Privacy Policy
Material Monitor · Last updated 9 September 2026
Material Monitor is a web app for small custom home builders, made and run by Lock Ten Studio LLC, a Maryland limited liability company. This policy explains what the app collects, why it collects it, who can see it, how long it is kept and how to get rid of it. It is written to be read by the person in the office who actually uses the software.
The short version. Your company's data belongs to your company. Only people your company invites can see it. We do not sell it, we do not advertise against it, and we do not use it to build anything for anybody else. If your company connects a vendor mailbox, we read only mail from senders your company has approved as vendors, and we never send mail from that mailbox. Ask us to delete your company and we delete it.
On this page
- Who we are
- What we collect and why
- Vendor email, and the three ways it reaches the app
- Google user data and the Limited Use requirements
- Microsoft 365 user data
- The reading pass and how it uses AI
- Who can see your data
- Service providers
- Where your data is stored
- How long we keep things
- Deleting your company and its data
- Security
- Cookies
- Children
- Changes to this policy
- Contact
Who we are
Material Monitor is operated by Lock Ten Studio LLC ("we", "us", "our"), a Maryland limited liability company. The app lives at app.materialmonitor.app. This policy covers that app, the emails it sends you, and the marketing site at materialmonitor.app.
In this policy, "your company" means the builder's business that signed up for an account, and "you" means a person using the app as a member of that company. Your company controls its own data. We hold it and run the software for your company.
What we collect and why
We collect only what the app needs to do its job. There is no advertising, no ad network, no data broker and no tracking pixel of our own anywhere in the product.
Account and company information
Your work email address, your name if you enter one, your company name, and which people your company has invited. We use this to sign you in, to show who did what inside your company, and to send you service email. Sign-in uses a six-digit code sent to your work email. There is no password, so we never store one.
Your order and delivery records
The finish material orders your company keeps per job: items, quantities, vendors, purchase order and tracking references, dates, notes, and the status of each order. When a delivery is received from a phone, that record includes counts, condition notes and any photos taken, such as a photo of the packing slip. We store this so the app can show you where every order stands and send the morning email.
Vendor email your company routes to the app
Order confirmations, ship notices, delay notices and similar mail from the vendors your company has approved. We store the message content and its attachments so the app can propose an update to the matching order and so a person can check the source when reviewing that proposal. The section below explains exactly how this mail reaches us and what is left out.
Technical records
Ordinary server and application logs: the time of a request, the page or action, an error if one occurred, and the account it belonged to. These exist so the app can be kept working and so we can investigate a problem. They are not used to profile anybody.
Vendor email, and the three ways it reaches the app
Reading vendor mail is a feature your company turns on. It is off until somebody at your company sets it up, and your company picks one of three ways to do it.
- A private forwarding address. We give your company its own address. Your office forwards vendor mail to it, either by hand or with a rule in your own mail system. We only ever see what is forwarded.
- A connected Microsoft 365 mailbox. Your company connects a mailbox through Microsoft's own sign-in screen. The connection is read only.
- A connected Google Workspace or Gmail mailbox. Your company connects a mailbox through Google's own sign-in screen. The connection is read only.
Whichever route your company picks, the same rules apply:
- We read only mail from senders your company has approved as vendors. Mail from anyone else is not used.
- Mail from your company's own domains is ignored, so your internal conversation stays out of the app.
- A person at your company confirms every proposed change to an order. The single exception is an exact tracking number match, which the app can apply on its own because there is nothing to interpret.
- Follow-up emails are drafts. Your office sends them from its own mailbox. The app never sends mail from a connected mailbox.
- Sign-in tokens for a connected mailbox are encrypted at rest and deleted when your company disconnects the mailbox.
Google user data and the Limited Use requirements
If your company connects a Google Workspace or Gmail mailbox, the app reads that mailbox through Google's Gmail API, with read only permission, after your company grants access on Google's own sign-in screen.
Material Monitor's use and transfer of information received from Google APIs to any other app will adhere to the Google API Services User Data Policy, including the Limited Use requirements.
In practice that means we use Google mailbox data only to provide the features your company asked for, we do not transfer it to anyone except as needed to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your company's explicit permission, when it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous. Your company can disconnect the mailbox at any time in the app, and can also revoke access from its own Google account settings.
Microsoft 365 user data
If your company connects a Microsoft 365 mailbox, the app reads that mailbox through the Microsoft Graph API, with read only permission, after your company grants access on Microsoft's own sign-in screen.
We hold Microsoft mailbox data to the same standard as Google's. We use it only to provide the features your company asked for, we do not transfer it to anyone except as needed to provide those features or as required by law, we do not use it for advertising, and we do not allow humans to read it except with your company's explicit permission, when it is necessary for security or to comply with the law, or where the data has been aggregated and made anonymous. Your company can disconnect the mailbox at any time in the app, and can also revoke access from its own Microsoft account settings.
The reading pass and how it uses AI
Turning a vendor email into a proposed order update takes a reading pass. When your company enables it, the text of an approved vendor's email is sent to Anthropic's API, which extracts the order facts in it: the item, the quantity, a ship date, a tracking number and so on. Anthropic's API terms do not permit training on that data.
What comes back is a proposal, not a change. A person at your company reviews and confirms it, with the exception of an exact tracking number match noted above. The app does not decide anything about your orders on its own.
Who can see your data
Your company's data is visible to the members of your company and to nobody else. There is no shared view across companies, no benchmark, no leaderboard and no aggregate product built from your records.
On our side, access is limited to the small number of people at Lock Ten Studio who keep the service running, and only when it is needed to fix a problem, investigate a security issue, or answer a support request from your company. We do not browse customer data.
We do not sell your data, and we do not share it with anyone for their own purposes. We share it only with the service providers listed below, who process it on our behalf, or where the law requires us to.
Service providers
These are the companies that handle some part of your data so that the app can work.
- Render hosts the application and the database.
- Resend sends the app's transactional email, such as your sign-in code and the morning email, and receives the mail sent to your company's private forwarding address.
- Anthropic provides the reading pass, for companies that have enabled it. Anthropic's API terms do not permit training on that data.
- Microsoft Graph and Google Gmail APIs, only for companies that have connected one of those mailboxes.
- Carrier tracking services, currently 17TRACK, UPS and FedEx, which we query with a tracking number to get a delivery status.
Transactional email providers add ordinary delivery instrumentation to the messages they send, which can include an open or click record. That is a feature of email delivery, not something we add for tracking, and we run no tracking pixel of our own.
Where your data is stored
Your data is stored in the United States.
How long we keep things
- Your company's orders, deliveries and photos: for as long as your company has an account, because the point of the app is the record. Your company can delete individual records at any time.
- Vendor email content: kept alongside the order it relates to for as long as your company has an account, so that a person reviewing a change can see the message it came from.
- Sign-in tokens for a connected mailbox: encrypted at rest and deleted as soon as your company disconnects that mailbox.
- Application and server logs: a short operational window, currently 30 days.
- After your company closes its account: we delete the company and its data within 30 days, and it falls out of routine encrypted backups within a further 35 days.
Deleting your company and its data
Write to info@lockten.ai from a work email address on the account and ask us to delete the company. We will confirm with an administrator of that company, then delete the company, its members, its orders, its delivery records and photos, and the vendor mail held against those orders, on the timetable above. Individual records can be deleted inside the app at any time without contacting us.
If you only want the mailbox connection gone, disconnect it in the app. That deletes the sign-in tokens immediately and stops any further reading.
Security
Access to the app requires a code sent to a work email address on the account. Traffic runs over encrypted connections. Sign-in tokens for connected mailboxes are encrypted at rest. Access on our side is limited to the people who run the service. No system is perfect, and we will tell your company promptly if we learn of a breach affecting its data.
Cookies
The app sets a session cookie so that it knows you are signed in. That is the only cookie it needs, and it is not used for advertising or for following you around the web. Clearing it signs you out.
Children
Material Monitor is a tool for a business. It is not directed at children and is not for anyone under 18. We do not knowingly collect information from anyone under 18. If we learn we have, we will delete it.
Changes to this policy
If we change this policy we will update the date at the top of the page, and if the change is a significant one we will tell account administrators by email before it takes effect. The current version always lives at this address.
Contact
Questions about this policy, or about your company's data, go to info@lockten.ai. Material Monitor is operated by Lock Ten Studio LLC, a Maryland limited liability company.
Back to Material Monitor