Trust & Privacy

This page is maintained by the BaselytIQ team to answer common security and privacy questions about the BaselytIQ Utility Input Tool. It describes the controls currently in place — it is not an independent certification or audit report.

Account isolation

Every project, building, utility account, and bill is scoped to the user who created it. Row-level security policies in our database ensure that no other customer can read, modify, or delete your data, even if they are signed in to BaselytIQ at the same time.

Authentication

Access requires a valid sign-in (email/password or Google). All requests to data endpoints must include a verified session token. We do not allow anonymous access to any utility data table.

Encryption

All traffic between your browser and our backend is encrypted in transit (HTTPS/TLS). Data at rest in our managed database is encrypted by the underlying cloud provider. Encryption keys are managed by the platform; we do not offer end-to-end encryption where the customer holds the keys.

AI bill extraction (subprocessing)

When you use the AI Extraction feature, the uploaded bill image or PDF is sent to our AI provider (Google Gemini, via the Lovable AI Gateway) for parsing into structured fields. The provider processes the file to return extracted values and does not use your bills to train their models under our gateway terms.

If a bill contains information you consider sensitive beyond standard utility data (for example, handwritten notes with personal identifiers), we recommend redacting it before upload.

File retention

BaselytIQ stores both the structured data extracted from each bill (dates, usage, demand, costs, validation status) and the original uploaded PDF or image. Originals are kept in a private, access-controlled storage bucket scoped to your account so you can retrieve the source document for M&V evidence or audit at any time. Only you can access files in your own bucket — no other customer can read, download, or delete them.

Structured data is retained for as long as you keep the associated project. Original files are deleted when you delete the corresponding bill or project, which cascades through the storage bucket.

Deletion & data ownership

You own your data. Deleting a project cascades to its buildings, utility accounts, bills, upload records, and original files in your private storage bucket. You can request full account deletion at any time and we will purge all associated records and files from production.

What we do not claim

We do not currently claim SOC 2, ISO 27001, GDPR, HIPAA, or PCI compliance. If your organization requires formal certification or a signed DPA, please contact us before sharing production utility data so we can confirm whether BaselytIQ is appropriate for your use case.

Questions or security concerns? Reach out to the BaselytIQ team and we will respond promptly.