CTR K

Privacy Policy

Last updated: 21 July 2026

1. Introduction

MechanixCalc ("we", "us", "our") is the data controller for personal data processed through this Service. This policy explains what data we collect, how we use it, and your rights under the General Data Protection Regulation (GDPR), UK GDPR, and other applicable privacy laws.

2. Data We Collect

We collect the following categories of personal data:

  • Account data: Name, email address, and OAuth provider tokens provided when you create an account or sign in via a third-party provider (managed by Clerk).
  • Billing data: Subscription status and transaction IDs. We never see or store your card numbers — all payment data is held by Paddle, our Merchant of Record.
  • Calculation data: When you use the cloud-save feature, we store the inputs and results of your saved calculations in our database (Neon Postgres, hosted in EU — Frankfurt, Germany). If you organise saved calculations into projects, we also store the project names and groupings you create. If you call our REST API (directly or through a CAD add-in), the inputs you submit are processed the same way as in the web app — computed on our servers and stored only if you choose to save the result. The MechanixCalc Copilot CAD add-in sends your chat messages plus the numeric model parameters you select (geometry dimensions, mass properties, measured distances, load values) to our server; the server forwards the conversation content to Anthropic, our LLM provider, to generate the response. Your CAD file itself never leaves your machine, and the add-in stores the conversation locally on your machine.
  • Schematic data:Saved P&ID, fluid power, and electrical diagrams you create and store within the Service.
  • API key data: If you create a personal REST API key (Expert plan), we store a one-way SHA-256 hash of the key, a short non-secret prefix for display (e.g. mxc_live_ab12cd34), any name you give the key, and its creation and last-used timestamps. The full key is shown to you only once, at creation, and is never stored. Legal basis: Contract performance (Art. 6(1)(b)) — operating the API access you have subscribed to.
  • Session & security data: IP address, hashed user agent, and session ID — collected to detect and prevent concurrent session abuse and credential sharing. Raw user agent strings are never stored; only a one-way hash is retained. Legal basis: Legitimate Interest (Article 6(1)(f) GDPR). Retained for 90 days, then automatically deleted.
  • Trial usage data: To enforce the anonymous 30-minute free preview and prevent fraudulent abuse, we use two signals: a server-side cookie (httpOnly, first-party) that identifies your preview window to your own browser, and a SHA-256 hash of your IP address (bucketed to a /64 prefix for IPv6) so that a second browser on the same internet connection continues the window already open there instead of starting a new one. Neither the raw IP nor any raw identifier is stored: only the hashes, in Vercel KV (Redis), for up to 30 days (the connection hash: 24 hours), after which they are automatically deleted. No personal identity can be recovered from these hashes. We do not use browser fingerprinting. No browser or device characteristics are read to identify you, and no fingerprinting library ships with the application. Legal basis: Legitimate Interest (Art. 6(1)(f) GDPR) — preventing fraud and protecting the integrity of our subscription model. CCPA category: Internet / electronic network activity information, used for security purposes only (not sold or shared).
  • AI chat data: When you use the AI Engineering Assistant (available on Core plan and above), the text of your messages and a plain-text summary of your current calculation inputs and results are sent to Anthropic, Inc. for processing. We do not store your chat messages on our servers — they are transmitted to Anthropic, processed, and discarded. Anthropic may retain data in accordance with their own Privacy Policy. No personally identifiable information beyond what you explicitly type is included in the transmission. Legal basis: Contract performance (Art. 6(1)(b)) — delivery of the AI feature you have subscribed to.
  • Copilot & API usage data: When you use the REST API or the MechanixCalc Copilot CAD add-in, we record per-key usage counters — daily request and AI output-token totals — to administer our monthly fair-use allowance. If you explicitly trigger a capability-gap report from the Copilot, we store the feature-request text you submit until it has been reviewed. We do not store your Copilot chat messages on our servers — the add-in stores the conversation locally on your machine. Legal basis: Contract performance (Art. 6(1)(b)) and Legitimate Interest (Art. 6(1)(f)) — operating and protecting the API service.
  • Usage & analytics data: We use two kinds of analytics. Vercel Web Analytics and Speed Insights collect aggregated, cookieless page-view and performance metrics with no personally identifiable information attached. PostHog (product analytics) records page views and feature-usage events; for signed-in users these events are associated with your account via a pseudonymous Clerk user ID and your subscription tier only — not your email address or name — so we can understand how the product is used and improve it. Anonymous visitors are not identified.We do not record your screen. PostHog’s session-replay feature is disabled in the application, so no recording of your session, your inputs, your results or your browser console is captured.None of this runs unless you agree to it. We ask on your first visit; until you accept, all three systems stay off. You can withdraw at any time in Settings → Privacy → Analytics, and that single switch stops all three. We do not use analytics for advertising, and we never sell this data. Legal basis: Consent (Art. 6(1)(a) GDPR; ePrivacy Art. 5(3)) — withdrawable at any time, as easily as it was given, with no effect on the Service.
  • Error & performance monitoring data: To detect and fix crashes and errors, we use Sentry. When the application hits an error, a diagnostic event is sent to Sentry containing the error message and stack trace, the page or API route where it occurred, and basic technical context (browser type, operating system, and app release version). We run Sentry with personally-identifiable information disabled (sendDefaultPii: false — IP addresses are not attached) and with no session recording or replay. Sentry processes this data in the EU (Germany). Legal basis: Legitimate Interest (Art. 6(1)(f) GDPR) — diagnosing faults and keeping the Service reliable and secure.

3. How We Use Your Data

We use your data for the following purposes, each with its GDPR legal basis:

  • Provide the Service — deliver calculations, cloud save, schematics, and all product features. Legal basis: Contract performance (Art. 6(1)(b))
  • Manage subscriptions — handle billing, plan entitlements, and renewals via Paddle. Legal basis: Contract performance (Art. 6(1)(b))
  • Enforce session limits — detect and prevent concurrent logins / credential sharing that violate our Terms of Service. Legal basis: Legitimate Interest (Art. 6(1)(f)) — protecting the integrity of our subscription model
  • Enforce free trial limits — the anonymous 30-minute preview uses an httpOnly first-party cookie plus a hash of your IP address to prevent repeated abuse. No browser fingerprinting is used, and no personal identity is derivable from the hash. The hashes expire after 30 days (the connection hash: 24 hours). Legal basis: Legitimate Interest (Art. 6(1)(f)) — fraud prevention. We have conducted a balancing test and concluded our interest in protecting our commercial model does not override user privacy, given the limited personal data involved and the absence of profiling.
  • Transactional emails — account confirmation, billing receipts, and service notices. Legal basis: Contract performance (Art. 6(1)(b))
  • Power AI Assistant responses— transmit your chat messages and a plain-text context of your current calculation to Anthropic's API to generate an engineering response. No chat content is stored by us. Legal basis: Contract performance (Art. 6(1)(b))
  • Diagnose and fix errors — capture crash and error diagnostics via Sentry (no IP/PII, no session replay) so we can keep the Service reliable and secure. Legal basis: Legitimate Interest (Art. 6(1)(f))
  • Back up and protect data — maintain automated encrypted database backups for disaster recovery and business continuity. Legal basis: Legitimate Interest (Art. 6(1)(f))
  • Legal compliance — respond to lawful requests and retain records required by law. Legal basis: Legal obligation (Art. 6(1)(c))

We do not sell your personal data to third parties. We do not use your data for advertising purposes.

4. Data Retention

We retain data only as long as necessary for the stated purpose:

CategoryRetention
Account & calculation dataDuration of account + 30 days after deletion
Schematic dataDuration of account + 30 days after deletion
API key hash & metadataUntil you revoke the key or delete your account
AI chat messagesNot stored — session only (discarded on page close)
Copilot / API usage metering (daily request & token counts per API key)12 months, then deleted (billing & fair-use administration)
Copilot capability-gap log (feature-request text you explicitly trigger)Until reviewed, max 12 months
Session / access logs90 days (auto-deleted)
Anonymous-preview window (httpOnly cookie id hash)30 days (auto-deleted)
Anonymous-preview connection hash (hashed IP)24 hours (auto-deleted)
Encrypted database backups (full daily snapshot, disaster recovery)Rolling 30 days, then auto-deleted — this is why deleted data can persist up to 30 days
Error-monitoring events (Sentry — no IP/PII attached)90 days (Sentry standard retention), then auto-deleted
Payment records7 years (EU VAT law, held by Paddle)
Anonymised analyticsAggregated — no personal data retained

5. Third-Party Processors (Sub-processors)

We work with the following sub-processors, and put in place Data Processing Agreements (DPAs) with them as required by GDPR Art. 28. Where a processor is outside the EEA/UK, the transfer relies on Standard Contractual Clauses (see Section 9).

ProviderPurposeLocationPolicy
ClerkAuth & user managementUSA (SCCs)clerk.com/privacy
PaddlePayments, Merchant of RecordUK / USApaddle.com/privacy
VercelHosting & CDNUSA (SCCs)vercel.com/legal/privacy-policy
NeonDatabaseEU (Frankfurt)neon.tech/privacy
Vercel KVTrial session store & AI rate-limit counters (Redis)USA (SCCs)vercel.com/legal/privacy-policy
AnthropicAI Assistant & MechanixCalc Copilot (Claude API)USA (SCCs)anthropic.com/privacy
PostHogProduct analytics — page views and feature-usage events (identified for signed-in users; session replay disabled; runs only with your consent)USA (SCCs)posthog.com/privacy
Resend / BrevoTransactional email (account, billing & trial notices)USA / EUresend.com/privacy
SentryError monitoring & crash diagnostics (no session recording; IP/PII not attached)EU (Germany)sentry.io/privacy
GitHub (Microsoft)Source control, CI/CD & encrypted off-site database backups (30-day retention)USA (SCCs)github.com/privacy

6. Cookies

We set no advertising cookies and no third-party cross-site tracking cookies. What we do set falls into two groups: cookies that are strictly necessary for the Service to work, which are always active; and a single analytics identifier, which is set only if you agree when asked on your first visit.

  • Authentication cookies (set by Clerk) — keep you signed in. Required for login to function.
  • Trial cookie (mxc_trial) — an httpOnly, SameSite=Lax cookie that stores a base64-encoded record of your trial start and expiry times. This cookie is set only for anonymous (unauthenticated) visitors and is part of the trial-abuse prevention system described in Section 2. It expires after 30 days. Legal basis: Legitimate Interest (Art. 6(1)(f)).
  • Preview-window cookie (mxc_did) — an httpOnly, SameSite=Lax cookie holding a random opaque id (no personal data, not derived from your device or browser characteristics). It exists so that returning in the same browser gives you back your preview window rather than a new one. Set only for anonymous visitors. It expires after about 13 months. Legal basis: Legitimate Interest (Art. 6(1)(f)).
  • Product-analytics identifier (set by PostHog) — a first-party cookie / local-storage value that assigns your browser a random analytics ID so product-usage events can be grouped into a session. It is not used for advertising and is never shared for cross-site tracking. This is the only non-essential item we store, and it is set only after you accept. Legal basis: Consent (Art. 6(1)(a); ePrivacy Art. 5(3)).

Your choice, and how to change it. On your first visit we ask whether you agree to analytics. Until you accept, none of our three measurement systems runs: PostHog is opted out and no analytics identifier is stored, Vercel Web Analytics sends nothing, and Speed Insights is not loaded at all. Declining is one click, exactly like accepting, and nothing about the Service is withheld if you decline.

You can change your mind at any time in Settings → Privacy → Analytics — switching it off withdraws consent and stops all three systems immediately. Your choice is stored in your browser, so it is made once per browser you use.

You can disable cookies in your browser, but doing so will prevent login and trial functionality from working correctly.

7. Your Rights (GDPR / UK GDPR)

If you are in the European Economic Area or United Kingdom, you have the following rights:

  • Right of access (Art. 15) — request a copy of the personal data we hold about you. Contact us at the address below.
  • Right to rectification (Art. 16) — request correction of inaccurate or incomplete data.
  • Right to erasure / "right to be forgotten" (Art. 17) — request deletion of your data. Use Settings → Privacy → Delete Account, or email us at privacy@mechanixcalc.com.
  • Right to restriction of processing (Art. 18) — request that we limit how we use your data in certain circumstances.
  • Right to data portability (Art. 20) — download your saved data in a machine-readable format via Settings → Privacy → Export My Data, or email us and we will provide it.
  • Right to object (Art. 21) — object to processing based on legitimate interest, including session-security logging.
  • Right to lodge a complaint — you may complain to your national supervisory authority (e.g. ICO in the UK, your local DPA in the EU).

To exercise any of these rights, contact: privacy@mechanixcalc.com. We will respond within 30 days.

8. Data Security

We apply appropriate technical and organisational measures to protect your data, including:

  • Encryption of your data in transit and at rest
  • Per-user data isolation — every record (saved calculations, projects, schematics, API keys) is scoped to the authenticated account, and every request is authorised against the signed-in user before any data is returned
  • API keys are never stored in readable form — the plaintext key is shown once, at creation, and cannot be retrieved afterwards
  • Access to personal data restricted to authorised personnel
  • Encrypted off-site backups, retained for a limited period for disaster recovery
  • Authentication is provided by Clerk (SOC 2 Type II certified); payment data is handled entirely by Paddle (PCI-DSS) and never reaches our servers
  • Periodic security reviews of our application and third-party data flows

No method of transmission over the internet is 100% secure. We cannot guarantee absolute security but commit to prompt notification in the event of a breach affecting your personal data, as required by GDPR Art. 33–34. To report a security concern, contact security@mechanixcalc.com.

9. International Data Transfers

Clerk, Vercel and GitHub are headquartered in the United States. Where personal data is transferred outside the EEA or UK — including the daily encrypted database backups stored with GitHub — we rely on Standard Contractual Clauses (SCCs) approved under GDPR Art. 46(2)(c) to ensure an adequate level of protection. Neon (our primary database) stores data exclusively in the EU (Frankfurt), and Sentry (error monitoring) processes data in the EU (Germany), so no international transfer occurs for those services. Paddle is established in the UK and subject to UK GDPR.

10. Children

The Service is not directed to children under 16. We do not knowingly collect personal data from anyone under 16. If you believe a minor has provided us with data, please contact us at privacy@mechanixcalc.com and we will delete it promptly.

11. Changes to This Policy

We may update this Privacy Policy from time to time. We will notify you of material changes by email to the address associated with your account, or by a prominent notice within the Service, at least 14 days before the change takes effect. Continued use of the Service after the effective date constitutes acceptance of the updated policy.

12. Contact

Privacy enquiries and data subject requests: privacy@mechanixcalc.com

Data controller: Mechanixer Dooel Skopje (operating MechanixCalc), Skopje, North Macedonia