Legal

Privacy Policy

Last updated: August 31, 2026

Korus Build ("Korus," "we," "us," or "our") is a construction management app developed and operated by SE Builders, Inc. This Privacy Policy explains how we collect, use, disclose, retain, and protect personal information when you use our websites, applications, software, and related services (collectively, the "Service"), including when you connect a Google Gmail or Microsoft Outlook account.

This Privacy Policy does not apply to third-party websites or services that have their own privacy policies. If you use Korus through an organization, that organization may separately collect, use, and control information associated with your work.

1Information we collect

  • Account and identity information. Name, business email address, phone number, job title, organization, role, profile information, authentication identifiers, and account settings.
  • Organization and contact information. Organization details, authorized users, administrators, permission assignments, and contact information for vendors, subcontractors, architects, owners, consultants, and other project participants entered by customers.
  • Customer and project content. Projects, plans, specifications, bids, estimates, contracts, schedules, reports, documents, photographs, messages, field records, comments, and other information uploaded to or created in the Service.
  • Connected-email data. OAuth account identifiers, tokens, connection status, and limited email information described in Section 3.
  • Subscription and transaction information. Plan, account status, invoices, payment status, and related records. Payment-card details may be processed directly by our payment processor and may not be stored by Korus.
  • Usage and device information. IP address, browser and device type, operating system, session identifiers, approximate location derived from IP address, pages or features viewed, actions taken, timestamps, diagnostic information, audit events, cookies, and similar technologies.
  • Support and communications. Information submitted when you contact support, request a demonstration, respond to a survey, report an issue, or otherwise communicate with Korus.
  • Derived information and feature outputs. Status classifications, document extractions, comparisons, summaries, usage metrics, security signals, and other information produced from the data described above as part of Service functionality.

2Sources of information

We collect information directly from you; from your organization and its administrators or other authorized users; from vendors, subcontractors, and recipients who communicate through the Service; from connected services that you authorize; automatically from browsers, devices, and Service activity; and from service providers that support authentication, security, billing, analytics, and Service operation.

3Connected email accounts

Connecting an email account is optional. Korus uses provider authorization, rather than asking for your email password. The permissions displayed during authorization determine what the provider technically allows Korus to access. Korus limits its processing of connected-email data to the user-facing features described below.

Google Gmail permissions

  • Basic profile (openid, email, profile). Identifies the Google account you connect and displays it in integration settings.
  • Send email (gmail.send). Sends project communications you initiate through Korus, such as bid invitations, contract-related communications, and document requests, from your connected address.
  • Read email (gmail.readonly). Detects and processes replies associated with email conversations that Korus sent on your behalf.

Microsoft Outlook permissions

  • Identity and connection (openid, profile, email, offline_access, and User.Read). Identifies the Microsoft account you connect, displays it in integration settings, and maintains the authorized connection until it is disconnected or revoked.
  • Send email (Mail.Send). Sends project communications you initiate through Korus from your connected address.
  • Read email (Mail.Read). Detects and processes replies associated with conversations that Korus sent on your behalf. Korus does not request Mail.ReadWrite for this functionality.

How connected-email data is processed

Korus is designed to process email only as necessary to identify and handle replies associated with project communications sent through Korus. Korus does not use connected-account access to create a general index of your mailbox or import unrelated email into your Korus workspace.

Email providers may deliver limited event data or message identifiers that Korus evaluates to determine whether a message belongs to a Korus-tracked conversation. Information unrelated to a tracked conversation is not retained as project content.

For replies associated with Korus-tracked conversations, Korus may process the message information needed to detect the reply and stores only the sender's email address, subject line, received date and time, a limited body preview or snippet, status information, and message, thread, or conversation identifiers needed for deduplication and threading. Korus does not retain the complete mailbox message or mailbox attachments unless a user separately imports or uploads that content through a feature that clearly requests it.

Restrictions on connected-account data

Korus does not use connected-account data for advertising, sell it, or share it for cross-context behavioral advertising. We disclose it only to contracted service providers as necessary to provide or secure the enabled functionality, to comply with law, or as otherwise directed by you or your organization.

Korus does not permit personnel to read connected-email content except when you affirmatively authorize access to specific data for support; access is reasonably necessary to investigate security, fraud, or abuse; or access is required by law. Any authorized access is limited to personnel with a business need and is subject to access controls and confidentiality obligations.

Korus Build's use and transfer of information received from Google APIs complies with the Google API Services User Data Policy, including the Limited Use requirements.

Disconnecting or revoking access

You may disconnect a connected account through Settings > Integrations. Disconnecting promptly invalidates or deletes active OAuth credentials held by Korus and stops future connected-mailbox access. Residual encrypted copies may remain in restricted backups until overwritten according to our backup-retention cycle.

Disconnecting does not delete project communication records already created in Korus, including stored sender, subject, date, preview, and threading information. Those records remain subject to the organization's project-content retention settings and applicable legal or contractual requirements.

You may also revoke Google access through Google Account connections or revoke Microsoft work or school account permissions through the Microsoft My Apps portal. An organization administrator may also restrict or revoke connected-app access.

4How we use information

We use personal information to:

  • provide, maintain, administer, and improve the Service;
  • create and manage accounts, authenticate users, and enforce organization roles and permissions;
  • process project content and provide estimating, bidding, scheduling, reporting, communication, and related features;
  • send emails and notifications initiated or configured by you or your organization and detect relevant replies as described above;
  • provide AI-assisted extraction, comparison, classification, summarization, and generation features enabled by users or organizations;
  • provide support, respond to requests, and communicate about the Service;
  • monitor performance, troubleshoot errors, analyze feature use, and develop improvements;
  • protect accounts and the Service, prevent abuse, investigate security incidents, and enforce agreements;
  • administer subscriptions, invoicing, and business operations; and
  • comply with legal obligations, respond to lawful requests, establish or defend legal claims, and protect rights and safety.

5AI-assisted processing

Korus may use artificial intelligence, machine learning, optical character recognition, and related service providers to extract, classify, compare, summarize, or generate information as part of features enabled by you or your organization. These providers may process relevant Customer Content on Korus's behalf under contractual restrictions.

Korus does not use Customer Content or connected-email data to train generalized artificial-intelligence models for use across unaffiliated customers unless the applicable organization expressly agrees in writing. We may use aggregated or de-identified information that cannot reasonably identify an individual or organization to analyze, secure, and improve the Service.

6How we disclose information

We may disclose personal information to the following categories of recipients for the purposes described in this policy:

  • Your organization. Administrators and authorized users may access information according to roles, permissions, and organization settings.
  • Communication recipients and project participants. Vendors, subcontractors, owners, consultants, and other recipients receive information included in communications, invitations, documents, and workflows directed to them.
  • Service providers. Providers supporting cloud hosting, database and file storage, identity, email connectivity and delivery, AI and OCR processing, analytics, error monitoring, cybersecurity, customer support, payment processing, and e-signature services may process information under contract on our behalf.
  • Connected third-party services. We disclose information to Google, Microsoft, and other integrations when you or your organization directs us to connect or use those services.
  • Professional advisers. Attorneys, auditors, accountants, insurers, and similar advisers may receive information when reasonably necessary for professional services and subject to appropriate duties.
  • Legal, safety, and enforcement recipients. We may disclose information when we reasonably believe disclosure is required by law or legal process, necessary to protect rights or safety, or appropriate to investigate fraud, abuse, or security incidents.
  • Business transaction participants. Information may be disclosed in connection with a financing, merger, acquisition, reorganization, bankruptcy, sale of assets, or similar transaction, subject to appropriate confidentiality protections.

We do not make Customer Content public unless you or your organization directs us to do so.

7No sale or behavioral advertising

Korus does not sell personal information. Korus does not share personal information for cross-context behavioral advertising and does not use connected-email data for advertising. If our practices change, we will update this policy and provide any notice and choices required by law before the change applies.

8Customer-controlled project data

When Korus processes project content for a customer organization, the organization generally determines why and how that content is used. Korus acts as a service provider or processor for that content, while the organization acts as the business or controller. The organization may retain project and communication records for contractual, regulatory, safety, accounting, insurance, litigation, or business purposes.

If you request access to, correction of, or deletion of information contained in an organization workspace, we may refer your request to that organization or ask for its instructions. Organization administrators may be able to fulfill requests directly through the Service.

9Data retention and deletion

We retain personal information for the period reasonably necessary to provide the Service, fulfill the purposes described in this policy, follow customer instructions, maintain security and business records, comply with legal obligations, and establish or defend claims. Retention periods depend on the type of information, account status, project lifecycle, organization settings, contractual requirements, sensitivity, and legal requirements.

  • OAuth credentials. Active access and refresh tokens are retained only while the integration remains connected. Disconnecting promptly invalidates or deletes active credentials held by Korus, subject to limited backup retention.
  • Email reply records. Stored sender, subject, date, preview, status, and threading identifiers are treated as organization project records and may remain after the integration is disconnected.
  • Account and project content. Information generally remains while the organization account is active and for any export or retention period stated in the subscription agreement. Following an approved deletion request or termination, applicable data is generally deleted or de-identified from active systems within 90 days, unless continued retention is required or permitted for customer instructions, legal obligations, security, fraud prevention, billing, backups, dispute resolution, or enforcement.
  • Backups and logs. Information may remain for a limited period in encrypted or access-restricted backups and security logs until overwritten or expired under our retention schedules.

10Security

We maintain reasonable administrative, technical, and organizational safeguards designed to protect personal information. Measures include encryption in transit using TLS, encryption of stored OAuth credentials, role-based access controls, organization-based access restrictions, audit logging, and restricted production access.

No method of transmission or storage is completely secure, and we cannot guarantee absolute security. You are responsible for protecting your credentials and devices, configuring roles and integrations appropriately, and promptly reporting suspected unauthorized access.

11Your choices and privacy rights

  • Account information. You may update certain profile and account details through the Service or through your organization administrator.
  • Email integrations. You may disconnect a connected email account through Settings > Integrations or revoke access through the provider, as described in Section 3.
  • Communications. You may opt out of nonessential marketing emails using the unsubscribe link. You may continue to receive transactional, security, account, and project communications.
  • Cookies. Browser settings may allow you to block or delete cookies, but doing so may affect authentication and Service functionality.

Depending on applicable law, you may have rights to request access to, correction of, deletion of, or a portable copy of personal information; to object to or restrict certain processing; to withdraw consent where processing is based on consent; and to appeal a decision concerning a request. We may verify your identity and authority before completing a request. You will not receive discriminatory treatment for exercising a legally protected privacy right.

To submit a request, email info@korus.build or write to the address in Section 17. An authorized agent may submit a request where permitted by law, subject to verification of the agent's authority and the individual's identity.

12California privacy notice

If the California Consumer Privacy Act applies to Korus's processing, California residents may have rights to know and access personal information, request correction or deletion, obtain portability, opt out of sale or sharing, limit certain uses of sensitive personal information, and receive nondiscriminatory treatment.

During the preceding 12 months, Korus may have collected the following California categories: identifiers; customer-record information; commercial and professional information; internet or electronic-network activity; approximate geolocation derived from IP address; inferences and feature outputs; and the contents of communications processed through Service features. We collect these categories from the sources described in Section 2 and use them for the purposes described in Section 4.

During the preceding 12 months, Korus may have disclosed these categories for business purposes to the recipients described in Section 6. Korus has not sold personal information or shared it for cross-context behavioral advertising. Korus does not use or disclose sensitive personal information for purposes that require a right to limit under California law.

California residents may submit requests using the methods in Section 11. Requests are subject to verification and legal exceptions. If information is controlled by a customer organization, Korus may direct the request to that organization.

13Cookies and tracking signals

Korus uses cookies and similar technologies for authentication, security, preferences, session continuity, analytics, diagnostics, and Service performance. We do not use connected-email data for advertising, and we do not permit third parties to use the Service to track individuals across unrelated websites for behavioral advertising.

Some browsers offer a "Do Not Track" setting. Because there is no uniform industry standard for interpreting that signal, the Service does not currently respond to it. Where legally required, we recognize valid opt-out preference signals such as Global Privacy Control. Because Korus does not sell personal information or share it for cross-context behavioral advertising, such a signal does not change those practices.

14International processing

Korus and its service providers may process information in the United States and other countries where they operate. Those countries may have privacy laws different from those in your location. Where required, we use appropriate contractual or legal safeguards for cross-border transfers.

15Children

The Service is intended for business users and is not directed to individuals under 18. We do not knowingly collect personal information from children under 13. If we learn that we collected such information without legally valid authorization, we will take appropriate steps to delete it.

16Changes to this Privacy Policy

We may update this Privacy Policy from time to time. We will post the updated policy and revise the "Last updated" date. We will provide notice through the Service, by email, or by another reasonable method before a material change takes effect when required by law.

17Contact

SE Builders, Inc. (operator of the Korus Build app)
13006 Philadelphia St., Suite 304
Whittier, CA 90601
Email: info@korus.build