Last updated 23 September 2026
Privacy Policy
This policy explains what personal data BuildAI collects when you use our website, the BuildAI Minecraft plugin and our APIs, why we collect it, and your rights. We only collect what we need to run the service, and we never sell your data.
1. Who we are
BuildAI (https://buildai.alexcutrupi.com) is run by Alex Cutrupi, an individual based in the United Kingdom. For the purposes of UK data protection law (the UK GDPR and the Data Protection Act 2018), Alex Cutrupi is the controller of your personal data. You can contact us about anything in this policy at alexcutrupi2022@gmail.com.
2. What we collect
Information you give us
- Account details: your email address and password. We only store your password as a secure one-way hash (Argon2id); we can’t see it.
- Purchases: what you bought, the amount, currency, tax and any refunds. Card payments are handled by Stripe, which collects your card and billing details (including your billing address). We never see or store your full card number.
- Waitlist: your email address, if you join the waitlist.
- Partner requests: if you apply to become a partner host: your company name, website, name, work email, optional Discord username, server count and message.
- Messages: anything you send us by email.
Information created when you use BuildAI
- Sessions: when you log in we record the time, your IP address and your browser’s user-agent, so you can stay logged in and we can spot suspicious activity.
- Credits: a history of credits added to or used from your account.
- Linked Minecraft servers: the name you give each server, its Minecraft, platform and plugin versions, and when it last contacted BuildAI.
- Builds: when the building feature is available, the text you or your players type to request a build, and details of the result, used to generate the build and charge credits.
- Your country: we look up the country of your IP address on our own server, only to show prices in your local currency. We don’t store it.
- Technical logs: our servers keep short-lived logs (such as requests and errors) to keep the service secure and working.
Information from others
- Hosting partners: if your Minecraft hosting company is a BuildAI partner, it may create a BuildAI account for you. It sends us your email address and its own reference for your server, and it can check whether your account is active, whether it has the plugin and your credit balance. Your host is responsible for having a lawful reason to share your email with us.
- Stripe: confirmation of your payment, fees, tax and refunds.
3. How and why we use it
- To provide BuildAI (performing our contract with you): creating and running your account, processing purchases, giving you the plugin and credits, linking your servers, generating builds and providing support.
- To keep BuildAI secure and working (our legitimate interests): preventing fraud and abuse, rate limiting, fixing problems and improving the service. We balance these interests against your rights.
- To meet legal obligations: keeping records of payments for tax and accounting, and responding to lawful requests.
- To contact you about your account, purchases or important changes to the service. We’ll only send marketing emails if you’ve asked for them (for example by joining the waitlist), and you can opt out at any time.
We don’t use your data for advertising, and we don’t make decisions about you that have legal or similar effects using only automated processing.
4. Who we share it with
We only share personal data with service providers who help us run BuildAI, and only what they need:
- Stripe: payment processing.
- Hetzner Online: hosting of our servers and database in Germany.
- Apple (iCloud Mail): sending our emails, such as password resets, receipts and account notices.
- Our AI provider (OpenAI): when the building feature is available, the text of build requests is sent to generate builds. We don’t send your email address or payment details.
- Your hosting partner: only if it created your account, as described in section 2.
- Professional advisers and authorities: where required by law or to protect our rights, users or the public.
If BuildAI is ever sold or transferred, your data may pass to the new owner, who would have to respect this policy. We never sell your personal data.
5. International transfers
Our servers are in the European Economic Area, which the UK recognises as providing adequate protection. Some providers (such as Stripe and OpenAI) may process data in the United States or elsewhere. Where they do, we rely on UK adequacy regulations (including the UK Extension to the EU–US Data Privacy Framework) or the UK International Data Transfer Addendum and standard contractual clauses to protect your data.
6. How long we keep it
- Account data: while your account exists. When you ask us to delete your account, we delete your account data within 30 days, except what we must keep by law.
- Payment records: 6 years after the end of the tax year they relate to, as required by UK tax law.
- Sessions: until you log out or they expire (30 days).
- Unlinked servers: shown in your account for 30 days after unlinking, and deleted with your account.
- Waitlist emails: until launch emails are sent or you ask us to remove you.
- Partner requests: for as long as the partnership (or discussion about it) lasts, then up to 2 years.
- Server logs: a few weeks at most.
7. Cookies
We only use two cookies, and no analytics, tracking or advertising cookies:
- buildai_session: keeps you logged in (strictly necessary; lasts up to 30 days).
- buildai_currency: remembers the currency you chose for prices (lasts 1 year).
Because these are necessary for the site to work or remember a choice you made, we don’t ask for cookie consent. Stripe may set its own cookies on its checkout page, covered by Stripe’s privacy policy.
8. Security
We use HTTPS everywhere, store passwords as Argon2id hashes, and store login links, API keys and server tokens only as hashes. Access to our servers is restricted. No system is perfectly secure, so please use a strong, unique password and keep any API keys or server tokens private. If we become aware of a breach affecting your data, we’ll tell you and the regulator where the law requires.
9. Your rights
Under UK data protection law you have the right to:
- access a copy of your personal data;
- have inaccurate data corrected;
- have your data deleted;
- restrict or object to how we use it (including for our legitimate interests or marketing);
- receive your data in a portable format; and
- withdraw consent where we rely on it.
To use any of these rights, email alexcutrupi2022@gmail.com from the address on your account. We’ll reply within one month. It’s free unless a request is clearly unfounded or excessive.
If you’re unhappy with how we’ve handled your data, please contact us first. You can also complain to the Information Commissioner’s Office (ICO) at ico.org.uk. If you live in the EU, you can contact your local data protection authority.
10. Children
BuildAI accounts are only for people aged 18 or over, and the service isn’t directed at children. If you believe someone under 18 has given us personal data, contact us and we’ll delete it.
11. Changes to this policy
We’ll update this page if the way we handle data changes, and change the “last updated” date above. If the changes are significant, we’ll tell you by email or on the site before they take effect. Also see our Terms of Service.
Questions? Email alexcutrupi2022@gmail.com. See also our Privacy Policy and Terms of Service.