Scope
This Privacy Policy explains how Build or die (also called “BOD,” “we,” “us,” or “our”) handles information when you visit build-or-die.ai, use the BOD macOS app, sign in, buy or run a Build Season, connect an optional data source, or use AI Coach.
BOD is a product companion for Builders. It converts verified, time-bound evidence about a Builder’s own product into a simple Daily Brief, a Main Quest, an expected signal to watch, and a retrospective. Evidence determines product outcomes; AI explains evidence and recommends actions but does not define a result.
This policy does not cover the independent privacy practices of Google, GitHub, Lemon Squeezy, Stripe, Paddle, PostHog, BytePlus, or another service you choose to connect.
Effective July 22, 2026 · Version 1.0Data we process
Builder Identity and device sessions
For Google sign-in, BOD validates the Google issuer and stable account subject identifier. We derive a non-reversible internal identity key and bind it to an opaque installation credential for your Mac. For sign-in, we do not store your email address, Google profile fields, authorization code, ID token, access token, or refresh token.
Purchases and Build Seasons
We process order references, product and offer versions, price, currency, payment status, refund or dispute status, timestamps, Season rules, Stage Contracts, Daily Brief records, Quest progress, outcome attestations, and retrospective records. Payment card details are collected and handled by the checkout provider, not BOD.
Optional connected evidence
You decide which sources to connect. Depending on your choices, BOD may process selected repository metadata, commit and pull-request metadata, normalized payment and refund evidence, aggregate product events, aggregate acquisition reports, search performance, and aggregate metric facts.
Provider credentials remain in the local Evidence Collector or the provider’s authorization system under the connection’s stated boundary. Season Authority does not receive raw provider credentials, full raw provider payloads, customer names or emails, or raw source code.
AI Coach and Prompt Artifacts
AI Coach processes a bounded set of aggregate metric facts, repository or evidence references, quality flags, product context, and the deterministic Quest Plan required to explain the day’s task. We store generated recommendations and Prompt Artifacts so they can be displayed, exported, and reviewed. BOD does not send AI Coach raw source code, provider credentials, customer names or emails, or unrestricted browser content.
Product operation data
We may collect privacy-safe product interaction events, reliability data, request timestamps, result codes, and coarse technical information needed to secure and improve BOD. The product analytics schema excludes provider credentials, raw source code, full browser URLs or content, customer PII, AI request and response bodies, and Prompt Artifact text.
Browser Work Context
If you explicitly enable Browser Work Context for a domain, BOD records only the authorized domain and a coarse duration bucket. It does not collect full browser URLs, page content, form contents, keystrokes, or browsing history.
Google data
Google sign-in is identity proof only. It requests the minimum OpenID identity permission needed to bind your BOD account across devices. It does not authorize Google Analytics, Search Console, Drive, advertising, email, or another Google product.
If you later connect Google Analytics or Google Search Console, BOD presents a separate purpose, separate permission request, separate disconnect control, and read-only request policy. Those optional connections are not created by signing in.
BOD’s use and transfer of information received from Google APIs will comply with the Google API Services User Data Policy, including its Limited Use requirements.
How we use data
We use information only to:
- create and recover your Builder Identity and authenticated device session;
- process purchases, entitlements, refunds, and provider-required commerce records;
- verify source readiness and project evidence under a frozen Stage Contract;
- publish one evidence-bound Daily Brief per Season and local day;
- generate and display concise analysis, recommendations, Prompt Artifacts, and retrospectives;
- show data quality limitations and correct a Brief when evidence becomes invalid;
- provide export, deletion, pause, disconnect, support, fraud prevention, and security functions; and
- maintain and improve the reliability and accessibility of BOD.
Depending on where you live, these uses may rely on performance of our contract with you, your consent for optional connections, our legitimate interests in operating and securing BOD, or compliance with legal obligations.
We do not sell personal information, use connected product data for targeted advertising, or use Google user data to determine creditworthiness or for lending.
Retention
We retain information only for as long as needed for the purpose described, to operate your account and Seasons, to resolve disputes, and to meet legal, tax, payment, security, and audit obligations.
- Google sign-in state, nonce, callback codes, and polling capabilities are short-lived and single-use.
- Local evidence caches remain on your Mac until removed through BOD or the device.
- Cloud-generated Coach recommendations may be deleted through BOD’s Privacy Center.
- Builder session records, commerce and provider-connection audit records, frozen Stage Contracts, Seasons, outcome attestations, and retrospectives may be retained after a deletion request when required to preserve purchase, result, fraud-prevention, or audit integrity.
When a record is no longer required, we delete it, de-identify it, or securely isolate it until deletion is practical.
Your choices and rights
The in-app Consent Center and Privacy Center let you inspect each capability’s purpose and data boundary, pause or disconnect optional sources, delete the local evidence cache, delete cloud-derived Coach recommendations, and export Builder records supported by the service.
You can also revoke a provider grant in that provider’s account settings. Revoking access prevents new collection but does not automatically erase records we must retain for commerce, security, or audit integrity.
Depending on your jurisdiction, you may have rights to access, correct, delete, restrict, object to, or receive a portable copy of personal information, and to appeal or complain to a regulator. We may need to verify your identity before completing a request.
Security
We use HTTPS in transit, protected server-side secret injection, scoped and short-lived authorization capabilities, hashed or HMAC-derived identifiers where appropriate, source-specific read-only request policies, and access controls designed to prevent raw credentials from entering Season Authority, analytics, logs, AI prompts, or the App bundle.
No system is perfectly secure. You are responsible for protecting your device, provider accounts, and any Prompt Artifact you copy to another tool. If you believe BOD or your account has been compromised, stop using the affected connection and contact us promptly.
International processing
BOD and its providers may process information in countries other than your own. Those countries may have different privacy laws. Where required, we use contractual or other lawful safeguards for international transfers.
Children
BOD is a business product for Builders and is not directed to children under 13 or the minimum digital-consent age in their jurisdiction. We do not knowingly collect personal information from children. If you believe a child has provided information to BOD, contact us so we can investigate and take appropriate action.
Changes to this policy
We may update this policy as BOD changes. We will post the updated version here and change the effective date. If a change materially expands how we use Google user data or another connected source, we will provide notice and request any consent required before applying the new use.
Contact
For privacy questions or requests, use the in-app Privacy Center or email zhang.chen@worldofcreator.com. Please do not email provider credentials, payment card details, raw customer data, or private source code.