Privacy policy

Last updated: 13 August 2026. Applies to all use of QS Takeoff ("the Service") at qstakeoff.com.

Note. This policy aims to meet the common requirements of the UK GDPR / Data Protection Act 2018 and the EU GDPR. It is not legal advice, and it is on our list to be reviewed by a UK-qualified data protection professional.

1. Who we are

The data controller is [YOUR NAME OR COMPANY], of [YOUR ADDRESS], contactable at . We're the people who decide how and why your personal data is processed when you use QS Takeoff.

If we ever need to register with the UK Information Commissioner's Office (ICO), our registration number will be listed here. Sole-trader operators usually only need to register if they process personal data for purposes beyond core service delivery.

2. What data we collect

CategoryExamplesSource
Account data Email address, display name (optional), hashed password (Argon2id - we never see your password in clear) You, when you register
Project data The take-off content you save: calibration values, markup geometry, subjects, trade tags, custom column values, project names You, when you click "Save to cloud"
Authentication data Session identifier (random string), CSRF tokens, password reset tokens Generated by the Service when you log in or initiate a password reset
Technical data IP address, browser type and version, pages visited, time of visit (server access logs); in-app product events (e.g. "first export") tied to your account, used only to improve the service Automatically by our hosting provider / the app
Analytics data (optional) Pages visited, approximate location, device/browser details, collected by Google Analytics — only if you accept analytics cookies in the cookie banner Google Analytics, with your consent
Billing data (Pro) Your plan, credit balance and purchase history, plus Stripe customer and subscription identifiers. We never see or store card numbers - payment details go directly to Stripe. You / Stripe, when you buy a Pro plan or credit pack
AI detection images (Pro, opt-in) When - and only when - you explicitly run AI detection, a rendered image of that drawing page is sent to our AI provider for analysis. See section 3. You, per explicit confirmation

We do not collect:

  • Your PDF drawings — they're processed entirely in your browser and never leave your device, unless you use the optional AI detection (Pro), in which case only the image of the page you run detection on is sent, and only after you confirm (section 3).
  • Analytics data, unless you opt in — Google Analytics runs only after you accept analytics cookies, and you can reject or withdraw at any time (section 5).
  • Advertising or cross-site tracking identifiers.
  • Card numbers — payments are processed entirely by Stripe.

3. Optional AI detection (Pro)

Pro accounts can run AI auto-detection of rooms, doors and windows. This is the only feature that sends drawing content off your device, and it is strictly opt-in:

  • Nothing is sent until you click the detect button and confirm the per-session prompt.
  • What is sent: a rendered image of the single page (or the region you selected) you run detection on - not the PDF file, not other pages, not your account data.
  • The image is analysed by one of our AI providers: Anthropic PBC (USA, commercial API - inputs and outputs are not used to train their models), or - while the feature is marked experimental - OpenRouter, Inc. (USA), which routes the image to third-party model hosts such as Google or NVIDIA. Free/experimental models may use submitted images to improve their models; the confirmation dialog tells you which kind of model you are using before anything is sent, so don't submit confidential drawings to a free model.
  • We record token counts, timings and model choice for each run (for metering and cost reconciliation) - not the image itself.
  • If you never use AI detection, nothing is ever sent.

4. Why we use your data and on what legal basis

PurposeLegal basis (UK/EU GDPR Article 6)
Creating and maintaining your accountContract (Art. 6(1)(b)) — necessary to provide the service you've signed up to
Storing your saved projects against your accountContract (Art. 6(1)(b))
Sending password-reset emailsContract (Art. 6(1)(b))
Keeping the service secure (rate limits, CSRF, logging suspicious activity)Legitimate interests (Art. 6(1)(f)) — our interest in operating a secure service
Server access logs for diagnosticsLegitimate interests (Art. 6(1)(f))
Improving the service based on feedback and product eventsLegitimate interests (Art. 6(1)(f)) — only with data you voluntarily share with us or generate using the app
Running AI detection you request (Pro)Contract (Art. 6(1)(b)) — performed only when you explicitly trigger it
Processing payments and managing subscriptions (Pro)Contract (Art. 6(1)(b))
Understanding site usage via Google AnalyticsConsent (Art. 6(1)(a)) — only if you accept analytics cookies; withdrawable at any time

5. Cookies and similar technologies

QS Takeoff sets two kinds of cookies: strictly necessary cookies (no consent needed) and optional analytics cookies, which are set only if you accept them in the cookie banner. We do not use advertising or third-party social media cookies.

NameTypePurposeLifetime
takeoff_sid Strictly necessary Maintains your logged-in session and protects login/registration forms against CSRF attacks. Set only on authentication pages and logged-in pages. Up to 30 days, or until you log out (whichever is sooner)
takeoff_consent Strictly necessary Remembers your cookie-banner choice (accept or reject) so we don't keep asking. 6 months
_ga, _ga_* Analytics (consent only) Google Analytics — helps us understand which pages are used and how visitors find the site. Never set unless you click Accept. Up to 2 years

The strictly necessary cookies are exempt from consent under regulation 6(4)(b) of the UK Privacy and Electronic Communications Regulations (PECR) and the equivalent provision of the EU ePrivacy Directive. Analytics cookies require consent, which the banner collects; rejecting them does not change anything about how the tool works. You can change your choice at any time via the Cookie settings link in the footer — withdrawing consent stops Google Analytics and removes its cookies from your browser.

6. Who we share your data with

We share data only with the sub-processors required to run the service:

Sub-processorWhat forWhere
Our hosting provider Stores the application files and the database (account + project data), processes server logs, relays outbound email for password resets UK / EU data centres
Anthropic PBC (AI provider) Opt-in only: analyses the rendered page image when you run an AI detection. API inputs/outputs are not used for model training under their commercial terms. USA
OpenRouter, Inc. (AI routing) and its model hosts (e.g. Google, NVIDIA) Opt-in only, experimental AI: routes the rendered page image to the AI model you select. Free/experimental models may retain and train on submitted images - disclosed in the confirmation dialog before anything is sent. USA
Stripe (payments) Pro only: processes card payments and subscriptions. Stripe receives your email and payment details directly; we store only customer/subscription identifiers and purchase history. Stripe Payments Europe (IE) / Stripe Inc (USA)
Google LLC (analytics) Consent only: Google Analytics processes usage data (pages visited, device details, approximate location) if you accept analytics cookies. IP anonymisation applies under GA4. USA

We do not sell or rent your data. We will only disclose it to third parties if required by law (e.g. a valid court order or regulator request).

7. International transfers

Account and project data is stored in our hosting provider's UK or EU data centres. Three features involve transfers to the USA, in each case under the UK Extension to the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable: AI detection (Pro, opt-in - page images analysed by Anthropic PBC), payments (Stripe), and analytics (Google, consent only). No other personal data is transferred to jurisdictions without an adequate level of data protection.

8. How long we keep your data

DataRetention
Account dataFor the life of your account. Deleted when you close your account or after 24 months of inactivity (we'll email you first).
Saved projectsUntil you delete them, or when your account is closed.
Billing records (purchases, credit ledger)6 years, as required for UK tax and accounting purposes.
AI usage records (token counts, model, timing)Up to 24 months, for metering and cost reconciliation.
Analytics data (Google Analytics, consent only)14 months, per our Google Analytics retention setting.
Password reset tokens1 hour after issue, or immediately on use.
Rate-limit records (IP + action)24 hours.
Server access logsHeld by our hosting provider per their retention policy (typically 30 days).

9. Your rights

Under the UK GDPR and EU GDPR you have the right to:

  • Access a copy of the personal data we hold about you (Art. 15)
  • Rectification — correct inaccurate data (Art. 16)
  • Erasure — ask us to delete your account and associated data (Art. 17)
  • Restriction of processing in certain circumstances (Art. 18)
  • Data portability — receive your project data in a structured, machine-readable format (CSV/JSON export inside the app already provides this) (Art. 20)
  • Object to processing based on legitimate interests (Art. 21)
  • Withdraw consent at any time, where we rely on consent — for analytics cookies, use the Cookie settings link in the footer

To exercise any of these rights, email . We aim to respond within 30 days.

You also have the right to complain to a supervisory authority. In the UK that's the Information Commissioner's Office (ICO). In the EU, your national data protection authority.

10. Security

Passwords are stored using Argon2id hashing — we cannot read them, even if we wanted to. Sessions use HttpOnly, SameSite=Lax cookies over HTTPS. State-changing requests are protected by CSRF tokens. Account-creation, login and password-reset endpoints are rate-limited per IP. That said, no service is 100% secure; if you suspect a breach of your account, contact us immediately at .

11. Children

QS Takeoff is a professional tool for quantity surveyors and is not directed at children under 16. We do not knowingly collect data from anyone under that age. If you believe a child has signed up, please contact us so we can remove their account.

12. Changes to this policy

We may update this policy as the service evolves. Material changes will be communicated by email to registered users at least 14 days before they take effect. The "last updated" date at the top of this page shows the version you're reading.

13. Contact

Questions about this policy or about your data: .