The short version: your bid documents, measurements and estimates are yours and stay private to your project. We use them to run Charlie for you and for nothing else. We don't sell data, we don't run ads, and we don't use tracking cookies. The details are below, in plain English.
01Who we are
Run It By Charlie ("Charlie", "we", "us") is a web application at runitbycharlie.com, operated by Loper Architectural Products LLC, a Texas company. When this policy says "you", it means the person or company using Charlie.
Questions about this policy or your data: charlie@runitbycharlie.com.
02What Charlie is
Charlie reads a commercial roofing bid set — the specification, the roof plans and details, the addenda — the way an estimator does, and writes up what it finds with the section or sheet it came from. It can also measure a roof plan, turn the measurements into quantities, take prices from a supplier quote you paste in, write a proposal PDF in your company's name, and send an estimate to your QuickBooks Online company if you choose to connect one.
Charlie is currently a test version. What it produces is a draft for you to check, and it will be wrong sometimes. That matters for privacy in one way: the people testing Charlie are helping us find its mistakes, and we look at what the product did in order to fix it (see section 06).
03What we collect
Your account
- Your email address and a password. The password is never stored as typed — our sign-in provider stores a one-way hash of it, and we cannot read it.
- When you signed up, confirmed your email, and last signed in.
- Your acknowledgement that Charlie is a test version, and the date you gave it.
Your projects
- Project names and the documents you upload (PDF), together with the text Charlie extracts from them so it can read them.
- What Charlie finds in those documents, and your decisions about each finding — confirmed or dismissed.
- Measurements you take on a roof plan, the takeoff quantities and factors built from them, any quantities or prices you change by hand, and the supplier quote text you paste in for pricing.
- Proposal details you type — your company name, address, contact, customer, terms — and the proposal PDFs Charlie generates from them.
- The email addresses of people you invite to a project.
QuickBooks (only if you connect it)
- Your QuickBooks company identifier and company name, the credentials (access and refresh tokens) that let Charlie write to that company on your behalf, and the identifiers of the customer, service item and estimate Charlie created or updated. See section 08.
How the product is used
- A record of each run: which project, when it started and finished, whether it completed, how much text it read, and its estimated cost to us. We use this to enforce the monthly run limit, to find failures, and to understand what Charlie costs to operate.
- Charlie saves your work to our servers as you go; those saves carry the time and the version of the page.
Technical information
- Our hosting and infrastructure providers keep standard server logs — your IP address, browser type, the pages and requests you make, and timestamps — as any website's providers do. We do not add analytics, advertising or fingerprinting code to Charlie.
We do not ask for, and you should not upload, payment card numbers, government identifiers, or anyone's personal health, financial or biometric information. Bid documents occasionally contain the names and contact details of architects, engineers, owners and contractors; that is expected, and it is treated as part of your project.
04How we use it
- To run Charlie for you. Reading your documents, producing findings, computing quantities, building proposals and order lists, and sending an estimate to QuickBooks when you ask.
- To operate and improve the product. Finding failures, measuring run cost and duration, fixing wrong output, and deciding what to build next. During the test period this includes looking at what Charlie produced on real projects to see where it helped and where it missed.
- To communicate with you. Transactional email only — confirming your address, resetting a password, a sign-in link, an invitation to a project — sent from charlie@runitbycharlie.com. We do not send marketing email, and we will not add you to a list.
- To keep the service safe. Enforcing limits, preventing abuse, and protecting accounts.
- To bill you, once paid plans exist. Card details will be handled by a payment provider; we will update this policy before that happens.
We do not sell your data. We do not share it with advertisers. We do not use your documents to build products for other customers.
05How the AI reads your documents
When you press Run it by Charlie or Manufacturer check, the text of your project's documents is sent from our servers to Anthropic's API, the large language model that does the reading, along with the relevant manufacturer documents from Charlie's own library. Anthropic processes it to produce the findings and returns them to us. Under the commercial API terms we use, Anthropic does not use content sent through the API to train its models.
What goes into a run is limited to the project being run and Charlie's own reference material: the manufacturer library, and a small set of general roofing principles that Charlie has confirmed over time. Other customers' projects, documents and findings are not part of your run, and yours are not part of theirs.
The model's output is a draft. Every finding is marked as an AI draft until a person confirms or dismisses it, and every finding cites where it came from so you can check it.
06Who can see your data
- You, and the people you invite to a project. A project member sees that project — its documents, findings and estimate — and nothing else of yours.
- Charlie's administrators — the small team that builds and operates Charlie. They can access projects and account records in order to run the service, support you, investigate a failure, and, during the test period, see how the product performed on real work. They do not use your data for any other purpose and are bound by this policy.
- Our service providers, listed in section 07, each only to the extent needed to do their part.
- Intuit, if you connect QuickBooks — see section 08.
- Where the law requires it. We may disclose data to comply with a legal obligation, a court order, or a lawful request, or to protect the rights and safety of Charlie, its users or others. Where we can, we will tell you.
- If Charlie changes hands. If the product or the company is acquired or merged, your data may transfer to the new owner under this policy or one at least as protective; we will tell you before that happens.
07The services we rely on
| Provider | What they do for Charlie | What they hold or see |
|---|---|---|
| Supabase | Database, sign-in, file storage, and the server functions that run Charlie's engines | All account and project data, uploaded documents, run records, QuickBooks credentials. Hosted in the United States (East US, Ohio). |
| Hostinger | Web hosting for runitbycharlie.com and outbound email | Server logs for page requests; the transactional emails we send you. |
| Anthropic | The AI model that reads documents and drafts findings | The text of the documents in the project being run, and Charlie's reference material, for the duration of the run. Not used to train models. |
| Intuit (QuickBooks Online) | Receives the estimates you send, if you connect | The estimate, customer and item Charlie creates in your company; Intuit sees Charlie's requests on your behalf. Only if you connect. |
| Google Fonts, Cloudflare (cdnjs), jsDelivr | Serve the page's typefaces and two open-source libraries (PDF and spreadsheet generation) | Your browser requests those files directly, so these networks see your IP address and the request, as with any website that uses them. No account or project data is sent to them. |
If we add a provider that handles your data, we will update this table.
08QuickBooks Online
Connecting QuickBooks is optional. If you do, here is exactly what happens.
- Authorization. You sign in to Intuit in a window Intuit controls and approve Charlie's access to your company. Charlie never sees your Intuit password. Intuit gives Charlie an access token and a refresh token for that company.
- Where the tokens live. On our server only, in a table that no browser and no other user can read. The page you use never receives them. They are used by Charlie's server code solely to make the requests below.
- What Charlie writes to QuickBooks. A customer (if you ask it to create one), a single service item named "Charlie estimate line", and an Estimate built from your takeoff sheet. Sending again updates the same Estimate rather than creating another.
- What Charlie reads from QuickBooks. Your company's name, your customer list (so you can pick one), your income accounts (to file the service item), and the estimate it created (to update it). Charlie does not read your invoices, bills, bank feeds, payroll, reports or any other accounting data.
- What we keep. The company identifier and name, the tokens, and the identifiers of the item, customer and estimate Charlie created. Nothing else from your books is copied to Charlie.
- Disconnecting. Disconnect in the QuickBooks card deletes the stored tokens from our server immediately and asks Intuit to revoke them. You can also revoke Charlie's access from within QuickBooks (Settings → Apps). The Estimate already in your books stays there; it is your record.
Intuit's handling of your QuickBooks data is governed by Intuit's own privacy policy and terms, not by this one.
09Cookies and tracking
Charlie sets no cookies of its own. When you sign in, your session (an access token and a refresh token) is kept in your browser's local storage on that device so you stay signed in; signing out removes it. Third-party services listed in section 07 may set cookies according to their own policies when your browser requests files from them. We use no analytics, advertising, or session-recording tools.
10How long we keep it, and how to delete it
- Projects. Kept until the project owner deletes the project. Deleting a project removes its documents, extracted text, findings, measurements, takeoff and proposal data. Run records for that project are kept for accounting of our own costs and carry no document content. One limit during the test period: a project on which findings have been confirmed cannot be deleted from the page, because confirmed findings are treated as a record; email us and we will delete it for you.
- Your account. Kept until you ask us to delete it. Email charlie@runitbycharlie.com from the address on the account; we will delete the account and every project it owns within 30 days and confirm by email. Projects owned by someone else that you were invited to stay with their owner.
- QuickBooks tokens. Deleted the moment you disconnect, or when your account is deleted.
- Backups. Our database provider keeps rolling backups for disaster recovery. Deleted data leaves those backups on their normal schedule, generally within 30 days.
- Records we must keep. Billing records, and anything we are legally required to retain, for as long as that requirement lasts.
11Security
- Every connection to Charlie and between Charlie and its providers uses TLS (HTTPS).
- Data is encrypted at rest by our database and storage provider.
- Access to project data is enforced in the database itself, row by row: a request only returns what the signed-in person is a member of. Uploaded files are stored under the same rule.
- QuickBooks credentials are reachable only by our server code, never by the page or by another user.
- Passwords are hashed by our sign-in provider; we cannot read them. Sign-in links and password resets expire after one hour.
- Charlie's engines will not run for an account that has not acknowledged the test-version terms, and each account has a monthly run limit.
No system is perfectly secure. If we learn of a breach affecting your data, we will tell you promptly and say what happened, what it touched, and what we are doing about it.
12Your choices and rights
- See and export your data. Everything in a project is visible on its page; the takeoff sheet exports to a spreadsheet and the proposal to PDF. For a full copy of your account data, email us.
- Correct it. Project content is yours to edit. To change the email on your account, email us.
- Delete it. Delete a project from its page; delete your account by emailing us (section 10).
- Disconnect QuickBooks at any time from the QuickBooks card.
- Object or ask questions. Write to us at the address in section 16. If you are in a jurisdiction that grants specific privacy rights (for example California, or the European Economic Area or United Kingdom), you can exercise them by the same email, and we will respond within the time that law allows. We do not discriminate against anyone for exercising a privacy right.
Charlie is built for businesses in the United States. If you use it from elsewhere, you are sending your data to the United States, where privacy law may differ from your own.
13Where your data lives
In the United States. Our database, file storage and server functions run in Supabase's East US (Ohio) region. Anthropic and Intuit process requests in the United States.
14Age
Charlie is a business tool for people 18 and older. We do not knowingly collect data from anyone under 18; if you believe we have, email us and we will delete it.
15Changes to this policy
When we change this policy we will change the date at the top and, for anything material — a new provider that handles your data, a new use of it, billing — we will tell you by email or in the product before it takes effect. Earlier versions are available on request.
16Contact
Run It By Charlie · Loper Architectural Products LLC · Texas, USA
charlie@runitbycharlie.com