Privacy Policy

Effective date: July 10, 2026

Lagarsoft LLC ("Lagarsoft," "we," "us," or "our") operates HUDA — Hub User & Deployment Administration (the "App"). This Privacy Policy explains what information the App collects, how we use it, and your choices regarding that information.

HUDA is an enterprise tool that lets Autodesk account administrators bulk-manage user permissions across Autodesk Construction Cloud projects via CSV upload. It is not intended for consumer use.

1. Information We Collect

Authentication Data

When you sign in, you authenticate through Autodesk's OAuth 2.0 flow. We receive an access token, refresh token, and your Autodesk user profile (email address and Autodesk ID). These are stored in encrypted, HTTP-only browser cookies — we do not store them in any server-side database.

User Profile Data

We read your email address and Autodesk ID from Autodesk's user profile API solely to identify your session. Your email is also stored in a browser-readable cookie for display purposes and analytics identification.

Project & Organization Data

The App reads hub, project, user, company, and folder information from Autodesk's APIs to display and manage your organization's data. This information is fetched on demand and cached briefly in server memory (up to 5 minutes). It is not stored in any persistent database.

CSV Upload Data

CSV files you upload (for bulk operations, user imports, or folder permissions) are parsed entirely in memory on the server. They are never written to disk or stored in a database. Once the HTTP request completes, the data is discarded.

2. How We Use Information

  • Authentication: To verify your identity and maintain your session.
  • Administration: To execute the bulk user permission operations you initiate (add, remove, update users across projects).
  • Product Analytics: To understand how the App is used, identify issues, and improve the experience. See Section 5 for details.

3. Cookies & Local Storage

The App uses the following cookies:

CookiePurposeDuration
aps_access_tokenAutodesk API access token (HTTP-only)~1 hour
aps_refresh_tokenSession renewal token (HTTP-only)30 days
aps_expires_atToken expiry timestamp (HTTP-only)30 days
aps_user_emailDisplay your email in the UI30 days
aps_autodesk_idYour Autodesk user ID (HTTP-only)30 days

The App also uses browser local storage for:

  • Theme preference (dark/light mode)
  • Last selected hub
  • Recently viewed projects (expires after 30 days)
  • Temporary API response cache

4. Data Sharing

We do not sell, rent, or share your personal information with third parties for marketing or advertising purposes. Data is only shared with Autodesk's APIs as necessary to perform the administration operations you request, and with the analytics providers described below.

5. Third-Party Services

  • Autodesk Platform Services — The App communicates with Autodesk's APIs to authenticate you and manage project data. Autodesk's use of your data is governed by Autodesk's Privacy Statement.
  • PostHog — We use PostHog for product analytics (feature usage, error tracking). Your email is used as an identifier. PostHog's privacy policy is available at posthog.com/privacy.
  • Google Analytics — We use Google Analytics 4 to understand traffic patterns. Google's privacy policy is available at policies.google.com/privacy.

6. Data Retention

The App does not operate a server-side database. Session cookies expire after 30 days or when you sign out. Server-side caches (hub and role data) are held in process memory for up to 5 minutes and are lost when the server restarts. CSV data is discarded immediately after processing.

7. Data Security

Authentication tokens are stored in HTTP-only, Secure cookies that are inaccessible to client-side JavaScript. All communication with Autodesk APIs uses TLS encryption. OAuth client credentials are stored as server-side environment variables and are never exposed to the browser.

8. Your Rights

You may request access to, correction of, or deletion of your personal information by contacting us at support@lagarsoft.com. Since the App does not maintain a persistent database of user data, most data is automatically removed when your session expires or you sign out.

9. Changes to This Policy

We may update this Privacy Policy from time to time. Changes will be reflected by updating the effective date at the top of this page. We encourage you to review this page periodically.

10. Contact Us

If you have questions about this Privacy Policy, contact us at:

Lagarsoft LLC
support@lagarsoft.com