Privacy policy
Last updated: 13 August 2026. Applies to all use of
QS Takeoff ("the Service") at
qstakeoff.com.
1. Who we are
The data controller is [YOUR NAME OR COMPANY], of [YOUR ADDRESS], contactable at . We're the people who decide how and why your personal data is processed when you use QS Takeoff.
If we ever need to register with the UK Information Commissioner's Office (ICO), our registration number will be listed here. Sole-trader operators usually only need to register if they process personal data for purposes beyond core service delivery.
2. What data we collect
| Category | Examples | Source |
|---|---|---|
| Account data | Email address, display name (optional), hashed password (Argon2id - we never see your password in clear) | You, when you register |
| Project data | The take-off content you save: calibration values, markup geometry, subjects, trade tags, custom column values, project names | You, when you click "Save to cloud" |
| Authentication data | Session identifier (random string), CSRF tokens, password reset tokens | Generated by the Service when you log in or initiate a password reset |
| Technical data | IP address, browser type and version, pages visited, time of visit (server access logs); in-app product events (e.g. "first export") tied to your account, used only to improve the service | Automatically by our hosting provider / the app |
| Analytics data (optional) | Pages visited, approximate location, device/browser details, collected by Google Analytics — only if you accept analytics cookies in the cookie banner | Google Analytics, with your consent |
| Billing data (Pro) | Your plan, credit balance and purchase history, plus Stripe customer and subscription identifiers. We never see or store card numbers - payment details go directly to Stripe. | You / Stripe, when you buy a Pro plan or credit pack |
| AI detection images (Pro, opt-in) | When - and only when - you explicitly run AI detection, a rendered image of that drawing page is sent to our AI provider for analysis. See section 3. | You, per explicit confirmation |
We do not collect:
- Your PDF drawings — they're processed entirely in your browser and never leave your device, unless you use the optional AI detection (Pro), in which case only the image of the page you run detection on is sent, and only after you confirm (section 3).
- Analytics data, unless you opt in — Google Analytics runs only after you accept analytics cookies, and you can reject or withdraw at any time (section 5).
- Advertising or cross-site tracking identifiers.
- Card numbers — payments are processed entirely by Stripe.
3. Optional AI detection (Pro)
Pro accounts can run AI auto-detection of rooms, doors and windows. This is the only feature that sends drawing content off your device, and it is strictly opt-in:
- Nothing is sent until you click the detect button and confirm the per-session prompt.
- What is sent: a rendered image of the single page (or the region you selected) you run detection on - not the PDF file, not other pages, not your account data.
- The image is analysed by one of our AI providers: Anthropic PBC (USA, commercial API - inputs and outputs are not used to train their models), or - while the feature is marked experimental - OpenRouter, Inc. (USA), which routes the image to third-party model hosts such as Google or NVIDIA. Free/experimental models may use submitted images to improve their models; the confirmation dialog tells you which kind of model you are using before anything is sent, so don't submit confidential drawings to a free model.
- We record token counts, timings and model choice for each run (for metering and cost reconciliation) - not the image itself.
- If you never use AI detection, nothing is ever sent.
4. Why we use your data and on what legal basis
| Purpose | Legal basis (UK/EU GDPR Article 6) |
|---|---|
| Creating and maintaining your account | Contract (Art. 6(1)(b)) — necessary to provide the service you've signed up to |
| Storing your saved projects against your account | Contract (Art. 6(1)(b)) |
| Sending password-reset emails | Contract (Art. 6(1)(b)) |
| Keeping the service secure (rate limits, CSRF, logging suspicious activity) | Legitimate interests (Art. 6(1)(f)) — our interest in operating a secure service |
| Server access logs for diagnostics | Legitimate interests (Art. 6(1)(f)) |
| Improving the service based on feedback and product events | Legitimate interests (Art. 6(1)(f)) — only with data you voluntarily share with us or generate using the app |
| Running AI detection you request (Pro) | Contract (Art. 6(1)(b)) — performed only when you explicitly trigger it |
| Processing payments and managing subscriptions (Pro) | Contract (Art. 6(1)(b)) |
| Understanding site usage via Google Analytics | Consent (Art. 6(1)(a)) — only if you accept analytics cookies; withdrawable at any time |
5. Cookies and similar technologies
QS Takeoff sets two kinds of cookies: strictly necessary cookies (no consent needed) and optional analytics cookies, which are set only if you accept them in the cookie banner. We do not use advertising or third-party social media cookies.
| Name | Type | Purpose | Lifetime |
|---|---|---|---|
takeoff_sid |
Strictly necessary | Maintains your logged-in session and protects login/registration forms against CSRF attacks. Set only on authentication pages and logged-in pages. | Up to 30 days, or until you log out (whichever is sooner) |
takeoff_consent |
Strictly necessary | Remembers your cookie-banner choice (accept or reject) so we don't keep asking. | 6 months |
_ga, _ga_* |
Analytics (consent only) | Google Analytics — helps us understand which pages are used and how visitors find the site. Never set unless you click Accept. | Up to 2 years |
The strictly necessary cookies are exempt from consent under regulation 6(4)(b) of the UK Privacy and Electronic Communications Regulations (PECR) and the equivalent provision of the EU ePrivacy Directive. Analytics cookies require consent, which the banner collects; rejecting them does not change anything about how the tool works. You can change your choice at any time via the Cookie settings link in the footer — withdrawing consent stops Google Analytics and removes its cookies from your browser.
6. Who we share your data with
We share data only with the sub-processors required to run the service:
| Sub-processor | What for | Where |
|---|---|---|
| Our hosting provider | Stores the application files and the database (account + project data), processes server logs, relays outbound email for password resets | UK / EU data centres |
| Anthropic PBC (AI provider) | Opt-in only: analyses the rendered page image when you run an AI detection. API inputs/outputs are not used for model training under their commercial terms. | USA |
| OpenRouter, Inc. (AI routing) and its model hosts (e.g. Google, NVIDIA) | Opt-in only, experimental AI: routes the rendered page image to the AI model you select. Free/experimental models may retain and train on submitted images - disclosed in the confirmation dialog before anything is sent. | USA |
| Stripe (payments) | Pro only: processes card payments and subscriptions. Stripe receives your email and payment details directly; we store only customer/subscription identifiers and purchase history. | Stripe Payments Europe (IE) / Stripe Inc (USA) |
| Google LLC (analytics) | Consent only: Google Analytics processes usage data (pages visited, device details, approximate location) if you accept analytics cookies. IP anonymisation applies under GA4. | USA |
We do not sell or rent your data. We will only disclose it to third parties if required by law (e.g. a valid court order or regulator request).
7. International transfers
Account and project data is stored in our hosting provider's UK or EU data centres. Three features involve transfers to the USA, in each case under the UK Extension to the EU–US Data Privacy Framework and/or Standard Contractual Clauses as applicable: AI detection (Pro, opt-in - page images analysed by Anthropic PBC), payments (Stripe), and analytics (Google, consent only). No other personal data is transferred to jurisdictions without an adequate level of data protection.
8. How long we keep your data
| Data | Retention |
|---|---|
| Account data | For the life of your account. Deleted when you close your account or after 24 months of inactivity (we'll email you first). |
| Saved projects | Until you delete them, or when your account is closed. |
| Billing records (purchases, credit ledger) | 6 years, as required for UK tax and accounting purposes. |
| AI usage records (token counts, model, timing) | Up to 24 months, for metering and cost reconciliation. |
| Analytics data (Google Analytics, consent only) | 14 months, per our Google Analytics retention setting. |
| Password reset tokens | 1 hour after issue, or immediately on use. |
| Rate-limit records (IP + action) | 24 hours. |
| Server access logs | Held by our hosting provider per their retention policy (typically 30 days). |
9. Your rights
Under the UK GDPR and EU GDPR you have the right to:
- Access a copy of the personal data we hold about you (Art. 15)
- Rectification — correct inaccurate data (Art. 16)
- Erasure — ask us to delete your account and associated data (Art. 17)
- Restriction of processing in certain circumstances (Art. 18)
- Data portability — receive your project data in a structured, machine-readable format (CSV/JSON export inside the app already provides this) (Art. 20)
- Object to processing based on legitimate interests (Art. 21)
- Withdraw consent at any time, where we rely on consent — for analytics cookies, use the Cookie settings link in the footer
To exercise any of these rights, email . We aim to respond within 30 days.
You also have the right to complain to a supervisory authority. In the UK that's the Information Commissioner's Office (ICO). In the EU, your national data protection authority.
10. Security
Passwords are stored using Argon2id hashing — we cannot read them, even if we wanted to. Sessions use HttpOnly, SameSite=Lax cookies over HTTPS. State-changing requests are protected by CSRF tokens. Account-creation, login and password-reset endpoints are rate-limited per IP. That said, no service is 100% secure; if you suspect a breach of your account, contact us immediately at .
11. Children
QS Takeoff is a professional tool for quantity surveyors and is not directed at children under 16. We do not knowingly collect data from anyone under that age. If you believe a child has signed up, please contact us so we can remove their account.
12. Changes to this policy
We may update this policy as the service evolves. Material changes will be communicated by email to registered users at least 14 days before they take effect. The "last updated" date at the top of this page shows the version you're reading.