Privacy Policy

Effective date: August 13, 2026

Written in plain English on purpose. If anything here is unclear, email us and we'll explain it like a person.

Introduction

Phixmo LLC ("Phixmo," "we," "us") operates the Phixmo platform at phixmo.com. This privacy policy explains what data we collect, how we use it, and your rights regarding that data. We believe in being straightforward, so this policy is written in plain English.

What data we collect

When you use Phixmo, we collect the following types of information:

  • Account information: your name, email address, company name, and password (hashed, never stored in plain text).
  • Project data: project names, addresses, cost estimates, line items, budgets, and any notes you enter.
  • Time entries: clock-in and clock-out times, GPS coordinates (when geofencing is enabled), and hours worked.
  • Uploaded files: receipts, compliance documents (W-9s, COIs, licenses), photos, and any other files you upload.
  • Financial data: invoice amounts, payment records, and change order details. Credit card information is processed by Stripe and never stored on our servers.
  • Usage analytics: pages visited, features used, and general usage patterns. We use this to improve the product, not to build advertising profiles.

How data is stored

Your data is stored in a PostgreSQL database hosted by Supabase on infrastructure located in the United States. All data is encrypted at rest using AES-256 encryption. Data in transit is encrypted via TLS 1.2 or higher. Uploaded files are stored in Supabase Storage with the same encryption standards.

We maintain regular backups and follow industry-standard security practices including role-based access controls, environment-separated secrets, and row-level security policies that prevent cross-organization data access.

How data is used

We use your data to:

  • Provide and operate the Phixmo platform, including all features you use.
  • Power AI features (the Phix assistant, document and receipt parsing, blueprint takeoffs, estimates, budget alerts, summaries).
  • Process payments and manage your subscription via Stripe.
  • Send transactional emails (account verification, password resets, billing receipts).
  • Improve the product based on aggregated, anonymized usage patterns.

We never sell your data to third parties. We never use your project data for advertising. Your data is yours.

Data sharing

We share data only with the following service providers, and only as needed to operate the platform:

  • Supabase: database hosting, authentication, and file storage.
  • Vercel: application hosting and CDN.
  • Stripe: payment processing and subscription management. Stripe receives billing details only.
  • Resend: transactional email delivery (invoices, change orders, compliance requests, account emails).
  • Anthropic: AI processing. AI features (the Phix assistant, document parsing, takeoffs) process customer content via Anthropic's API as a subprocessor; model providers do not train on this data per our API terms.
  • Google Maps: converting job-site addresses to coordinates for geofenced time tracking.
  • Intuit (QuickBooks Online): only when your organization connects QuickBooks — invoices and customer records you choose to sync are sent to Intuit.

We may also share data if required by law, such as in response to a valid subpoena or court order. We will notify you if this happens unless legally prohibited from doing so.

Your rights

You have the right to:

  • Access: request a copy of all data we hold about you and your organization.
  • Export: download your project data, line items, invoices, and reports at any time via the in-app export features.
  • Correction: update or correct any inaccurate information in your account.
  • Deletion: request that we delete your account and all associated data. We will process deletion requests within 30 days.

To exercise any of these rights, email us at phaz@phixmo.com.

Connected AI apps

An organization admin can connect an external AI app (such as Claude) to Phixmo. When connected, that app can read the organization's Phixmo data and can prepare actions — drafts, messages, document requests — that must be approved inside Phixmo by a person before anything is sent. Access tokens for these connections are stored hashed, never in plain text. An admin can see every connected app and revoke any connection at any time in Settings, under Integrations.

California privacy rights (CCPA)

If you are a California resident, you have the right to know what personal information we collect (described above), to request deletion, and to not be discriminated against for exercising these rights. We do not sell personal information, so there is nothing to opt out of selling. To exercise any right, email us at the address below and we will respond within the timeframes the law requires.

Cookies

Phixmo uses cookies only for authentication session management. We do not use tracking cookies, advertising cookies, or third-party analytics cookies. When you log in, a session cookie is set to keep you authenticated. That is the only cookie we use.

Data retention

We retain your data for as long as your account is active. If you cancel your subscription, your data remains accessible for 30 days so you can export anything you need. After that period, or upon a deletion request, we permanently delete all account data from our systems and backups within 30 days.

Children's privacy

Phixmo is a business tool and is not directed at anyone under the age of 18. We do not knowingly collect personal information from children. If you believe a child has provided us with personal information, please contact us and we will delete it promptly.

Changes to this policy

We may update this privacy policy from time to time. If we make material changes, we will notify you via email at least 30 days before the changes take effect. The "last updated" date at the top of this page always reflects the most recent version.

Contact

If you have questions about this privacy policy or how we handle your data, email us at phaz@phixmo.com.