Privacy notice
Last updated 29 September 2026
Who we are
MakerProof is operated by Greg Cloke, a sole trader trading as MakerProof, based in the United Kingdom. MakerProof is a trading name rather than a limited company, so the data controller for everything described here is Greg Cloke.
For questions about this notice or about your data, contact support@makerproof.app. Our postal address is 124 City Road, London, EC1V 2NX.
What we collect, and why
Only what the service needs to work. Specifically:
- Account
- Your name, email address and a hashed password. Needed to sign you in and to send renewal reminders — which is the thing the service exists to do, so an unverified address makes the account unusable rather than merely limited.
- Workshop settings
- Country, currency, electricity and labour rates, failure rate and target margin. Country determines your currency and number formatting; the rates feed the cost calculations and are never shared.
- Licence records
- Designer and model names, platform, licence type and reference, purchase and renewal dates, the price you paid, any notes you write, and a snapshot of the terms if you paste one.
- Proof documents
- Receipts, invoices and screenshots you choose to upload. We do not routinely review, index or analyse their contents — there is no process that opens them. We may access one where we genuinely need to: investigating a security problem or suspected abuse, fixing a fault you have reported, or complying with a legal obligation. They are stored encrypted and are served only to you.
- Stock and print records
- Filament spools, printers, finished items, print logs and waste records. Used to calculate your costs and nothing else.
- Server logs
- Our servers record each request: the page asked for, the time, the response, the browser's user-agent string and the IP address it came from. This is ordinary operational record-keeping — diagnosing faults and spotting abuse — and it is kept for seven days, after which it is deleted automatically.
- Site statistics
- We keep counts of which pages are read, from which country, on mobile or desktop, with which operating system and browser, and which site linked to us. Operating system and browser are recorded as a family only — “Windows”, “Chrome” — never the full version string your browser sends, because that string is detailed enough to help single out an individual device. This is measured from the server logs above rather than by anything running in your browser. Your IP address is not kept. What happens to it is this: it is combined with a secret that changes every day, hashed to produce a short visitor identifier, and the address itself is then discarded rather than written anywhere. The daily secret is destroyed after 48 hours, so once it is gone we cannot recompute or match those identifiers even if we wanted to. The identifier only distinguishes one visitor from another within a single day. We also record which requests came from search engine crawlers and uptime checks, so those are not counted as readers.
- MakerProof AI
- Optional, and only when you use it: nothing is sent unless you press a MakerProof AI button, and every part of MakerProof works without it. MakerProof AI runs on Claude, an AI model made by Anthropic, and what you send it is processed in the United States (see below). To read a licence's terms, the terms you saved are sent to be read. To fill in a licence from a receipt, the receipt you choose is sent — it may show your name, address and part of your payment details, and it is read once and not kept by us (attach it as proof separately if you want it kept). To check a shop listing, the listing text you paste and the licence's saved terms are sent, and the listing is not kept. To read a spool label, the photo you take is sent, read once and not kept by us. To match a spreadsheet's columns, its headings and first five rows are sent. To answer a question about your workshop, your question and the figures from your records needed to answer it are sent. We keep terms readings with the licence they belong to, and a record of each use (which feature, when, and its size) so monthly allowances work. We do not keep your questions, the answers, receipts, listings or label photos.
No tracking cookies, and nothing to consent to. There is no analytics script, no advertising network and no cross-site tracking. Nothing is stored on your device for measurement. Visiting any public page of this site sets no cookies at all — the ones below appear only when you do the thing that needs them.
| Cookie | What it is for | When it is set | How long |
|---|---|---|---|
__Secure-better-auth.session_token | Keeps you signed in. Without it every page would ask for your password again. | When you sign in | Until the session expires or you sign out |
better-auth sign-in state | Protects the Google sign-in handshake against request forgery. Discarded as soon as the sign-in completes. | Only if you choose “Continue with Google” | Minutes |
mp_theme | Remembers whether you chose light, dark or system. It holds one of those three words and nothing else — no identifier, nothing about you. | Only when you click the theme control | One year |
mp_plan | Remembers which plan you chose before you created your account, so the right one is waiting at checkout. It holds one of four fixed words and nothing else — no identifier, nothing about you. | Only if you pick a paid plan before signing up | Two hours |
Your browser also keeps three small settings for this site in its own storage rather than as cookies. None holds anything about you, and none is ever sent to us:
mp.signin: whether you last signed in with a password or a link, so the sign-in page opens the way you use it. Set when you press either button.mp.labels.v1: your choices on the spool labels page, such as the label sheet. Set when you change one.mp.install.dismissed: when you closed the suggestion to install the app, so it does not keep appearing. Set when you close it.
All of these exist to do something you asked for, so there is no consent banner. We would rather not interrupt you to ask about cookies we would have to set anyway to let you log in.
Why we are allowed to hold it
Data protection law requires a lawful basis for each use. Ours are:
- Contract
- Your account, workshop settings, licence records, proof documents, and stock and print records. We hold these because we cannot provide the service you signed up for without them. The same applies to MakerProof AI: when you use it, sending what you ask it to work on to its provider is how the feature you chose does its job.
- Legitimate interests
- Server logs and site statistics — keeping the service secure and working, and understanding whether anyone is reading the site. We have weighed this against your privacy, which is why logs last seven days and statistics carry no address. You can object; see Your rights below.
- Legal obligation
- Billing and accounting records. Tax law sets how long these must be kept, and that overrides a deletion request for those records specifically.
Renewal reminders, verification, sign-in link and password-reset emails and billing notices are service communications sent under the contract, not marketing. We will not send you marketing without asking separately first.
What we never do
- We do not sell your data, and we do not share it for advertising.
- We do not use your records or documents to train machine-learning models, and under its commercial terms the provider behind MakerProof AI may not either.
- We do not tell designers or marketplaces what you have licensed.
- We do not check whether your licence records are true. MakerProof flags the dates you enter — what those dates mean commercially is between you, the designer and the platform.
Where it is kept
Your data is held in the United Kingdom — the server is in London and the document and backup storage is in a UK region. The two exceptions are email, which passes through Brevo in the EU, and MakerProof AI, which is processed by Anthropic's Claude in the United States when you use it (see below). The database sits on an encrypted volume; proof documents are stored with server-side encryption; backups are encrypted before they leave the server. Every connection is over HTTPS.
Your documents are stored under a prefix belonging to your account alone, and are only ever served through a request carrying your own session — they are never given a shareable link and are never cached by our CDN.
Who processes it for us
- IONOS
- Server hosting, in their London data centre. Everything you store lives here, in the United Kingdom. IONOS SE is a German company, so its own corporate operations are in Germany — but your data is held in the UK.
- Wasabi
- Storage for proof documents and encrypted backups, in their UK region.
- Bunny
- Content delivery and security filtering. Every request passes through Bunny, which means it handles the connection itself and not only metadata about it. Pages containing your data are marked never to be cached, so they are passed through rather than stored at the edge; only public files such as the logo and stylesheets are cached.
- Brevo
- Sends service email, from the EU — verification, sign-in links, password resets, renewal reminders and billing notices. Receives your email address and the contents of that message.
- Cloudflare
- DNS for the domain, and nothing more. Traffic is not proxied through Cloudflare, so it sees requests to look up where makerproof.app is — not the pages you visit or anything you send us.
- Stripe
- Payments. Card details go directly to Stripe and never reach us.
- Anthropic
- Provides Claude, the AI model behind MakerProof AI. Our contract is with Anthropic Ireland, Limited; the processing itself takes place in the United States, by Anthropic, PBC and its subprocessors. Anthropic receives only what you ask MakerProof AI to work on, as described above, and only when you use it. Its standard retention period for what it receives is 30 days, subject to exceptions in its terms (for example, where its usage policy or the law requires it to keep something longer). Under its commercial terms it may not use what we send to train its models.
Sending data outside the UK
The server and the storage holding your data are both in the United Kingdom. Some of the suppliers above are international companies — IONOS is German, Brevo French, Bunny Slovenian, Wasabi and Cloudflare American — whose support and operations teams may access data from outside the UK and the EEA even though the data itself is stored here. What you send to MakerProof AI goes to Anthropic Ireland, Limited, in the EEA, which UK law recognises as adequately protecting personal data. Anthropic then processes it with Claude in the United States, and that onward transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses in Anthropic's data processing terms.
Where that happens, we rely on the transfer safeguards UK data protection law requires — an adequacy decision covering the country concerned, or the International Data Transfer Agreement or Addendum in our contract with that supplier. You can ask us which applies to a particular supplier at support@makerproof.app.
How long we keep it
For as long as your account exists. Delete your account and the records are removed immediately, along with every proof document — the documents are deleted from storage before the database rows, so nothing is left stranded in a bucket with no record pointing at it.
Encrypted backups are the exception, and they run on a longer clock than the live service. We keep hourly backups for around two days, daily backups for about a month, and one backup per month for twelve months — so a copy of an account deleted today can persist in an encrypted backup for up to twelve months, after which it ages out and is gone. We keep a year of monthly copies so that damage discovered late — a corruption or a mistake that went unnoticed for months — is still recoverable. Backups are encrypted before they leave the server and are only ever restored wholesale after a failure, never to retrieve one person's data.
MakerProof AI: we do not keep what you send it, except terms readings, which are kept with their licence and go when the licence or your account does. The record of each use is kept with your account. Anthropic's standard retention for what it receives is 30 days, subject to the exceptions in its terms.
Logs and statistics run to their own clock, because they are not tied to an account:
- Server logs
- Seven days, then deleted automatically.
- Individual page records
- Twelve months, then moved to encrypted archive storage and held for a further year so year-on-year comparisons are possible. They contain no name, no email address and no IP address.
- Daily totals
- Kept indefinitely. These are counts only — a date, a page, a country, a device or browser family and a number — with nothing that identifies anyone, which is why they can be kept without a deletion date.
Your rights
Depending on the circumstances and the law that applies to you, you may have the right to ask for a copy of your data, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable form, and to complain to a regulator. Some of these depend on the lawful basis involved — for example, records we must keep for tax purposes cannot simply be deleted on request. Two are built in and need no request at all:
- A copy of everything — Your account → Download your data. It produces a zip of every record we hold about you as CSV files, which open in any spreadsheet, plus the original proof documents.
- Deletion — Your account → Delete account. Immediate and irreversible.
For anything else, email support@makerproof.app. We will respond within one month.
If you are not happy with how we have handled it, you can complain to the Information Commissioner’s Office, the UK data protection regulator — online at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. You can complain to them without contacting us first, though we would rather have the chance to put it right.
Changes
If this notice changes in a way that affects you, we will email you before it takes effect rather than quietly updating the date at the top.