Your idea is product data—not ad inventory.
This notice explains what BuildMakr collects, why it is needed, and where the current product draws the line.
Effective July 20, 2026Information we handle
- Account data: name, email, password hash, session records, plan state, and workspace membership.
- Product data: the briefs, project models, screens, entities, roles, workflows, assets, and runtime records you choose to create.
- Operational data: build status, audit activity, storage metadata, subscription records, and service errors needed to run and secure the platform.
- Product-map preview: the server processes your answers to return the preview but does not store those answers unless you explicitly save the map.
- Saved product-map claim: choosing to save creates a private seven-day draft linked to an opaque browser cookie. The raw brief and context are removed from that claim record after the map becomes a project artifact.
Conversion measurement without reading the idea
After you allow optional analytics, the acquisition funnel records allowlisted events such as landing view, map submitted, signup completed, and project created. These events use a pseudonymous browser identifier, a server-created event ID, allowlisted campaign attribution, and coarse properties such as template type. They do not contain the brief, email, name, raw IP address, user agent, or full referrer. Rejecting optional analytics prevents the anonymous funnel cookie and client measurement events.
Public-site analytics
BuildMakr offers consent controls required before optional measurement begins. Google Analytics is not loaded and no request is made to Google until you allow analytics. If allowed, BuildMakr uses Google Analytics only on the public marketing and article pages listed in the sitemap. The tag is not rendered in login, registration, password or email-verification flows, the authenticated studio and account areas, APIs, or customer runtime and published-app surfaces. Before the analytics runtime starts, BuildMakr reduces the public browser address and the configured initial page-location field to the page path plus standard UTM campaign fields, removing fragments and other query parameters. Same-site public referrers receive the same filtering in the configured referrer field, while other referrers are reduced to their origin. UTM values are user-controlled campaign inputs and should not contain personal or confidential information.
Google Analytics may receive the public page path, allowlisted campaign fields, referring site, browser and device characteristics, interaction measurements enabled for the public data stream, approximate location derived from the network connection, and pseudonymous identifiers or cookies. This implementation disables Google signals and ad-personalization signals; it does not load Google Ads or DoubleClick tags. The operator should audit the Google Analytics Enhanced Measurement settings—including Site Search query parameters and browser-history pageviews—and disable measurements that are not needed for this bounded public-site use.
Why we use the information
We use it to authenticate BuildMakr staff/workspace members, create and operate workspaces, generate the requested project, enforce plan limits, process uploads, diagnose failures, prevent abuse, and understand whether the BuildMakr signup journey works. Mobile build data is sent externally only when the deployment operator has activated a provider and a user submits a job.
Cookies and retention
- Session and OAuth cookies support secure sign-in.
- The product-map claim cookie is HttpOnly, SameSite=Lax, and expires after seven days.
- Expired, non-materialized product-map drafts are removed during routine cleanup.
- You can discard a saved, non-materialized map from the product-map interface before that deadline.
- Pseudonymous funnel events are retained for up to 90 days.
- Google Analytics may use pseudonymous analytics cookies on public marketing pages only after consent; withdrawing consent disables later events and clears accessible BuildMakr-domain Google Analytics cookies.
- Allowlisted UTM attribution is retained for up to 90 days after analytics consent. Advertising click identifiers are stored only after separate advertising-attribution consent; no advertising pixel is currently active.
- Account and project data remains until deleted under the operator's retention process or as required for legal and security obligations.
Infrastructure and service providers
The deployment uses or may use Postgres, Redis, S3-compatible object storage, Stripe, Google OAuth, Google Analytics for the bounded public-site measurement described above, and a configured transactional-email provider. Expo Application Services receives build data only if the deployment operator completes provider activation and a job is accepted. A provider should receive only the data needed for the service you activate. Credentials and production providers must be configured by the deployment operator.
Your choices
You can preview without saving, copy or download the result, discard a saved draft in the product-map interface, sign in to an existing authorized account, reject optional measurement, or reopen Cookie settings in the site footer to change or withdraw consent. Public account enrollment is currently closed. You may request access, correction, export, or deletion from the organization operating this deployment. The operator remains responsible for publishing a privacy contact, configuring any consent controls required for its visitors, and adding jurisdiction-specific disclosures before commercial launch.