Huskybim
huskybim.comHuskyBIM is a free AI connector platform that links Claude Desktop to AEC/BIM software (Revit, ArchiCAD, MS Project and others) via MCP servers running locally on the user's machine. The privacy architecture is notably user-favorable: the vendor states it never receives BIM model content, file contents, or Claude conversation prompts, collecting only email, a hashed machine identifier, connector version, and an activity log. The main risks are the standard for a free tool — broad warranty disclaimers, a EUR 100 liability cap, minimal formal compliance certifications, and no enterprise/DPA documentation. For professional use, the chief external dependency to understand is that model data is processed by Anthropic under Anthropic's own terms, outside HuskyBIM's control.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The privacy policy states HuskyBIM never receives or stores BIM model data, file contents, prompts, or Claude conversation content, as the connector runs locally. Because the vendor does not collect the user's input data at all, there is no assertion of ownership or license over it. This is a strongly user-favorable posture.
Output Data Ownership
The documents do not explicitly assign ownership of AI-generated output to the user; the Terms only state that HuskyBIM's own software is proprietary and that no ownership rights are transferred by use. Since output is generated via Claude and not stored by HuskyBIM, ownership of output is effectively silent in these documents. The absence of an explicit output-ownership grant is a minor ambiguity for professional users.
Training Data Usage
HuskyBIM states it does not collect BIM model content, prompts, or Claude conversation content, so it has no user input data to train on. There is no clause in the supplied documents claiming any right to use user data for model training or improvement. Note that model data sent to Claude is governed by Anthropic's terms, not HuskyBIM's, which users should review separately.
Data Retention & Deletion
The privacy policy provides a clear deletion mechanism (email contact) and a 30-day deletion SLA, with account records retained for the life of the account. There is no formal audit-log retention schedule tied to a compliance regime, but given the minimal data collected this is proportionate. The retention terms are user-favorable and reasonably specific.
Third-Party Data Sharing
The vendor names its sub-processors (Anthropic/Claude Desktop, Cloudflare, Brevo) and their respective roles, and states it does not sell or share personal data for marketing. The sharing that occurs is limited to infrastructure necessary to deliver the service (email delivery, CDN/DNS, and the AI engine). Disclosure is clear and limited to what the service requires.
Opt-Out Rights
The policy provides an explicit, user-controllable opt-out for anonymous usage data via an account-page toggle, and account deletion is available on request. The anonymous data collection is on by default but can be turned off, and already-collected anonymous data is stated to be untraceable. Data-subject rights (access, correction, deletion, objection) are also offered.
Compliance & Certifications
The documents name no formal compliance frameworks or certifications — no SOC 2, ISO 27001, ISO 27017/27018, CSA STAR, GDPR, or CCPA are claimed or attested, despite the vendor operating from Denmark (an EU/GDPR jurisdiction) and offering the tool globally. The privacy policy gestures at data-subject rights but does not name GDPR itself. Silence on all relevant baseline and sector frameworks warrants a RED for this category, though the low overall data-collection footprint mitigates practical risk.
Model Explainability & Auditability
The Terms candidly disclose that the AI engine is Claude (Anthropic) and that output may contain errors requiring verification, which provides basic transparency about the model source. However, the documents offer no enterprise auditing capability, model-behavior documentation, or explainability tooling. For a productivity connector this is expected, but auditability commitments are absent.
Security Practices & Breach History
The policy discloses HTTPS for transmission, encrypted storage, and access controls on a private server, and the local-only architecture reduces the attack surface for model data. However, there is no mention of penetration testing, bug bounty, incident response procedures, formal breach notification commitments, or a dedicated trust center. No breach history is disclosed. Security disclosures are basic rather than comprehensive.
Enterprise vs. Consumer Risk Delta
HuskyBIM is described as free to use with no current paid tiers, and the Terms note paid plans may be introduced in the future. No enterprise agreement, DPA, or MSA was supplied, so there is no differentiated enterprise data-handling posture to evaluate. Business users seeking contractual protections (DPA, SLAs, named sub-processor commitments) would find none in these documents.
Human Review of User Inputs
The policy states HuskyBIM does not collect prompts, model data, or Claude conversation content, and that anonymous usage telemetry never sees what the user asked or tool arguments. There is therefore no reserved right for staff to read user inputs or outputs. The support event log is limited to account activity and explicitly excludes conversation content.
Regulatory & Litigation Exposure
The documents are silent on government data requests, law enforcement cooperation, and litigation, other than a generic 'except where retention is required by law' clause. Given the minimal personal data held, there is little to disclose to authorities, but the absence of a transparency/law-enforcement policy leaves this category unaddressed. Governing law is Denmark with exclusive jurisdiction in Danish courts.
PII & SPI Data Inventory
HuskyBIM collects a minimal PII set — email address, a one-way hashed machine identifier, connector version, and an account activity log — with clear purpose limitation for each. It expressly does not collect payment data, IP addresses (beyond Cloudflare's network layer), or any BIM/model/prompt content, and no SPI categories are collected. This is a low-data-footprint design with adequate disclosure.
Policy–Product Currency
The Privacy Policy is dated September 4, 2026 and the Terms April 30, 2026 — both well within 12 months of the September 2026 analysis date. The policies explicitly address the product's AI-first architecture, naming Claude/Anthropic as the AI engine, the MCP connector model, and the local-execution data flow that matches the marketed platform. Coverage of the shipped capabilities is demonstrated, supporting a GREEN rating.
Cross-Document Consistency
Three documents were supplied — the Terms of Service and two identical copies of the Privacy Policy (one at huskybim.com and one at mcp.huskybim.com). The two privacy policies are verbatim identical, and their statements on data collection, retention, and third-party use are consistent with the Terms. No contradictions were found across the documents.
You've read all 15 risk ratings for Huskybim. Create a free account to see the exact policy wording behind each rating.