Skip to content
Struct
TermsOpen Struct →

Legal

Privacy Notice

This notice explains what information Struct processes, why we use it, when we share it, and the choices available to you.

Effective July 21, 2026 · Version 2026-07-21

This notice applies to Struct’s website and hosted engineering workspace. An organization may separately control the Customer Content its users place in Struct.

1. Information we collect

Account and organization information

We process your name, email address, authentication provider identifier, organization membership and role, security settings, and records of accepted legal versions. If your organization uses SSO, we process the identity attributes its provider sends to us.

Workspace content

We process the diagrams, specifications, project metadata, comments, review records, attachments, access rules, and other Customer Content you choose to store or synchronize. Private offline projects remain on your device unless you choose a cloud or sharing action.

Billing and support

Our payment processor provides customer, subscription, invoice, plan, seat-count, and payment-status information. Struct does not store full payment-card numbers. We process messages and files you send when requesting sales or support.

Usage and security data

We process IP-derived security identifiers, browser and device information, request timing, session and audit events, errors, feature usage, and diagnostic logs needed to operate and protect the service. We configure product analytics to avoid diagram bodies and engineering content.

2. How we use information

  • Provide accounts, organizations, synchronization, sharing, exports, billing, and support.
  • Authenticate users, enforce permissions and plan entitlements, prevent abuse, and investigate security incidents.
  • Process requested agent actions and supplier lookups.
  • Maintain, troubleshoot, and improve reliability and product experience.
  • Communicate service, billing, security, and legal updates.
  • Comply with law and enforce our agreements.

3. AI-assisted features

When you use the hosted agent, Struct sends the prompt and the bounded project context needed to fulfill the request to our AI service provider. The browser never receives Struct’s provider key. Struct keeps bounded conversation state for continuity and does not enable provider tracing by default. Do not submit data to the agent unless your organization permits that processing, and review all output before use.

4. When we share information

We share information only as needed with service providers that host infrastructure, process payments, provide authentication, deliver AI functionality, supply requested catalog results, provide analytics, or support operations. We may also disclose information to comply with law, protect rights and safety, complete a corporate transaction with appropriate safeguards, or follow an organization administrator’s instruction. We do not sell personal information or use Customer Content for third-party advertising.

5. Retention

We retain account and Customer Content while the applicable organization is active and for a limited period afterward to support recovery, security, legal, and billing obligations. Organization retention settings apply where offered. Audit, billing, backup, and security records may follow separate limited retention periods. Browser-only and offline data remains under your device and browser controls. You may request deletion as described below.

6. Security

Struct uses transport encryption, tenant and role checks, signed sessions, anti-forgery protections, rate limits, audit records, and encryption for stored identity secrets. No system is perfectly secure. Protect your identity-provider account, enable multi-factor authentication where available, and report suspected unauthorized access promptly.

7. Your choices and rights

You can update many account and organization settings in Struct, manage your subscription in the billing portal, disconnect optional integrations, and control browser storage through your device. Depending on your location, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal or complain to a regulator.

For Customer Content controlled by your employer or another organization, contact that organization first. For a direct privacy request, email info@structspace.com. We may verify your identity and authority before acting.

8. International processing

Struct and its providers may process information in the United States and other countries. Where required, we use contractual and organizational safeguards for transfers across borders.

9. Children

Struct is designed for professional and organizational use and is not directed to children under 13. We do not knowingly collect personal information from children under 13.

10. Changes and contact

We may update this notice as Struct and applicable law change. We will post the revised version and effective date and provide additional notice when required. Privacy and data-protection questions can be sent to info@structspace.com.

© 2026 Struct
Terms of ServiceSecurityContact