This policy covers MEPdetect: the website, the dashboard, the detection and training APIs, and anything you upload to them. It says what we collect, why, who else sees it, and what you can make us do about it. Where something is not yet true of our systems, it says that too.
MEPdetect is operated by [LEGAL ENTITY NAME], [BUSINESS ADDRESS]. For anything in this policy, including requests about your data, write to [PRIVACY EMAIL].
Your email address, and your name, company and phone number if you give them. If you sign in with a password we store a one-way hash of it, never the password itself. If you sign in with Google we store the Google account identifier and the email address Google confirms, and we never see your Google password.
Your drawing files, the images we render from them, and every output we produce: symbol counts, detection coordinates, annotated sheets, circuit netlists and traced overlays. These are stored on our servers under a job identifier so you can download the results.
For each job we record which endpoint was called, how many files it had, how many detections came back, how long it took, which model ran, and when. We use this to enforce plan limits, to bill correctly and to find faults.
Payments are processed by Stripe. Your card details go to Stripe directly and never reach our servers. We store the Stripe customer identifier, which plan you are on and the state of your subscription.
If you use a contact or support form we keep the message, the address you sent it from and our reply.
Our web servers keep standard access logs: IP address, timestamp, the page or endpoint requested, and the browser's user-agent string.
We process your account details, uploads and usage records because we cannot provide the service you asked for without them. We process billing data to perform the contract and to meet tax and accounting obligations. We use technical logs and bot protection on the legitimate interest of keeping the service up and unabused. Where we rely on consent — for example, optional marketing email — you can withdraw it at any time.
We do not sell your personal information, and we do not share it for cross-context behavioural advertising. We do not use your drawings to train models for other customers. The only third parties involved in running the service are:
We will also disclose data if the law requires it, and we will tell you when we are permitted to.
You keep every right you had in the files you upload and in the results we produce from them. We use them to run the job you asked for, to show you the results, and to investigate a fault if you report one. We do not use your drawings to train the shared detection models. If you train a custom model on your own drawings, that model is yours and is not made available to other customers.
Account records last as long as your account does. Usage and billing records are kept for as long as tax and accounting rules require.
Uploaded drawings and their results are currently kept until you ask us to delete them. There is no automatic expiry today. If that matters to you — and on live project drawings it usually should — email us and we will delete a job, or all of them, and confirm when it is done.
Wherever you are, you can ask us to show you the personal data we hold about you, correct it, delete it, or send you a copy in a portable format. Write to [PRIVACY EMAIL] and we will answer within 30 days.
If you are in California, the CCPA as amended by the CPRA gives you the rights to know, to delete, to correct, to opt out of sale or sharing, and not to be discriminated against for exercising them. We do not sell or share personal information as those terms are defined, so there is nothing to opt out of, but the other rights apply and the address above is how to use them.
If you are in the UK or the EU, you have the equivalent rights under the UK GDPR and the GDPR, including the right to object to processing and the right to complain to your supervisory authority.
Traffic between your browser and our servers is encrypted with TLS. Passwords are stored only as one-way hashes. Access to the production servers and the database is restricted to the people who operate the service. Each customer's jobs are separated by account, and downloads require your session.
We do not claim that stored files are encrypted at rest, because the current deployment does not do that. Enterprise customers who need drawings never to leave their own network can run MEPdetect on their own infrastructure.
No service is immune. If a breach affects your personal data we will tell you and the relevant regulator within the time limits the law sets.
Our servers are located in [HOSTING REGION]. Our processors, including Stripe and Google, may handle data in other countries under the safeguards their own terms provide.
MEPdetect is a tool for construction professionals. It is not intended for anyone under 18, and we do not knowingly collect their data.
If we change this policy we will update the date at the top, and for any change that materially affects your rights we will email account holders before it takes effect.
Privacy questions and data requests: [PRIVACY EMAIL]. Anything else: [email protected].