Privacy Policy
Last updated:
1. Introduction
Construct Computer (“Construct,” “we,” “us,” or “our”) operates a cloud-based work platform with scoped personal and team workspaces powered by AI agents. Team members intentionally share team resources. This Privacy Policy explains how we collect, use, disclose, and safeguard your information when you visit our website at construct.computer, use our web platform, interact with your agent through Slack, Telegram, Discord slash commands, or the native agent inbox, or use any of our related services (collectively, the “Services”). By using the Services, you consent to the practices described in this policy.
2. Information We Collect
2.1 Account Information
When you create an account or join our waitlist, we collect:
- Your email address and name (provided directly or via Google OAuth)
- Google profile information if you sign in with Google, including your profile ID and avatar URL
- Any additional information you voluntarily provide, such as responses on our waitlist form
2.2 Workspace & Agent Data
When you use the Construct platform, the following data is created and stored in user- or workspace-scoped platform resources:
- Workspace files - any files, documents, code, or other content you upload or that the AI agent creates on your behalf, stored under scoped prefixes in Cloudflare R2
- Chat & session history - conversations between you and your agent across supported surfaces (responsive web desktop, Slack, Telegram, Discord slash commands, and agent inbox), stored in per-agent Cloudflare Durable Objects and the account-scoped chat archive
- Agent memory - long-term memory containing source episodes, versioned assertions, temporal context, and related entities. You can inspect, search, correct, forget, or restore memories from the Memories app
- Workflows - reusable procedures, published versions, run state, step results, and retry information
- Scheduled jobs - one-time and recurring agent tasks or workflow runs stored with their schedule and execution state
- Calendar - scheduled jobs, recurring rules, and run status used to coordinate background work
- Agent email inbox - each eligible user can claim one native address at <username>@agents.construct.computer; incoming messages, threads, and sent replies are retained to provide thread state
- Activity history - bounded action summaries with timestamp, source, status, and best-effort reasons. Tool inputs and outputs are not stored in the Activity feed
- Access-control records - per-platform inbound policy, trusted-user list, and approval records when approval-required mode is enabled
2.3 Integration Credentials
If you connect third-party services to your Construct environment, we record connection state and credentials that Construct manages:
- Composio connected accounts - connection identifiers and state for supported apps from the live Composio catalog. Composio manages the underlying OAuth credentials, scopes, and refresh process.
- Direct integrations - Slack, Telegram, and Discord credentials and any OAuth tokens issued directly to Construct
- Custom app configuration - endpoint, manifest, and permission settings for custom MCP servers and private workspace apps. Public registry submissions are not active in current v2.
- Bring-Your-Own-Key (BYOK) API keys - optional model provider keys for supported OpenRouter, OpenAI, Anthropic, Amazon Bedrock, or xAI access
Construct-stored BYOK keys and Slack or Discord bot credentials are encrypted using AES-GCM and decrypted when needed. Composio manages credentials for its own connected accounts.
2.4 Billing & Subscription Data
If you subscribe to a paid plan, we store the subscription state (tier, status, period) and a customer identifier from our payments processor. Payment method details (card numbers, bank info) are never stored by Construct - they are handled entirely by our processor, Dodo Payments. We also record per-call usage (service, model, token counts, latency, and real dollar cost via Cloudflare AI Gateway) so you can view usage history and we can enforce plan and per-session limits.
2.5 Technical & Usage Data
- IP address (used for rate limiting and security purposes)
- Browser type and operating system
- Authentication tokens (JSON Web Tokens stored in your browser’s local storage)
- Operational logs and metered model-usage records, including service, model, token counts, latency, and cost where available
2.6 Public Website Analytics
The public Construct website uses PostHog through a first-party proxy to measure page views, navigation, beta conversions, heatmaps, and masked session replays. Replay masks form inputs and blocks the beta signup dialog. We do not send your waitlist email address to PostHog, and captured URLs are reduced to known canonical paths without query strings or fragments. PostHog may use cookies or local storage to maintain an anonymous browser and session identifier. We respect the browser Do Not Track signal where supported. Analytics retention and processing region are configured in our PostHog project.
3. How We Use Your Information
- Providing the Services - to operate your agent and sandbox, maintain your workspace, route inbound messages across surfaces, and facilitate the integrations you connect
- Authentication - to verify your identity via Google OAuth or magic-link email and manage your session
- Personalization - to enable your agent to remember preferences, context, and prior interactions across sessions and platforms
- Communication - to send authentication, workspace, subscription, and other transactional emails, and, with your consent, product updates
- Billing - to process subscriptions, meter usage against plan caps, and reconcile BYOK vs bundled cost
- Security & abuse prevention - to enforce rate limits, verify webhook signatures (Slack HMAC-SHA256, Telegram, Dodo Payments), detect unauthorized access, and protect infrastructure
- Improvement - to diagnose technical issues, monitor model behavior via aggregated analytics, and improve the Services
4. Third-Party Services & Data Sharing
We do not sell your personal information. Your data may be shared with or processed by third parties only in the following circumstances:
4.1 Services You Connect
When you choose to integrate third-party services with your Construct environment, data is exchanged with those services as necessary to provide the integration:
- Google - if you sign in with Google or connect Google Workspace tools, your account data, calendar events, and files are exchanged with Google’s APIs as needed
- Composio - manages OAuth and executes tool calls against supported apps from its live catalog. Prompts, parameters, and returned results for tools you invoke are processed by Composio on your behalf
- Slack, Telegram & Discord - if you connect these services, messages, files, and metadata are processed to enable communication with your agent
- Model providers - prompts and conversations are sent to the model provider serving your plan. If you provide a BYOK OpenRouter key, model traffic is routed through OpenRouter - see OpenRouter’s privacy policy
- Composio Browser - powers interactive browser tasks. Target URLs and task inputs relevant to browsing are processed by Composio and streamed back to the work desktop
- Construct inbox - inbound messages, drafts, sent mail, and thread metadata are stored to provide native agent email
- Custom MCP and workspace apps - tool parameters and permitted network requests are processed according to each app's manifest and configured connection
4.2 Platform & Infrastructure
Construct runs on Cloudflare (Workers, Durable Objects, D1, R2, Sandbox SDK, AI Gateway). Data-at-rest and in-transit for platform state is handled by Cloudflare. Application logs flow to Cloudflare's observability services.
4.3 Email & Payments
We use Resend to deliver transactional emails (magic-link sign-in, usage alerts). We use Dodo Payments to process subscriptions; Dodo holds payment-method data and sends us signed webhooks for subscription lifecycle events. Your email address is shared with these providers solely for these purposes.
4.4 Legal & Safety
We may disclose your information if required by law, regulation, or legal process, or if we believe in good faith that disclosure is necessary to protect the rights, safety, or property of Construct Computer, our users, or the public.
4.5 Business Transfers
In the event of a merger, acquisition, reorganization, or sale of assets, your information may be transferred as part of that transaction. We will notify you of any such change.
5. Data Storage & Security
We take the security of your data seriously and implement the following measures:
- Scoped platform resources - agent chat state uses per-agent Durable Objects, memory uses a user-owned MemorySpace, and sandbox containers are scoped to the active personal or team workspace. Team members intentionally share team resources
- Encrypted Construct credentials - Construct-stored BYOK keys and Slack or Discord bot credentials use AES-GCM. Composio manages its connected-account credentials separately
- Resource & budget limits - plans set model budgets, task steps, temporary-agent concurrency, storage, and schedule limits. Sandbox commands currently share a five-minute runtime cap
- Rate limiting - authentication endpoints, app calls, and API routes are rate-limited to prevent brute-force and resource-abuse attacks
- Webhook verification - Slack HMAC-SHA256 signatures with a 5-minute replay window, Telegram bot-token verification, and signed Dodo Payments events
- JWT authentication - sessions are managed via signed JSON Web Tokens with configurable expiration
- Role & access control - inbound senders are evaluated against the channel's access policy and trusted-user list. Guests are blocked by default; approval-required mode uses a review queue
Despite these measures, no system is completely secure. We cannot guarantee absolute security of your data.
6. Metered Usage and Bring Your Own Key
Construct supports bundled model access and optional BYOK routing:
- Bundled (default) - your plan includes model usage subject to monthly and per-session limits. Usage is metered and is visible in your account’s usage history
- BYOK - on Pro, you may configure supported OpenRouter, OpenAI, Anthropic, Amazon Bedrock, or xAI credentials. Routing can be off, automatic fallback after bundled limits, or exclusive. BYOK traffic is billed directly by the provider and does not count against your bundled budget. Conversation content remains stored as needed to provide chat history and context
7. Data Retention
We retain your data as follows:
- Account data - retained for as long as your account is active. You may request deletion at any time
- Virtual desktop data - workspace files, agent memory, chat history, Activity history, Calendar, and agent email persist for as long as your account is active and are deleted when your account is closed
- Webhook event IDs - retained briefly for idempotency and replay protection, then pruned
- Waitlist data - email addresses and responses are retained for up to 180 days, or until you request removal
8. Cookies & Local Storage
The Construct product stores authentication tokens in your browser’s local storage rather than a regular-user session cookie. The public website may use PostHog cookies or local storage for analytics and replay as described above. The beta-access gate stores only a granted flag and timestamp, never your email address. An HTTP-only session cookie is used for administrative access to internal dashboards and does not apply to regular users.
9. Your Rights
Depending on your jurisdiction, you may have the right to:
- Access the personal data we hold about you
- Correct inaccurate or incomplete data
- Request deletion of your account and all associated data, including your sandbox container, workspace files, memory, Activity history, and agent email
- Inspect, search, and delete individual memories at any time from the Memories app
- Object to or restrict the processing of your data
- Withdraw consent for optional processing at any time
- Request a portable copy of your data
- Disconnect third-party integrations and direct messaging connections through account settings, subject to the connected provider's revocation behavior
To exercise any of these rights, please contact us - see our Support page.
10. Children's Privacy
The Services are not directed to individuals under the age of 13. We do not knowingly collect personal information from children under 13. If we become aware that we have collected data from a child under 13 without parental consent, we will promptly delete that information and terminate the associated account.
11. Autonomous Browsing & Third-Party Links
Our website and your workspace may contain links to third-party websites. The AI agent may also navigate to third-party websites on your behalf via the remote browser, extract content, or submit forms. We are not responsible for the privacy practices or content of those websites, and you are responsible for tasks you delegate to the agent. We encourage you to review the privacy policies of any third-party service you connect or visit.
12. Changes to This Policy
We may update this Privacy Policy from time to time. We will notify you of material changes by posting the updated policy on this page with a revised “Last updated” date. Your continued use of the Services after any changes constitutes your acceptance of the updated policy.
13. Contact Us
If you have any questions about this Privacy Policy or wish to exercise your data rights, please contact us at: support@construct.computer.