Privacy Policy

Last updated September 11, 2026

Archon Inspect (“Archon Inspect,” “we,” “us”) is a code-compliance and inspection assistant for building inspectors, operated by Nebustream Technologies LLC, a Texas company (8751 Collin McKinney Pkwy STE 1102 #519, McKinney, TX 75070). This policy describes what we collect through the Archon Inspect mobile app, web app, client report portal, and website, why, how long we keep it, and how to delete it.

Information we collect

  • Account data. Email address and name, collected at sign-up. Authentication is handled by AWS Cognito; we never see or store your password.
  • Agreement records. When you accept our End User License Agreement, we record the version accepted, the time, the platform (web or mobile), and the IP address and browser or device identifier string of the request, so we can show what you agreed to and when.
  • Site photos. Photos you capture or attach of building sites, stored on our servers and used to generate compliance findings and reports.
  • Voice input.The mobile app offers two kinds of voice input. Dictated inspection comments are transcribed on your device using the operating system’s speech recognition; that audio never reaches our servers. If you use the microphone to ask the AI assistant a question, the clip is sent for transcription and is not retained afterward — only the resulting text is kept, as part of your chat history.
  • Inspection content. Project names and site addresses, inspection appointments and schedules, findings, violations, reviewer notes, compliance events, uploaded documents, floor plans, form and report templates, and generated reports that you or your organization add.
  • Client contact information.Names, phone numbers, and email addresses of the homeowners, contractors, and other clients you add to a project so that you can schedule inspections and share reports with them. See “Information about your clients” below.
  • Chat content. The questions you ask the AI assistant and the answers it returns, including any code sections cited.
  • Organization data.If you create or join an organization, we store the organization’s name and settings, its members and their roles, invitations sent (including approved email domains), and its contract and invoice records.
  • Billing data. Your plan, trial status, and usage against plan limits. Payments are processed by Stripe; we receive the subscription status and a customer reference, never your full card number.
  • Feedback. Anything you send us through the in-app feedback form.
  • Launch-list sign-ups. If you sign up for updates on our website, we store the name, email address, and role you enter, and where the sign-up came from.
  • Technical data.Standard request metadata our servers log to operate and secure the service (timestamps, request paths, error logs, IP addresses), and usage counts we keep to enforce plan limits (for example, the number of photo scans you run). The mobile app and the product itself run no analytics or advertising SDK and collect no device advertising identifier; the marketing website runs ad measurement unless you opt out — see “Cookies and tracking” below.

Information about your clients

Inspectors enter information about people who are not Archon Inspect users — typically the homeowner or contractor for a site — and may share reports with them through the client portal. We process that information only on your behalf and only to provide the service to you: to schedule the inspection, generate the report, and deliver it to the recipient you choose. You are responsible for having a lawful basis to give us that information. If you are a client who received a report from an inspector using Archon Inspect and you have a question about your information, contact the inspector, or contact us at info@nebustream.com and we will help.

How we use third-party AI providers

Archon Inspect’s assistant is built on hosted AI providers. Each request contains only the content needed to produce the response you asked for — the question, photo, or document excerpt — and never your name, email address, or account identifier. None of these providers are used for advertising:

  • DeepSeekprocesses text: chat questions and answers, summaries of code sections, classification of code sections during ingestion, report narrative drafts, and writing suggestions. DeepSeek is headquartered in the People’s Republic of China, and requests to it are processed on servers outside the United States.
  • Google (Gemini) analyzes site photos to identify potential code violations.
  • OpenAI transcribes voice questions and generates the search embeddings used to retrieve relevant code sections.

Each provider is used under its business API terms, which govern how long it may retain request content. We do not opt in to any program that uses your content to improve a provider’s models, and we do not send your content to a provider for any purpose other than generating your response. See “International data transfers” below. We may change or add providers as the product evolves; this page is updated when we do.

Other service providers

  • Amazon Web Services hosts the service, its database, and uploaded files (US East region), provides sign-in through Cognito, and sends our email through Amazon SES.
  • Stripe processes payments and stores your payment method under its own privacy policy. Checkout happens on Stripe-hosted pages.
  • Google Maps Platform may be used, where enabled, to geocode site addresses and estimate drive times between appointments. Only the address is sent, never who it belongs to.
  • Meta Platforms (Meta Pixel and Conversions API) and Google(Google Ads and Google Analytics) receive ad-measurement events from the marketing website, and — for Meta — from our server when you create and confirm a trial account, unless you have opted out. See “Cookies and tracking” below.

We do not sell, rent, or share your personal information with third parties for their own marketing purposes. The one exception, as that term is defined by the California Consumer Privacy Act: the marketing website shares limited ad-measurement events (which page you visited, the ad click id if you arrived from one, and — when you sign up — a one-way hash of your email address together with your IP address and browser identifier) with Meta and Google for cross-context behavioral advertising, so we can tell which ads lead to sign-ups. Never your name, your inspection content, or anything from inside the product. You can opt out at any time via “Do Not Sell or Share My Personal Information” in the website footer, and we honor that choice for both the browser pixel and the server-side events.

Email we send

We send transactional email you or someone you work with triggered: sign-in codes and password resets (from Cognito), organization invitations, report-portal links to the clients you choose, and account notices such as deletion confirmations. If you joined our launch list, we may also email you product updates; every such message carries an unsubscribe link, and unsubscribing stops those updates immediately without affecting your account. We record delivery failures and complaints so that we stop mailing addresses that bounce or object.

Client report portal

When an inspector shares a report, the recipient gets a unique link that works for a limited time and may be password-protected by the inspector. Opening a password-protected report sets a cookie so the recipient does not have to re-enter the password on every page; it holds no personal information and identifies only that link. We log portal views to show the inspector that the report was opened.

Cookies and tracking

The web app sets one essential cookie to keep you signed in (your Cognito session) and one to remember a UI preference (whether the sidebar is expanded); the client portal sets the unlock cookie described above. These are not used for advertising or cross-site tracking, and none of them are set on the marketing website (the pages before you sign in).

The marketing website sets two first-party cookies of its own, whether or not you opt out: archon_consent records that choice itself, and archon_attrib records which page you landed on and, if you followed an ad or a link with tracking parameters, which campaign — no advertising SDK reads either cookie; the ad click id that archon_attrib may record is the one piece of it included in the server-side Meta event described below, and nothing else in either cookie is shared with anyone.

When you visit the website, it loads the Meta Pixel and a Google tag (Google Ads and, where configured, Google Analytics) to measure how our ad campaigns perform — for example, that a visit from a Facebook ad led to a trial sign-up — and shows a notice telling you so. When you create and then confirm a trial account, our server also sends Meta a matching “lead” and “registration” event containing a one-way hash of your email, your IP address, your browser’s user-agent string, and the Meta cookie ids from the page. We run no analytics platform, advertising SDK, or tracking pixel anywhere else: not in the signed-in product, not in the mobile app.

To opt out, choose “Opt out” on the notice, or use “Do Not Sell or Share My Personal Information” in the website footer at any time, which reopens it. Opting out removes the pixel and the Google tag from the site and stops the server-side events; the archon_consentcookie is how we remember that choice. If any of this ever changes — a new provider, or tracking anywhere it doesn’t run today — we will update this page.

Organizations and teams

If you belong to an organization, the projects, inspections, reports, and chat sessions you create within it are visible to the other members that organization’s settings allow, and its administrators can manage members, roles, plan settings, and organization-owned content. Projects remain owned by the member who created them even when shared with an organization, and photos, documents, and scans you add to another member’s project stay with that project.

How we protect your data

Data is encrypted in transit (HTTPS/TLS) between your device, our servers, and every provider listed above, and at rest in our managed database and storage. Access to production data is limited to the engineers who operate the service, and our personnel do not review your content except as needed to operate, secure, or troubleshoot the service or respond to your support request. No method of transmission or storage is 100% secure, so we can’t guarantee absolute security, but we design the system to minimize what any single provider or component ever sees.

International data transfers

Our infrastructure is hosted in the United States. As described above, text sent to DeepSeek is processed outside the United States, and other providers may route data through other countries in the ordinary course of processing your request. Where required, we rely on our providers’ standard contractual safeguards for cross-border transfer.

Retention

We keep your account and content for as long as your account is active, so your projects, findings, reports, and chat history remain available to you. Server logs are kept for a limited operational period and then discarded. Encrypted backups of the database are kept on a rolling basis and overwritten over time.

You can delete your account at any time from Profile → Danger Zone in the mobile app, or by emailing info@nebustream.comfrom your account address. Deleting your account signs you out immediately and schedules your data for permanent deletion 30 days later. You can cancel the deletion and keep your account by signing back in before that date. After the 30 days, the projects you own — including any shared with your organization — and your code libraries, photos, documents, floor plans, reports, and chat history are permanently deleted, and your account is removed from our identity provider. Other members’ projects are unaffected. If you have added photos, documents, or scans to a project owned by another member, that content belongs to their project, and we will contact you before completing the deletion to resolve it. Billing records are retained as long as tax and accounting law requires.

One exception: if a reviewer on your team left a note on a finding, that note is kept as part of the project’s audit trail after your account is deleted, with your name replaced by “Deleted user” and your identifier removed.

Your rights

Depending on where you live, you may have the right to:

  • Access the personal information we hold about you
  • Correct inaccurate or incomplete information
  • Delete your personal information (see “Retention” above)
  • Export your information in a portable format
  • Object to, or request that we restrict, certain processing
  • Opt out of marketing email (use the unsubscribe link in any message)

To exercise any of these rights, contact us at info@nebustream.comor use the in-app deletion path described above. We’ll respond within a reasonable time and consistent with applicable law (including the GDPR and the CCPA, where they apply to you). We will never charge you a fee or discriminate against you for exercising these rights. If you are in the European Economic Area or the United Kingdom, you may also lodge a complaint with your local supervisory authority.

Children

Archon Inspect is a professional tool for building and code-compliance inspectors. You must be at least 18 to hold an account, and the service is not directed to children. If we learn we’ve collected personal information from a child under 13, we’ll delete it.

Changes to this policy

We’ll update the date at the top of this page when this policy changes, and will make reasonable efforts to notify you of material changes.

Contact

Questions about this policy or your data: info@nebustream.com, or by mail at the address above.