Qikbim
qikbim.comQikBIM is an AI-assisted BIM and construction-documentation automation platform operated by OFA Group, Inc., a Cayman Islands company with US operations. The supplied Privacy Policy and Consent Agreement are recent (Effective July 20, 2026) and do address AI/ML processing, training use, and human review, which is a positive currency signal. However, the documents are consumer-facing, silent on input/output ownership, contain no compliance certifications, permit broad use of Inputs (including for model training) with human review, and provide no explicit retention schedule or deletion SLA. The Terms and Conditions and any DPA were inaccessible, so ownership and licensing terms cannot be verified. Professional users handling proprietary design files should obtain contractual protections before submitting sensitive project data.
AI Transparency Facts
Independent analysis by TermsWatchdog · © 2026 TermsWatchdog
Input Data Ownership
The Privacy Policy and Consent Agreement define user-submitted prompts, files, drawings, and models as 'Inputs' but never state who owns them; ownership terms would typically live in the Terms and Conditions, which was inaccessible. The Consent Agreement requires users to warrant they have all rights to submit Inputs but grants no explicit ownership assurances back to the user. The silence on ownership is a risk for a tool handling proprietary architectural work product.
Output Data Ownership
The documents define AI-generated drawings, plans, and models as 'Outputs' but are silent on who owns them; ownership would be governed by the inaccessible Terms and Conditions. The Consent Agreement stresses that Outputs are preliminary, may contain errors, and require professional review, but does not address ownership or licensing. This silence leaves output rights unresolved in the supplied text.
Training Data Usage
The vendor explicitly reserves the right to use Inputs and usage data to develop, improve, and train its AI models. Opt-out of training is only a conditional future possibility ('if and when' the Company offers such settings), meaning by default user design files may feed model training. This is a significant risk for professional users submitting proprietary work.
Data Retention & Deletion
The Privacy Policy states data is retained 'as long as necessary' but provides no defined retention schedule or deletion SLA. Users may request deletion by contacting support, and the vendor commits to respond within timeframes required by applicable law. The absence of concrete retention periods or an audit-log retention commitment lowers confidence.
Third-Party Data Sharing
The vendor discloses sharing with named service providers (Wix, Stripe, and cloud/analytics/security providers), affiliates, and in legal or business-transfer contexts. It states it does not sell personal information for money and offers opt-out where a disclosure constitutes a 'sale' or 'sharing.' Sharing is disclosed and limited to service operations, but the broad affiliate and business-transfer language warrants a moderate rating.
Opt-Out Rights
Users can opt out of marketing emails, exercise deletion/access rights, and opt out of any 'sale'/'sharing' with recognized signals like Global Privacy Control honored where required. However, opt-out of model training is only a conditional future feature ('if and when'), so a key opt-out for a design-automation tool is not currently guaranteed.
Compliance & Certifications
The documents reference GDPR and CCPA/CPRA obligations and legal bases but claim no third-party certifications or attestations (no SOC 2, ISO 27001, ISO 27018, ISO 27017, CSA STAR). For a developer/enterprise-oriented tool, the absence of any named security certification or audit report is a material gap. Only privacy-law compliance is referenced, without evidence of external attestation.
Model Explainability & Auditability
The Privacy Policy notes AI/ML is used to process Inputs and generate Outputs and states no legally significant decisions are made solely by automated processing, but it offers no enterprise auditing capability or model transparency commitment. The documents provide no explainability tooling or audit access. This limits transparency for professional review needs.
Security Practices & Breach History
The Privacy Policy describes 'reasonable administrative, technical, and organizational measures' but names no specific controls such as encryption at rest/in transit, penetration testing, or a bug bounty, and no trust center or security page is referenced. No breach history is disclosed. The generic, unspecific security language and absence of a dedicated security page reduce confidence.
Enterprise vs. Consumer Risk Delta
The supplied documents are consumer/standard terms and describe no differentiated free-versus-paid data handling; payment and subscription processing is mentioned but no tier-specific privacy carve-outs. No enterprise agreement or DPA was accessible to compare. The absence of any enterprise data-handling distinction means professional users get the same default terms, including default training use.
Human Review of User Inputs
The vendor explicitly reserves the right for authorized personnel to review Inputs and Outputs for safety, abuse prevention, quality assurance, and service improvement. This human-review right applies to proprietary design files and is broadly framed. Combined with the instruction not to submit sensitive personal information, this is a notable confidentiality risk.
Regulatory & Litigation Exposure
The Privacy Policy discloses that personal information may be disclosed to comply with law, legal process, or governmental request and to establish or defend legal claims. No specific litigation, breach, or law-enforcement request history is disclosed. The language is standard but broad, and cross-border Cayman/US processing adds jurisdictional complexity.
PII & SPI Data Inventory
The vendor collects a range of PII including name, email, company/role, IP address, device identifiers, approximate location, and usage data, plus payment details processed by Stripe (not stored in full). It instructs users not to submit sensitive personal information and states the service is not directed at children. PII collection is significant but disclosed with purpose limitation, and SPI is discouraged rather than collected.
Policy–Product Currency
Both documents carry an Effective Date of July 20, 2026, less than one month before the analysis date, and they demonstrably address the AI/ML processing, model training, and automated Input/Output handling visible in the product surface (an AI-assisted BIM design-automation platform). The policy explicitly acknowledges AI use, human review, and training. The named third-party providers (Wix, Stripe) match disclosed infrastructure, though ETABS/SAFE/Revit integrations from the product surface are not addressed.
Cross-Document Consistency
Two documents were supplied — the Privacy Policy and the Consent Agreement — and they are mutually consistent on AI processing, training use, human review, international transfers, and consent withdrawal. No contradictions were found between them. Both share the same Effective Date and reinforce each other's provisions, though the referenced Terms and Conditions and System Use Disclaimer were not accessible to cross-check.
You've read all 15 risk ratings for Qikbim. Create a free account to see the exact policy wording behind each rating.