Privacy Policy
Last updated — July 2026
01What we collect
- Account data — name, email, password hash, plan and billing status.
- Project content — mix design inputs and chat messages, LCA form data, SPT/CPT field data, BOQ project settings, elements, rates, and the drawing files (PDF/PNG/JPEG) you upload for extraction.
- Usage data — feature usage counts (e.g. extraction sheets used), device/browser metadata, and server logs kept for security and debugging.
- Billing data — handled by Stripe. We never see or store full card numbers.
02How we use it
To operate the four studios, compute your results, generate reports and exports, enforce plan limits, provide support, secure the Service, and improve it. We do not sell personal data, and we do not use your project content to advertise to you.
03AI processing
When you use AI-drafting features, the relevant content is sent to Anthropic (our AI API provider) for processing: uploaded drawing sheets for BOQ extraction, drafting inputs, and study context for report narratives. API content is processed under Anthropic's commercial API terms, which do not permit training on customer content by default. Deterministic calculations never leave our infrastructure and are never performed by an AI model.
04Storage & retention
- Account and chat data are stored with Supabase; studio project data is stored in our PostgreSQL databases.
- Uploaded drawings and the sheet images rendered from them are retained while the associated BOQ project exists, so you can re-open the review screen. Deleting the project deletes them.
- Deleting your account deletes your content within 30 days, except minimal records we must keep for legal or accounting reasons.
- Processing occurs on infrastructure located in the EU and/or the United States.
06Your rights
You can access, export, correct, or delete your data — from account settings or by emailing support@miksir.app. Depending on your jurisdiction, you may also have rights to restrict processing or lodge a complaint with a supervisory authority.
07Security
All traffic is encrypted in transit (TLS). Passwords are hashed. Access to production data is restricted and logged. No system is perfectly secure — if we learn of a breach affecting your data we will notify you without undue delay.
08Changes
We will announce material changes to this policy by email or in-app before they take effect. Questions: support@miksir.app.