrect or incomplete, you have the right to request we correct it.
Deletion (right to erasure): You may request that we delete your personal information. You can delete your account yourself in the app under You, Profile.
Withdrawal of consent: If we are processing your personal information based on your consent, you have the right to withdraw that consent at any time.
Objection to processing: You have the right to object to certain processing activities.
Restriction of processing: You can request that we temporarily limit the processing of your personal information in certain situations.
Data portability: For EU and UK users (and others where applicable), you have the right to data portability. The app does not yet include an export tool; contact us and we will provide your data in a machine-readable format.
Automated decision-making: Supasite does not make solely automated decisions with legal or similarly significant effects.
Controls in the app: You can turn transcript saving on or off (You, App, Notes and transcripts), turn each category of notification on or off (You, Notifications), revoke share links (You, Sharing links), turn the spoken call announcement on or off (You, Phone calls), disconnect a calendar or BuildPass account (You, Integrations), leave a team (You, Teams), and withdraw contacts, microphone, camera and tracking permissions in iOS Settings.
Capture participant rights: If you participated in, appeared in or were audible during a Supasite capture, or you called a supa number, you may request access to, correction of or deletion of personal information about you. We may need information that identifies the capture and may need to coordinate with the relevant account holder. We will still respond within the timeframes required by applicable law.
If an account holder does not cooperate with a valid request, BuildPass may act directly where legally permitted or required and may suspend the account under the Terms of service.
How to exercise your rights: You can exercise most of the above rights by contacting us (see Section 12). For certain requests, we may need to verify your identity to ensure we don't disclose or delete data to the wrong person.
Requesting a phone call transcript: Section 3A explains that phone call transcripts are not shown in the app. You can request a copy of the transcript for a call on your account by contacting us at hello@supasite.com. We will verify who you are before we release it. Where a capture participant who is not the account holder makes a request under this section, we will take the privacy of the other people in that capture into account when we respond.
12. Questions, complaints and contacting us
If you have any questions about this privacy policy, wish to exercise any of your rights, or have a concern or complaint about privacy, please contact us:
Privacy contact office: Email: hello@supasite.com
Australia: Postal mail: The Privacy Officer BuildPass Pty Ltd (Supasite) Unit 2, 33 Stewart St Richmond, VIC 3121, Australia
United States: Postal mail: The Privacy Officer BuildPass Inc (Supasite) 3212 E Cesar Chavez, Building 1, Suite 1115 Austin, TX 78702, United States
If you are not satisfied with our response to a privacy complaint, you have the right to escalate the matter to the appropriate supervisory authority. For Australian users, you may contact the Office of the Australian Information Commissioner (OAIC). For individuals in the EU or EEA, you can reach out to your local Data Protection Authority. UK users can contact the Information Commissioner's Office (ICO).
13. Changes to this privacy policy
Supasite and our data practices may change over time. The Updated date at the top of this policy shows when it was last revised, and the current version is always available at supasite.com/privacy-policy.
Changes take effect on the Updated date. We may correct, clarify or expand this policy, update the provider list in Sections 7 and 8, or describe a new feature, without asking you to accept the policy again, provided the change does not reduce your rights or use your personal information for a materially different purpose.
If we make a change that requires your consent under applicable law, or that materially expands how we use personal information you have already given us, Supasite will present the updated policy in the app before you can continue into the affected service, and may also notify you on our website or by SMS or email. Where applicable law requires consent for a particular collection, use, disclosure or transfer, we will request that consent separately.