Skip to content

Privacy policy

Last updated 2026-09-09Version v1.1Applies to Alluvaris · MaatCraft

MaatCraft is made by Alluvaris. This policy says what we collect when you use the MaatCraft app on Android, iOS, Windows and macOS, and in a browser where we offer it, why we collect it, who can see it, and how to have it removed. It is written to be read, not skimmed.

Two things up front. We do not use analytics or advertising kits, and we do not sell, rent or trade personal data. Your designs are yours; we store them so your workshop can open them, and for no other reason.

1. Who we are

Alluvaris ("we", "us") makes MaatCraft and is the controller of the personal data described here. Our full name and address are: Alluvaris [CONFIRM: legal form and commercial register number], [CONFIRM: street and district], Cairo, Egypt. That is our registered address, and it is also the postal address for anything you send us on paper. You can reach us at [email protected].

2. What we collect

Your account

  • Your email address or phone number, and a password. We store the password only as a salted hash (argon2). We cannot read it.
  • If you sign in with Google or Apple: the identifier and email address the provider gives us, and, for Apple, the name you chose to share. We never receive your Google or Apple password.
  • Your name, your preferred language, a location you type in (free text, printed on your cut lists and exports), and an optional web address for an avatar image. You edit all four in Settings › General.
  • Verification codes we send by email or by SMS. We keep a hash of the code, not the code, and it expires.
  • A record that you accepted our Terms of Service: which version, when, the language you read it in, and the IP address and the browser or device user-agent it was accepted from. It is the evidence of the agreement, so we keep it for as long as the account exists (see section 6).

Your devices and sessions

  • A random device identifier the app creates the first time it runs, plus your platform, app version, build number and release channel. These travel with every request so the server can tell you when an update is required.
  • For each signed-in session: the IP address, a country derived from it, the browser or device user-agent string, a device name, and when the session was last seen. We use these to show you your signed-in devices, to enforce the limit on how many devices can be signed in at once, and to notice a sign-in that looks wrong, such as a new device or an unusual location, and ask for a code before letting it in.
  • An audit log of security-relevant requests: which endpoint, when, from which device and IP address, and which project it touched. Kept for 90 days.

Your work

  • Projects and everything in them: furniture items, boards, rooms, project settings, orders and cut-list submissions, and your workshop's materials catalogue with its sheets, edging, hardware and prices. Everything is saved on your device first and then synced to our servers so the members of your workshop can see it and so you can open it on another device.
  • Pictures. When you publish a 3D capture to the gallery, the image is uploaded and stored with the project. When you request a render, the scene is uploaded, rendered on our servers, and the result is stored with the project.
  • Not uploaded: PDF cut lists, CNC files and Blender scene exports. Those are written where you choose or handed to your device's share sheet. The server records that an export was authorised (its type and time, for quota) but never the file.

Your workshop

  • Which workshops you belong to, your role in each, and whether you hold a seat. An invitation carries the email address you invite.

Billing

  • Your workshop's plan, its subscription state, its seats and its usage counters. Payment, when a billing provider is in place, happens on the provider's own pages. Card numbers never reach us. We may hold the card brand, its last four digits and its expiry so we can show you what is on file.

Diagnostics

  • The activity log on your device. It is a rotating set of four files of 4 MB each, and it stays on the device until you choose to share it from Settings › Logging. It records what the app did, such as sign-ins, saves, syncs and renders, using identifiers rather than names, and never a password, a token or an email address.
  • Crash reports, but only if you turn them on. The switch is in Settings › Legal and it starts off. While it is off we do not start the error-tracking software at all: nothing on your device is watching for a crash, nothing is being kept in memory in case one happens, and nothing is sent.
  • When crash reports are on, a report carries the log line that failed and its structured fields, the activity-log entries that came just before it — up to a hundred of them, so the report shows what led up to the fault — your user id and workshop id, the app version and build number, the platform, and the device and operating-system details the error-tracking software gathers, such as the model and the system version. Before it leaves the device it is scrubbed of email addresses, phone numbers, tokens and file paths, and a report that cannot be scrubbed is dropped. Our error-tracking provider also sees the IP address the report was sent from, as the receiving end of any connection does; the app does not put it in the report. A crash report never contains your designs. Switching the toggle off stops reporting at once.
  • Sync counters, such as queue depth, bytes sent and failures. These are written to the local activity log only.

3. Why we use it

  • To run the service: your account, syncing, sharing within a workshop, renders and exports. This is necessary to provide what you signed up for.
  • To keep your account safe: sessions, sign-in challenges, the audit log. This is in our legitimate interest and yours, and in places a legal duty.
  • To bill your workshop, when it is on a paid plan.
  • To fix the app: crash reports, if you have turned them on, and any diagnostics you choose to send us. Crash reporting rests on your consent alone — that is why it is off until you switch it on, why switching it off withdraws it, and why nothing about it is collected in the meantime. Working on what you have sent us, so the app keeps running, is our legitimate interest.
  • To show what was agreed: the record of your acceptance of our Terms. Holding the agreement we are both performing, and being able to say which version was accepted and when, is necessary for the contract between us.
  • To tell you what you need to know: verification codes, invitations, and reminders about a renewal. We do not send marketing email.

We do not profile you and we do not make automated decisions about you with legal or similar effects. The sign-in challenge is a security check on a request, not a decision about you.

4. Who can see it

  • Members of your workshop see your name, your email address and your role. A project belongs to the workshop, so its members can open it.
  • Providers who process data on our instructions: hosting and databases (Railway, running PostgreSQL and Redis), object storage for images (an S3-compatible store), email delivery (Resend, or an SMTP provider), error tracking (Sentry, and only when you have turned crash reports on), sign-in (Google and Apple, when you use them), and a billing provider when your workshop subscribes. Each is bound by a contract and acts only on our instructions.
  • Authorities, when the law requires it and only to the extent it requires.
  • Nobody else. We do not share personal data with advertisers or data brokers.

5. Where it is stored

  • On your device: your projects, designer snapshots, the gallery cache and your app settings. Your sign-in tokens, device id and user id are kept in the platform's secure storage (Keychain on Apple devices, Keystore-backed storage on Android, the credential store on Windows) and are excluded from device backups.
  • On our servers, hosted by Railway in its us-west1 region, in Oregon in the United States. We are an Egyptian company and our servers are American, so your personal data is transferred out of the country you live in and processed in the United States — that is true of everyone who uses MaatCraft, not only of people outside Egypt. It is the only transfer of that kind we make. Where the law requires a safeguard for it, as the GDPR and the UK GDPR do, we rely on the European Commission's standard contractual clauses, with the United Kingdom's addendum where that applies, agreed with each provider that holds data for us.
  • If you use MaatCraft in a browser, the same data is kept in that browser's storage. On every platform, we set no tracking cookies and run no analytics.

6. How long we keep it

  • Your account and your work: for as long as the account exists.
  • After you ask to delete your account: 30 days in which you can change your mind, then the account and its data are purged (see section 7).
  • Projects you delete: kept for 30 days so they can be recovered, then gone.
  • The security audit log: 90 days.
  • Your acceptance of our Terms, with the IP address and the user-agent it was accepted from: for as long as the account exists, and deleted with the account. This is the one record here that keeps an IP address for longer than the 90 days above; we keep it because it is what shows which version of the agreement was accepted, and from where.
  • A copy of your data that you asked for (see section 7): 7 days from the moment the archive is ready, then it is deleted and the download stops working.
  • Sessions: until you sign out, revoke the device, or the session expires.
  • Usage counters and billing events: about 13 months, for invoices and disputes.
  • Crash reports, if you turned them on: 90 days in Sentry, then they are deleted.
  • The activity log on your device: a rolling 16 MB, oldest dropped first. It never leaves the device unless you send it.

7. Your choices and rights

  • See and change your details. Name, language, location and avatar are in Settings › General. Email, phone, password and signed-in devices are in Settings › Account.
  • Take your work with you. Export PDF cut lists and CNC files from the app at any time. For a copy of the data we hold about your account, go to Settings › Legal and ask for an export: we build a downloadable archive of your account and sessions, your workshops and projects, your submissions and renders as records, your billing, the versions you accepted, and your own 90-day audit log. It is usually ready within a few minutes. You can ask for a new one once a day, and each archive stays available for 7 days. Some things are left out on purpose: secrets such as your password and your sign-in tokens, other people's details (a colleague appears as a name and a role, because their email address is their data and not yours), and the picture files themselves, which are listed with their size and date instead. Because a project belongs to the workshop rather than to one person, a workshop you share travels with all of its projects and the cut lists submitted from them, including work a colleague authored — the same work you can already open in the app. If you need something the archive does not carry, write to us.
  • Delete your account. Go to Settings › Account › Delete account. You confirm with your password or a code. For 30 days you can sign back in, and your account and your own workshop come back exactly as they were; your membership of other people's workshops ends as soon as you ask, so rejoining one is a fresh invitation rather than an undo. After that, your account, your personal workshop, and the projects and images in it are deleted. Before deleting, you must hand ownership of any workshop that has other members to someone else, and cancel any paid subscription. Work you contributed to other people's workshops stays with those workshops, attributed to "Deleted user".
  • Leave a workshop. Settings › Workshop › General.
  • Turn crash reports on or off. They are off unless you turn them on, and the switch is in Settings › Legal. Turned on in the middle of a session it covers crashes from that moment; anything that fails while the app is starting is covered from the next launch. Turning it off stops reporting at once.
  • Where data-protection law gives you rights, such as under the GDPR or the UK GDPR, you can ask us for access to your data, to correct it, to erase it, to restrict or object to how we use it, and to receive it in a portable form. You can also complain to your data-protection authority. Write to [email protected]. We answer within 30 days and may ask you to confirm your identity first.

8. Security

  • Every connection uses HTTPS. Release builds refuse to talk to an address that is not secure.
  • Passwords and verification codes are stored only as hashes. Sign-in tokens live in the platform's secure storage. The number of signed-in devices is limited, and an unusual sign-in is challenged.
  • Diagnostics are scrubbed of personal data before they leave the device.
  • No system is perfectly secure. If a breach affects you, we will tell you, and any authority the law requires, without undue delay.

9. Children

MaatCraft is a tool for workshops. It is not directed at children, and we do not knowingly collect data from anyone under 16. If you believe a child has created an account, write to us and we will delete it.

10. Changes to this policy

When this policy changes, the new version appears here with a new effective date. If the change is material, we tell you inside the app before it takes effect. Earlier versions are available on request.

11. Contact

Email [email protected]. Post: our registered address, which is in section 1.