Privacy Policy

Effective Date: 11/29/2024

BIMO Privacy Policy

Last updated: August 21, 2026

This policy explains how BIMO Add-in for Revit and the associated web service ("BIMO", "we", "our", or "us") collect, use, and protect information.


1. Information We Collect

a. Google OAuth Data

  • Email address: Used for authentication, identification, and account creation within the web service.

  • Profile information (name and profile picture): Displayed in the web interface to personalize your experience.

b. Plugin Usage Data

  • Command execution data: Command identifier and variant, server receive time, execution result, and execution duration.

  • Technical data: Revit version, add-in version, Revit language, and whether the command ran during debugging.

  • Element-operation counts: Numbers of elements created, modified, deleted, or highlighted. BIMO does not include model contents, element properties, project paths, or command settings in this usage event.

  • License context: If the client has a license key, the event can include it for product analytics. New metric records store only a SHA-256 identifier derived from the normalized key. Legacy metric records created by earlier versions may contain the raw license key; access to these records is restricted and the owner interface does not display legacy keys in full. Events without a key, with an inactive or invalid key, and from commands not yet present in the server catalog may still be retained.

  • Network metadata: The client IP address can be processed for rate limiting, abuse prevention, and operational logging. It is not stored in the command usage metric record.

c. Web Request and Operational Data

  • Hosting and security logs: Request URL paths, response status, timing, IP address, user-agent, and referrer metadata can be processed by the hosting platform and application logs for security, abuse prevention, reliability, and troubleshooting.

  • AI-discovery diagnostics: For selected search crawler user agents or referrals from recognized AI services, BIMO records only a coarse crawler or referral classification, a bounded public route category, response status, and request duration. This dedicated diagnostic event does not record the request query string, full referrer URL, full user-agent string, or IP address.

d. Web Service Data

  • Workspace configuration: Shared settings, plugin configuration, and workspace participants.

  • Interaction data: Information about collaboration through the web interface and changes to shared configurations.


2. How We Use Your Information

  • Authenticate users and provide the web service.

  • Synchronize and manage workspace configuration.

  • Analyze command adoption, reliability, and performance to improve BIMO.

  • Monitor security and service stability and provide technical support.

  • Verify that public BIMO content remains reachable by search engines and retrieval services without weakening authentication, rate limiting, or other security controls.

  • Comply with legal obligations and protect our rights.


3. Data Storage and Security

  • Data is processed using Google Cloud Run and stored in Google Cloud SQL where applicable.

  • Operational request and application logs are processed by the configured Google Cloud logging infrastructure.

  • Data is transmitted over encrypted connections.

  • Usage data is minimized and pseudonymized where possible. A hashed license identifier is pseudonymous rather than fully anonymous because it can group events from the same license.

  • We use technical and organizational measures to protect data against unauthorized access, loss, or alteration.


4. Data Retention

We retain data only for as long as necessary for the purposes described in this policy, after which it is deleted or anonymized.


5. Your Rights

You may request access to, correction of, or deletion of personal data associated with your account. Some usage records may not be attributable to an individual when no account or license identifier is present.

To exercise these rights, contact support@bimo.tools.


6. Third-Party Services

  • Google OAuth: Used for authentication and account management. Use of Google services is subject to Google's Privacy Policy.

  • Google Cloud: Used for hosting, managed infrastructure, and operational logging.


7. Changes to This Policy

We may update this policy to reflect changes in the service or legal requirements. Updates will be published on our website, with material changes communicated through appropriate channels.


8. Contact Us

An error has occurred. This app may no longer respond until reloaded. Reload 🗙