Feezible
feezible.usFeezible is a deterministic, formula-based fee/staffing estimation tool for architects and design firms, offered by Barbieri Technology Group LLC. Its consumer-facing Terms and Privacy Policy are unusually clear and user-favorable on the data questions that matter most: users own their content and outputs, data is explicitly never sold and never used for AI training, no advertising trackers are used, retention periods are spelled out with concrete schedules, and deletion is available. The documents also make several vendor-favorable but standard legal commitments — an 'as is' disclaimer, a liability cap at the greater of 12 months' fees or $100, a broad indemnity, and mandatory individual arbitration with a class-action waiver (with a 30-day opt-out). The main residual risks are the aggressive liability/indemnity/arbitration provisions and the vendor's own admission that it holds no independent security certification (SOC 2/ISO), though it discloses solid technical safeguards and relies on certified infrastructure providers.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
Users retain full ownership of the content and inputs they submit; BTG explicitly disclaims ownership and takes only a limited service-operation license. This is a clearly user-favorable position.
Output Data Ownership
Users may freely use, copy, modify, and share the outputs and exports for their business, including in client proposals, and outputs already exported remain usable after the plan ends. BTG retains rights only in its own Model Engine, templates, and branding, granting a perpetual license to use them within outputs.
Training Data Usage
The documents state repeatedly and unambiguously that user data is never used to train, fine-tune, or improve any AI or ML model, and that Feezible does not use AI at all. The vendor commits to updating the policy before introducing any AI feature.
Data Retention & Deletion
The Privacy Policy provides a detailed retention schedule with concrete timeframes (usage events 90 days, rate-limit IP records 24 hours, billing up to 7 years, backups ~90 days) and a 30-day deletion window after a verified account-deletion request. Users can delete individual items in-app immediately. No formal security audit-log retention obligation (e.g., SOC 2) is claimed, consistent with the vendor holding no such certification.
Third-Party Data Sharing
Data is explicitly never sold or rented, and sharing is limited to a named, purpose-specific list of service providers (Supabase, Stripe, Doteasy, IPinfo, Google Fonts) plus a user's own Firm Workspace and legally required disclosures. The sub-processor list includes purpose, data categories, and location, which is strong transparency.
Opt-Out Rights
Users can unsubscribe from marketing/launch emails, delete individual items or their whole account, and the vendor honors Global Privacy Control signals where legally required. Because there is no sale, targeted advertising, or AI training, the policy states there is nothing further to opt out of, which is a positive posture rather than a denial of rights.
Compliance & Certifications
BTG explicitly states it holds no independent security certification such as SOC 2 or ISO 27001 and does not claim one, instead relying on certified infrastructure providers (Stripe PCI DSS Level 1, Supabase SOC 2 Type II). It claims alignment with applicable privacy laws (CCPA/CPRA, other state laws, NJ Data Privacy Act, GDPR/UK GDPR, CAN-SPAM) without third-party attestation. The candid denial of certifications and claimed-only privacy alignment place this at moderate risk.
Model Explainability & Auditability
Because the engine is deterministic rather than AI-based, the vendor provides strong transparency: documented formulas in a user guide, a math validation export showing calculation steps on paid plans, and versioning of the engine with a revisions log. No automated decisions with legal effect are made about users.
Security Practices & Breach History
The Privacy Policy discloses concrete controls: encryption in transit (HTTPS/HSTS) and at rest, database row-level security, salted-hash passwords, private storage buckets, rate limiting, CSP and browser security headers, and a security vulnerability reporting channel. The vendor states no data breach has occurred to date. There is no independent security certification (see Category 7), and no pen-test or bug bounty program is described.
Enterprise vs. Consumer Risk Delta
The Privacy Policy states that the same privacy protections apply on every plan (Free, Pro, Lifetime Pro, Firm), with differences being purely functional (e.g., Free plans cannot save/export and keep inputs in-browser only). No tier is used for advertising or AI training, so there is no material data-handling penalty for using the free tier.
Human Review of User Inputs
BTG states its staff do not read the contents of user scenarios, calibration records, or branding except at the user's request, during security/abuse/Terms investigations, or when legally required. The admin console explicitly does not display saved scenario contents, which is a strong access-limitation commitment.
Regulatory & Litigation Exposure
The policy commits to disclosing data to authorities only when legally required, reviewing each request for legal sufficiency, notifying affected users where permitted, and disclosing only what is required. It states no government request for user data has been received to date. Note the Terms impose mandatory individual arbitration and a class-action waiver, which shapes user litigation options (see the arbitration provisions in the Terms).
PII & SPI Data Inventory
Collection is limited and purpose-bound: account details, project/scenario inputs, billing status (card data goes directly to Stripe), coarse city/region/country location, and short-lived IP-based rate-limit records. The vendor explicitly asks users NOT to submit sensitive personal information and states it does not collect SPI for inferring characteristics. IP addresses are collected but not stored alongside usage events, and precise geolocation is disclaimed.
Policy–Product Currency
Both documents carry an effective and last-updated date of September 21, 2026 — the same as the analysis date, so they are fully current. The policy coverage matches the shipped product surface: the marketing describes fee validation, sheet count, and staffing outputs from fixed inputs, and both documents accurately describe a deterministic, non-AI model engine with named third-party providers (Stripe, Supabase). The policy also pre-commits to updating before any AI feature launches, closing the AI-coverage gap.
Cross-Document Consistency
Two documents (Terms of Service and Privacy Policy) were supplied and are internally consistent with each other on ownership, no-sale, no-AI-training, retention, and deletion. They were evidently drafted together, include a defined order of precedence for privacy conflicts, and a Quick Reference table cross-maps claims between them. No contradictions were found.
You've read all 15 risk ratings for Feezible. Create a free account to see the exact policy wording behind each rating.