Operator and roles. Structspace LLC, a California limited liability company (“Struct,” “we,” “us,” or “our”), operates the website and hosted engineering workspace covered by this notice. An organization may control the Customer Content its users place in Struct and may act as the controller or business for that content; Struct may process it as the organization’s service provider or processor. The organization’s agreement with Struct controls where it supplements this notice.
1. Notice at collection
This summary is provided at or before collection and links to the fuller explanations below. We collect the following categories from you, your organization, your browser or device, identity providers, payment providers, and service interactions for the stated business purposes. We do not sell personal information or share it for cross-context behavioral advertising.
- Account and security: name, email, authentication-provider identifiers, password hashes for legacy accounts, phone numbers used for SMS MFA, MFA and recovery-code data, organization role, accepted legal versions, session metadata, IP-derived security identifiers, and audit events. We use this to authenticate, secure, administer, and support accounts; active-account records remain while the account or organization is active, subject to the schedules in section 5.
- Customer Content and agent inputs: diagrams, specifications, project metadata, comments, attachments, access rules, prompts, bounded project context, rendered visual-review images, and agent results. We use this to synchronize, render, share, review, and perform actions you request; retention depends on the organization and the schedules in section 5.
- Billing and support: Stripe customer, subscription, invoice, plan, seat, billing-address, tax, and payment-status data, plus messages or files sent to support or sales. We use this to provide paid services, collect payment, prevent fraud, and respond to requests; financial and support records may be retained for legal, accounting, dispute, and security needs.
- Usage, analytics, and diagnostics: page title and path, permitted event names, browser and device details, request timing, errors, and service telemetry. If configured, Google Analytics 4 is loaded through Google Tag Manager with analytics and advertising storage denied by default; GPC and Do Not Track disable this optional measurement. We exclude diagram bodies and URL query strings and retain telemetry according to the provider and operational schedule.
- Integrations and catalog lookups: OAuth or SSO identifiers and attributes, token hashes, scopes, expiration and revocation data, supplier lookup inputs and results, and MCP authorization data when you connect a client. We use this to authenticate integrations and return the content or catalog information you request; provider and organization controls determine retention and access.
See section 2, section 5, and section 6 for sources, purposes, disclosures, and retention details.
2. Information we collect
Account and organization information
We process your name, email address, authentication provider identifier, organization membership and role, security settings, product-update email preference and enrollment timestamps, and records of accepted legal versions. Google Identity Platform processes passwords, email verification, enrolled MFA phone numbers, and SMS challenges for current password accounts. Legacy passwords are stored as one-way hashes during migration; legacy MFA secrets are encrypted and recovery codes are stored as hashes until phone enrollment succeeds. If your organization uses SSO, we process the identity attributes its provider sends to us.
Workspace content
We process the diagrams, specifications, project metadata, comments, review records, attachments, access rules, prompts, bounded context, rendered review images, and other Customer Content you choose to store or synchronize. Private offline projects remain on your device unless you choose a cloud or sharing action.
Billing and support
Stripe may provide customer, subscription, invoice, plan, seat-count, billing-address, tax, and payment-status information. Struct does not store full payment-card numbers. Resend may process email addresses, product-update preferences, and delivery events for account, product, and support messages. We process messages and files you send when requesting sales or support.
Usage and security data
We process IP-derived security identifiers, browser and device information, request timing, session and audit events, errors, feature usage, supplier lookup diagnostics, and other logs needed to operate and protect the service. Product analytics is designed to exclude diagram bodies, project content, URL query strings, and URL fragments.
3. How we use information
- Provide accounts, organizations, synchronization, sharing, exports, billing, and support.
- Authenticate users, record legal acknowledgments and product-email preference changes, enforce permissions and plan entitlements, prevent abuse, and investigate security incidents.
- Process requested agent actions, visual reviews, web searches, MCP requests, and supplier lookups.
- Maintain, troubleshoot, measure, and improve reliability and product experience using appropriate de-identification or aggregation where practical.
- Communicate service, billing, security, and legal updates, and send occasional product updates unless you opt out.
- Comply with law, respond to valid legal process, and enforce our agreements.
4. AI-assisted features
When you use the hosted agent, Struct may send your prompt, the bounded project context needed for the request, and the resulting action state to OpenAI or another configured AI provider. Visual review sends a rendered image of the selected project view. When the agent uses web search, it may send a query derived from your request to the configured search capability. The browser never receives Struct’s provider key, provider tracing is disabled by default, and requests are configured not to be stored as application state by the provider API where that option is available. Providers may nevertheless retain limited safety, abuse-monitoring, or service records under their current terms. Do not submit data to the agent unless your organization permits that processing, and review all output before use.
6. Retention
We retain information only for as long as needed for the purposes described here, then delete, de-identify, or restrict it where practical. Current application defaults and windows include:
- Account and Customer Content remain while the organization is active. An organization administrator can select a data-retention period from 30 to 3,650 days; the default is 365 days. Soft-deleted projects are purged after that organization period, subject to backups, legal holds, security needs, and provider schedules.
- Browser sessions default to 12 hours; invitations default to 72 hours; share links may be configured up to one year; password-reset tokens expire after 60 minutes.
- Process-local multi-turn agent memory is purged after up to 24 hours of inactivity. For in-flight reconnect recovery across application instances, Struct temporarily stores an HMAC request fingerprint and encrypted typed agent output and action events. Active recovery records become eligible for deletion 30 minutes after the last lease activity and completed records after 10 minutes; a delete-only sweep runs every 30 seconds, so normal completed-record deletion occurs within 11 minutes. Encrypted database backups and AI providers follow their separately disclosed schedules. Supplier lookup cache data is process-local and may remain stale for up to 24 hours.
- Audit, billing, accounting, security, dispute, backup, and legal records may be retained longer where reasonably necessary or required by law. Third-party providers apply their own retention and deletion schedules.
- Browser-only and offline data, including locally cached project or conversation state, remains under your device, browser, and local-storage controls until you clear it or the application replaces it.
Organization administrators should configure retention and export needed Customer Content before deleting a project or organization.
7. Security
Struct uses transport encryption, tenant and role checks, signed sessions, anti-forgery protections, rate limits, audit records, encryption for stored identity secrets, and authenticated encryption for temporary agent turn-recovery events. No system is perfectly secure. Protect your identity-provider account, enable multi-factor authentication where available, and report suspected unauthorized access promptly.
8. Your choices and rights
You can update many account and organization settings in Struct, turn product updates off or back on from Account settings, unsubscribe from any product-update email, manage a subscription in the Stripe billing portal, disconnect optional integrations, and control browser storage through your device. Turning off product emails does not affect required transactional or security messages. Depending on your location and role, you may have rights to access, correct, delete, restrict, object to, or obtain a copy of personal information, and to appeal or complain to a regulator.
For Customer Content controlled by your employer or another organization, contact that organization first. For a direct privacy request, email info@structspace.com. Identify the request you are making, do not send passwords or secret keys, and provide enough information for us to verify your identity and authority. We generally respond within the period required by applicable law; California requests may generally receive an initial response within 45 days, subject to a lawful extension. We do not discriminate against people for exercising applicable privacy rights.
9. California privacy disclosures
If the California Consumer Privacy Act applies to Struct or to a particular processing activity, California residents may request the categories and specific pieces of personal information we collect, the purposes and sources, the categories of recipients, correction, deletion, and other rights provided by law. The categories we collect are summarized in section 1 and described in sections 2 through 6. We do not sell personal information and do not share personal information for cross-context behavioral advertising. If that practice changes, we will provide the notices and opt-out controls required by law. Requests and appeals can be sent to info@structspace.com.
10. International processing
Struct and its providers may process information in the United States and other countries. Where required, we use contractual and organizational safeguards for transfers across borders. If the GDPR, UK GDPR, or another similar law applies, the relevant controller or organization determines the applicable legal basis; available rights may include access, correction, deletion, restriction, objection, portability, and withdrawal of consent. Complaints may be made to the applicable supervisory authority.
11. Cookies and local storage
Struct uses necessary cookies for sessions, security, and sign-in flows. The application may use local storage for offline projects, preferences, and bounded agent conversation continuity. Optional analytics is disabled when GPC or Do Not Track is present and is configured with Google storage and ad signals denied by default. We do not intentionally place advertising cookies through the application.
12. Children
Struct is designed for professional and organizational use and is not directed to children under 13. We do not knowingly collect personal information from children under 13.
13. Changes and contact
We may update this notice as Struct and applicable law change. We will post the revised version and effective date and provide additional notice when required. Privacy and data-protection questions can be sent to info@structspace.com. If a law requires a separate representative or data-protection contact, we will publish the applicable details.