Legal
Privacy policy
What we collect, why we collect it, who else sees it, and the choices you have.
Last updated: September 9, 2026 · Version: 2026-09-09
1. Who is responsible
MightyBuilder operates this website and the service at app.mightybuilder.ai (the Service). MightyBuilder is responsible for personal information used to create and manage accounts, provide the Service, process purchases, keep the Service secure, and communicate with customers.
The person responsible for privacy is the Privacy Lead, MightyBuilder, reachable at hello@mightybuilder.ai.
A customer controls the purpose and content of the website they build. If a customer site collects personal information from its visitors through analytics, scripts, forms or another integration, the customer is ordinarily responsible for that collection and for giving its visitors an appropriate privacy notice. MightyBuilder may process limited visitor information to host and deliver the site on the customer's behalf.
2. The short version
- We collect account details and records needed to operate, secure and bill for the Service.
- We store the sites you build, including pages, files, settings, revisions and conversations with the AI.
- Prompts and relevant site content are sent to AI providers to perform the work you request. Those providers may keep limited logs for safety, abuse prevention, debugging or legal compliance.
- Stripe processes payment-card details. We do not receive or store your full card number, although we receive transaction, billing and limited card information from Stripe.
- We do not sell personal information or share it for behavioural advertising.
- You may request access, correction or deletion. Deletion removes active data but is subject to shared-site, backup, security, accounting and legal-retention limits explained below.
- Our primary infrastructure and several providers process information in the United States.
3. Information we collect
Account and contact information
We collect your first name, last name, email address and account identifiers. If you sign up with a password, we store a cryptographic hash rather than the password itself. We also keep records of verification, sessions, account membership and security-related events.
Sites, files and AI conversations
We collect everything you put into or create through a site, including pages, images, code, settings, domains, revisions, prompts, AI responses, tool results, generated material, uploaded or imported files, and screenshots or attachments you add to a conversation. Prompts and activity records may include excerpts of site content or error details needed to explain and diagnose what happened.
Activity and usage
We keep a site activity history, including sign-ins, publishing, content and settings changes, file and domain actions, AI requests, the model used, processing outcome and credits consumed. We use this to operate the Service, show an itemised history, investigate problems and abuse, and answer questions about changes and charges.
Payment and subscription information
Stripe collects and processes your payment details. We receive information such as Stripe customer and transaction identifiers, billing contact details, purchase and refund information, subscription status, card brand, expiry and the last digits of the card. We maintain a ledger of credits bought and used. We do not receive or store the full payment-card number or security code.
Technical and visitor information
When somebody uses the marketing site, dashboard or a customer site we host, our systems and providers may receive ordinary request information such as IP address, date and time, requested address, referring page, browser or device details, response status and diagnostic information. We use this information to deliver pages, prevent abuse, secure the Service and diagnose failures.
Messages to us
If you contact us, we collect the message, contact details, attachments and related correspondence so we can respond and maintain an appropriate support, complaint or legal record.
4. Why we use information
We use personal information to:
- create accounts, authenticate users and provide requested Service features;
- host, publish, edit and deliver customer sites;
- send requested content to AI and image-processing providers;
- process purchases, subscriptions, credits, refunds and accounting;
- send verification, security, billing, service and support communications;
- maintain, troubleshoot and improve the reliability and usability of the Service;
- protect users, enforce our terms, prevent fraud and investigate security incidents; and
- meet tax, accounting, court, regulatory and other legal obligations.
Where the law requires a legal basis, we rely on performance of our contract with you, compliance with legal obligations, your consent where requested, and our legitimate interests in operating, securing, supporting and improving the Service. You may ask about the basis for a particular use by contacting us.
5. AI and image processing
To carry out an AI request, we send the selected provider your prompt, relevant conversation history, the parts of your site needed for the task, and any files, images or screenshots needed to understand it. Depending on the feature and model, processing is performed by Google directly or through Amazon Bedrock. Images you upload, import or generate may also be analysed by Amazon Rekognition and an Amazon Bedrock vision model to determine dimensions, a useful crop and alternative text.
MightyBuilder does not use customer prompts or site content to train a model of its own. We use commercial AI services intended not to use paid API inputs and outputs to train their general-purpose models. That is not the same as zero retention: providers may temporarily log, retain or permit authorised review of content for safety, abuse prevention, service debugging and legal compliance. Google Search-grounded features may retain prompts, context and output for the service period stated by Google. Provider terms, technical settings and retention can change, and we will update this policy if their handling changes materially.
Do not submit confidential, sensitive or personal information unless you have authority to do so and it is reasonably necessary for the result you want.
6. Service providers and disclosure
We use the following main providers:
- Amazon Web Services — application hosting, databases, storage, content delivery, AI models through Amazon Bedrock, and image analysis through Amazon Rekognition.
- Google — Gemini AI models, image generation, Search-grounded AI results and, where selected for a customer site, web-font files.
- Stripe — checkout, payment, refund and subscription processing.
- MailPace — transactional and account email.
Providers receive the information reasonably needed to perform their function. We may also disclose information when reasonably necessary to comply with law or legal process, protect a person or the Service, investigate fraud or abuse, establish or defend legal claims, or complete a financing, merger, reorganisation or sale. A successor must handle personal information under this policy and applicable law.
We do not sell personal information or share it for behavioural advertising.
7. International processing
Our primary Amazon Web Services infrastructure is in the United States. Google, Stripe, MailPace and their subprocessors may process information in the United States and other countries. This means information may be subject to the laws of those places and may be accessible to courts, law enforcement or national-security authorities where legally permitted. Where required, we use contractual or other approved safeguards for international transfers.
8. Cookies and customer-site tools
The dashboard uses a session cookie so you can remain signed in. It is scoped to the dashboard host and is not readable from customer sites. The MightyBuilder marketing site does not currently set cookies or run analytics or advertising scripts.
Customer sites can contain code, analytics, fonts and other services selected or generated by the customer. Those services may set cookies or collect visitor information independently. The customer is responsible for reviewing that code, choosing lawful settings, obtaining consent where required, and giving visitors an accurate privacy and cookie notice. MightyBuilder is not the operator of a customer's business merely because it hosts the site.
9. How long we keep information
- Account information: while the account is open and afterward only as reasonably needed for security, disputes, legal compliance and records that must be retained.
- Current sites and their history: pages, underlying page bodies, files, settings, activity history, revision metadata and AI conversations remain until the site is deleted. They do not expire merely because a page has not recently changed.
- Temporary site material: published snapshot copies are scheduled to expire after 90 days; chat attachment copies after 30 days; browser captures after 14 days; and drafting checkpoints after 7 days. Separate active files or page content remain under the preceding rule.
- Deleted and overwritten storage: the Service uses versioned storage for recovery. Non-current copies are scheduled to expire after 90 days. We do not restore deleted data to active service unless needed for recovery, security or law.
- Technical logs: for the period reasonably needed for delivery, security, diagnostics and abuse prevention, taking into account the log's sensitivity and usefulness.
- Payment, tax and legal records: for the period required by applicable law or reasonably needed to resolve a charge, complaint or claim.
We may retain particular information longer if required by law, a preservation request, litigation hold, security investigation or unresolved dispute. When retention ends, information is deleted, de-identified or allowed to expire from the applicable system.
10. Deleting a site or account
Deleting a site from the dashboard removes its domains and active content, files, history and AI conversations. Temporary non-current copies may remain for the periods above. Site deletion is intended to be permanent, so export or independently copy anything you need first.
Account deletion is handled by request to hello@mightybuilder.ai. Deleting an account removes its account records and site memberships, subject to the exceptions in this policy. It does not automatically delete a site that has other members, because doing so would delete their work. References needed to preserve a shared site's activity and billing history may also remain. If you are the only member of a site, delete the site first or tell us how you want it handled as part of the request.
11. Your privacy choices and rights
Depending on where you live, you may have the right to access personal information we hold about you; obtain a copy; correct it; ask us to delete or restrict it; object to particular uses; withdraw consent; or complain to a privacy regulator. Withdrawing consent does not affect earlier lawful processing and may prevent us from providing a feature that needs the information.
Send a request to hello@mightybuilder.ai. Describe what you want and the account email involved. We may need to verify your identity and authority before acting. We will respond within the period required by applicable law and explain if an exception prevents us from completing all or part of the request.
You may also complain to the privacy or data-protection authority where you live. In Canada, this may include the Office of the Privacy Commissioner of Canada or the applicable provincial authority. People in the UK or European Economic Area may contact their national data-protection authority.
12. Children
The Service is for people aged 18 or older and is not directed to children. Do not create an account for a child or submit a child's personal information to the AI. If you believe a child has provided personal information through the Service, contact us so we can investigate and take appropriate action. Customers are responsible for ensuring their own published sites comply with laws that apply to child visitors.
13. Security and incidents
We use administrative, technical and organisational safeguards appropriate to the nature of the Service. Data is encrypted in transit and at rest; customer sites are separated from the dashboard; and uploaded SVG files are sanitised before being served. Access to production information is limited to people and providers who need it for their work.
No system is perfectly secure. If a privacy or security incident occurs, we will investigate, mitigate it, keep the records required by law, and notify affected people and regulators when applicable law requires notice.
14. Changes to this policy
We may update this policy as the Service, providers or law changes. We will update the date and version above. If a change materially affects how we use your information or reduces your choices, we will give reasonable advance notice by email or through the Service unless an urgent legal or security change requires faster action.
15. Contact
Privacy questions, requests and complaints may be sent to the Privacy Lead at hello@mightybuilder.ai.