MakerProof

Who we are

MakerProof is operated by Greg Cloke, a sole trader trading as MakerProof, based in the United Kingdom. MakerProof is a trading name rather than a limited company, so the data controller for everything described here is Greg Cloke.

For questions about this notice or about your data, contact support@makerproof.app. Our postal address is 124 City Road, London, EC1V 2NX.

What we collect, and why

Only what the service needs to work. Specifically:

Account
Your name, email address and a hashed password. Needed to sign you in and to send renewal reminders — which is the thing the service exists to do, so an unverified address makes the account unusable rather than merely limited.
Workshop settings
Country, currency, electricity and labour rates, failure rate and target margin. Country determines your currency and number formatting; the rates feed the cost calculations and are never shared.
Licence records
Designer and model names, platform, licence type and reference, purchase and renewal dates, the price you paid, any notes you write, and a snapshot of the terms if you paste one.
Proof documents
Receipts, invoices and screenshots you choose to upload. We do not routinely review, index or analyse their contents — there is no process that opens them. We may access one where we genuinely need to: investigating a security problem or suspected abuse, fixing a fault you have reported, or complying with a legal obligation. They are stored encrypted and are served only to you.
Stock and print records
Filament spools, printers, finished items, print logs and waste records. Used to calculate your costs and nothing else.
Server logs
Our servers record each request: the page asked for, the time, the response, the browser's user-agent string and the IP address it came from. This is ordinary operational record-keeping — diagnosing faults and spotting abuse — and it is kept for seven days, after which it is deleted automatically.
Site statistics
We keep counts of which pages are read, from which country, on mobile or desktop, with which operating system and browser, and which site linked to us. Operating system and browser are recorded as a family only — “Windows”, “Chrome” — never the full version string your browser sends, because that string is detailed enough to help single out an individual device. This is measured from the server logs above rather than by anything running in your browser. Your IP address is not kept. What happens to it is this: it is combined with a secret that changes every day, hashed to produce a short visitor identifier, and the address itself is then discarded rather than written anywhere. The daily secret is destroyed after 48 hours, so once it is gone we cannot recompute or match those identifiers even if we wanted to. The identifier only distinguishes one visitor from another within a single day. We also record which requests came from search engine crawlers and uptime checks, so those are not counted as readers.
MakerProof AI
Optional, and only when you use it: nothing is sent unless you press a MakerProof AI button, and every part of MakerProof works without it. MakerProof AI runs on Claude, an AI model made by Anthropic, and what you send it is processed in the United States (see below). To read a licence's terms, the terms you saved are sent to be read. To fill in a licence from a receipt, the receipt you choose is sent — it may show your name, address and part of your payment details, and it is read once and not kept by us (attach it as proof separately if you want it kept). To check a shop listing, the listing text you paste and the licence's saved terms are sent, and the listing is not kept. To read a spool label, the photo you take is sent, read once and not kept by us. To match a spreadsheet's columns, its headings and first five rows are sent. To answer a question about your workshop, your question and the figures from your records needed to answer it are sent. We keep terms readings with the licence they belong to, and a record of each use (which feature, when, and its size) so monthly allowances work. We do not keep your questions, the answers, receipts, listings or label photos.

No tracking cookies, and nothing to consent to. There is no analytics script, no advertising network and no cross-site tracking. Nothing is stored on your device for measurement. Visiting any public page of this site sets no cookies at all — the ones below appear only when you do the thing that needs them.

CookieWhat it is forWhen it is setHow long
__Secure-better-auth.session_tokenKeeps you signed in. Without it every page would ask for your password again.When you sign inUntil the session expires or you sign out
better-auth sign-in stateProtects the Google sign-in handshake against request forgery. Discarded as soon as the sign-in completes.Only if you choose “Continue with Google”Minutes
mp_themeRemembers whether you chose light, dark or system. It holds one of those three words and nothing else — no identifier, nothing about you.Only when you click the theme controlOne year
mp_planRemembers which plan you chose before you created your account, so the right one is waiting at checkout. It holds one of four fixed words and nothing else — no identifier, nothing about you.Only if you pick a paid plan before signing upTwo hours

Your browser also keeps three small settings for this site in its own storage rather than as cookies. None holds anything about you, and none is ever sent to us:

All of these exist to do something you asked for, so there is no consent banner. We would rather not interrupt you to ask about cookies we would have to set anyway to let you log in.

Why we are allowed to hold it

Data protection law requires a lawful basis for each use. Ours are:

Contract
Your account, workshop settings, licence records, proof documents, and stock and print records. We hold these because we cannot provide the service you signed up for without them. The same applies to MakerProof AI: when you use it, sending what you ask it to work on to its provider is how the feature you chose does its job.
Legitimate interests
Server logs and site statistics — keeping the service secure and working, and understanding whether anyone is reading the site. We have weighed this against your privacy, which is why logs last seven days and statistics carry no address. You can object; see Your rights below.
Legal obligation
Billing and accounting records. Tax law sets how long these must be kept, and that overrides a deletion request for those records specifically.

Renewal reminders, verification, sign-in link and password-reset emails and billing notices are service communications sent under the contract, not marketing. We will not send you marketing without asking separately first.

What we never do

Where it is kept

Your data is held in the United Kingdom — the server is in London and the document and backup storage is in a UK region. The two exceptions are email, which passes through Brevo in the EU, and MakerProof AI, which is processed by Anthropic's Claude in the United States when you use it (see below). The database sits on an encrypted volume; proof documents are stored with server-side encryption; backups are encrypted before they leave the server. Every connection is over HTTPS.

Your documents are stored under a prefix belonging to your account alone, and are only ever served through a request carrying your own session — they are never given a shareable link and are never cached by our CDN.

Who processes it for us

IONOS
Server hosting, in their London data centre. Everything you store lives here, in the United Kingdom. IONOS SE is a German company, so its own corporate operations are in Germany — but your data is held in the UK.
Wasabi
Storage for proof documents and encrypted backups, in their UK region.
Bunny
Content delivery and security filtering. Every request passes through Bunny, which means it handles the connection itself and not only metadata about it. Pages containing your data are marked never to be cached, so they are passed through rather than stored at the edge; only public files such as the logo and stylesheets are cached.
Brevo
Sends service email, from the EU — verification, sign-in links, password resets, renewal reminders and billing notices. Receives your email address and the contents of that message.
Cloudflare
DNS for the domain, and nothing more. Traffic is not proxied through Cloudflare, so it sees requests to look up where makerproof.app is — not the pages you visit or anything you send us.
Stripe
Payments. Card details go directly to Stripe and never reach us.
Anthropic
Provides Claude, the AI model behind MakerProof AI. Our contract is with Anthropic Ireland, Limited; the processing itself takes place in the United States, by Anthropic, PBC and its subprocessors. Anthropic receives only what you ask MakerProof AI to work on, as described above, and only when you use it. Its standard retention period for what it receives is 30 days, subject to exceptions in its terms (for example, where its usage policy or the law requires it to keep something longer). Under its commercial terms it may not use what we send to train its models.

Sending data outside the UK

The server and the storage holding your data are both in the United Kingdom. Some of the suppliers above are international companies — IONOS is German, Brevo French, Bunny Slovenian, Wasabi and Cloudflare American — whose support and operations teams may access data from outside the UK and the EEA even though the data itself is stored here. What you send to MakerProof AI goes to Anthropic Ireland, Limited, in the EEA, which UK law recognises as adequately protecting personal data. Anthropic then processes it with Claude in the United States, and that onward transfer is covered by the UK International Data Transfer Addendum to the EU Standard Contractual Clauses in Anthropic's data processing terms.

Where that happens, we rely on the transfer safeguards UK data protection law requires — an adequacy decision covering the country concerned, or the International Data Transfer Agreement or Addendum in our contract with that supplier. You can ask us which applies to a particular supplier at support@makerproof.app.

How long we keep it

For as long as your account exists. Delete your account and the records are removed immediately, along with every proof document — the documents are deleted from storage before the database rows, so nothing is left stranded in a bucket with no record pointing at it.

Encrypted backups are the exception, and they run on a longer clock than the live service. We keep hourly backups for around two days, daily backups for about a month, and one backup per month for twelve months — so a copy of an account deleted today can persist in an encrypted backup for up to twelve months, after which it ages out and is gone. We keep a year of monthly copies so that damage discovered late — a corruption or a mistake that went unnoticed for months — is still recoverable. Backups are encrypted before they leave the server and are only ever restored wholesale after a failure, never to retrieve one person's data.

MakerProof AI: we do not keep what you send it, except terms readings, which are kept with their licence and go when the licence or your account does. The record of each use is kept with your account. Anthropic's standard retention for what it receives is 30 days, subject to the exceptions in its terms.

Logs and statistics run to their own clock, because they are not tied to an account:

Server logs
Seven days, then deleted automatically.
Individual page records
Twelve months, then moved to encrypted archive storage and held for a further year so year-on-year comparisons are possible. They contain no name, no email address and no IP address.
Daily totals
Kept indefinitely. These are counts only — a date, a page, a country, a device or browser family and a number — with nothing that identifies anyone, which is why they can be kept without a deletion date.

Your rights

Depending on the circumstances and the law that applies to you, you may have the right to ask for a copy of your data, to have it corrected or deleted, to restrict or object to how it is used, to receive it in a portable form, and to complain to a regulator. Some of these depend on the lawful basis involved — for example, records we must keep for tax purposes cannot simply be deleted on request. Two are built in and need no request at all:

For anything else, email support@makerproof.app. We will respond within one month.

If you are not happy with how we have handled it, you can complain to the Information Commissioner’s Office, the UK data protection regulator — online at ico.org.uk/make-a-complaint or by phone on 0303 123 1113. You can complain to them without contacting us first, though we would rather have the chance to put it right.

Changes

If this notice changes in a way that affects you, we will email you before it takes effect rather than quietly updating the date at the top.