1. Controller
Daniel Haag, Theodorstraße 8, 12099 Berlin
Email: info.meshminds@gmail.com
2. Data we collect
Always (necessary for service): the URL or idea description you submit, the analysis result (score, verdict, market data), and a SHA-256-hashed version of your IP address used solely to enforce daily scan limits. Raw IP addresses are never stored.
If you sign up: email address, hashed password (managed by Supabase Auth), and your saved scans. Public/private toggle controls visibility of saved scans.
If you enter your email on the free-tips form: email address, marketing consent (yes/no), the URL/score/verdict you saw, and a timestamp.
With your consent (analytics, optional): a random session ID stored in your browser, anonymous behavioural events (page views, button clicks), approximate country/city derived from your IP via ipapi.co, browser user-agent and screen width.
3. Purpose and legal basis
Scan analysis & account: Art. 6 (1)(b) GDPR - performance of the contract / pre-contractual measures.
IP hashing for rate limiting and abuse prevention: Art. 6 (1)(f) GDPR - legitimate interest in protecting the service.
Marketing emails: Art. 6 (1)(a) GDPR - your consent (the checkbox at email entry).
Analytics & geo lookup: Art. 6 (1)(a) GDPR - your consent (cookie banner). You can withdraw at any time.
Payments: Art. 6 (1)(b) GDPR - Stripe processes payment data on a separate page; we never see your card details.
4. Service providers (processors / sub-processors)
Vercel Inc. (USA, EU–US Data Privacy Framework certified): hosting and serverless functions. Receives every request including your IP address (used only in real time for routing & abuse prevention; not retained by us in raw form).
Supabase Inc. (data hosted in EU - Frankfurt): authentication, scan storage, email leads, rate-limit logs.
Anthropic, PBC (USA, EU–US Data Privacy Framework certified): AI analysis of product data and idea descriptions via Claude. Inputs are not used for model training (per Anthropic's commercial terms).
Firecrawl (USA): scraping of the MakerWorld / Printables / Cults3D product page and Etsy / eBay / Amazon Handmade search results. We send only public URLs - no personal data.
Stripe Payments Europe Ltd. (Ireland): payment processing for Pro subscriptions. Card details are entered on Stripe's own page; we never receive them.
ipapi.co (USA): IP-based geo lookup for analytics. Only loaded after you accept analytics in the cookie banner.
Google LLC (USA, EU–US Data Privacy Framework certified): legacy email-leads sheet (in transition to Supabase) and the analytics endpoint that receives anonymous behavioural events when you accept the cookie banner.
5. Pro members - additional privacy guarantee
If you save a scan while you are a Pro subscriber, that scan is locked to private forever. It will never appear in the community feed, will not be used as training or calibration data, and the privacy lock is enforced server-side: even after a Pro subscription ends, those scans remain private and the public-toggle is disabled for them.
6. Retention
Saved scans: kept until you delete them or close your account. Email leads: until you object or unsubscribe. IP-hash rate-limit logs: 30 days. Analytics events: 12 months. Server access logs (Vercel): up to 30 days for security purposes.
7. Your rights (GDPR)
You have the right to: access (Art. 15), rectification (Art. 16), erasure (Art. 17), restriction of processing (Art. 18), objection (Art. 21), and withdrawal of consent (Art. 7 (3) GDPR). Contact us at: info.meshminds@gmail.com
8. Right to lodge a complaint
You have the right to lodge a complaint with the competent data protection supervisory authority: Berliner Beauftragte für Datenschutz und Informationsfreiheit, Friedrichstr. 219, 10969 Berlin.
8. Cookies and tracking
This website does not use cookies or tracking.