Bricks Privacy Policy
Effective August 27, 2026. Bricks is a workspace-based field intelligence app for solar and home-services teams. This policy explains the data Bricks handles to record pitches, score field conversations, coach reps, and run a protected company workspace.
Third-party AI: OpenAI
OpenAI is the AI provider used by Bricks. When you allow AI processing and use these features, Bricks sends the following inputs through its server-side APIs. The inputs can identify you, a customer, or another person.
- Recording and live-coaching audio, transcripts, and conversation details. These may include your voice, other people's voices, names, addresses, phone numbers, and other information discussed during a pitch.
- Mason messages, relevant chat history, coaching notes, selected performance and team context, and selected door or location context. Images and screenshots you attach may also be sent.
- Utility-bill images or PDFs and field-verification photos you submit. Visible information may include customer names, service addresses, account numbers, utility usage, people, or properties.
- Coaching and search text, including relevant transcript excerpts and search queries. Generated Mason reply text is sent when speech playback is requested.
Why this information is shared
Transcribe and coach pitches, answer Mason requests, find relevant coaching, verify submitted documents and photos, and produce requested spoken replies.
Provider handling and your controls
OpenAI states that API data is not used to train its models unless the API customer opts in. Provider retention and processing rules depend on the API and its data controls; Bricks does not promise zero retention for every AI request. See OpenAI's API data controls.
Bricks requires third-party processing protections consistent with this policy. OpenAI's published API terms incorporate a data processing addendum requiring processing on customer instructions, confidentiality, security safeguards, and comparable data-protection obligations for subprocessors. See OpenAI's Data Processing Addendum and Services Agreement. This describes the published provider terms, not a promise of zero retention or a separate negotiated contract.
Your account's AI setting controls future Bricks AI requests. Review AI sharing in Profile settings. Existing workspace records and previously returned AI results follow the retention and deletion practices below.
What Bricks Collects
- Account details such as name, email, optional profile photo, role, office, workspace, login activity, access status, and an optional Cash Tag used only for externally fulfilled company rewards.
- Field recording details such as customer name, address, phone or email when entered, pitch type, outcome, score, transcript, audio file, coaching notes, clips, and review history.
- Files a user deliberately submits, including a utility bill used to verify an RFP or lead, competition comments, approved finder photos, and private Mason coaching preferences.
- When a rep grants location permission in their device or browser, Bricks may collect app-active field coordinates between 8 AM and 10 PM local time. Bricks uses them for the rep's map, recording context, the workspace owner's field-presence view, a work-zone summary that collapses ordinary driving, and short-lived proximity proof for an eligible field objective or Care Package.
- Operational data such as app version, competition and notification engagement, request state, audit events, processing status, and error information needed to run and secure Bricks.
How Bricks Uses Data
- To let reps record pitches, upload or save audio, and review feedback.
- To transcribe, score, summarize, and coach recordings using the Bricks Way and manager-approved rubrics.
- To verify a submitted RFP or lead against its mapped address, run office-scoped competitions and field objectives, and show authorized leadership an external reward destination. Bricks does not move money or settle prizes.
- To help managers and owners review team activity, assign coaching, manage access, understand competition engagement, and monitor retention or failed processing.
- To show the workspace owner a rep's current or last field location and meaningful daily work zones, including doors supported by a recording or saved door outcome. Bricks does not collect this field-presence stream while the app is inactive or between 10 PM and 8 AM.
- To keep Bricks secure, prevent unauthorized access, debug issues, and maintain audit history.
Your Choice Before AI Processing
- Bricks asks for your permission before sending your data to OpenAI for AI features. Permission is recorded for your account and this disclosure version; a workspace owner cannot give it on your behalf. Reading this policy or allowing microphone access is not AI consent.
- You can decline and continue using non-AI features. AI transcription, scoring, Mason answers, AI verification, and related generation are unavailable without permission. Review or withdraw permission in Profile settings; withdrawal stops future AI requests but does not undo requests already sent or delete prior submissions and results.
- Only record or submit information you are authorized to share. Your AI permission is separate from microphone or location permissions and any permission needed from people whose voices or information you submit.
- Mason keeps each rep's free-form coaching memory private. Organization learning can promote only a small allowlisted lesson after multiple reps and real outcomes support it; raw chats, customer data, locations, and personal notes are not shared into that team layer.
- Bricks does not sell field recordings, transcripts, or coaching data.
Sharing And Access
- Workspace owners and managers can access recordings and coaching data according to their role and office permissions.
- Current field presence and daily work-zone replay are restricted to the workspace owner; administrators, managers, and ordinary reps cannot view another rep's location.
- Utility bills and their detailed verification evidence stay limited to the submitting rep and authorized leadership in that office scope. Competition surfaces receive only the eligible verified result, not the private bill.
- OpenAI processes the AI inputs described in this policy. Convex provides backend, database, authentication, and file storage; Vercel hosts the web app; Resend delivers account emails; and Google supplies maps, address lookup, and property context. These services receive information for the features they provide, such as email addresses for account emails or an address or coordinates for a map lookup.
- Bricks may disclose information if required to comply with law, protect the service, or prevent misuse.
Retention And Deletion
- Workspace owners can configure recording retention. When audio is removed by retention policy, Bricks keeps the business record, score, transcript, coaching output, and audit evidence unless the workspace removes access or data separately.
- Original utility-bill files used for RFP verification are erased after 90 days. Bricks keeps the derived verification result, document fingerprint, lead record, and audit receipt without keeping the original financial document.
- Access deactivation keeps historical recordings and audit history intact for manager and owner review.
- Raw app-active location samples are retained for no more than eight days. Bricks may retain the smaller derived work-zone and verified-door business record according to workspace retention needs.
- Short-lived Care Package claim coordinates are reduced to a verification receipt, denied raw claim attempts expire, and earned reward inventory expires according to the stated game rules.
- You can delete your own account in Profile → Settings → Security → Delete my account, or contact Bricks Support about access, correction, export, deletion, or retention of your personal information. A workspace owner does not need to make an individual request on your behalf. We may need to verify your identity and coordinate workspace-held business records with the organization.
- Deleting an account removes sign-in access and account contact details and starts cleanup of associated private information. Some workspace business records, including recordings, appointments, and scores, may remain; those records can still contain personal information. Contact support to discuss the information in those records. The only active workspace owner must arrange another owner before using self-service account deletion.
Security
- Bricks uses authenticated access, role and office scoping, HTTPS, security headers, audit events, and server-side secrets.
- Private AI credentials are kept on Bricks servers. Access to saved recordings, bills, and workspace data is checked against the signed-in account and its role and office scope. These controls reduce risk; no system can guarantee absolute security.
Contact
For support, privacy, data export, account deletion, access removal, or retention requests, email bricks@gobricks.app. You do not need to sign in or ask a workspace owner to contact us for you.