Legal

Privacy Policy

Last updated 23 July 2026 · Applies to the SitesAI app (app.sitesai.net and the iOS/Android apps), SitesAI Estimate (takeoff.sitesai.net) and sitesai.net.

SitesAI is operated by BLUEXPLUS PTY LTD (ABN 72 655 259 331), an Australian company ("we", "us"). We build software for construction and civil teams. This policy explains what information we collect, why, where it lives, and the choices you have. We comply with the Australian Privacy Act 1988 (Cth) and the Australian Privacy Principles (APPs), and we extend equivalent rights to users outside Australia.

1. What we collect

  • Account details — your name and email address, received from the sign-in provider you choose (Google, Microsoft or Apple). We never see your password. If you use Apple's "Hide My Email", we only receive the relay address.
  • Profile details — information you or your company add to your profile, such as role, phone number, licences and certificates.
  • Work records — content created while using the app: worktime entries and dockets, signatures, task and job records, induction answers, documents you upload, and photos you take on site.
  • Location — only if your company enables site sign-in / geofenced clock-in, and only at the moment you clock in or sign into a site.
  • Automatic site clock-in/out (optional) — if your employer enables automatic clocking on a site and you accept the in-app consent, the SitesAI app monitors that site’s boundary and records the moment you enter or leave it — including when the app is closed. Only these entry/exit events are recorded: there is no continuous tracking, no location history between sites, and nothing outside the listed work sites. Each automatic record is flagged on your timesheet, you can revoke consent at any time in Settings, and signing out or leaving the company stops it immediately. Employers are responsible for any workplace-surveillance notice required in their state (e.g. 14 days’ written notice in NSW).
  • Device push token — if you install the mobile app and allow notifications, we store an anonymous device token so we can deliver them.
  • Technical logs — sign-in events (time, IP address, browser/app) and notification delivery logs, kept for security and support.

2. How we use it

To run the product: showing your company's records to the right people, generating dockets and certificates, sending the notifications you and your company have enabled, and keeping accounts secure. We do not sell your data or show ads inside the product.

Analytics and advertising — the website only. There is an important distinction between our marketing website and our software:

  • The website (sitesai.net) — the pages you are reading now — uses Google Analytics to measure which pages are read and whether our marketing works. It sets cookies, and you control them through our Cookie Policy. Visitors in the UK, EEA and Switzerland are asked to opt in before anything is set; everyone else can opt out at any time. We do not currently run any advertising tags; if that changes, this page and the Cookie Policy will say so before it does.
  • The portal (app.sitesai.net) and SitesAI Estimate (takeoff.sitesai.net) use Google Analytics only, to count visits and see which screens get used, so we know what to improve. They contain no advertising trackers of any kind. Page addresses are redacted before they are sent: document, quote and invitation links, record numbers and email addresses are all replaced with placeholders, so a share link or a customer's address can never reach Google. Your work records, timesheets, photos and site data are never sent to any analytics or advertising service, never used for advertising, and never shared with any advertising network.
  • The SitesAI mobile apps contain no advertising trackers and no third-party analytics whatsoever.

3. Who sees your records

SitesAI is a multi-company platform. Records you create inside a company workspace (for example a timesheet for your employer) belong to that company and are visible to its authorised managers. Owners and managers of a company see that company's data; workers see their own records and those they're authorised for. We only access customer data to provide support or as required by law.

4. Where your data lives

  • Application database — hosted on servers operated for us by Hostinger.
  • Files and photos — stored in Google Drive under our managed business account.
  • Email notifications — sent via Google's Gmail service.
  • Push notifications — delivered via Google Firebase Cloud Messaging and Apple's notification service.
  • Sign-in — handled by Google, Microsoft or Apple, depending on your choice.

All traffic between your device and SitesAI is encrypted in transit (TLS). Some providers above process data outside Australia; we rely on those providers' standard safeguards for such transfers.

5. How long we keep it

Your data is kept while your account or your company's workspace is active. You can delete your account in the app (Settings → Delete account) — this permanently deletes your own workspace and personal account data. Records you created for an employer's company remain that company's business records; Australian employers are required to retain employee records (for example under the Fair Work Regulations, generally seven years). See our account-deletion guide.

6. Your rights

You can access and correct your information in the app, ask us for a copy of it, ask us to correct or delete it, or object to how it's handled by emailing admin@sitesai.net. We respond within 30 days. If you're unsatisfied, you can complain to the Office of the Australian Information Commissioner (oaic.gov.au). Users in other jurisdictions may exercise equivalent rights (access, rectification, erasure, portability) via the same email.

7. Cookies

In the mobile apps we use only strictly necessary cookies: a signed session cookie to keep you logged in and a preference cookie for your theme. No advertising or cross-site tracking cookies.

In the portal and SitesAI Estimate (app.sitesai.net, takeoff.sitesai.net) we use those same strictly necessary cookies, plus the Google Analytics _ga cookies described in our Cookie Policy — analytics only, never advertising. In the UK, EEA and Switzerland no analytics cookie is set at all.

On this website (sitesai.net) we additionally use analytics and advertising cookies, subject to your choice. Every one of them is listed — name, who sets it, what it does and how long it lasts — in our Cookie Policy, where you can also change your preferences at any time.

8. AI connectors (Claude, ChatGPT and other AI clients)

SitesAI publishes connectors (MCP servers) so you can ask a third-party AI assistant — such as Claude or ChatGPT — about your own SitesAI data. Connectors are off by default: nothing is shared with any AI client until someone in your company deliberately connects one.

  • How a connection is authorised — either a company API key you create yourself in the portal (Settings → AI keys, at app.sitesai.net/ai-keys), or an OAuth sign-in from the AI client, which shows you a consent screen and then issues a revocable key. For the SitesAI app the OAuth consent step is restricted to company owners and managers, and it is where they choose whether the connection is read-only or read and write — it is read-only unless an owner or manager explicitly approves read and write on that screen. A read-and-write connection can create and change records; each write tool is separate and labelled, and the ones that delete, overwrite or notify someone are labelled as such.
  • What the AI client can reach — only the data of the one company the key belongs to. Every request is scoped to that company on the server, so a connector can never read another company's records. Depending on the product this can include leads and quotes, tasks, sites, services and items, worktime and shifts, members' names and roles, processes and checklists, and files or photos attached to those records; in SitesAI Estimate it is the takeoff projects, plan layers and estimates in that account.
  • Why — solely to answer the question you asked in your AI client, and to perform the actions you ask for where the connector is not read-only. We do not use connector traffic for advertising, profiling or model training.
  • Who receives it — the operator of the AI client you connect (for example Anthropic for Claude, or OpenAI for ChatGPT). Once data reaches your AI client it is handled under that provider's privacy policy and your settings with them, including whatever retention or training choices you have made there. We have no control over that side and encourage you to check it.
  • What we keep — an access log of each connector request (time, key, and the endpoint called) in our audit log for security and troubleshooting, purged after 90 days. Answers returned to the AI client are not stored by us beyond that log entry.
  • Your controls — view and revoke any key or OAuth connection at any time at app.sitesai.net/ai-keys (SitesAI Estimate: Account → MCP access). Revocation takes effect immediately. Rate limits apply per key. If you never create a key and never complete an OAuth consent, no AI client can reach your data at all.

Technical documentation for both connectors, including the full list of available tools and what each one can do, is on our AI connectors page.

9. Children

SitesAI is a workplace tool and is not directed at children under 16.

10. Changes & contact

If we change this policy we'll update this page and the date above; material changes will be announced in the app. Questions: admin@sitesai.net, or write to BLUEXPLUS PTY LTD, PO Box 1226, Surrey Hills North VIC 3127, Australia.