Struxen Docs

Privacy and data

What Struxen holds, how it is scoped, what deleting a project actually removes, the audit log, sub-processors, and how to request an export

This page describes the data controls that exist in the product. The binding legal terms are elsewhere, and where the two touch, the legal document governs:

What Struxen holds

Three categories:

  1. Project documents. Drawings, specifications, schedules, and any other file you upload or import from Autodesk.
  2. Derived data. Extracted text, embeddings, classifications, graph records, and the outputs STRUX and VANTAGE produce from your documents.
  3. Account and record metadata. User profiles, organization membership, project metadata, the records you create in the field and cost modules, audit log entries, and billing records.

How it is scoped

Everything is scoped to your organization. A user resolves against their own organization only, and a cross-organization request fails closed rather than returning a partial answer. A member of your organization who has not been added to a project resolves to no access on it.

Struxen staff can act on behalf of a user for support purposes. Every such action is written to the audit log, with the acting staff identity recorded.

Where staff access, retention commitments, model-training restrictions, breach notification and international transfers are concerned, the DPA is the instrument that binds. It covers sub-processor obligations in Section 9, breach notification in Section 12, and the Standard Contractual Clauses for transfers. Those are contractual terms, not product settings, and this page deliberately does not restate them.

Deleting a project

Owners, Admins, the project's creator, and project Managers can delete a project from Settings, then Danger zone (/settings/project-danger). You confirm by typing the project name. The demo project cannot be deleted.

Deletion is a real cascade, not a flag:

StepWhat is removed
Drive itemsEvery file the project holds in Drive. This step is a hard gate: if it fails, nothing else runs and the project is not deleted.
Derived dataThe project's vectors and graph records are purged from the search and graph stores
Object storageEvery object stored under the project
Document recordsEvery document row
Autodesk sync stateThe project's sync configuration and its synced record rows
MembershipsEvery project membership row

The confirmation you get back is honest about which of these succeeded. If the outcome is uncertain, Struxen says the outcome is unknown rather than reporting a success it did not observe.

Deleting a single document from the Documents page removes its versions with it.

Cancelling and purge

Cancelling the organization's subscription moves every project to pending purge and starts a 30-day clock. Resubscribing before it expires restores them. See Billing.

The audit log

Owners and Admins read the organization's audit log from Settings, then Audit log (/settings/audit-log).

  • It records significant actions with the actor, the action, the target, the outcome, the timestamp, and the originating IP address.
  • Retention is two years, for every organization. There is no shorter or longer tier.
  • It can be filtered by action, actor, and date range, and searched by text.
  • Export is CSV, from the same screen. An export that would exceed 10,000 rows is refused rather than silently truncated, so narrow the date or action range and run it again.
  • Reading or exporting the log is itself gated on a session that used two-factor authentication, because the caller is an Owner or Admin.

Exporting your personal data

Struxen can produce a portability export of the personal data it holds about you as a user. Be precise about what that is, because the name invites larger expectations.

The export is a single JSON document containing:

IncludedNotes
Your user profileComplete
Projects you ownThe project records, not their contents
Your credit transactionsComplete
Your AI usage historyLast 90 days only
Your activity log entriesLast 90 days only

It does not contain project documents, drawings, specifications, findings, or anything belonging to the organization rather than to you. It is a per-user record, not an organization archive.

There is no self-service screen for this today. The privacy section of the profile is not yet built. To request the export, email support@struxen.io from the address on the account.

If you need the organization's project content instead, that is a different request. Documents are downloadable individually from the Documents page, and several modules produce their own PDF or CSV exports. There is no whole-organization archive.

Deleting your account

There is no working self-service account deletion. Do not rely on any in-product control to erase your data.

To have an account closed and its personal data removed, email support@struxen.io from the address on the account, or from your organization Owner's address. If you own an organization that has other members, ownership has to be transferred first; see Organizations.

Cookies

The cookie banner lives in the authenticated app, not on the marketing site. Three categories:

  • Necessary. Required for sign-in and security. Always on.
  • Analytics. Off unless you turn it on.
  • Marketing. Off unless you turn it on.

Both optional categories default to off, everywhere, for everyone. Your choice is stored on the device you made it on.

Where the data lives

Struxen's primary region is us-east-1, in the United States. There is no regional residency option today. Where data crosses a border, the transfer terms in the DPA apply.

Sub-processors and AI providers

The current sub-processor list is published at the Trust Center: 17 vendors across 8 categories, covering cloud infrastructure, AI models, engineering and development tooling, observability, productivity, customer communications, billing, and optional integrations.

That list is reproduced in Section 9 of the DPA and the two are kept identical. Section 9 is also where the notice period for adding or replacing a sub-processor is defined, along with your right to object.

Prompts and document excerpts are sent to the configured model provider at the moment a query runs. The commitments governing what a provider may do with that content are contractual and set out in the DPA; read them there rather than here.

Subject access requests

If your name appears in Struxen data but you do not have an account, for example because you are named in an uploaded RFI, email support@struxen.io. The response time and scope are set by the Privacy Policy.

Reporting a security issue

Email security@struxen.io with a subject line beginning Vulnerability:. Keep exploit detail out of the first message; you will get a secure channel back. Good-faith research is welcome.

On this page