Privacy Policy

Last updated: [[ EFFECTIVE DATE β€” πŸ”‘ user to fill ]]
⚠️ Draft β€” pending legal reviewThis document is boilerplate and has not been reviewed by legal counsel. Items shown in red are placeholders that must be replaced with accurate company information before launch.
This Privacy Policy explains what personal data [[ LEGAL ENTITY NAME β€” πŸ”‘ user to fill ]] (operating the Craftwork Make service, the β€œService”, β€œwe”, β€œus”) collects, why we collect it, the legal basis for processing, how long we keep it, and the rights you have under the EU/UK General Data Protection Regulation (GDPR) and similar laws.

1. Data Controller

The data controller responsible for your personal data is:[[ DATA CONTROLLER β€” legal entity name, registered address β€” πŸ”‘ user to fill ]]For any privacy question or to exercise your rights, contact us at [[ PRIVACY CONTACT EMAIL β€” πŸ”‘ user to fill ]]. If we are required to appoint one, our Data Protection Officer can be reached at [[ DPO CONTACT β€” πŸ”‘ user to fill (or remove) ]].

2. Data We Collect

We process the following categories of data:
β€’Account & authentication data β€” your email address and the authentication session needed to sign you in (we use passwordless magic-link sign-in; we do not store a password).
β€’Design documents & assets β€” the design files, layers, images and other content you create, upload, or generate, plus file metadata (names, timestamps, thumbnails).
β€’AI prompts & usage β€” the text prompts and reference images you submit to AI features, the models invoked, token counts, and the resulting credit usage, so we can provide the feature, bill correctly, prevent abuse, and operate the Service.
β€’Billing data β€” subscription tier, credit balance, and payment-related identifiers. Card/payment details are handled by our payment processor (Polar); we do not store full payment-card numbers.
β€’Cookies & analytics β€” a same-origin session cookie required to keep you signed in, and (only with your consent) product-analytics events via Amplitude. See Section 7.
β€’Technical & anti-abuse data β€” limited request metadata such as IP address and approximate country, used to detect fraud/abuse and to secure the Service.

3. How We Use Your Data & Legal Basis

β€’To provide the Service (store your documents, run AI generations, sign you in) β€” legal basis: performance of a contract.
β€’To bill and meter usage (credits, subscriptions) β€” legal basis: performance of a contract / legal obligation.
β€’To secure the Service and prevent abuse (rate limits, fraud signals, content moderation) β€” legal basis: legitimate interests.
β€’To improve the product via analytics β€” legal basis: your consent (you may decline; see Section 7).
β€’To send service or, where you opt in, marketing emails β€” legal basis: legitimate interests / consent. You can opt out at any time from your account settings.

4. Third-Party Processors

We share data with the following sub-processors strictly to operate the Service. Each processes data on our behalf under its own terms; data may be transferred outside the EEA under appropriate safeguards (e.g. Standard Contractual Clauses) β€” confirm the safeguards in place before launch.
β€’Postgres β€” database, authentication and file/asset storage (your account, documents and assets).
β€’OpenAI, Recraft, OpenRouter, Google β€” AI providers that receive the prompts/images you submit to AI features in order to generate a result.
β€’Polar β€” billing, subscriptions and payments.
β€’Craftwork β€” design-asset library accessed through the Service.
β€’Amplitude β€” product analytics (only with consent).
β€’Telegram β€” internal operational alerts (does not receive end-user content; included for transparency).
A current, complete sub-processor list with locations and roles must be maintained here: [[ SUB-PROCESSOR LIST / LINK β€” πŸ”‘ user to fill ]].

5. Data Retention

We keep your account data and documents for as long as your account is active. When you delete content or your account, we delete the associated records and purge stored assets; cascading deletion removes related files, shares and assets. Some data may be retained longer where required for legal, accounting, or fraud-prevention purposes, or in encrypted backups for a limited period before they expire.Specific retention periods must be confirmed: [[ RETENTION PERIODS (account, backups, billing records) β€” πŸ”‘ user to fill ]].

6. Your Rights

Under the GDPR and similar laws you have the right to access, rectify, erase, restrict, and port your personal data, to object to certain processing, and to withdraw consent at any time.
β€’Access & portability (self-serve): you can download a machine-readable copy of your own data at any time from /api/user/export (also surfaced in your account settings).
β€’Erasure: request deletion of your account and data by contacting us at the address in Section 1.
β€’Complaints: you may lodge a complaint with your local supervisory authority ([[ SUPERVISORY AUTHORITY / LEAD DPA β€” πŸ”‘ user to fill ]]).

7. Cookies & Analytics

We use a strictly necessary, same-origin session cookie to keep you signed in β€” this cannot be disabled without breaking sign-in. We use Amplitude product analytics only after you give consent via the cookie banner; you can decline or change your choice at any time, in which case no analytics events are sent.

8. Children

The Service is not directed to children under [[ MINIMUM AGE β€” πŸ”‘ user to fill ]] and we do not knowingly collect their data.

9. Changes to This Policy

We may update this policy from time to time. Material changes will be communicated through the Service or by email, and the β€œlast updated” date above will change.