Skip to content
LumberSet

Security and data handling

A builder trusted you with those drawings. Here is how we keep that trust.

Plan sets are a builder's confidential work. Your catalog and prices are your competitive position. This page says plainly who can see what, where it lives, and what we will never do with it.

The short version

Six commitments.

Yard isolation

Every record a yard owns carries that yard's identity, and every query is filtered by the yard taken from the signed-in session, never from the request. One yard cannot address another yard's data, even by guessing a link.

Encrypted in transit and at rest

Traffic between your browser and LumberSet is encrypted in transit with TLS. Plan sets and rendered sheets are stored in Cloudflare R2, which encrypts them at rest, and nightly database backups are kept on a separate volume.

No training without opt-in

Your drawings are never used to train models unless you explicitly opt in. The default is off, and saying no costs you nothing.

Limited staff access

LumberSet reviewers open a plan set to review its takeoff. Support staff open one when you ask for help. Nobody else at LumberSet has a reason to, and no other yard ever can.

You can delete it

Delete a project and its plan sets, takeoffs and quotes go with it. Close your yard's workspace and we delete the yard's data, keeping only the billing records the law requires.

Payments by Stripe

Card details are entered on Stripe's forms and stored by Stripe. LumberSet keeps a ledger of charges, credits and refunds, not your card number.

The longer version

Where your data goes, stage by stage.

Uploading a plan set

When you upload PDFs, your browser sends them straight to private file storage over an encrypted connection, using a short-lived upload link issued for that one upload. The files are not public and cannot be fetched by address: every download is authorized against your yard's session first.

Reading the drawings

Reading is the one step that uses AI. Rendered sheets are sent to our AI provider, Anthropic, through its commercial API, to be read into a building model. We send the sheets, and nothing from your catalog, your prices or your customer records. We do not permit your drawings to be used for training models, by us or by a provider, unless you opt in.

Computing the takeoff

The takeoff is computed by LumberSet's own rules engine. It is ordinary arithmetic running on our servers and in your browser. No third party is involved, and your estimating standards never leave your yard's workspace.

Review and support

LumberSet staff work in a separate staff panel with their own sign-in. Reviewers see the plan sets and takeoffs in the review queue. Support staff see a yard's workspace when helping that yard. Corrections a reviewer makes are recorded with a reason, so there is a trail of who changed what.

Your catalog and prices

Your catalog, prices and margin are used for exactly one thing: pricing your own quotes. They are not pooled, benchmarked, or shown to other yards, and they are not part of what reviewers need to see to check a takeoff.

Your customers

The builders and contractors you add are your customers, not ours. We email them only when you send them a quote, and we do not market to them.

Retention and deletion

We keep your data for as long as your yard's workspace is open, because old quotes are part of how a yard works. Deleting a project removes its plan sets, sheets, takeoffs and quotes from live systems. Backups age out on a rolling schedule after that. When you close your workspace, we delete the yard's data and keep only the billing records we are legally required to retain.

Accounts and access inside your yard

Each person signs in as themselves, as an owner, a manager or an estimator, and sees what that role needs. Sessions are held in secure, host-scoped cookies. When someone leaves the yard, an owner removes them and their access ends.

Service providers

The companies that process data for us.

We use a short list of providers, each for one purpose. None of them may use your data for their own ends.

Service providers and what each one processes
ProviderPurposeWhat it processes
StripeCard paymentsCard paymentsPayment details and billing contact. Card numbers go directly to Stripe and never reach LumberSet's servers.
AnthropicAI reading of sheetsAI reading of sheetsRendered sheets from the plan sets you upload, sent through Anthropic's commercial API for reading.
CloudflareFile storageFile storageThe PDF plan sets you upload, the rendered sheets and the quote PDFs, held in private object storage.
ResendTransactional emailTransactional emailEmail addresses and message content for sign-in, invitations and the quotes you send.

Straight talk

Reporting a problem, and what we do not claim.

Found a security problem?

Write to hello@lumberset.com with "Security report" in the subject. Tell us what you found and how to reproduce it. We read every report and will reply to you.

What we do not claim

LumberSet is a new product. We do not hold a SOC 2 report or an ISO certification today, and we will not imply that we do. If your yard needs a security questionnaire answered, send it and we will answer it honestly.

Quote the next plan set with LumberSet.

Create your yard's workspace, set your standards and catalog, and upload the drawings. You pay when a takeoff is released to you, and not before.

$200 per quote. No monthly fee. No seat licenses. No contract.